Back to Frameworks

Data Protection Act 2017

Mauritius
v2017 (amended 2022)
7 domains
22 controls

Mauritius Data Protection Act 2017 (Act No. 20 of 2017), as amended by the Data Protection (Amendment) Act 2022, a GDPR-aligned data protection law administered by the Data Protection Office and the Data Protection Commissioner; repealed the Data Protection Act 2004. Parts I-IX: preliminary; Data Protection Office; registration of controllers and processors; obligations (principles, lawful processing, consent, special categories, child's data, security, breach notification, records); risk processing and DPIA; transfer outside Mauritius; rights of data subjects; offences and penalties; miscellaneous.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Mauritius DPA 2017: Part II - Data Protection Office and Commissioner

2 controls
Controls in the Mauritius DPA 2017: Part II - Data Protection Office and Commissioner domain of Data Protection Act 20172 controls
CodeTitle
MU-DPA17-s4-5Data Protection Office and functions of the Commissioner
MU-DPA17-s6-13Investigation, enforcement notices and powers of the Commissioner

Mauritius DPA 2017: Part III - Registration of Controllers and Processors

1 controls
Controls in the Mauritius DPA 2017: Part III - Registration of Controllers and Processors domain of Data Protection Act 20171 controls
CodeTitle
MU-DPA17-s14-20Registration of controllers and processors

Mauritius DPA 2017: Part IV - Obligations on Controllers and Processors

10 controls
Controls in the Mauritius DPA 2017: Part IV - Obligations on Controllers and Processors domain of Data Protection Act 201710 controls
CodeTitle
MU-DPA17-s21Principles relating to processing of personal data
MU-DPA17-s22-23Duties of controller and collection of personal data
MU-DPA17-s24Conditions for consent
MU-DPA17-s25-26Notification and communication of a personal data breach
MU-DPA17-s27Duty to destroy personal data
MU-DPA17-s28Lawful processing
MU-DPA17-s29Special categories of personal data
MU-DPA17-s30Personal data of a child
MU-DPA17-s31Security of processing
MU-DPA17-s33Record of processing operations

Mauritius DPA 2017: Part V - Risk Processing (DPIA)

1 controls
Controls in the Mauritius DPA 2017: Part V - Risk Processing (DPIA) domain of Data Protection Act 20171 controls
CodeTitle
MU-DPA17-s34-35Data protection impact assessment and prior consultation

Mauritius DPA 2017: Part VI - Transfer Outside Mauritius

1 controls
Controls in the Mauritius DPA 2017: Part VI - Transfer Outside Mauritius domain of Data Protection Act 20171 controls
CodeTitle
MU-DPA17-s36Transfer of personal data outside Mauritius

Mauritius DPA 2017: Part VII - Rights of Data Subjects

4 controls
Controls in the Mauritius DPA 2017: Part VII - Rights of Data Subjects domain of Data Protection Act 20174 controls
CodeTitle
MU-DPA17-s37Right of access
MU-DPA17-s38Automated individual decision making
MU-DPA17-s39Rectification, erasure or restriction of processing
MU-DPA17-s40-41Right to object and exercise of rights

Mauritius DPA 2017: Part VIII-IX - Offences, Enforcement and Miscellaneous

3 controls
Controls in the Mauritius DPA 2017: Part VIII-IX - Offences, Enforcement and Miscellaneous domain of Data Protection Act 20173 controls
CodeTitle
MU-DPA17-s42-43Offences and penalties (unlawful disclosure)
MU-DPA17-s44Exceptions and restrictions
MU-DPA17-s45-48Annual report, compliance audit, codes and certification

Maps to 2 other frameworks

22 total controls
GDPR
7 source controls mapped|7 target controls covered
32%
ISO 27701:2019
1 source controls mapped|1 target controls covered
5%

Frequently Asked Questions

What is Data Protection Act 2017?

Data Protection Act 2017 is a compliance framework from Mauritius with 7 domains and 22 controls. Mauritius Data Protection Act 2017 (Act No. 20 of 2017), as amended by the Data Protection (Amendment) Act 2022, a GDPR-aligned data protection law administered by the Data Protection Office and the Data Protection Commissioner; repealed the Data Protection Act 2004. Parts I-IX: preliminary; Data Protection Office; registration of controllers and processors; obligations (principles, lawful processing, consent, special categories, child's data, security, breach notification, records); risk processing and DPIA; transfer outside Mauritius; rights of data subjects; offences and penalties; miscellaneous. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Data Protection Act 2017 have?

Data Protection Act 2017 has 22 controls organised across 7 domains. The largest domains are Mauritius DPA 2017: Part IV - Obligations on Controllers and Processors (10 controls), Mauritius DPA 2017: Part VII - Rights of Data Subjects (4 controls), Mauritius DPA 2017: Part VIII-IX - Offences, Enforcement and Miscellaneous (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Data Protection Act 2017 map to?

Data Protection Act 2017 maps to 2 other compliance frameworks. The top mapping partners are GDPR (32% coverage), ISO 27701:2019 (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Data Protection Act 2017 compliance?

Start your Data Protection Act 2017 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Data Protection Act 2017 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required