The Data Protection Act 2017 vs GDPR: What Is Different in Mauritius

04 August 2026 · Jenny Legal AI

Mauritius tracks the GDPR closely, but three differences catch businesses out: mandatory registration with the Commissioner, criminal penalties including imprisonment, and a distinct regime for transfers outside Mauritius.

The Data Protection Act 2017 was drafted to align Mauritius with the GDPR, and much of it will look familiar to anyone who has done GDPR work. The processing principles, the 72-hour breach notification and the data subject rights all map closely.

But three differences matter commercially, and the first one is a compliance obligation that has no GDPR equivalent at all.

1. You must register with the Commissioner before processing

This is the difference that catches businesses out. Section 14 is short and absolute:

Subject to section 44, no person shall act as controller or processor unless he or it is registered with the Commissioner.

Under the GDPR, the old notification-and-registration regimes were deliberately abolished. Mauritius kept one. Acting as a controller or processor without registration is not a documentation gap — it is a breach of section 14.

Section 15 sets out the application. It requires, among other particulars:

Registration is not permanent. Section 17 requires notification of a change in particulars, section 18 governs renewal of the registration certificate, and section 19 allows cancellation or variation of the terms and conditions of registration. Section 20 provides for a public register of controllers and processors.

Practical consequence: a Mauritian business that has built its compliance programme from GDPR templates will very likely have no registration, because there is nothing to copy across. Exceptions and restrictions are in section 44, which section 14 is expressly subject to — read it before concluding you are outside the requirement.

2. The penalties are criminal, and include imprisonment

The GDPR's headline sanction is administrative: up to 4 per cent of global annual turnover. Mauritius takes a different route.

Section 43 provides the general penalty where no specific penalty is set:

Any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding 200,000 rupees and to imprisonment for a term not exceeding 5 years.

Two points are worth drawing out.

The monetary maximum is low; the custodial exposure is not. Rs 200,000 is modest against GDPR fines. A term of up to five years' imprisonment is not, and it attaches to individuals.

The Court has additional powers. Section 43(2) permits the Court, in addition to any penalty, to order forfeiture of equipment or any article used or connected with the commission of the offence, and to order or prohibit the doing of an act to stop a continuing contravention.

So the risk profile inverts relative to the GDPR: less balance-sheet exposure, more personal exposure. That changes who in an organisation needs to care.

Separately, section 42 creates an offence of unlawful disclosure of personal data.

3. Transfers outside Mauritius follow their own regime

The GDPR routes international transfers through adequacy decisions, standard contractual clauses and binding corporate rules. Section 36 of the Mauritian Act does not use those instruments. It sets out its own gateways, and the default one is regulator-facing.

A controller or processor may transfer personal data to another country where:

The legitimate-interests gateway is narrow. It applies only where the transfer is not repetitive and concerns a limited number of data subjects, and where the controller or processor has assessed all the circumstances surrounding the transfer and acted on that assessment.

The practical difference from GDPR: limb (a) contemplates proof going to the Commissioner, rather than a self-assessed transfer mechanism documented internally. A routine, high-volume export cannot rest on limb (c)(vi).

Where the two regimes agree

Much does carry across, and GDPR work is not wasted.

The processing principles. Section 21 requires personal data to be:

That is materially GDPR Article 5, with the accountability principle expressed through other provisions rather than listed here.

Breach notification: 72 hours. Section 25(1)(a) requires the controller to notify the Commissioner of a personal data breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it." Where the controller misses that window, section 25(1)(b) requires it to give the Commissioner the reasons for the delay — the deadline is not simply waived.

Section 25(2) requires a processor who becomes aware of a breach to notify the controller without undue delay. Section 25(3) prescribes the content of the notification: the nature of the breach including categories and approximate numbers of data subjects and records; the contact point for further information; and recommended measures to address the breach and mitigate adverse effects. Section 25(4) requires the controller to specify the facts, effects and remedial action so the Commissioner can verify compliance.

Section 26 covers communication of a breach to the data subject.

Data subject rights. Section 37 gives a right of access, section 38 addresses automated individual decision-making, section 39 covers rectification, erasure and restriction of processing, and section 40 the right to object. Section 41 governs how rights are exercised.

Accountability machinery. Section 31 requires security of processing, section 33 a record of processing operations, and section 34 a data protection impact assessment. Section 32 adds a prior security check and section 35 prior authorisation and consultation — the latter having a narrower GDPR analogue.

Other provisions worth noting: section 24 on conditions for consent, section 27 on the duty to destroy personal data, section 28 on lawful processing, section 29 on special categories of personal data, and section 30 on the personal data of a child.

A short compliance checklist for Mauritius

If you have a GDPR programme and are extending it to Mauritius, the gaps are usually these:

  1. Register as controller or processor under sections 14 and 15 — check section 44 first for exceptions. Diarise renewal under section 18 and changes under section 17.
  2. Re-paper international transfers against section 36. Identify which limb each transfer relies on, and whether limb (a) requires you to put proof of safeguards to the Commissioner.
  3. Brief individuals, not just the company, on section 43 exposure. Imprisonment is not a corporate risk.
  4. Point your breach runbook at the Commissioner on the section 25 timeline, with the section 25(3) content requirements built into the template, and a route to record reasons for delay under section 25(1)(b).
  5. Keep the section 33 record and section 34 DPIAs — these travel across largely unchanged from GDPR practice.

The bottom line

Mauritius is close enough to the GDPR that the analysis transfers, and different enough that the compliance artefacts do not. The registration requirement in section 14 has no GDPR counterpart, the penalty in section 43 reaches individuals, and section 36 does not recognise the transfer tools most GDPR programmes are built on.

Read sections 14 to 20 for registration, 21 to 36 for the substantive obligations, 37 to 41 for data subject rights, and 42 to 44 for offences and exceptions.

Ask Jenny instead of searching

Jenny is an AI legal assistant trained on Mauritian legislation — the Companies Act 2001, Workers' Rights Act 2019, Data Protection Act 2017 and more. She cites the section she relies on, so you can verify every answer.

Try Jenny free

This article is general information about Mauritian law, not legal advice. Legislation is amended and courts reinterpret it. Verify the current text of any provision and consult a qualified Mauritian legal practitioner before acting.