GDPR & DPA: protecting personal data in Mauritius
Published on February 16, 2025
The protection of digital data is now of fundamental importance for both businesses and governments. All Mauritian companies that provide goods or services to EU residents, including those monitoring their behavior, must comply with the GDPR and the Data Protection Act (DPA) 2017, or risk heavy penalties. Here are some expert insights for your business, provided by our partner BDO Mauritius.
At Mauritius, the Data Protection Act 2017 (DPA 2017)
In Mauritius, the Data Protection Act 2017 replaced the Data Protection Act 2004, significantly modernizing the framework for personal data protection. The DPA 2017 is closely aligned with the GDPR, positioning Mauritius in compliance with global privacy standards and offering enhanced protection of personal data. If you provide goods or services to EU residents, you must ensure compliance with both regulations.
Similarities Between the DPA 2017 and the GDPR
The DPA 2017 and the GDPR share many fundamental principles and requirements for personal data protection. Both emphasize responsible and secure data processing practices. The main common points include:
Core principles such as lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, and storage limitation.
Rights of data subjects, including access, rectification, erasure, restriction of processing, and objection.
Accountability, requiring organizations to demonstrate compliance.
Key obligations such as:
- Consent: freely given, specific, informed, and unambiguous
- Security measures: appropriate technical and organizational safeguards
- Data Protection Impact Assessment (DPIA): required for high-risk processing
- Controller–processor agreements: written contracts defining responsibilities
- Use of compliant subcontractors
- Records of processing activities
- Data breach notification to authorities and, where applicable, affected individuals
Differences Between the DPA 2017 and the GDPR
The DPA 2017 includes specific obligations such as mandatory registration of data controllers and processors with the supervisory authority, which is not required under the GDPR. It also requires the notification of all data breaches to the authority, whereas the GDPR focuses on breaches that pose a high risk to individuals’ rights and freedoms.
The DPA 2017 is also more criminal in nature, with penalties that may include imprisonment. In contrast, the GDPR is primarily civil and provides for significant administrative fines. Other notable differences relate to geographical scope, supervisory authorities, conditions for lawful processing, and certain procedural requirements.
Cross-Border Data Transfers
Cross-border personal data transfers are a key issue in data protection. Both the Mauritian DPA 2017 and the EU GDPR include specific provisions to regulate such transfers.
Article 36 of the DPA 2017 sets out criteria for international transfers, including adequate safeguards approved by the Data Protection Commissioner, consent, among others. Mauritius has also signed the Council of Europe’s Convention 108+, becoming the first African country to do so. This should facilitate data transfers, particularly with Council of Europe member states, and strengthens Mauritius’ position as a country with a high level of data protection.
As a result, international companies transferring data to Mauritius must rely on safeguards such as Standard Contractual Clauses or Binding Corporate Rules to comply with GDPR requirements. Efforts are ongoing to obtain an adequacy decision, which would further simplify data transfers and align Mauritius more closely with EU standards.
What Is a Data Protection Impact Assessment (DPIA)?
A Data Protection Impact Assessment (DPIA) is an essential tool for any organization processing personal data. It helps identify, assess, and mitigate risks related to data protection. Mandatory under both the GDPR and the DPA 2017—especially for high-risk processing—it guides organizations in implementing appropriate security measures.
In Mauritius, the Data Protection Office has published guidance on high-risk processing activities. This helps organizations determine whether their processing poses a high risk to individuals’ rights and freedoms. If it does, controllers must complete a DPIA form and submit it to the Data Protection Office for consultation.
By complying with both the DPA 2017 and the GDPR, Mauritian companies not only meet legal obligations but also strengthen their brand image, build customer trust, and reduce reputational risk.
Want to assess your compliance?
Contact our partner BDO IT Consulting, which offers a range of services tailored to the specific needs of each organization.
Know more about BDO IT Consulting