Data Protection Act 2017
Mauritius DPA 2017: Part IV - Obligations on Controllers and Processors

Data Protection Act 2017 MU-DPA17-s27: Duty to destroy personal data

Requires the controller to destroy or erase personal data as soon as it is reasonable to assume that the purpose for which it was collected is no longer being served by its retention.

Other controls in Mauritius DPA 2017: Part IV - Obligations on Controllers and Processors

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.