Breach notification
Data Protection Act 2017, personal data breach notification
Data Protection Act 2017 (Act No. 20 of 2017), ss. 25-26 (notification and communication of personal data breach)official Act text, Financial Services Commission of Mauritius (Government Gazette reproduction)
In force since 15 January 2018. Binds public and private bodies.
What this law does
A controller must notify the Commissioner of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, giving reasons for any later notification, and a processor must notify the controller without undue delay.
Where a breach is likely to result in a high risk to a data subject's rights and freedoms, the controller must also communicate it to the data subject without undue delay, unless the affected data was rendered unintelligible (for example by encryption), the risk has been neutralised by later measures, or individual communication would involve disproportionate effort and a public communication is made instead.
What it requires