Law / Mauritius

Mauritius

10 of 11 named instruments researched to a stage, across three of the six areas of law we track: 9 in force and 1 repealed, withdrawn or blocked. As of 16 September 2026.

When they take effect8 of 10 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 repealed, withdrawn or blocked) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (200 words)

Mauritius's comprehensive personal-data statute is the Data Protection Act 2017 (Act No. 20 of 2017), in force since 15 January 2018, which binds the State and every controller or processor established in Mauritius or using equipment in Mauritius, and is enforced by the Data Protection Office under the Data Protection Commissioner.

The Act treats racial or ethnic origin, political opinion, religious belief, trade union membership, health, sexual orientation, genetic data and biometric data as special categories of personal data carrying heightened processing conditions, requires a parent or guardian's consent before the personal data of a child below 16 is processed, and gives a data subject a right against a decision based solely on automated processing that produces a legal or significant effect.

A controller must notify the Commissioner of a personal data breach within 72 hours where feasible, and cross-border transfer requires proof of safeguards to the Commissioner, the data subject's consent, or another listed condition.

The Act carries no general carve-out for personal data that is otherwise publicly accessible, and no provision arms a private plaintiff with a civil right of action; contravention is enforced through the Commissioner's enforcement notice and, ultimately, criminal penalties of a fine and imprisonment.

Breach notification

Data Protection Act 2017, personal data breach notification

Data Protection Act 2017 (Act No. 20 of 2017), ss. 25-26 (notification and communication of personal data breach)official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

In force since 15 January 2018. Binds public and private bodies.

What this law does

A controller must notify the Commissioner of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, giving reasons for any later notification, and a processor must notify the controller without undue delay.

Where a breach is likely to result in a high risk to a data subject's rights and freedoms, the controller must also communicate it to the data subject without undue delay, unless the affected data was rendered unintelligible (for example by encryption), the risk has been neutralised by later measures, or individual communication would involve disproportionate effort and a public communication is made instead.

What it requires

Comprehensive regime

Data Protection Act 2017, establishment and lawful processing

Data Protection Act 2017 (Act No. 20 of 2017), ss. 1-28, 30 (establishment, principles, lawful processing, and personal data of a child)official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

In force since 15 January 2018. Binds public and private bodies.

What this law does

The Data Protection Act 2017 establishes the Data Protection Office, headed by the Data Protection Commissioner, and requires every controller or processor to process personal data lawfully, fairly and transparently, only for an explicit and legitimate purpose.

Processing must rest on one of a listed set of grounds, including the data subject's consent, contractual necessity, a legal obligation, or the controller's legitimate interests, and a contravention of this lawful-processing duty is itself an offence. No person may process the personal data of a child below 16 unless the child's parent or guardian has consented, and the controller must make a reasonable effort to verify that consent, taking into account available technology.

What it requires

Cross border transfer

Data Protection Act 2017, transfer of personal data outside Mauritius

Data Protection Act 2017 (Act No. 20 of 2017), s. 36 (transfer of personal data outside Mauritius)official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

In force since 15 January 2018. Binds public and private bodies.

What this law does

A controller or processor may transfer personal data to another country only where it has given the Commissioner proof of appropriate safeguards, the data subject has given explicit informed consent, the transfer is necessary for a contract or legal claim, or another listed condition applies. The Commissioner may require a person transferring data to demonstrate the effectiveness of its safeguards and may prohibit, suspend or condition a transfer to protect data subjects' rights.

What it requires

Data subject rights

Data Protection Act 2017, rights of data subjects

Data Protection Act 2017 (Act No. 20 of 2017), ss. 37-41 (rights of data subjects, including automated individual decision making, s. 38)official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

In force since 15 January 2018. Binds public and private bodies.

What this law does

Every data subject has a right of access to their personal data, and a right to rectification, erasure or restriction of processing and to object to processing.

Section 38 gives a data subject a right not to be subject to a decision based solely on automated processing, including profiling, that produces a legal effect or significantly affects them, subject to exceptions for contractual necessity, a law with safeguards, or the data subject's explicit consent, and any automated processing intended to evaluate personal aspects of an individual must not be based on special categories of personal data.

What it requires

Enforcement supervision

Data Protection Act 2017, enforcement, offences and penalties

Data Protection Act 2017 (Act No. 20 of 2017), ss. 9, 42-43, 51-54 (enforcement, offences and penalties)official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

In force since 15 January 2018. Binds public and private bodies.

What this law does

Where the Commissioner considers that a controller or processor has contravened, is contravening, or is about to contravene the Act, the Commissioner may serve an enforcement notice requiring specified steps within a specified period, with a right of appeal.

Unlawfully disclosing personal data outside the purpose for which it was collected, or without the controller's or processor's prior authority, is a separate offence, and any offence for which no specific penalty is provided, or any other contravention of the Act, carries a general penalty.

What it requires

Sensitive categories

Data Protection Act 2017, special categories of personal data

Data Protection Act 2017 (Act No. 20 of 2017), s. 29 (special categories of personal data)official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)

In force since 15 January 2018. Binds public and private bodies.

What this law does

Special categories of personal data, defined to include racial or ethnic origin, political opinion, religious or philosophical belief, trade union membership, physical or mental health, sexual orientation, and genetic or biometric data uniquely identifying a person, may be processed only on a specific ground: the general lawful-processing test plus a not-for-profit body's legitimate activity with appropriate safeguards, data manifestly made public by the data subject, or necessity for a legal claim, healthcare, carrying out an obligation or exercising a right of the controller or the data subject, or protecting vital interests.

Health data processed for preventive or occupational medicine or healthcare must be handled by or under a person bound by professional secrecy.

What it requires

Scraping law3 instruments, 2 in force, 1 repealed, withdrawn or blocked

Research summary (248 words)

Mauritius has no scraping-specific statute, so general law governs each dimension separately.

The Cybersecurity and Cybercrime Act 2021 criminalises unauthorised access to a computer system, but the offence requires the person to gain access to a program or data held in a computer system without entitlement or consent, and no reported Mauritian case has tested whether reading a public, unauthenticated page falls within that requirement; the Act repealed and replaced the earlier Computer Misuse and Cybercrime Act 2003, which defined the offence in materially the same terms.

No Mauritian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act 2014 permits quotation only for the purpose of caricature, parody or pastiche, and permits reproduction for scientific research, teaching illustration, library preservation, and reporting current events, but Mauritius has not enacted a text-and-data-mining-specific exception, so training a model on scraped copyrighted text must fit within one of these narrow existing exceptions.

Mauritius's copyright statute protects an original database only as a compilation work and confers no sui generis database right. The Data Protection Act 2017 applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Mauritian website remains subject to the Act's lawful-processing, special-categories, and cross-border-transfer duties (recorded under the privacy topic).

No Mauritian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Misuse and Cybercrime Act 2003 (repealed)

Computer Misuse and Cybercrime Act 2003 (Act 22 of 2003)official Act text (2017 consolidated version), MauritiusLII

Repealed: no longer in force, effective 9 August 2003. Binds public and private bodies.

What this law does

The Computer Misuse and Cybercrime Act 2003 made it an offence to cause a computer system to perform a function, knowing that the access secured is unauthorised, with a fine of up to 50,000 rupees and penal servitude of up to 5 years. The Cybersecurity and Cybercrime Act 2021 repealed this Act in full, and its unauthorised-access offence no longer binds; the Cybersecurity and Cybercrime Act 2021, section 7, is the current provision covering the same conduct.

What it requires

Cybersecurity and Cybercrime Act 2021, unauthorised access offences

Cybersecurity and Cybercrime Act 2021 (Act No. 16 of 2021), Part III (ss. 7-13, unauthorised access and related offences)official Act text, ICT Authority of Mauritius

In force since 10 December 2021. Binds public and private bodies.

What this law does

Section 7 makes it an offence for a person to gain unauthorised access to any program or data held in a computer system, carrying a fine of up to 1,000,000 rupees and penal servitude of up to 10 years. Access is unauthorised where the person is not entitled to control access of that kind and has not been authorised by someone who is. A related offence, unauthorised modification of computer data under section 11, carries the same fine but penal servitude of up to 20 years.

The Act repealed and replaced the Computer Misuse and Cybercrime Act 2003, defining the unauthorised-access offence in substantially the same terms; because the trigger is unauthorised access rather than defeating a security measure, whether reading a public, unauthenticated page without any such access falls within the offence has not been tested by a Mauritian court.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (183 words)

Mauritius has no press-publisher neighbouring right and no compelled platform-to-publisher bargaining regime; an aggregator's reproduction of news content is governed by the general exceptions in the Copyright Act 2014.

Section 21 permits, without the copyright owner's authorisation, the reproduction in a newspaper or periodical, or the broadcasting or other communication to the public, of an article on current economic, political or religious topics published in a newspaper or periodical, unless the right to authorise reproduction has been expressly reserved, and separately permits reproducing and broadcasting short excerpts of a work seen or heard in the course of reporting current events, to the extent justified by that purpose.

Section 18 permits quotation from a lawfully published work compatible with fair practice, but only where the quotation is used for caricature, parody or pastiche, which is narrower than a general quotation right and would not on its own cover an aggregator excerpting a headline or lede for informational purposes.

No Mauritian statute or reported case addresses hot-news misappropriation, the liability of hyperlinking or framing, or a machine-readable text-and-data-mining opt-out as it bears on indexing news.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.