Law / Mauritius

Data Protection Act 2017, establishment and lawful processing

Data Protection Act 2017 (Act No. 20 of 2017), ss. 1-28, 30 (establishment, principles, lawful processing, and personal data of a child)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 15 January 2018.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Process personal data lawfully, fairly and transparently, only for an explicit and legitimate purpose that fits one of the Act's listed lawful-processing grounds.
  • Obtain the consent of a child's parent or guardian, verified with reasonable effort, before processing the personal data of a child below 16.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

A person who processes personal data without a lawful ground under section 28(1) commits an offence and is liable on conviction to a fine not exceeding 100,000 rupees and to imprisonment for a term not exceeding 5 years (s. 28(2)).

Penalty structure

Fine only under section 28(2); the same subsection also allows imprisonment of up to 5 years instead of or in addition to the fine, for processing personal data without a lawful ground under section 28(1).

Rule
Fixed only
As of
5 September 2026
Currency
MUR
Fixed cap
100,000

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Data Protection Act 2017 establishes the Data Protection Office, headed by the Data Protection Commissioner, and requires every controller or processor to process personal data lawfully, fairly and transparently, only for an explicit and legitimate purpose.

Processing must rest on one of a listed set of grounds, including the data subject's consent, contractual necessity, a legal obligation, or the controller's legitimate interests, and a contravention of this lawful-processing duty is itself an offence. No person may process the personal data of a child below 16 unless the child's parent or guardian has consented, and the controller must make a reasonable effort to verify that consent, taking into account available technology.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • serves_minors

Read the law

official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

Back to the example  ·  Lint your app