Law / Mauritius

Data Protection Act 2017, personal data breach notification

Data Protection Act 2017 (Act No. 20 of 2017), ss. 25-26 (notification and communication of personal data breach)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 15 January 2018.

A breach notification rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Notify the Data Protection Commissioner without undue delay, and where feasible within 72 hours, of becoming aware of a personal data breach, giving reasons if notification is later.
  • Communicate a personal data breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, unless an exception in section 26(3) applies.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A controller must notify the Commissioner of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, giving reasons for any later notification, and a processor must notify the controller without undue delay.

Where a breach is likely to result in a high risk to a data subject's rights and freedoms, the controller must also communicate it to the data subject without undue delay, unless the affected data was rendered unintelligible (for example by encryption), the risk has been neutralised by later measures, or individual communication would involve disproportionate effort and a public communication is made instead.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

Back to the example  ·  Lint your app