Operate Mauritius DPA governance structure including DPO designation + ROPA + DPIA + sectoral Codes of Conduct + Commissioner registration. Section 25-DPO mandatory Data Protection Officer designation for public authorities + bodies whose core activities consist of large-scale regular and systematic monitoring + bodies whose core activities consist of large-scale processing of sensitive data + bodies whose processing is likely to result in high risk to rights and freedoms. DPO independent + reports to highest management + contact published + DPO Mauritius notification. ROPA (Records of Processing Activities) under Section 22 in English or French covering controller and processor activities including identity + purposes + categories of data subjects + categories of personal data + categories of recipients + cross-border transfers + retention + technical and organisational measures. DPIA (Data Protection Impact Assessment) under Section 34 mandatory for high-risk processing including large-scale sensitive + systematic monitoring of public areas + profiling presenting significant risk + AI/ML processing with significant individual impact. Commissioner consultation under Section 35 for unmitigated high residual risk. Section 38 Codes of Conduct registered with Commissioner for sectors (banking + insurance + healthcare + telecommunications + ICT + financial services + offshore business). Section 39 certification mechanisms via accredited certification bodies. Commissioner public register of DPOs and codes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.