Data Protection Act 2017
The Data Protection Act 2017 (Act No. 13 of 2017), as amended by the Data Protection (Amendment) Act 2022, provides a comprehensive data protection framework aligned with international standards. It establishes processing principles, lawful bases for processing, data subject rights (access, rectification, erasure, restriction, data portability, objection), obligations for data controllers and processors, breach notification requirements, cross‑border transfer rules, and is overseen by the Data Protection Office under the Data Protection Commissioner.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
Cross-Border Transfers
| Code | Title |
|---|---|
| DPA17-TRANSFER | International Transfers |
Data Subject Rights
| Code | Title |
|---|---|
| DPA17-RIGHTS | Exercise of Data Subject Rights |
Governance
| Code | Title |
|---|---|
| DPA17-ACCOUNTABILITY | Accountability |
Incident Response
| Code | Title |
|---|---|
| DPA17-BREACH | Notification of Personal Data Breach |
Lawful Basis
| Code | Title |
|---|---|
| DPA17-CHILD | Processing of a Child's Personal Data |
| DPA17-CONSENT | Conditions for Consent |
Part I - Preliminary
| Code | Title |
|---|---|
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 4 | Exemptions |
| Sec. 6 | Establishment of the Commission |
Part II - Principles and Lawful Processing
| Code | Title |
|---|---|
| Sec. 20 | Purpose Limitation |
| Sec. 21 | Data Minimisation |
| Sec. 22 | Accuracy |
| Sec. 23 | Storage Limitation |
Part III - Rights of Data Subjects
| Code | Title |
|---|---|
| Sec. 37 | Financial Penalties |
| Sec. 38 | Right to Data Portability |
| Sec. 39 | Voluntary Undertakings |
| Sec. 40 | Right to Object |
| Sec. 41 | Administrative Fines |
| Sec. 42 | Automated Decision-Making |
Part IV - Obligations of Controllers and Processors
| Code | Title |
|---|---|
| Sec. 28 | Duty to Notify |
| Sec. 29 | Data Protection Council |
| Sec. 30 | Right to Information |
| Sec. 31 | Unauthorised Disclosure |
| Sec. 32 | Right of Access |
Part V - Transfer of Data Outside Mauritius
| Code | Title |
|---|---|
| Sec. 36 | Right to Erasure |
| Sec. 36A | Adequacy Assessment |
Part VI - Registration and Enforcement
| Code | Title |
|---|---|
| Sec. 44 | Intelligence Services Processing |
| Sec. 45 | Penalties |
| Sec. 49 | Exemptions |
| Sec. 53 | Offences and Penalties |
Principles
| Code | Title |
|---|---|
| DPA17-ACCURACY | Accuracy |
| DPA17-MINIMISATION | Data Minimisation |
| DPA17-PRINCIPLES | Lawfulness, Fairness and Transparency |
| DPA17-PURPOSE | Purpose Limitation |
| DPA17-RETENTION | Storage Limitation |
Registration
| Code | Title |
|---|---|
| DPA17-REGISTRATION | Controller and Processor Registration |
Regulator Cooperation
| Code | Title |
|---|---|
| DPA17-COMMISSIONER | Cooperation with the Commissioner |
Risk Assessment
| Code | Title |
|---|---|
| DPA17-DPIA | DPIA for High Risk Processing |
Security
| Code | Title |
|---|---|
| DPA17-INTEGRITY | Integrity and Confidentiality |
Third Parties
| Code | Title |
|---|---|
| DPA17-PROCESSOR | Controller-Processor Contracts |
Transparency
| Code | Title |
|---|---|
| DPA17-NOTICE | Information at Collection |
Your Compliance Coverage
If you comply with Data Protection Act 2017, you already cover:
EU AI Act
30%
13 controls mapped
Compare →Ethiopia Personal Data Protection Proclamation (No. 1321/2024)
30%
13 controls mapped
Compare →Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)
30%
13 controls mapped
Compare →+ 548 more: Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) (30%), Law on Personal Data Protection (Official Gazette No. 42/2020) (30%)
See all 551 mapped frameworks ↓Maps to 551 other frameworks
Frequently Asked Questions
What is Data Protection Act 2017?
Data Protection Act 2017 is a compliance framework from Mauritius with 18 domains and 43 controls. The Data Protection Act 2017 (Act No. 13 of 2017), as amended by the Data Protection (Amendment) Act 2022, provides a comprehensive data protection framework aligned with international standards. It establishes processing principles, lawful bases for processing, data subject rights (access, rectification, erasure, restriction, data portability, objection), obligations for data controllers and processors, breach notification requirements, cross‑border transfer rules, and is overseen by the Data Protection Office under the Data Protection Commissioner. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Data Protection Act 2017 have?
Data Protection Act 2017 has 43 controls organised across 18 domains. The largest domains are Part III - Rights of Data Subjects (6 controls), Part I - Preliminary (5 controls), Part IV - Obligations of Controllers and Processors (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Data Protection Act 2017 map to?
Data Protection Act 2017 maps to 551 other compliance frameworks. The top mapping partners are EU AI Act (30% coverage), Ethiopia Personal Data Protection Proclamation (No. 1321/2024) (30% coverage), Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Data Protection Act 2017 compliance?
Start your Data Protection Act 2017 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Data Protection Act 2017 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required