Mauritius
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Personal data can leave Mauritius, but almost never without paperwork. You have to satisfy the privacy regulator that the data will still be protected, and in practice the regulator signs transfers off one at a time. Every organisation that handles personal data must also register with it. From January 2027 each one must name a trained, certified privacy officer from its own staff.
Data governance in Mauritius
The eight things that decide how you handle data about people in Mauritius. Same eight on every country page, so you can compare.
Who has to follow these rules
Only if you have a foothold on the island. The law catches you if you are set up in Mauritius, meaning you live there or run an office, branch or agency there. It also catches you if you are not set up there but use equipment inside Mauritius to handle the data. Selling to Mauritians from abroad, with no kit on the island, is not enough by itself. If you do use equipment there, you must name a representative based in Mauritius, and you must register with the privacy regulator before you start. There is no size or revenue floor to duck under.
Section 3(5) of the Data Protection Act 2017 applies the Act to a controller or processor who '(a) is established in Mauritius and processes personal data in the context of that establishment; and (b) is not established in Mauritius but uses equipment in Mauritius for processing personal data, other than for the purpose of transit through Mauritius.' Section 3(7) deems a person established in Mauritius if ordinarily resident there or carrying out processing through an office, branch or agency there. This is the pre-2018 European 'use of equipment' test, not the targeting test used by the European General Data Protection Regulation and copied by India, Brazil and others. Practical effect: a foreign software vendor with a Mauritius data centre, colocated servers or on-island devices is in scope; a pure offshore web service with Mauritian customers and no on-island infrastructure has a genuine argument that it is out. Section 3(6) then requires every in-scope foreign controller or processor to nominate a representative established in Mauritius. Section 14 separately bars anyone from acting as controller or processor at all unless registered with the Commissioner; section 16(3) makes the registration certificate valid for three years. The Act binds the State and its ministries, and does not apply to purely personal or household activity, to need-to-know information exchange between ministries and public sector agencies, or to sharing under the Child Sex Offender Register Act 2020.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 3(5) to 3(8), 14, 15 and 16
mitci.govmu.org
“Subject to section 44, this Act shall apply to a controller or processor who - (a) is established in Mauritius and processes personal data in the context of that establishment; and (b) is not established in Mauritius but uses equipment in Mauritius for processing personal data, other than for the purpose of transit through Mauritius.”
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusRegistration of controllers and processors
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - 3,076 registration certificates issued in 2024; 21,219 controllers and 1,157 processors registered since August 2020
dataprotection.govmu.org
Link checked 19 August 2026
Where the data is allowed to live
Yes, but you have to earn it. The general rule is that personal data may go abroad if you can show the privacy regulator that it will still be properly protected, or if a narrow exception applies such as the person's explicit informed consent. In practice the regulator handles this as an approval queue: it cleared 112 transfer requests in 2024. There is no list of pre-approved countries, so no destination is automatically safe. Several industries add their own gate on top, and company law adds a hard one that has nothing to do with privacy.
SECTOR BY SECTOR, checked 19 August 2026. GENERAL LAW - conditional. Section 36(1) of the Data Protection Act 2017 permits transfer where the controller or processor 'has provided to the Commissioner proof of appropriate safeguards', or on explicit informed consent, or under listed necessity grounds (contract, public interest, legal claims, vital interests, or compelling legitimate interests for a non-repetitive transfer of limited scope, which itself still needs proof of safeguards filed with the Commissioner). Section 36(4) lets the Commissioner demand that you demonstrate the safeguards actually work and 'prohibit, suspend or subject the transfer to such conditions as he may determine'. Section 35(1) goes further and requires prior authorisation from the Office where the appropriate safeguards in section 36 cannot be provided. BANKING - conditional, regulator-gated. The Bank of Mauritius does not require data to stay in Mauritius, but a bank must notify it at least 60 days before deploying material cloud services and must maintain a pre-agreed list of the countries where data will be processed. Material outsourcing of any kind needs the Bank's prior authorisation at least 15 working days before signing. Contracts must give the Bank audit rights and the right to take possession of the cloud services and data if the licence is revoked. Free or consumer cloud storage is banned outright. INSURANCE, SECURITIES, FUNDS AND GLOBAL BUSINESS - conditional, regulator-gated. The Financial Services Commission's Cloud Computing Guidelines require 15 business days' written notice before deploying material cloud services, disclosure of the countries where data is stored, notice of any change of location, and the ability to retrieve any stored record at any time. No location ban. EVERY MAURITIUS COMPANY - mirror, and this is the hard wall. Section 190 of the Companies Act 2001 requires the company's constitution, share register, minutes, directors' certificates, financial statements and accounting records to be kept at the registered office, and section 190(4) permits them to be moved only to 'any other place in Mauritius'. Section 194 allows accounting records to be kept outside Mauritius only if accounts and returns disclosing the financial position at intervals of not more than six months 'are sent to, and kept at, a place in Mauritius' and the Registrar is notified. Because Mauritius is an international financial centre, this bites on a very large share of the entities operating there. GAMBLING - conditional, approval-gated. Under the Gambling Regulatory Authority Act 2007 a gaming machine or limited payout machine operator must connect machines 'to a server located at such place designated by the operator and approved by the Board' and must give the Authority direct access to that server. Interactive gambling is licence-only, and section 91A bans anyone in Mauritius from taking part in interactive gambling run from outside the country. TELECOMS - no localisation or mandatory retention rule found in the Information and Communication Technologies Act 2001, checked 19 August 2026. HEALTH - no health-specific storage or transfer rule found, checked 19 August 2026. A Public Health Bill 2026 covering electronic medical records went to consultation in May 2026 and is a draft only. GOVERNMENT CLOUD, EDUCATION, DEFENCE, MAPPING - no published localisation instrument found, checked 19 August 2026.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 35 and 36 (transfer of personal data outside Mauritius)
mitci.govmu.org
“A controller or processor may transfer personal data to another country where - (a) he or it has provided to the Commissioner proof of appropriate safeguards with respect to the protection of the personal data...”
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - the Commissioner authorised 112 requests for transfer of personal data outside Mauritius
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001, sections 190 and 194 (company records and place accounting records to be kept)
attorneygeneral.govmu.org
“A company shall keep its accounting records in Mauritius, except where the directors determine that the accounting records may be kept outside Mauritius... Where the records are not kept in Mauritius - (a) the company shall ensure that the accounts and returns for the operations of the company... are sent to, and kept at, a place in Mauritius”
Link checked 19 August 2026
- Official sourceBank of MauritiusGuideline on the Use of Cloud Services, effective 7 September 2022
bom.mu
Link checked 19 August 2026
- Official sourceFinancial Services Commission, MauritiusGuidelines on Cloud Computing Services, issued 30 November 2023
fscmauritius.org
Link checked 19 August 2026
- Official sourceGambling Regulatory Authority, Republic of MauritiusGambling Regulatory Authority Act 2007 as at 16 June 2026, sections 28, 28B and 91A
gra.govmu.org
“Every gaming machine operator shall connect... to a server located at such place designated by the operator and approved by the Board.”
Link checked 19 August 2026
- Official sourceRepublic of MauritiusInformation and Communication Technologies Act 2001 (consolidated) - no telecom data localisation or retention mandate located
civil-aviation.govmu.org
Link checked 19 August 2026
Sending data out of the country
The model is case-by-case approval, not a country list. Before personal data leaves, you must put appropriate protections in place and file proof of them with the privacy regulator. If you cannot provide those protections, you must go and ask the regulator for permission first. Mauritius has published no list of approved destinations and no official standard contract template, so you cannot rely on where the data is going. Requests go through the regulator's online portal, and it approved 112 of them in 2024.
The instrument is section 36 of the Data Protection Act 2017 read with section 35. Section 36(1)(a) is the main route: proof of appropriate safeguards provided to the Commissioner. The alternatives are the data subject's explicit consent given after being told about the risks, or necessity for a contract with or in the interest of the data subject, public interest laid down by law, legal claims, vital interests, or compelling legitimate interests where the transfer is non-repetitive, concerns a limited number of people, and is still backed by proof of safeguards filed with the Commissioner. Public authorities cannot use the safeguards route or the contract and legitimate-interest routes at all (section 36(3)). Section 35(1) requires prior authorisation from the Office where the safeguards under section 36 cannot be provided, and section 35(3) lets the Office prohibit the intended processing outright. Section 36(4) is a standing power to demand evidence and to prohibit, suspend or condition a transfer after the fact. What is absent matters as much as what is present. There is no adequacy list, no gazetted standard contractual clauses, no binding corporate rules scheme and no certification route on the regulator's site as at 19 August 2026. That leaves a bespoke filing for each transfer, submitted through the DPO Portal at dpo.govmu.org. There is no published statutory decision deadline, so build lead time into any project plan. Mauritius acceded to the Council of Europe data protection convention and its 2018 modernising protocol, which is why the Act reads like a European one, but that produces no automatic transfer route in or out.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, section 35(1) (prior authorisation) and section 36
mitci.govmu.org
“Every controller or processor shall obtain authorisation from the Office prior to processing personal data in order to ensure compliance of the intended processing with this Act and in particular to mitigate the risks involved for the data subjects where a controller or processor cannot provide for the appropriate safeguards referred to in section 36 in relation to the transfer of personal data to another country.”
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusTransfer of data abroad - routed through the DPO Portal
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - 112 transfer requests authorised
dataprotection.govmu.org
Link checked 19 August 2026
The regulator, and whether it actually acts
The Data Protection Office, headed by Commissioner Drudeisha Madhub, who has held the post since 2007. It is real and it is working: 209 published decisions up to November 2025, 179 new complaints and 65 site inspections in 2024, 105 breach reports received and 112 transfer approvals granted. But it is thinly staffed, with one officer in post against twelve requested, and its own report says enforcement action has been delayed by that. It issues no fines, because every penalty in the Act is a criminal one that a court must impose. Financial and gambling regulators enforce separately and are fully active.
The Data Protection Office is established by section 4 of the Data Protection Act 2017 and must 'act with complete independence and impartiality'. Evidence it is operational, all from its own site: a continuous published decision series reaching Decision No 209 dated 11 November 2025, roughly 26 decisions issued during 2025, and an Annual Report for 2024 recording 179 new complaints, 65 site-visit inspections carried out with police assistance, 105 notified personal data breaches, 3,076 registration certificates issued and 112 authorised cross-border transfers. The same report records only 1 data protection officer or senior officer in post against 12 requested, and 3 assistant officers against 6 requested, and its foreword attributes delayed enforcement to resource constraints. The important structural point is that the Act contains no administrative fining power. Sections 15, 42 and 43 create criminal offences prosecuted before a court, with the residual offence under section 43 carrying up to 200,000 rupees (roughly 4,300 US dollars) and up to five years' imprisonment. The Commissioner's own output is therefore determinations, enforcement notices, inspections and refusals rather than penalties. The published decisions are dominated by closed-circuit television complaints. Rated active rather than aggressive: the regulator decides cases continuously and gates transfers, but no completed prosecution was reported for 2024 and the money at stake is small. Other enforcers are separate and busy: the Bank of Mauritius for banks, the Financial Services Commission for insurance, securities, funds and global business, the Information and Communication Technologies Authority for networks and content, the Gambling Regulatory Authority for gaming, and CERT-MU for cyber incidents.
Sources
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - complaints, inspections, breach notifications, registrations, transfer authorisations and staffing
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusDecisions on complaints - series running to Decision No 209 dated 11 November 2025
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusThe Data Protection Commissioner - Mrs Drudeisha Madhub, appointed August 2007
dataprotection.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 4, 5, 42 and 43
mitci.govmu.org
“Any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding 200, 000 rupees and to imprisonment for a term not exceeding 5 years.”
Link checked 19 August 2026
How long you must keep it — and when to delete it
Two forces pull against each other. The privacy law says delete: keep personal data only as long as you need it, and destroy it as soon as the purpose has gone. Company law and money-laundering rules say keep: seven years for company records, accounting records and customer due diligence files. The keep rules win where they apply, because the privacy law lets you process where a law requires it. In practice you set a seven-year clock on financial and corporate paperwork and a short, purpose-based clock on everything else.
CEILING. Section 21(e) of the Data Protection Act 2017 requires personal data to be 'kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed'. Section 27 goes further than most laws and imposes a positive duty: where the purpose for keeping personal data has lapsed the controller shall destroy the data as soon as is reasonably practicable and notify any processor holding it, and the processor must then destroy it too. There is no fixed maximum number of years. FLOOR. Section 190(2A) of the Companies Act 2001 requires directors to keep the listed company records 'for a period of at least 7 years from the date of the completion of the transaction, act or operation to which it relates', and to keep doing so even after the company is struck off the register. Section 190(2) fixes seven years or seven completed accounting periods for minutes, directors' certificates, shareholder communications and financial statements. The Bank of Mauritius anti-money-laundering guideline repeatedly sets seven years after completion of the transaction, closure of the account or the date of a report to the Financial Intelligence Unit. CONFLICT RESOLUTION. Section 28 of the Data Protection Act allows processing that is necessary for compliance with a legal obligation, so a statutory retention duty overrides the destruction duty for as long as it runs. The practical trap is the tail: once the seven years expire the section 27 destruction duty revives and the data must actually be deleted, not archived indefinitely.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 21(e), 27 and 28
mitci.govmu.org
“Where the purpose for keeping personal data has lapsed, every controller shall - (a) destroy the data as soon as is reasonably practicable; and (b) notify any processor holding the data.”
Link checked 19 August 2026
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001, sections 190(2), 190(2A) and 193
attorneygeneral.govmu.org
“The directors of a company shall, at all times and even where the company is removed from the register, ensure that the records referred to in subsection (2) are kept for a period of at least 7 years from the date of the completion of the transaction, act or operation to which it relates.”
Link checked 19 August 2026
- Official sourceBank of MauritiusGuideline on Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation, January 2020 - seven-year record retention
bom.mu
Link checked 19 August 2026
If something goes wrong
One firm clock and several soft ones. A personal data breach must be reported to the Commissioner without undue delay and, where possible, within 72 hours of you finding out. If you miss that, you must explain why you were late. Where the breach is likely to seriously harm people, you must also tell them, without undue delay. A supplier who spots a breach must tell the organisation it works for straight away. Cyber incidents affecting critical national systems go to the national cyber team as well, and that route has no fixed deadline in the law.
CLOCK ONE, the only hard one. Section 25(1)(a) of the Data Protection Act 2017: 'In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner.' Section 25(1)(b) requires reasons for any delay. The notification must describe the nature of the breach, approximate numbers of people and records, a contact point, and recommended mitigation. Section 25(2) requires a processor to notify its controller without any undue delay, with no stated hour count. Section 26 requires communication to affected individuals where the breach is likely to result in a high risk to their rights and freedoms, and section 26(4) lets the Commissioner order that communication if you have not made it. The Office received 105 breach notifications in 2024, so the channel is live. CLOCK TWO, soft. Section 35 of the Cybersecurity and Cybercrime Act 2021 requires owners of critical information infrastructure to notify the National Cybersecurity Committee of cybersecurity incidents impacting national security, public safety or public interest, with CERT-MU reporting up to the Committee. No hour count appears in the Act. From 1 June 2026, five sectors are formally designated critical information infrastructure - financial services banking and non-banking, the public service, information and communication technology and broadcasting, energy and water supply, and transport - so this route now has named addressees. CLOCK THREE, supervisory. Banks and non-bank financial institutions also owe incident and outsourcing-failure reporting to the Bank of Mauritius and the Financial Services Commission under their respective guidelines. The common failure is treating the 72-hour privacy clock as the only one and missing the sector notification entirely.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 25 and 26
mitci.govmu.org
“In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationCybersecurity and Cybercrime Act 2021, sections 34 and 35
mitci.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationCybersecurity and Cybercrime (Critical Information Infrastructure Designation) Regulations 2026, GN 113 of 2026, in operation 1 June 2026
mitci.govmu.org
Link checked 19 August 2026
- Official sourceComputer Emergency Response Team of MauritiusCERT-MU incident and vulnerability reporting channel
cert-mu.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024 - 105 personal data breaches reported in 2024
dataprotection.govmu.org
Link checked 19 August 2026
What catches people out
Five things that catch people out. One: suppliers must register too, not just the organisation in charge, and the certificate expires every three years. Two: from January 2027 every organisation must name a privacy officer from its own payroll, holding a certificate from the regulator or a school the regulator approves, with no exemption for tiny firms. Three: getting it wrong is a crime, not a fine, and a person can go to prison for up to five years. Four: your company paperwork must physically stay in Mauritius. Five: the telecoms regulator can order the internet shut off, and did in November 2024.
1. REGISTRATION REACHES PROCESSORS. Section 14 bars any person from acting as controller OR processor unless registered with the Commissioner. A pure supplier that never decides anything about the data still has to register, file a description of the data, say whether it holds special categories, and name the countries it may transfer to. The certificate lasts three years (section 16(3)) and false information on the form is an offence carrying up to 100,000 rupees, about 2,100 US dollars, and five years' imprisonment. 2. THE PRIVACY OFFICER MUST BE YOUR OWN CERTIFIED EMPLOYEE. Regulation 3(1) of the 2026 regulations requires every controller to designate the officer 'from a staff member of the organisation'. You cannot buy this as an outsourced service. Regulation 5(d) requires evidence of certification issued either by the Data Protection Office itself after its own training, or by a training institution the Office has approved. Regulation 3(4) requires the officer's particulars to be sent to the Office within 14 days of designation and within 14 days of any change; regulation 8(1) requires the contact details to be published on the premises or the website. Breaching either is an offence carrying up to 100,000 rupees and five years' imprisonment. There is no size threshold anywhere in the instrument. 3. EVERYTHING IS CRIMINAL. The Act has no administrative fining power. The residual offence under section 43 is up to 200,000 rupees, about 4,300 US dollars, and up to five years' imprisonment, and the court may also order forfeiture of equipment and prohibit the continuing act. The money is small; the criminal record and the stop order are not. 4. COMPANY RECORDS CANNOT LEAVE. Section 190 of the Companies Act 2001 keeps the constitution, share register, minutes, directors' certificates, financial statements and accounting records at the registered office or another place in Mauritius, with 14 days to tell the Registrar if the place changes. Section 194 lets accounting records sit abroad only if six-monthly accounts and returns are sent to and kept at a place in Mauritius. This applies to every Mauritius company, including the thousands of global business entities, and it is invisible if you only read the privacy law. 5. BANK SECRECY SITS ON TOP OF PRIVACY. Section 64 of the Banking Act 2004 makes publishing customer or institution information without express written consent an offence, with up to 500,000 rupees, about 10,600 US dollars, and three years' imprisonment for an individual and up to one million rupees for a body corporate. A standard processor contract does not discharge it; you need explicit secrecy undertakings. 6. THE NETWORK KILL SWITCH IS REAL. Section 18 of the Information and Communication Technologies Act 2001 empowers the Authority to 'take steps to regulate or curtail the harmful and illegal content on the Internet and other information and communication services'. In November 2024 that power was used to order internet providers to block social media platforms nationally in the run-up to the general election; the order was withdrawn after about 24 hours. Nothing has changed in the law since.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 14, 15, 16 and 43
mitci.govmu.org
“Subject to section 44, no person shall act as controller or processor unless he or it is registered with the Commissioner.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026, regulations 3, 5, 8 and 9
mitci.govmu.org
“every controller shall, for the purpose of section 22(2)(e) of the Act, designate, from a staff member of the organisation, a data protection officer for the purpose of carrying out the tasks specified under regulation 4.”
Link checked 19 August 2026
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001, sections 190 and 194
attorneygeneral.govmu.org
Link checked 19 August 2026
- Official sourceBank of MauritiusPublic Notice - Confidentiality obligations under the Banking Act, 21 October 2019
bom.mu
Link checked 19 August 2026
- Official sourceRepublic of MauritiusInformation and Communication Technologies Act 2001 (consolidated), section 18(m)
civil-aviation.govmu.org
“take steps to regulate or curtail the harmful and illegal content on the Internet and other information and communication services”
Link checked 19 August 2026
What's changing next
One dated change dominates: on 1 January 2027 every organisation must have its certified in-house privacy officer in place, so the work has to start now. Owners of systems the government has labelled critical - banking, public service, technology and broadcasting, energy and water, transport - have until 1 June 2027 to comply with directions. Beyond that the government has announced a national cyber agency, a digital identity bill, artificial intelligence rules and social media responsibility measures, none of them law yet. Several powers already on the books could change the picture with no warning.
DATED AND BINDING. - 1 January 2027: the Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026, made 17 June 2026, come into operation. Certification has to be obtained from the Data Protection Office or an Office-approved institution, so capacity is the constraint, not the drafting. - 1 June 2027: owners of designated critical information infrastructure must comply with the Cybersecurity and Cybercrime (Critical Information Infrastructure Designation) Regulations 2026, GN 113 of 2026, which came into operation on 1 June 2026 with a twelve-month compliance window. Designations are reviewed every three years. ANNOUNCED, NOT LAW. The Ministry of Information Technology said in August 2025 that it would bring an Electronic Identity Management Bill anchored on the central population database, critical information infrastructure regulations, artificial intelligence regulation on a hybrid European risk-based and British principles-based model, and social media responsibility measures, and that a National Cyber-Resilience and Cybersecurity Agency would be set up. The Budget Speech 2026-2027 delivered in June 2026 funds a cyber forensic laboratory, a national cybersecurity survey, information security management systems across government, a national fraud reporting and response mechanism at CERT-MU and a threat intelligence sharing platform at the Bank of Mauritius, and promises a National Artificial Intelligence Guideline for higher education and the civil service. A Public Health Bill 2026 covering electronic medical records went to consultative workshop in May 2026. All of these are proposals; none creates an obligation today. DORMANT SWITCHES, which matter more than the bills. - Section 36(4) of the Data Protection Act lets the Commissioner prohibit, suspend or impose conditions on any transfer already under way, with no consultation and no list to check. - Section 35(3) lets the Office prohibit intended processing outright where it thinks risks are insufficiently mitigated. - Section 18 of the Information and Communication Technologies Act supports network-level blocking orders; used in November 2024. - Section 34 of the Cybersecurity and Cybercrime Act 2021 lets a regulatory body direct critical infrastructure owners on security policies and assessments; with the sectors now designated, this can be used immediately and could in principle reach hosting arrangements. - Section 91A of the Gambling Regulatory Authority Act lets the Authority direct internet providers to block offshore gambling sites and direct banks to stop payments.
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026
mitci.govmu.org
“These regulations shall come into operation on 1 January 2027.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationCybersecurity and Cybercrime (Critical Information Infrastructure Designation) Regulations 2026, GN 113 of 2026
mitci.govmu.org
“Every owner of a designated critical information infrastructure shall, within 12 months of the coming into operation of these regulations, comply with these regulations.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationMauritius to roll out new digital regulations in line with National ICT Blueprint, 21 August 2025
mitci.govmu.org
Link checked 19 August 2026
- Official sourceNational Assembly of MauritiusBudget Speech 2026-2027, National Assembly, June 2026 - cyber forensic laboratory, national cybersecurity survey, CERT-MU fraud reporting mechanism, National Artificial Intelligence Guideline
mauritiusassembly.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationMauritius moves towards a modern public health legislation with the Public Health Bill 2026, 22 May 2026
mitci.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017, sections 35(3) and 36(4)
mitci.govmu.org
“The Commissioner may request a person who transfers data to another country to demonstrate the effectiveness of the safeguards or the existence of compelling legitimate interests and may, in order to protect the rights and fundamental freedoms of data subjects, prohibit, suspend or subject the transfer to such conditions as he may determine.”
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Guideline on the Use of Cloud Services, read with the Guidelines on Outsourcing by Financial Institutions
Regulator guideline · BOM/BSD 46/September 2022; Guidelines on Outsourcing revised 13 October 2020
Banks may host data outside Mauritius, but only with the Bank of Mauritius told in advance, given audit and seizure rights in the contract, and kept informed of exactly which countries hold the data. Banking secrecy sits on top and is enforced as a crime.
Enforced by Bank of Mauritius
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Register or notifyNotify the Bank at least 60 days before deploying material cloud services; obtain the Bank's prior authorisation at least 15 working days before signing any material outsourcing agreement.
- Written vendor contractAgreements must give the Bank, the institution, its auditors and any Bank appointee audit and on-site inspection rights, and let the Bank take possession of the services and data if the licence is revoked or a conservator is appointed.
- Secure the dataData on the cloud and the access channel must be encrypted, with the institution retaining the encryption key. Free, personal or community cloud storage is prohibited.
- Keep records of processingMaintain a pre-agreed list of the countries where data will be processed and know the city and country of hosting.
- Keep data for a minimum period — 7 yearsSeven-year retention for customer due diligence, transaction and suspicious transaction records under the anti-money-laundering guideline.
What it costs if you get it wrong
- Loss of your licenceSupervisory action for breach of guidelines issued under the Banking Act 2004
- Criminal liability: MUR 500,000 and 3 years' imprisonment for an individual; MUR 1,000,000 for a body corporate — about $21 thousandDisclosure or publication of customer information contrary to the Banking Act 2004 confidentiality duty
Sources
- Official sourceBank of MauritiusGuideline on the Use of Cloud Services, effective 7 September 2022
bom.mu
“Financial institutions shall notify the Bank of the proposed deployment of material cloud services”
Link checked 19 August 2026
- Official sourceBank of MauritiusGuidelines on Outsourcing by Financial Institutions, revised 13 October 2020
bom.mu
“A financial institution that intends to outsource a material activity is required to notify and obtain the prior authorization of the Bank.”
Link checked 19 August 2026
- Official sourceBank of MauritiusPublic Notice - Confidentiality obligations under the Banking Act, 21 October 2019
bom.mu
Link checked 19 August 2026
- Official sourceBank of MauritiusGuideline on Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation, January 2020
bom.mu
Link checked 19 August 2026
Guidelines on Cloud Computing Services
Regulator guideline · Financial Services Commission, issued 30 November 2023 under the Financial Services Act 2007
Insurers, fund managers, securities firms, management companies and global business entities may use offshore cloud, but must tell the Financial Services Commission 15 business days before anything material goes live, must know and disclose which countries hold the data, and must be able to pull any record back at any time.
Enforced by Financial Services Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Register or notifyNotify the Financial Services Commission in writing at least 15 business days before deploying any material cloud computing service.
- Keep records of processingObtain from the provider the countries where data is stored and the safeguards in place, and require reasonable notice of any change of storage or processing location. Keep an updated register of the services used.
- Written vendor contractThe licensee must be able to retrieve any information or document held by the provider at any point in time.
- Independent auditBoard-level responsibility for compliance with the record-keeping obligations under the Financial Services Act.
What it costs if you get it wrong
- Loss of your licenceRegulatory action for breach of guidelines issued by the Commission
Sources
- Official sourceFinancial Services Commission, MauritiusGuidelines on Cloud Computing Services, 30 November 2023
fscmauritius.org
“Licensees shall notify the FSC in writing, at least 15 business days prior to the deployment of any material cloud computing services.”
Link checked 19 August 2026
- Official sourceFinancial Services Commission, MauritiusCirculars and legal framework
fscmauritius.org
Link checked 19 August 2026
Gambling Regulatory Authority Act 2007
Act of parliament · Act No. 9 of 2007 as at 16 June 2026, sections 28, 28B and 91A; section 91A added by Act 12 of 2023
Gambling operators cannot choose where their game servers sit. The regulator's board must approve the location and the Authority must get direct access to the server. It can also order internet providers to block offshore gambling sites and order banks to stop payments to them.
Enforced by Gambling Regulatory Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryGaming machines and limited payout machines must be connected to a server at a place designated by the operator and approved by the Board, and the Authority must be given direct access to that server.
- Register or notifyInteractive gambling requires a licence; a person is deemed to conduct interactive gambling if he maintains any computer or electronic communication system in Mauritius by means of which it is operated.
- Keep records of processingRegulations may require that proper records are kept and that the operation is supervised by the Authority and its inspectors.
What it costs if you get it wrong
- Loss of your licenceOperating or connecting a server without Board approval
- Order to stopDirections to internet providers to block offshore gambling sites and to banks to stop payments, under section 91A
- Criminal liabilityOperating interactive gambling from outside Mauritius while allowing access to people physically present in Mauritius
Sources
- Official sourceGambling Regulatory Authority, Republic of MauritiusGambling Regulatory Authority Act 2007 as at 16 June 2026, sections 28(5), 28B(6), 91 and 91A
gra.govmu.org
“Every gaming machine operator shall connect - (a) forthwith any gaming machine brought into operation on or after 10 September 2007... to a server located at such place designated by the operator and approved by the Board.”
Link checked 19 August 2026
- Official sourceGambling Regulatory Authority, Republic of MauritiusLegislations and Policies
gra.govmu.org
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Data Protection Act 2017
Act of parliament · Act No. 20 of 2017; proclaimed by Proclamation No. 3 of 2018
The general privacy law. It reaches you only if you are established in Mauritius or use equipment there, but if it does reach you, you must register, name a local representative if you are foreign, and get the regulator comfortable before personal data goes abroad. All penalties are criminal.
Enforced by Data Protection Office
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Register or notifyControllers and processors alike. Certificate valid 3 years.
- Appoint a local representative — applies at: Foreign controllers and processors using equipment in MauritiusRepresentative must be established in Mauritius.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of processing
- Assess high-risk projectsRequired for high-risk processing; must be provided to the Office on request.
- Report breaches to the regulator — within 72 hoursReasons required if late.
- Tell affected peopleWhere the breach is likely to result in a high risk.
- Delete data after a periodPositive duty to destroy once the purpose has lapsed, and to tell processors to destroy.
- Put a transfer safeguard in placeProof of appropriate safeguards must be provided to the Commissioner.
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: MUR 200,000 and 5 years' imprisonment — about $4 thousandResidual offence: any contravention with no specific penalty
- Criminal liability: MUR 100,000 and 5 years' imprisonment — about $2 thousandFalse or misleading information in a registration application
- Order to stop: Court order prohibiting the act; prohibition or suspension of a transfer by the CommissionerContinuing contravention, or unsafe cross-border transfer
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection Act 2017 (consolidated text)
mitci.govmu.org
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationLegislations page listing the Data Protection Act 2017 and its regulations
mitci.govmu.org
Link checked 19 August 2026
- Official sourceData Protection Office, Republic of MauritiusData Protection Office Annual Report 2024
dataprotection.govmu.org
Link checked 19 August 2026
Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026
Directly binding regulation · Government Notice No. 117 of 2026, made under section 55 of the Data Protection Act
From 1 January 2027 every organisation that decides how personal data is used must appoint a data protection officer from its own staff, certified by the regulator or a regulator-approved trainer, tell the regulator within 14 days and publish the contact details. This instrument does not restrict where data is stored; it restricts who can hold the job.
Enforced by Data Protection Office
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Appoint a data protection officer — applies at: Every controller, no size exemption, from 1 January 2027Must be designated from a staff member of the organisation. Where more than one is designated, a lead officer must be named as primary contact with the Office.
- Hold a security certificate — from 1 January 2027The officer must hold certification from the Data Protection Office after its training, or from a training institution approved by the Office.
- Publish a complaints contact — from 1 January 2027Contact details must be published at a conspicuous place on the premises or on the website.
- Tell people what you do — from 1 January 2027Officer's particulars must be communicated to the Office within 14 days of designation and within 14 days of any change.
- Independent audit — from 1 January 2027The officer must run internal audits and assist the Office with compliance audits, security checks and inspections.
What it costs if you get it wrong
- Criminal liability: MUR 100,000 and 5 years' imprisonment — about $2 thousandFailure to notify the officer's particulars within 14 days, or failure to publish the officer's contact details
Sources
- Official sourceMinistry of Information Technology, Communication and InnovationData Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, GN 117 of 2026
mitci.govmu.org
“These regulations shall come into operation on 1 January 2027. Made by the Minister, after consultation with the Data Protection Commissioner, on 17 June 2026.”
Link checked 19 August 2026
- Official sourceMinistry of Information Technology, Communication and InnovationLegislations page listing the 2026 data protection officer regulations
mitci.govmu.org
Link checked 19 August 2026
Companies Act 2001
Act of parliament · Act No. 15 of 2001, sections 190, 191, 193 and 194; section 190 amended by Act 11 of 2018
Every Mauritius company must keep its constitution, share register, minutes, directors' certificates, financial statements and accounting records inside Mauritius. Accounting records may sit abroad only if summary accounts and returns are still sent back to and held at a place in Mauritius and the Registrar is told where.
Enforced by Registrar of Companies (Corporate and Business Registration Department)
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryCompany records must be kept at the registered office or, on notice to the Registrar, at any other place in Mauritius. Accounting records may be kept abroad only if six-monthly accounts and returns are sent to and kept at a place in Mauritius.
- Keep data for a minimum period — 7 yearsAt least 7 years from completion of the transaction, act or operation, and the duty survives removal of the company from the register.
- Keep records of processingRecords must be in English or French, or in a form easily convertible to written English or French, with measures to prevent and detect falsification.
Sources
- Official sourceAttorney General's Office, Republic of MauritiusCompanies Act 2001 (Revised Laws of Mauritius), sections 190, 191, 193 and 194
attorneygeneral.govmu.org
“Subject to subsection (4) and to sections 91 (1) and 194, a company shall keep at its registered office the records specified in subsection (2)... The documents specified in subsection (2) may be kept at any other place in Mauritius, notice of which shall be given to the Registrar.”
Link checked 19 August 2026
- Official sourceMinistry of Finance, Republic of MauritiusCompanies Act 2001 as published by the Ministry of Finance
mof.govmu.org
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the Data Protection Office publishes no adequacy list, no standard contractual clauses and no binding corporate rules scheme
This is a negative. We searched the regulator's own site on 19 August 2026 and found only a portal-based transfer request route and no published mechanism library. Absence of evidence, not proof of absence.
Whether the Data Protection Office has issued any decision, or the Commissioner has changed, between November 2025 and 19 August 2026
The published decisions page ends at Decision No 209 dated 11 November 2025 and the latest annual report on the site covers 2024. We cannot tell whether nothing was decided or nothing was published.
Whether there is any statutory or published service standard for how long a cross-border transfer authorisation takes
No timeframe found in the Act or on the regulator's site. Plan for an open-ended wait.
Telecom-specific data retention or localisation obligations in licence conditions
The Information and Communication Technologies Act 2001 contains no retention or localisation mandate that we could locate. Individual licence conditions issued by the ICT Authority are not published in full, so a licence-level obligation cannot be ruled out.
Any government cloud, public sector hosting or education data localisation policy
No published instrument found on government domains, checked 19 August 2026. Government hosting is concentrated at the Government Online Centre in practice, but we found no rule requiring it.
Health sector storage rules
No health-specific data storage or transfer instrument found. The Public Health Bill 2026 is at consultation stage only and its text is not published on a government domain we could reach.
Tax record retention periods under the Income Tax Act 1995 and the Value Added Tax Act 1998
The Mauritius Revenue Authority overview page does not state a retention period and we did not reach the operative sections of the tax statutes. The seven-year figure in this record comes from company law and anti-money-laundering rules, which we did verify.
Whether the Cybersecurity and Cybercrime Act 2021 has been fully proclaimed
The Act says it comes into operation on a date fixed by Proclamation and the consolidated copy we read does not carry the proclamation note. The 2026 critical information infrastructure regulations were made under it and are in force, which strongly implies commencement, but we could not open the proclamation itself.
That Mauritius has acceded to the Council of Europe data protection convention and its modernising protocol
Widely reported and consistent with the shape of the Act, but the accession instruments sit on a Council of Europe domain, not a Mauritius government domain, so this is stated as background only.
Whether the six-month compliance moratorium reported by professional commentators for the 2026 data protection officer regulations exists
The gazetted text contains only a commencement date of 1 January 2027 and no transitional provision. Treat 1 January 2027 as the hard date.
Insurance-specific and securities-specific record location rules beyond the cloud guidelines
We verified the Financial Services Commission cloud guidelines but did not open the underlying record-keeping provisions of the Financial Services Act 2007 or the Insurance Act 2005.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.
Put this next to another country
Mauritius versus
Compare