HomeAdvisoryData Protection Audit

DPA 2017 compliance for Mauritius controllers and processors

The Mauritius Data Protection Act 2017 covers every business that processes personal data — from small DNFBPs to financial institutions and global multinationals. We help you map your data, draft policies that match the law, register with the Data Protection Office, and stand up the operational practices a regulator inspection will test.

Our advisory is practical, not theoretical. We start with what you actually do with personal data, and build the framework around your real workflows.

What we deliver

  • Data inventory & processing map — what data you hold, where it lives, who has access, why you process it.
  • Lawful basis review — the legal ground you rely on for each processing activity.
  • Policy drafting — Data Protection Policy, Privacy Notice, Cookie Policy, Retention Schedule.
  • Data subject rights process — access, rectification, erasure, objection — documented and operational.
  • Third-party processor agreements — the contractual safeguards required when you share data.
  • Cross-border transfer assessments — for transfers to recipients outside Mauritius.
  • Breach response readiness — detection, internal escalation, DPO notification within statutory timeframes.
  • Independent audit — periodic testing of the framework with a board-ready findings report.

Why this matters now

Personal data is no longer a back-office concern. The Data Protection Office has stepped up enforcement, and breach incidents now trigger reputational, contractual and regulatory consequences in days, not months.

A Mauritius firm that serves EU customers — financial services, e-commerce, hospitality — is also in scope of GDPR. We design frameworks that satisfy the DPA 2017 and GDPR together where it's needed, without duplicating effort.

Frequently asked questions

Who must comply with the DPA 2017?
Every controller or processor established in Mauritius that processes personal data, regardless of size. Processors outside Mauritius processing data on behalf of a Mauritius controller may also be in scope. Registration with the Data Protection Office is mandatory for most controllers.
What does a Data Protection audit involve?
A data inventory (what personal data you hold and why), lawful basis review, privacy notices, data subject rights handling, security measures, third-party processor agreements, retention schedules, breach response readiness and DPO arrangements. We test the framework on paper and in practice.
Do I need a Data Protection Officer?
If your core activities involve regular and systematic monitoring of data subjects at scale, or large-scale processing of sensitive data, a dedicated DPO is strongly advised. Smaller organisations should still identify a person responsible for DPA compliance.
How does this relate to GDPR?
The Mauritius DPA 2017 is broadly aligned with GDPR principles — lawful basis, data subject rights, breach notification, accountability. If you serve EU customers you may be in scope of both, and we design frameworks that satisfy both regimes where applicable.

Related

  • AML/CFT Audit — the other regulator-mandated independent review.
  • Audacia Training — Data Protection awareness for staff handling personal data.
  • Sherlock Privacy — a living processing register instead of a static policy document.

Get your DPA 2017 compliance on track

A 30-minute call to scope your Data Protection needs and timing.