01Two laws, one operating model
Mauritian organisations that touch personal data of EU residents — or that act for EU controllers — are subject to both the Mauritius Data Protection Act 2017 (DPA 2017) and the EU General Data Protection Regulation (GDPR). The two laws are deliberately aligned; DPA 2017 was modernised in 2017 specifically to mirror GDPR principles and unlock cross-border data flows.
Operationally, the right approach is to build one privacy programme that satisfies both, with a thin Mauritius-specific overlay where the local regulator requires it.
