What Is Data Protection Act 2017 (Act No. 20 of 2017)?
Mauritius's Data Protection Act 2017 (Act No. 20) came into force on 15 January 2018 by Proclamation No. 3 of 2018, repealing the prior 2004 Act. The COVID-19 (Miscellaneous Provisions) Act 2020 amended section 44, and later 2026 instruments (fees regulations, DPO designation regulations, and a controller/processor online-registration requirement) add to the current regulatory layer without replacing the Act's core rights. The Data Protection Office (DPO), led by the Data Protection Commissioner, supervises compliance. Access requests use a Rights of Data Subject form and are to be met free of charge within one month per the DPO's official leaflet; rectification, erasure, and restriction follow without undue delay under the DPO's published guidance, subject to statutory grounds and exceptions (including public-health, research, legal-obligation, and legal-claim limitations for erasure). A person may object to processing, including direct marketing, and complain to the DPO by downloading and emailing complaint and declaration forms to dpo@govmu.org. This is a source-backed evidence profile. No Mauritius-specific data-broker registry or public-record suppression route was located.
At a glance
- Full name
- Data Protection Act 2017 (Act No. 20 of 2017)
- Short code
- Mauritius DPA 2017
- Jurisdiction
- Mauritius
- Enacted
- 2017
- Last major update
- In force 15 January 2018 (Proclamation No. 3 of 2018); amended by the COVID-19 (Miscellaneous Provisions) Act 2020, with Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 as the latest located regulatory instrument
- Regulator
- Data Protection Office (DPO), headed by the Data Protection Commissioner
- Private right of action
- Limited
- Statutory citation
- Data Protection Act 2017 (Act No. 20 of 2017)
Scope, who Mauritius DPA 2017 covers
Protected data
Data subject rights
Access: confirmation of processing, purposes, categories, recipients, retention criteria, and a free copy within one month of a written request
Rectification of inaccurate or incomplete data without undue delay (section 39 guidance)
Erasure where data is no longer needed, consent is withdrawn, an objection succeeds, or processing was unlawful, subject to public-health, research, legal-obligation, and legal-claim limitations
Restriction where accuracy is contested, the controller no longer needs the data but the subject needs it for a legal claim, or an objection is being assessed
Objection to processing, including to direct marketing and related profiling
Protection from decisions based solely on automated processing (section 38), subject to statutory exceptions and safeguards
Notable features
A June 2026 Ministry communiqué requires controllers and processors to submit registration applications online through the DPO. The DPO publishes separate guidance pages for each right (access, rectification/erasure/restriction, objection, automated decision-making).
Enforcement & penalties
Regulator: Data Protection Office (DPO), headed by the Data Protection Commissioner
Penalties: The DPO materials reviewed for this research pass focused on rights and complaint procedure rather than a consolidated penalty schedule; check the Act’s offence provisions directly before publishing a fine figure.
Private right of action: The DPO investigates complaints unless frivolous or vexatious and notifies the complainant in writing; an aggrieved complainant may appeal to the ICT Appeal Tribunal within 21 days. The reviewed sources describe this administrative/appeal route rather than a separate civil damages action.
Relevance to data brokers
No Mauritius-specific data-broker registry, opt-out service, or public-record suppression route was located. The usable general route is a rights request to the relevant controller, then a DPO complaint if the person’s privacy rights are allegedly prejudiced; this does not establish that a particular broker accepts a request or that a request produces deletion.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
How do I access my data held by a Mauritius-based controller?+
Write to the controller or use the DPO’s Rights of Data Subject Form; the official leaflet says access and a copy should be provided free within one month of a written request, subject to the Act’s conditions.
Who handles data-protection complaints in Mauritius?+
The Data Protection Office, headed by the Data Protection Commissioner. Download and email its complaint and declaration forms to dpo@govmu.org, or send signed forms by post to its Ebène office.
Official sources & citations
Other international privacy regimes
Mauritius DPA 2017 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
