Cybersecurity and Cybercrime Act 2021, unauthorised access offences
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 10 December 2021.
A computer misuse rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not gain unauthorised access to any program or data held in a computer system, that is, access you are not entitled to control and have not been authorised to make.
- Reading a public, unauthenticated page without defeating any access control has not been confirmed either way against this section by a Mauritian court.
If you get it wrong
Criminal exposureYes
Criminal exposure note
A fine not exceeding 1,000,000 rupees and penal servitude for a term not exceeding 10 years on conviction (s. 7(1)). Unauthorised modification of computer data under section 11, a related but separate offence, carries the same fine but penal servitude of up to 20 years (s. 11(1)-(2)).
Penalty structure
Fine only under section 7(1); the same subsection also allows penal servitude of up to 10 years for the unauthorised-access offence. Section 11, a separate offence of unauthorised modification of computer data, carries the same fine but penal servitude of up to 20 years.
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- MUR
- Fixed cap
- 1,000,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 7 makes it an offence for a person to gain unauthorised access to any program or data held in a computer system, carrying a fine of up to 1,000,000 rupees and penal servitude of up to 10 years. Access is unauthorised where the person is not entitled to control access of that kind and has not been authorised by someone who is. A related offence, unauthorised modification of computer data under section 11, carries the same fine but penal servitude of up to 20 years.
The Act repealed and replaced the Computer Misuse and Cybercrime Act 2003, defining the unauthorised-access offence in substantially the same terms; because the trigger is unauthorised access rather than defeating a security measure, whether reading a public, unauthenticated page without any such access falls within the offence has not been tested by a Mauritian court.
When LexLint raises it
crawls_webtrains_models