CC··
IP
TZ
Venn diagram comparing GDPR and Mauritius DPA 2017 — shared principles versus EU-only and Mauritius-only items
Updated 12 June 2026Reading time 16 minRegion Mauritius

EU regulation

GDPR · 2016/679

effective 25 May 2018

Mauritius statute

DPA 2017

effective 15 January 2018

Principles

7 + 6 + 8

principles · lawful bases · rights

Max fine (EU)

€20M / 4%

global turnover under Art. 83

01Two laws, one operating model

Mauritian organisations that touch personal data of EU residents — or that act for EU controllers — are subject to both the Mauritius Data Protection Act 2017 (DPA 2017) and the EU General Data Protection Regulation (GDPR). The two laws are deliberately aligned; DPA 2017 was modernised in 2017 specifically to mirror GDPR principles and unlock cross-border data flows.

Operationally, the right approach is to build one privacy programme that satisfies both, with a thin Mauritius-specific overlay where the local regulator requires it.

02The seven processing principles

DPA 2017 (s.21) and GDPR (Art. 5) share the same processing principles:

  • Lawfulness, fairness and transparency — you must have a clear lawful basis and tell people what you do.
  • Purpose limitation — collect for specified purposes, don't repurpose silently.
  • Data minimisation — only what you need.
  • Accuracy — keep records up to date.
  • Storage limitation — defined retention.
  • Integrity and confidentiality — technical and organisational security measures.
  • Accountability — be able to demonstrate compliance, not just claim it.

03Choosing a lawful basis

Six lawful bases (Art. 6 GDPR / s.28 DPA 2017):

  • Consent — freely given, specific, informed and unambiguous. Withdrawable.
  • Contract — necessary to perform a contract with the data subject.
  • Legal obligation — required by Mauritian or EU law.
  • Vital interests — life or death of an individual.
  • Public task — for public bodies and authorised tasks in the public interest.
  • Legitimate interests — for private bodies, balanced against the rights and freedoms of the data subject (not available to public authorities in their public functions).

04Data subject rights you must operationalise

  • Right to information — clear privacy notice at the point of collection.
  • Right of access — a copy of the data, and the reasoning, within statutory deadlines.
  • Right to rectification — fix inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — subject to specific exemptions.
  • Right to restriction — pause processing while disputes are resolved.
  • Right to data portability — structured, commonly-used, machine-readable format.
  • Right to object — particularly for direct marketing.
  • Rights related to automated decision-making — meaningful information about the logic, and human review.

05Data Protection Officer (DPO)

Under DPA 2017 s.14 and GDPR Art. 37, a DPO is required where the core activities consist of large-scale, regular and systematic monitoring of data subjects, or large-scale processing of special category data, or processing by a public authority. The DPO must be independent, properly resourced, and report directly to the highest management level. Many Mauritian SMEs use a Virtual DPO (vDPO) arrangement — Trivanta provides this as a managed service.

06Cross-border transfers

Mauritius and the EU mutually recognise broadly equivalent data-protection regimes, which simplifies many transfers. Where transfers go to third countries without adequate protection:

  • Standard Contractual Clauses (SCCs) — the EU 2021 SCCs are the standard mechanism for transfers from EU controllers.
  • Binding Corporate Rules — for intra-group transfers across multinationals.
  • Transfer impact assessments (TIA) — for transfers to jurisdictions with surveillance regimes that could undermine SCCs.

07Breach notification — Mauritius and EU timing

A personal-data breach must be notified to the Mauritian Data Protection Office without undue delay, and to affected data subjects where there is a high risk to their rights and freedoms. Under GDPR Art. 33–34 the EU deadline is 72 hours for notification to the supervisory authority. Build a breach playbook that can deliver both notifications from the same incident detection — same severity criteria, same evidence chain.

08Enforcement and penalties

GDPR penalties up to €20M or 4% of global annual turnover are well known. DPA 2017 enforcement powers include compliance orders, monetary penalties, and offences under Part VIII. The Mauritius Data Protection Office can investigate complaints, conduct audits, and issue enforcement notices.

Reputational cost is often higher than the fine. A breach affecting EU data subjects, followed by a finding of non-compliance, can disqualify Mauritian providers from EU procurement for years.

resources.consultation --book
Want a concrete plan for your context? Book a working session with our Mauritius consultants.