Mauritius
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Mauritius — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Personal data can leave Mauritius, but almost never without paperwork. You have to satisfy the privacy regulator that the data will still be protected. The regulator signs transfers off one at a time. Every organisation that handles personal data must also register with it. From January 2027 each one must name a trained, certified privacy officer from its own staff.
Data governance in Mauritius
The eight things that decide how you handle data about people in Mauritius. Same eight on every country page, so you can compare.
Who has to follow these rules
Only if you have a foothold on the island. The law catches you if you are set up in Mauritius, meaning you live there or run an office, branch or agency there. It also catches you if you are not set up there but use equipment inside Mauritius to handle the data. Selling to Mauritians from abroad, with no kit on the island, is not enough by itself. If you do use equipment there, you must name a representative based in Mauritius, and you must register with the privacy regulator before you start. There is no size or revenue floor to duck under.
- What you have to do here:
- Appoint a representative · Register or notify
Section 3(5) of the Data Protection Act 2017 covers two cases. The first is a company set up in Mauritius that handles personal data through that business. The second is a company that is not set up in Mauritius but uses equipment in Mauritius to handle personal data, other than to pass it through the country. Section 3(7) treats you as set up in Mauritius if you normally live there, or if you work through an office, branch or agency there. This is the old European 'use of equipment' test. It is not the targeting test used by the European General Data Protection Regulation and copied by India, Brazil and others. What that means for you: a foreign software vendor with a Mauritius data centre, rented servers or devices on the island is covered. A pure offshore web service with Mauritian customers and nothing on the island has a real argument that it is not. Section 3(6) then requires every foreign company that is covered to name a representative based in Mauritius. Section 14 separately bans anyone from deciding how personal data is used, or handling it for someone else, unless registered with the Commissioner. Section 16(3) makes the registration certificate valid for three years. The Act binds the State and its ministries. It does not apply to purely personal or household activity. It also does not apply to need-to-know information sharing between ministries and public sector agencies, or to sharing under the Child Sex Offender Register Act 2020.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 3(5) to 3(8), 14, 15 and 16
mitci.govmu.org
“Subject to section 44, this Act shall apply to a controller or processor who - (a) is established in Mauritius and processes personal data in the context of that establishment; and (b) is not established in Mauritius but uses equipment in Mauritius for processing personal data, other than for the purpose of transit through Mauritius.”
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusRegistration of controllers and processors
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - 3,076 registration certificates issued in 2024; 21,219 controllers and 1,157 processors registered since August 2020
dataprotection.govmu.org
Link checked 19 August 2026
Where the data is allowed to live
Yes, but you have to earn it. The general rule is that personal data may go abroad if you can show the privacy regulator it will still be properly protected. A few narrow exceptions also work, such as the person's explicit informed consent. The regulator runs this as an approval queue. It cleared 112 transfer requests in 2024. There is no list of pre-approved countries, so no destination is automatically safe. Several industries add their own gate on top, and company law adds a hard one that has nothing to do with privacy.
- What you have to do here:
- Keep the data in the country · Put a transfer safeguard in place
SECTOR BY SECTOR, checked 19 August 2026. GENERAL LAW - conditional. Section 36(1) of the Data Protection Act 2017 lets you transfer data where you have 'provided to the Commissioner proof of appropriate safeguards'. You can also rely on explicit informed consent, or on listed grounds of necessity. Those grounds are a contract, the public interest, legal claims, vital interests, or compelling legitimate interests for a one-off transfer of limited scope. That last one still needs proof of safeguards filed with the Commissioner. Section 36(4) lets the Commissioner demand that you show the safeguards actually work. It also lets the Commissioner 'prohibit, suspend or subject the transfer to such conditions as he may determine'. Section 35(1) goes further. You need permission from the Office in advance where you cannot provide the safeguards in section 36. BANKING - conditional, regulator-gated. The Bank of Mauritius does not require data to stay in Mauritius. But a bank must tell it at least 60 days before it starts using material cloud services. The bank must also keep an agreed list of the countries where data will be handled. Any material outsourcing needs the Bank's permission at least 15 working days before signing. Contracts must give the Bank audit rights, and the right to take possession of the cloud services and the data if the licence is revoked. Free or consumer cloud storage is banned outright. INSURANCE, SECURITIES, FUNDS AND GLOBAL BUSINESS - conditional, regulator-gated. The Financial Services Commission's Cloud Computing Guidelines require 15 business days' written notice before you start using material cloud services. You must say which countries hold the data, tell the Commission if the location changes, and be able to retrieve any stored record at any time. There is no ban on any location. EVERY MAURITIUS COMPANY - mirror, and this is the strict one. Section 190 of the Companies Act 2001 says the company's constitution, share register, minutes, directors' certificates, financial statements and accounting records must be kept at the registered office. Section 190(4) lets you move them only to 'any other place in Mauritius'. Section 194 lets you keep accounting records outside Mauritius only if accounts and returns showing the financial position at least every six months 'are sent to, and kept at, a place in Mauritius', and the Registrar is told. Mauritius is an international financial centre, so this catches a very large share of the companies there. GAMBLING - conditional, approval-gated. Under the Gambling Regulatory Authority Act 2007, an operator of gaming machines or limited payout machines must connect the machines 'to a server located at such place designated by the operator and approved by the Board'. The operator must give the Authority direct access to that server. Interactive gambling needs a licence. Section 91A bans anyone in Mauritius from taking part in interactive gambling run from outside the country. TELECOMS - we found no rule about where data must be stored, and no duty to keep records, in the Information and Communication Technologies Act 2001, checked 19 August 2026. HEALTH - we found no health-specific rule on storage or transfer, checked 19 August 2026. A Public Health Bill 2026 covering electronic medical records went to consultation in May 2026 and is still a draft. GOVERNMENT CLOUD, EDUCATION, DEFENCE, MAPPING - we found no published rule about where data must be stored, checked 19 August 2026.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 35 and 36 (transfer of personal data outside Mauritius)
mitci.govmu.org
“A controller or processor may transfer personal data to another country where - (a) he or it has provided to the Commissioner proof of appropriate safeguards with respect to the protection of the personal data...”
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - the Commissioner authorised 112 requests for transfer of personal data outside Mauritius
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001, sections 190 and 194 (company records and place accounting records to be kept)
attorneygeneral.govmu.org
“A company shall keep its accounting records in Mauritius, except where the directors determine that the accounting records may be kept outside Mauritius... Where the records are not kept in Mauritius - (a) the company shall ensure that the accounts and returns for the operations of the company... are sent to, and kept at, a place in Mauritius”
Link checked 19 August 2026
- Official sourceBank of MauritiusGuideline on the Use of Cloud Services, effective 7 September 2022
bom.mu
Link checked 19 August 2026
- Official sourceFinancial Services Commission, MauritiusGuidelines on Cloud Computing Services, issued 30 November 2023
fscmauritius.org
Link checked 19 August 2026
- Official sourceGambling Regulatory Authority, Republic of MauritiusGambling Regulatory Authority Act 2007 as at 16 June 2026, sections 28, 28B and 91A
gra.govmu.org
“Every gaming machine operator shall connect... to a server located at such place designated by the operator and approved by the Board.”
Link checked 19 August 2026
- Official sourceRepublic of MauritiusInformation and Communication Technologies Act 2001 (consolidated) - no telecom data localisation or retention mandate located
civil-aviation.govmu.org
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Mauritius.
Sending data out of the country
The model is case-by-case approval, not a country list. Before personal data leaves, you must put appropriate protections in place and file proof of them with the privacy regulator. If you cannot provide those protections, you must go and ask the regulator for permission first. Mauritius has published no list of approved destinations and no official standard contract template, so you cannot rely on where the data is going. Requests go through the regulator's online portal, and it approved 112 of them in 2024.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life
The rules are section 36 of the Data Protection Act 2017, read with section 35. Section 36(1)(a) is the main route: you give the Commissioner proof of appropriate safeguards. The alternatives are narrower. The person can give explicit consent after being told about the risks. Or the transfer is needed for a contract with the person, or in their interest. Or it is needed for a public interest set out in law, for legal claims, or for vital interests. Or you rely on compelling legitimate interests, where the transfer is one-off and covers a limited number of people, and you still file proof of safeguards with the Commissioner. Public authorities cannot use the safeguards route, the contract route or the legitimate-interest route at all (section 36(3)). Section 35(1) makes you get permission from the Office in advance where you cannot provide the safeguards in section 36. Section 35(3) lets the Office ban the intended work outright. Section 36(4) is a standing power to demand evidence and to stop, suspend or add conditions to a transfer after the fact. What is missing matters as much as what is there. As at 19 August 2026 the regulator's site shows no list of approved countries, no published standard contract clauses, no group-wide rules scheme and no certification route. So you file a bespoke request for each transfer, through the DPO Portal at dpo.govmu.org. No law sets a deadline for a decision, so build waiting time into any project plan. Mauritius joined the Council of Europe data protection convention and its 2018 update. That is why the Act reads like a European one. It does not create any automatic route for data in or out.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, section 35(1) (prior authorisation) and section 36
mitci.govmu.org
“Every controller or processor shall obtain authorisation from the Office prior to processing personal data in order to ensure compliance of the intended processing with this Act and in particular to mitigate the risks involved for the data subjects where a controller or processor cannot provide for the appropriate safeguards referred to in section 36 in relation to the transfer of personal data to another country.”
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusTransfer of data abroad - routed through the DPO Portal
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - 112 transfer requests authorised
dataprotection.govmu.org
Link checked 19 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
The Data Protection Office, headed by Commissioner Drudeisha Madhub, who has held the post since 2007. It is real and it is working: 209 published decisions up to November 2025, 179 new complaints and 65 site inspections in 2024, 105 breach reports received and 112 transfer approvals granted. But it is thinly staffed, with one officer in post against twelve requested, and its own report says enforcement action has been delayed by that. It issues no fines, because every penalty in the Act is a criminal one that a court must impose. Financial and gambling regulators enforce separately and are fully active.
- What it costs if you get it wrong:
- Criminal liability
The Data Protection Office is established by section 4 of the Data Protection Act 2017 and must 'act with complete independence and impartiality'. Evidence it is operational, all from its own site: a continuous published decision series reaching Decision No 209 dated 11 November 2025, roughly 26 decisions issued during 2025, and an Annual Report for 2024 recording 179 new complaints, 65 site-visit inspections carried out with police assistance, 105 notified personal data breaches, 3,076 registration certificates issued and 112 authorised cross-border transfers. The same report records only 1 data protection officer or senior officer in post against 12 requested, and 3 assistant officers against 6 requested, and its foreword attributes delayed enforcement to resource constraints. The important structural point is that the Act contains no administrative fining power. Sections 15, 42 and 43 create criminal offences prosecuted before a court, with the residual offence under section 43 carrying up to 200,000 rupees (roughly 4,300 US dollars) and up to five years' imprisonment. The Commissioner's own output is therefore determinations, enforcement notices, inspections and refusals rather than penalties. The published decisions are dominated by closed-circuit television complaints. Rated active rather than aggressive: the regulator decides cases continuously and gates transfers, but no completed prosecution was reported for 2024 and the money at stake is small. Other enforcers are separate and busy: the Bank of Mauritius for banks, the Financial Services Commission for insurance, securities, funds and global business, the Information and Communication Technologies Authority for networks and content, the Gambling Regulatory Authority for gaming, and CERT-MU for cyber incidents.
Sources
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - complaints, inspections, breach notifications, registrations, transfer authorisations and staffing
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusDecisions on complaints - series running to Decision No 209 dated 11 November 2025
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusThe Data Protection Commissioner - Mrs Drudeisha Madhub, appointed August 2007
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 4, 5, 42 and 43
mitci.govmu.org
“Any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding 200, 000 rupees and to imprisonment for a term not exceeding 5 years.”
Link checked 19 August 2026
How long you must keep it — and when to delete it
Two forces pull against each other. The privacy law says delete. Keep personal data only as long as you need it, and destroy it as soon as the purpose has gone. Company law and money-laundering rules say keep. That is seven years for company records, accounting records and customer due diligence files. The keep rules win where they apply, because the privacy law lets you use data where a law requires it. So set a seven-year clock on financial and company paperwork, and a short, purpose-based clock on everything else.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep records of how you use data
WHAT YOU MUST DELETE. Section 21(e) of the Data Protection Act 2017 says you may only keep personal data in a form that identifies people for as long as you need it for the purpose. Section 27 goes further than most laws. Once the reason for keeping personal data has gone, you must destroy it as soon as is reasonably practicable. You must also tell anyone holding it for you, and they must destroy it too. There is no fixed maximum number of years. WHAT YOU MUST KEEP. Section 190(2A) of the Companies Act 2001 makes directors keep the listed company records 'for a period of at least 7 years from the date of the completion of the transaction, act or operation to which it relates'. That duty continues even after the company is struck off the register. Section 190(2) sets seven years, or seven completed accounting periods, for minutes, directors' certificates, shareholder communications and financial statements. The Bank of Mauritius anti-money-laundering guideline repeatedly sets seven years. That runs from completion of the transaction, closure of the account, or the date of a report to the Financial Intelligence Unit. WHICH WINS. Section 28 of the Data Protection Act allows you to use data where a law requires it. So a legal duty to keep records overrides the duty to destroy for as long as that duty runs. The trap is the tail end. Once the seven years expire, the section 27 duty to destroy comes back, and the data must actually be deleted, not archived forever.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 21(e), 27 and 28
mitci.govmu.org
“Where the purpose for keeping personal data has lapsed, every controller shall - (a) destroy the data as soon as is reasonably practicable; and (b) notify any processor holding the data.”
Link checked 19 August 2026
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001, sections 190(2), 190(2A) and 193
attorneygeneral.govmu.org
“The directors of a company shall, at all times and even where the company is removed from the register, ensure that the records referred to in subsection (2) are kept for a period of at least 7 years from the date of the completion of the transaction, act or operation to which it relates.”
Link checked 19 August 2026
- Official sourceBank of MauritiusGuideline on Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation, January 2020 - seven-year record retention
bom.mu
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
One firm clock and several soft ones. A personal data breach must be reported to the Commissioner without undue delay and, where possible, within 72 hours of you finding out. If you miss that, you must explain why you were late. Where the breach is likely to seriously harm people, you must also tell them, without undue delay. A supplier who spots a breach must tell the organisation it works for straight away. Cyber incidents affecting critical national systems go to the national cyber team as well, and that route has no fixed deadline in the law.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents · Secure the data
CLOCK ONE, the only firm one. Section 25(1)(a) of the Data Protection Act 2017 says that after a personal data breach you 'shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner'. Section 25(1)(b) makes you give reasons for any delay. The report must describe the breach, roughly how many people and records are affected, a contact point, and what you recommend to limit the damage. Section 25(2) makes a supplier tell the company it works for without undue delay, with no stated hour count. Section 26 makes you tell the affected people where the breach is likely to put their rights and freedoms at high risk. Section 26(4) lets the Commissioner order you to tell them if you have not. The Office received 105 breach reports in 2024, so the channel is live. CLOCK TWO, soft. Section 35 of the Cybersecurity and Cybercrime Act 2021 makes owners of critical information infrastructure tell the National Cybersecurity Committee about incidents that hit national security, public safety or the public interest. CERT-MU reports up to the Committee. The Act sets no hour count. From 1 June 2026, five sectors are formally designated critical information infrastructure. Those are financial services banking and non-banking, the public service, information and communication technology and broadcasting, energy and water supply, and transport. So this route now has named addressees. CLOCK THREE, supervisory. Banks and non-bank financial institutions also owe incident and outsourcing-failure reports to the Bank of Mauritius and the Financial Services Commission under their own guidelines. The common mistake is to treat the 72-hour privacy clock as the only one and miss the industry report entirely.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 25 and 26
mitci.govmu.org
“In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationCybersecurity and Cybercrime Act 2021, sections 34 and 35
mitci.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationCybersecurity and Cybercrime (Critical Information Infrastructure Designation) Regulations 2026, GN 113 of 2026, in operation 1 June 2026
mitci.govmu.org
Link checked 19 August 2026
- Official sourceComputer Emergency Response Team of MauritiusCERT-MU incident and vulnerability reporting channel
cert-mu.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - 105 personal data breaches reported in 2024
dataprotection.govmu.org
Link checked 19 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that catch people out. One: suppliers must register too, not just the organisation in charge, and the certificate expires every three years. Two: from January 2027 every organisation must name a privacy officer from its own payroll, holding a certificate from the regulator or a school the regulator approves, with no exemption for tiny firms. Three: getting it wrong is a crime, not a fine, and a person can go to prison for up to five years. Four: your company paperwork must physically stay in Mauritius. Five: the telecoms regulator can order the internet shut off, and did in November 2024.
- What you have to do here:
- Register or notify · Hold a security certificate · Extra vendor secrecy terms · Keep the data in the country
- What it costs if you get it wrong:
- Criminal liability · Order to stop
1. SUPPLIERS MUST REGISTER TOO. Section 14 bans any person from deciding how personal data is used, or handling it for someone else, unless registered with the Commissioner. A pure supplier that never decides anything about the data still has to register. It must file a description of the data, say whether it holds special categories, and name the countries it may send data to. The certificate lasts three years (section 16(3)). False information on the form is an offence carrying up to 100,000 rupees, about 2,100 US dollars, and five years' imprisonment. 2. THE PRIVACY OFFICER MUST BE YOUR OWN CERTIFIED EMPLOYEE. Regulation 3(1) of the 2026 regulations says you must pick the officer 'from a staff member of the organisation'. You cannot buy this as an outsourced service. Regulation 5(d) requires proof of certification. That must come from the Data Protection Office after its own training, or from a training institution the Office has approved. Regulation 3(4) makes you send the officer's details to the Office within 14 days of appointment, and within 14 days of any change. Regulation 8(1) makes you publish the contact details on your premises or your website. Breaking either rule is an offence carrying up to 100,000 rupees and five years' imprisonment. There is no size threshold anywhere in these regulations. 3. EVERYTHING IS CRIMINAL. The Act gives the regulator no power to issue fines itself. The catch-all offence under section 43 carries up to 200,000 rupees, about 4,300 US dollars, and up to five years' imprisonment. The court may also order forfeiture of equipment and stop you from carrying on. The money is small. The criminal record and the stop order are not. 4. COMPANY RECORDS CANNOT LEAVE. Section 190 of the Companies Act 2001 keeps the constitution, share register, minutes, directors' certificates, financial statements and accounting records at the registered office, or another place in Mauritius. You have 14 days to tell the Registrar if the place changes. Section 194 lets accounting records sit abroad only if six-monthly accounts and returns are sent to and kept at a place in Mauritius. This applies to every Mauritius company, including the thousands of global business entities. You will not see it if you only read the privacy law. 5. BANK SECRECY SITS ON TOP OF PRIVACY. Section 64 of the Banking Act 2004 makes it an offence to publish customer or institution information without express written consent. The penalty is up to 500,000 rupees, about 10,600 US dollars, and three years' imprisonment for an individual, and up to one million rupees for a company. A standard supplier contract is not enough. You need explicit secrecy promises. 6. THE NETWORK KILL SWITCH IS REAL. Section 18 of the Information and Communication Technologies Act 2001 lets the Authority 'take steps to regulate or curtail the harmful and illegal content on the Internet and other information and communication services'. In November 2024 that power was used to order internet providers to block social media platforms across the country, ahead of the general election. The order was withdrawn after about 24 hours. Nothing has changed in the law since.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 14, 15, 16 and 43
mitci.govmu.org
“Subject to section 44, no person shall act as controller or processor unless he or it is registered with the Commissioner.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026, regulations 3, 5, 8 and 9
mitci.govmu.org
“every controller shall, for the purpose of section 22(2)(e) of the Act, designate, from a staff member of the organisation, a data protection officer for the purpose of carrying out the tasks specified under regulation 4.”
Link checked 19 August 2026
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001, sections 190 and 194
attorneygeneral.govmu.org
Link checked 19 August 2026
- Official sourceBank of MauritiusPublic Notice - Confidentiality obligations under the Banking Act, 21 October 2019
bom.mu
Link checked 19 August 2026
- Official sourceRepublic of MauritiusInformation and Communication Technologies Act 2001 (consolidated), section 18(m)
civil-aviation.govmu.org
“take steps to regulate or curtail the harmful and illegal content on the Internet and other information and communication services”
Link checked 19 August 2026
What's changing next
One dated change dominates. On 1 January 2027 every organisation must have its certified in-house privacy officer in place, so the work has to start now. Owners of systems the government has labelled critical have until 1 June 2027 to comply with directions. Those are banking, public service, technology and broadcasting, energy and water, and transport. Beyond that the government has announced a national cyber agency, a digital identity bill, artificial intelligence rules and social media measures. None of them is law yet. Several powers already on the books could change the answer with no warning.
- What you have to do here:
- Appoint a data protection officer · Hold a security certificate
DATED AND BINDING. - 1 January 2027: the Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026, made 17 June 2026, come into operation. Certification has to come from the Data Protection Office or an Office-approved institution. The constraint is training capacity, not the drafting. - 1 June 2027: owners of designated critical information infrastructure must comply with the Cybersecurity and Cybercrime (Critical Information Infrastructure Designation) Regulations 2026, GN 113 of 2026. Those came into operation on 1 June 2026 with a twelve-month window to comply. Designations are reviewed every three years. ANNOUNCED, NOT LAW. The Ministry of Information Technology said in August 2025 that it would bring an Electronic Identity Management Bill built on the central population database. It also promised critical information infrastructure regulations, artificial intelligence rules on a mix of the European risk-based and British principles-based models, and social media responsibility measures. It said a National Cyber-Resilience and Cybersecurity Agency would be set up. The Budget Speech 2026-2027, delivered in June 2026, funds a cyber forensic laboratory, a national cybersecurity survey, information security management systems across government, a national fraud reporting and response mechanism at CERT-MU, and a threat intelligence sharing platform at the Bank of Mauritius. It also promises a National Artificial Intelligence Guideline for higher education and the civil service. A Public Health Bill 2026 covering electronic medical records went to a consultation workshop in May 2026. All of these are proposals. None of them creates a duty today. POWERS ALREADY HELD, which matter more than the bills. - Section 36(4) of the Data Protection Act lets the Commissioner stop, suspend or add conditions to any transfer already running, with no consultation and no list to check. - Section 35(3) lets the Office ban intended work outright where it thinks the risks are not sufficiently reduced. - Section 18 of the Information and Communication Technologies Act supports network-level blocking orders. It was used in November 2024. - Section 34 of the Cybersecurity and Cybercrime Act 2021 lets a regulator direct critical infrastructure owners on security policies and assessments. The sectors are now designated, so this can be used immediately and could in principle reach hosting arrangements. - Section 91A of the Gambling Regulatory Authority Act lets the Authority order internet providers to block offshore gambling sites, and order banks to stop payments.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026
mitci.govmu.org
“These regulations shall come into operation on 1 January 2027.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationCybersecurity and Cybercrime (Critical Information Infrastructure Designation) Regulations 2026, GN 113 of 2026
mitci.govmu.org
“Every owner of a designated critical information infrastructure shall, within 12 months of the coming into operation of these regulations, comply with these regulations.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationMauritius to roll out new digital regulations in line with National ICT Blueprint, 21 August 2025
mitci.govmu.org
Link checked 19 August 2026
- Official sourceNational Assembly of MauritiusBudget Speech 2026-2027, National Assembly, June 2026 - cyber forensic laboratory, national cybersecurity survey, CERT-MU fraud reporting mechanism, National Artificial Intelligence Guideline
mauritiusassembly.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationMauritius moves towards a modern public health legislation with the Public Health Bill 2026, 22 May 2026
mitci.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 35(3) and 36(4)
mitci.govmu.org
“The Commissioner may request a person who transfers data to another country to demonstrate the effectiveness of the safeguards or the existence of compelling legitimate interests and may, in order to protect the rights and fundamental freedoms of data subjects, prohibit, suspend or subject the transfer to such conditions as he may determine.”
Link checked 19 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking rules
Official name: Guideline on the Use of Cloud Services, read with the Guidelines on Outsourcing by Financial Institutions · BOM/BSD 46/September 2022; Guidelines on Outsourcing revised 13 October 2020 · Regulator guideline
Banks may host data outside Mauritius, but only with the Bank of Mauritius told in advance, given audit and seizure rights in the contract, and kept informed of exactly which countries hold the data. Banking secrecy sits on top and is enforced as a crime.
Enforced by Bank of Mauritius
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Register or notifyNotify the Bank at least 60 days before deploying material cloud services; obtain the Bank's prior authorisation at least 15 working days before signing any material outsourcing agreement.
- Written vendor contractAgreements must give the Bank, the institution, its auditors and any Bank appointee audit and on-site inspection rights, and let the Bank take possession of the services and data if the licence is revoked or a conservator is appointed.
- Secure the dataData on the cloud and the access channel must be encrypted, with the institution retaining the encryption key. Free, personal or community cloud storage is prohibited.
- Keep records of how you use dataMaintain a pre-agreed list of the countries where data will be processed and know the city and country of hosting.
- Keep data for a minimum period — 7 yearsSeven-year retention for customer due diligence, transaction and suspicious transaction records under the anti-money-laundering guideline.
What it costs if you get it wrong
- Loss of your licenceSupervisory action for breach of guidelines issued under the Banking Act 2004
- Criminal liability: MUR 500,000 and 3 years' imprisonment for an individual; MUR 1,000,000 for a body corporate — about $21 thousandDisclosure or publication of customer information contrary to the Banking Act 2004 confidentiality duty
Sources
- Official sourceBank of MauritiusGuideline on the Use of Cloud Services, effective 7 September 2022
bom.mu
“Financial institutions shall notify the Bank of the proposed deployment of material cloud services”
Link checked 19 August 2026
- Official sourceBank of MauritiusGuidelines on Outsourcing by Financial Institutions, revised 13 October 2020
bom.mu
“A financial institution that intends to outsource a material activity is required to notify and obtain the prior authorization of the Bank.”
Link checked 19 August 2026
- Official sourceBank of MauritiusPublic Notice - Confidentiality obligations under the Banking Act, 21 October 2019
bom.mu
Link checked 19 August 2026
- Official sourceBank of MauritiusGuideline on Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation, January 2020
bom.mu
Link checked 19 August 2026
Cloud and outsourcing rules
Official name: Guidelines on Cloud Computing Services · Financial Services Commission, issued 30 November 2023 under the Financial Services Act 2007 · Regulator guideline
Insurers, fund managers, securities firms, management companies and global business entities may use offshore cloud, but must tell the Financial Services Commission 15 business days before anything material goes live, must know and disclose which countries hold the data, and must be able to pull any record back at any time.
Enforced by Financial Services Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Register or notifyNotify the Financial Services Commission in writing at least 15 business days before deploying any material cloud computing service.
- Keep records of how you use dataGet from the provider the countries where data is stored and the safeguards in place. Require reasonable notice of any change of location. Keep an up-to-date register of the services you use.
- Written vendor contractThe licensee must be able to retrieve any information or document held by the provider at any point in time.
- Independent auditThe board is responsible for meeting the record-keeping duties under the Financial Services Act.
What it costs if you get it wrong
- Loss of your licenceRegulatory action for breach of guidelines issued by the Commission
Sources
- Official sourceFinancial Services Commission, MauritiusGuidelines on Cloud Computing Services, 30 November 2023
fscmauritius.org
“Licensees shall notify the FSC in writing, at least 15 business days prior to the deployment of any material cloud computing services.”
Link checked 19 August 2026
- Official sourceFinancial Services Commission, MauritiusCirculars and legal framework
fscmauritius.org
Link checked 19 August 2026
Payment data rules
Official name: Gambling Regulatory Authority Act 2007 · Act No. 9 of 2007 as at 16 June 2026, sections 28, 28B and 91A; section 91A added by Act 12 of 2023 · Act of parliament
Gambling operators cannot choose where their game servers sit. The regulator's board must approve the location and the Authority must get direct access to the server. It can also order internet providers to block offshore gambling sites and order banks to stop payments to them.
Enforced by Gambling Regulatory Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryGaming machines and limited payout machines must be connected to a server at a place designated by the operator and approved by the Board, and the Authority must be given direct access to that server.
- Register or notifyInteractive gambling needs a licence. You count as running interactive gambling if you keep any computer or communication system in Mauritius that it runs on.
- Keep records of how you use dataRegulations may require that proper records are kept and that the operation is supervised by the Authority and its inspectors.
What it costs if you get it wrong
- Loss of your licenceOperating or connecting a server without Board approval
- Order to stopDirections to internet providers to block offshore gambling sites and to banks to stop payments, under section 91A
- Criminal liabilityOperating interactive gambling from outside Mauritius while allowing access to people physically present in Mauritius
Sources
- Official sourceGambling Regulatory Authority, Republic of MauritiusGambling Regulatory Authority Act 2007 as at 16 June 2026, sections 28(5), 28B(6), 91 and 91A
gra.govmu.org
“Every gaming machine operator shall connect - (a) forthwith any gaming machine brought into operation on or after 10 September 2007... to a server located at such place designated by the operator and approved by the Board.”
Link checked 19 August 2026
- Official sourceGambling Regulatory Authority, Republic of MauritiusLegislations and Policies
gra.govmu.org
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Data Protection Act 2017 · Act No. 20 of 2017; proclaimed by Proclamation No. 3 of 2018 · Act of parliament
The general privacy law. It reaches you only if you are set up in Mauritius or use equipment there. If it does reach you, you must register with the regulator. If you are foreign, you must also name a local representative. And you must satisfy the regulator before personal data goes abroad. All penalties are criminal.
Enforced by Data Protection Office
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Register or notifyThis covers you whether you decide how the data is used or just handle it for someone else. The certificate is valid for 3 years.
- Appoint a representative — applies at: Foreign controllers and processors using equipment in MauritiusRepresentative must be established in Mauritius.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of how you use data
- Assess high-risk projectsRequired where the work is high risk. You must give it to the Office on request.
- Report breaches to the regulator — within 72 hoursReasons required if late.
- Tell affected peopleWhere the breach is likely to result in a high risk.
- Delete data after a periodPositive duty to destroy once the purpose has lapsed, and to tell processors to destroy.
- Put a transfer safeguard in placeProof of appropriate safeguards must be provided to the Commissioner.
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: MUR 200,000 and 5 years' imprisonment — about $4 thousandResidual offence: any contravention with no specific penalty
- Criminal liability: MUR 100,000 and 5 years' imprisonment — about $2 thousandFalse or misleading information in a registration application
- Order to stop: Court order prohibiting the act; prohibition or suspension of a transfer by the CommissionerContinuing contravention, or unsafe cross-border transfer
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017 (consolidated text)
mitci.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationLegislations page listing the Data Protection Act 2017 and its regulations
mitci.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024
dataprotection.govmu.org
Link checked 19 August 2026
General data protection law (2027)
Official name: Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 · Government Notice No. 117 of 2026, made under section 55 of the Data Protection Act · Directly binding regulation
From 1 January 2027 every organisation that decides how personal data is used must appoint a data protection officer from its own staff. The officer must be certified by the regulator or a regulator-approved trainer. You must tell the regulator within 14 days and publish the contact details. This rule does not restrict where data is stored. It restricts who can hold the job.
Enforced by Data Protection Office
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Appoint a data protection officer — applies at: Every controller, no size exemption, from 1 January 2027Must be designated from a staff member of the organisation. Where more than one is designated, a lead officer must be named as primary contact with the Office.
- Hold a security certificate — from 1 January 2027The officer must hold certification from the Data Protection Office after its training, or from a training institution approved by the Office.
- Publish a complaints contact — from 1 January 2027Contact details must be published at a conspicuous place on the premises or on the website.
- Tell people what you do — from 1 January 2027Officer's particulars must be communicated to the Office within 14 days of designation and within 14 days of any change.
- Independent audit — from 1 January 2027The officer must run internal audits and assist the Office with compliance audits, security checks and inspections.
What it costs if you get it wrong
- Criminal liability: MUR 100,000 and 5 years' imprisonment — about $2 thousandFailure to notify the officer's particulars within 14 days, or failure to publish the officer's contact details
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026
mitci.govmu.org
“These regulations shall come into operation on 1 January 2027. Made by the Minister, after consultation with the Data Protection Commissioner, on 17 June 2026.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationLegislations page listing the 2026 data protection officer regulations
mitci.govmu.org
Link checked 19 August 2026
Personal data needs a copy kept in the country
Official name: Companies Act 2001 · Act No. 15 of 2001, sections 190, 191, 193 and 194; section 190 amended by Act 11 of 2018 · Act of parliament
Every Mauritius company must keep its constitution, share register, minutes, directors' certificates, financial statements and accounting records inside Mauritius. Accounting records may sit abroad only if summary accounts and returns are still sent back to and held at a place in Mauritius and the Registrar is told where.
Enforced by Registrar of Companies (Corporate and Business Registration Department)
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryCompany records must be kept at the registered office or, on notice to the Registrar, at any other place in Mauritius. Accounting records may be kept abroad only if six-monthly accounts and returns are sent to and kept at a place in Mauritius.
- Keep data for a minimum period — 7 yearsAt least 7 years from completion of the transaction, act or operation, and the duty survives removal of the company from the register.
- Keep records of how you use dataRecords must be in English or French, or in a form easily convertible to written English or French, with measures to prevent and detect falsification.
Sources
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001 (Revised Laws of Mauritius), sections 190, 191, 193 and 194
attorneygeneral.govmu.org
“Subject to subsection (4) and to sections 91 (1) and 194, a company shall keep at its registered office the records specified in subsection (2)... The documents specified in subsection (2) may be kept at any other place in Mauritius, notice of which shall be given to the Registrar.”
Link checked 19 August 2026
- Official sourceMinistry of Finance, Republic of MauritiusCompanies Act 2001 as published by the Ministry of Finance
mof.govmu.org
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the Data Protection Office publishes no adequacy list, no standard contractual clauses and no binding corporate rules scheme
We found no published library of transfer mechanisms. The regulator's site shows only a portal-based request route, checked 19 August 2026. If you plan a transfer, ask the Office what it will accept.
Whether the Data Protection Office has issued any decision, or the Commissioner has changed, between November 2025 and 19 August 2026
The published decisions page ends at Decision No 209 dated 11 November 2025, and the latest annual report on the site covers 2024. We cannot tell whether nothing was decided or nothing was published. Check the regulator's decision page for anything newer.
Whether there is any statutory or published service standard for how long a cross-border transfer authorisation takes
We found no deadline in the Act or on the regulator's site. Plan for an open-ended wait, and ask the Office for an expected timeline before you commit to a launch date.
Telecom-specific data retention or localisation obligations in licence conditions
We found no duty in the Information and Communication Technologies Act 2001 to keep records or to store data in Mauritius. Individual licence conditions from the ICT Authority are not published in full, so a duty in your own licence is possible. If you hold a telecoms licence, read its conditions.
Any government cloud, public sector hosting or education keeping data in the country policy
We found no published rule requiring government data to stay in Mauritius, checked 19 August 2026. Government hosting is concentrated at the Government Online Centre, but we found no rule that requires it. If you sell to a Mauritian public body, ask what its contract requires.
Health sector storage rules
We found no health-specific rule on storing or transferring data. The Public Health Bill 2026 is at consultation stage and we could not find its text on a government site. If you work in health, check with the Ministry of Health before you rely on this.
Tax record retention periods under the Income Tax Act 1995 and the Value Added Tax Act 1998
We could not confirm a tax record retention period from a government source. The Mauritius Revenue Authority overview page does not state one. The seven-year figure in this record comes from company law and anti-money-laundering rules, which we did verify. Check with your tax adviser before you set a tax retention period.
Whether the Cybersecurity and Cybercrime Act 2021 has been fully proclaimed
We could not confirm the commencement date. The Act says it starts on a date fixed by Proclamation, and the consolidated copy we read does not carry that note. The 2026 critical information infrastructure regulations were made under the Act and are in force, which strongly suggests it has started.
That Mauritius has acceded to the Council of Europe data protection convention and its modernising protocol
Widely reported and consistent with how the Act is written. The accession papers sit on a Council of Europe site rather than a Mauritius government site, so we treat this as background only.
Whether the six-month compliance moratorium reported by professional commentators for the 2026 data protection officer regulations exists
The published text gives a start date of 1 January 2027 and says nothing about a transition period. Treat 1 January 2027 as a firm date.
Insurance-specific and securities-specific record location rules beyond the cloud guidelines
We verified the Financial Services Commission cloud guidelines. We did not read the record-keeping sections of the Financial Services Act 2007 or the Insurance Act 2005, so those exact duties are unconfirmed. Check them if you are licensed under either Act.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.