MAURITIUS Law and Practice Contributed by: Sameer K. Tegally, Sonia Xavier and Ashvan Luckraz, Venture Law
• collected for explicit, specified and legitimate pur - poses; • adequate, relevant and limited to what is neces - sary; • accurate and, where necessary, kept up to date, with all reasonable steps being taken to ensure that inaccurate personal data are erased or rectified; and • retained only for as long as necessary. In addition, data controllers and processors must: • adopt policies to implement appropriate data security and organisational measures to protect personal data; • designate an officer responsible for data protec - tion; and • ensure that processing is carried out in line with the data subject’s rights. A data controller is defined as “any person who or public body which, alone or jointly with others, deter - mines the purposes and means of the processing of personal data and has decision-making power with respect to the processing”. On 20 February 2025, the Mauritius Data Protection Office (DPO) issued a communiqué specifying that, among other things, all public and private organisa - tions, sociétés , partnerships, professionals such as doctors, lawyers, engineers, architects, notaries and sole traders such as jewellers, bookmakers and any other entity processing and collecting personal data of living individuals, are required to register themselves as a controller with the DPO. The Act provides that it is a criminal offence for a data controller to personal data without any lawful excuse or where it is incompatible with the purposes for which the data was collected. Lawful excuses include: • compliance with a legal obligation; • performance of a contract with the data subject; and • protection of the vital interests of the data subject or another person.
Consent constitutes one of the key lawful bases for processing personal data under the Act. On the one hand, data controllers and processors must seek and obtain the consent of persons whose data they wish to process and, on the other hand, data subjects may give or withdraw their consent at any time. A data subject is defined as a person who may be identified or may become identifiable by reference to features, including their name, identification number, location data and physiological, genetic, mental, eco - nomic, cultural or social identity. Consent must be free, specific, informed and unam - biguous and can be in the form of a statement or a clear affirmative action. Under the Act, any local or foreign individual or organi - sation handling or processing the personal data of a Mauritian data subject is required to register with the DPO in order to act as a data controller or processor in Mauritius and must comply with the applicable legal requirements for processing, including consent where required. Transfers of personal data outside Mauritius are per - mitted, subject to the following: • proof that appropriate safeguards for an adequate level of protection have been provided to the DPO; • the data subject has given explicit consent; • the transfer is necessary (i) for the performance of a contract with the data subject; (ii) for reasons of public interest as provided by law; (iii) for the establishment, exercise or defence of legal claims; or (iv) to protect the vital interest to the data sub - ject; and • there are compelling legitimate interests of the controllers or processors. Mauritius also launched its National Data Strategy 2025–29 in January 2026, aimed at strengthening data governance, cybersecurity and the protection of personal data. 8.2 Geographical Scope The Act applies to any data controllers or proces - sors established in Mauritius and any data controller
663 CHAMBERS.COM
Powered by FlippingBook