Law / Mauritius

Data Protection Act 2017, transfer of personal data outside Mauritius

Data Protection Act 2017 (Act No. 20 of 2017), s. 36 (transfer of personal data outside Mauritius)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 15 January 2018.

A cross border transfer rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Give the Commissioner proof of appropriate safeguards, obtain the data subject's explicit informed consent, or otherwise satisfy a condition under section 36(1), before transferring personal data outside Mauritius.
  • Be prepared to demonstrate the effectiveness of your transfer safeguards to the Commissioner on request.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A controller or processor may transfer personal data to another country only where it has given the Commissioner proof of appropriate safeguards, the data subject has given explicit informed consent, the transfer is necessary for a contract or legal claim, or another listed condition applies. The Commissioner may require a person transferring data to demonstrate the effectiveness of its safeguards and may prohibit, suspend or condition a transfer to protect data subjects' rights.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

Back to the example  ·  Lint your app