HomeAdvisoryData Protection Audit
DPA 2017 compliance for Mauritius controllers and processors
The Mauritius Data Protection Act 2017 covers every business that processes personal data — from small DNFBPs to financial institutions and global multinationals. We help you map your data, draft policies that match the law, register with the Data Protection Office, and stand up the operational practices a regulator inspection will test.
Our advisory is practical, not theoretical. We start with what you actually do with personal data, and build the framework around your real workflows.
What we deliver
- Data inventory & processing map — what data you hold, where it lives, who has access, why you process it.
- Lawful basis review — the legal ground you rely on for each processing activity.
- Policy drafting — Data Protection Policy, Privacy Notice, Cookie Policy, Retention Schedule.
- Data subject rights process — access, rectification, erasure, objection — documented and operational.
- Third-party processor agreements — the contractual safeguards required when you share data.
- Cross-border transfer assessments — for transfers to recipients outside Mauritius.
- Breach response readiness — detection, internal escalation, DPO notification within statutory timeframes.
- Independent audit — periodic testing of the framework with a board-ready findings report.
Why this matters now
Personal data is no longer a back-office concern. The Data Protection Office has stepped up enforcement, and breach incidents now trigger reputational, contractual and regulatory consequences in days, not months.
A Mauritius firm that serves EU customers — financial services, e-commerce, hospitality — is also in scope of GDPR. We design frameworks that satisfy the DPA 2017 and GDPR together where it's needed, without duplicating effort.
Frequently asked questions
Who must comply with the DPA 2017?
What does a Data Protection audit involve?
Do I need a Data Protection Officer?
How does this relate to GDPR?
Related
- AML/CFT Audit — the other regulator-mandated independent review.
- Audacia Training — Data Protection awareness for staff handling personal data.
- Sherlock Privacy — a living processing register instead of a static policy document.
Get your DPA 2017 compliance on track
A 30-minute call to scope your Data Protection needs and timing.