Skip to the content
Global Data RulesData governance rules, country by country

Mauritius

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Mauritius — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Personal data can leave Mauritius, but almost never without paperwork. You have to satisfy the privacy regulator that the data will still be protected. The regulator signs transfers off one at a time. Every organisation that handles personal data must also register with it. From January 2027 each one must name a trained, certified privacy officer from its own staff.

Data governance in Mauritius

The eight things that decide how you handle data about people in Mauritius. Same eight on every country page, so you can compare.

Who has to follow these rules

Only if you have a foothold on the island. The law catches you if you are set up in Mauritius, meaning you live there or run an office, branch or agency there. It also catches you if you are not set up there but use equipment inside Mauritius to handle the data. Selling to Mauritians from abroad, with no kit on the island, is not enough by itself. If you do use equipment there, you must name a representative based in Mauritius, and you must register with the privacy regulator before you start. There is no size or revenue floor to duck under.

What you have to do here:
Appoint a representative · Register or notify

Where the data is allowed to live

Yes, but you have to earn it. The general rule is that personal data may go abroad if you can show the privacy regulator it will still be properly protected. A few narrow exceptions also work, such as the person's explicit informed consent. The regulator runs this as an approval queue. It cleared 112 transfer requests in 2024. There is no list of pre-approved countries, so no destination is automatically safe. Several industries add their own gate on top, and company law adds a hard one that has nothing to do with privacy.

What you have to do here:
Keep the data in the country · Put a transfer safeguard in place

What to do: Get the paperwork for one of the routes below signed before any data leaves Mauritius.

Sending data out of the country

The model is case-by-case approval, not a country list. Before personal data leaves, you must put appropriate protections in place and file proof of them with the privacy regulator. If you cannot provide those protections, you must go and ask the regulator for permission first. Mauritius has published no list of approved destinations and no official standard contract template, so you cannot rely on where the data is going. Requests go through the regulator's online portal, and it approved 112 of them in 2024.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

The Data Protection Office, headed by Commissioner Drudeisha Madhub, who has held the post since 2007. It is real and it is working: 209 published decisions up to November 2025, 179 new complaints and 65 site inspections in 2024, 105 breach reports received and 112 transfer approvals granted. But it is thinly staffed, with one officer in post against twelve requested, and its own report says enforcement action has been delayed by that. It issues no fines, because every penalty in the Act is a criminal one that a court must impose. Financial and gambling regulators enforce separately and are fully active.

What it costs if you get it wrong:
Criminal liability

How long you must keep it — and when to delete it

Two forces pull against each other. The privacy law says delete. Keep personal data only as long as you need it, and destroy it as soon as the purpose has gone. Company law and money-laundering rules say keep. That is seven years for company records, accounting records and customer due diligence files. The keep rules win where they apply, because the privacy law lets you use data where a law requires it. So set a seven-year clock on financial and company paperwork, and a short, purpose-based clock on everything else.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

One firm clock and several soft ones. A personal data breach must be reported to the Commissioner without undue delay and, where possible, within 72 hours of you finding out. If you miss that, you must explain why you were late. Where the breach is likely to seriously harm people, you must also tell them, without undue delay. A supplier who spots a breach must tell the organisation it works for straight away. Cyber incidents affecting critical national systems go to the national cyber team as well, and that route has no fixed deadline in the law.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents · Secure the data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that catch people out. One: suppliers must register too, not just the organisation in charge, and the certificate expires every three years. Two: from January 2027 every organisation must name a privacy officer from its own payroll, holding a certificate from the regulator or a school the regulator approves, with no exemption for tiny firms. Three: getting it wrong is a crime, not a fine, and a person can go to prison for up to five years. Four: your company paperwork must physically stay in Mauritius. Five: the telecoms regulator can order the internet shut off, and did in November 2024.

What you have to do here:
Register or notify · Hold a security certificate · Extra vendor secrecy terms · Keep the data in the country
What it costs if you get it wrong:
Criminal liability · Order to stop

What's changing next

One dated change dominates. On 1 January 2027 every organisation must have its certified in-house privacy officer in place, so the work has to start now. Owners of systems the government has labelled critical have until 1 June 2027 to comply with directions. Those are banking, public service, technology and broadcasting, energy and water, and transport. Beyond that the government has announced a national cyber agency, a digital identity bill, artificial intelligence rules and social media measures. None of them is law yet. Several powers already on the books could change the answer with no warning.

What you have to do here:
Appoint a data protection officer · Hold a security certificate

What to do: Diarise 1 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking rules

Official name: Guideline on the Use of Cloud Services, read with the Guidelines on Outsourcing by Financial Institutions · BOM/BSD 46/September 2022; Guidelines on Outsourcing revised 13 October 2020 · Regulator guideline

In forceYes, with paperwork

Banks may host data outside Mauritius, but only with the Bank of Mauritius told in advance, given audit and seizure rights in the contract, and kept informed of exactly which countries hold the data. Banking secrecy sits on top and is enforced as a crime.

In force since 7 September 2022Enforced from 7 September 2023

Enforced by Bank of Mauritius

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed

Finance

Cloud and outsourcing rules

Official name: Guidelines on Cloud Computing Services · Financial Services Commission, issued 30 November 2023 under the Financial Services Act 2007 · Regulator guideline

In forceYes, with paperwork

Insurers, fund managers, securities firms, management companies and global business entities may use offshore cloud, but must tell the Financial Services Commission 15 business days before anything material goes live, must know and disclose which countries hold the data, and must be able to pull any record back at any time.

In force since 30 November 2023Enforced from 30 May 2024

Enforced by Financial Services Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed

Online gaming

Payment data rules

Official name: Gambling Regulatory Authority Act 2007 · Act No. 9 of 2007 as at 16 June 2026, sections 28, 28B and 91A; section 91A added by Act 12 of 2023 · Act of parliament

In forceYes, with paperwork

Gambling operators cannot choose where their game servers sit. The regulator's board must approve the location and the Authority must get direct access to the server. It can also order internet providers to block offshore gambling sites and order banks to stop payments to them.

In force since 10 September 2007Enforced from 20 July 2023

Enforced by Gambling Regulatory Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Data Protection Act 2017 · Act No. 20 of 2017; proclaimed by Proclamation No. 3 of 2018 · Act of parliament

In forceYes, with paperwork

The general privacy law. It reaches you only if you are set up in Mauritius or use equipment there. If it does reach you, you must register with the regulator. If you are foreign, you must also name a local representative. And you must satisfy the regulator before personal data goes abroad. All penalties are criminal.

In force since 15 January 2018

Enforced by Data Protection Office

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

General data protection law (2027)

Official name: Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 · Government Notice No. 117 of 2026, made under section 55 of the Data Protection Act · Directly binding regulation

Passed, not yet fully in forceYes — store it anywhere

From 1 January 2027 every organisation that decides how personal data is used must appoint a data protection officer from its own staff. The officer must be certified by the regulator or a regulator-approved trainer. You must tell the regulator within 14 days and publish the contact details. This rule does not restrict where data is stored. It restricts who can hold the job.

In force since 1 January 2027

Enforced by Data Protection Office

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Personal data needs a copy kept in the country

Official name: Companies Act 2001 · Act No. 15 of 2001, sections 190, 191, 193 and 194; section 190 amended by Act 11 of 2018 · Act of parliament

In forceA copy must stay

Every Mauritius company must keep its constitution, share register, minutes, directors' certificates, financial statements and accounting records inside Mauritius. Accounting records may sit abroad only if summary accounts and returns are still sent back to and held at a place in Mauritius and the Registrar is told where.

In force since 1 December 2001

Enforced by Registrar of Companies (Corporate and Business Registration Department)

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Data Protection Office / Bureau de la protection des donnees

    General personal data protection, registration of controllers and processors, cross-border transfer authorisations

    Fully constituted and issuing decisions. Commissioner Mrs Drudeisha Madhub has held the post since August 2007. Published decision series reaches Decision No 209 dated 11 November 2025. In 2024 it recorded 179 new complaints, 65 site-visit inspections, 105 breach notifications, 3,076 registration certificates and 112 authorised cross-border transfers. Severely under-resourced: 1 data protection officer or senior officer in post against 12 requested, and its own annual report attributes delayed enforcement to that. It issues no fines because the Act creates only criminal offences; no completed prosecution was reported for 2024.

  • Ministry of Information Technology, Communication and Innovation

    Rule-making under the Data Protection Act and the Cybersecurity and Cybercrime Act; publisher of the official legislation set

    Active. Made the data protection officer regulations on 17 June 2026 and the critical information infrastructure designation regulations on 29 May 2026.

  • Bank of Mauritius / Banque de Maurice

    Banks and non-bank deposit takers: outsourcing, cloud, anti-money-laundering and banking confidentiality

    Active supervisor. Issues guidelines, public notices and enforcement action, and is rolling out a bank threat intelligence sharing platform announced in the 2026-2027 Budget.

  • Financial Services Commission, Mauritius

    Insurance, securities, funds, management companies, global business and fintech

    Active. Issued cloud computing guidelines in November 2023 and maintains a live circulars series.

  • ICT Authority

    Telecoms and internet licensing, network standards, content-related directions to internet service providers

    Active.

  • CERT-MU

    National cyber incident response and reporting for critical information infrastructure

    Active. Operates incident and vulnerability reporting channels and was funded in the 2026-2027 Budget to build a national fraud reporting and response mechanism.

  • Gambling Regulatory Authority

    Gaming and betting licensing, server approval and blocking directions

    Active. Published a consolidated Act as at 16 June 2026, licensing guidelines in February 2026 and technical standards regulations in 2024.

  • Registrar of Companies

    Company incorporation, registered office and company records requirements

    Active registry. Receives the statutory notices about where a company keeps its records.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the Data Protection Office publishes no adequacy list, no standard contractual clauses and no binding corporate rules scheme

    We found no published library of transfer mechanisms. The regulator's site shows only a portal-based request route, checked 19 August 2026. If you plan a transfer, ask the Office what it will accept.

  • Whether the Data Protection Office has issued any decision, or the Commissioner has changed, between November 2025 and 19 August 2026

    The published decisions page ends at Decision No 209 dated 11 November 2025, and the latest annual report on the site covers 2024. We cannot tell whether nothing was decided or nothing was published. Check the regulator's decision page for anything newer.

  • Whether there is any statutory or published service standard for how long a cross-border transfer authorisation takes

    We found no deadline in the Act or on the regulator's site. Plan for an open-ended wait, and ask the Office for an expected timeline before you commit to a launch date.

  • Telecom-specific data retention or localisation obligations in licence conditions

    We found no duty in the Information and Communication Technologies Act 2001 to keep records or to store data in Mauritius. Individual licence conditions from the ICT Authority are not published in full, so a duty in your own licence is possible. If you hold a telecoms licence, read its conditions.

  • Any government cloud, public sector hosting or education keeping data in the country policy

    We found no published rule requiring government data to stay in Mauritius, checked 19 August 2026. Government hosting is concentrated at the Government Online Centre, but we found no rule that requires it. If you sell to a Mauritian public body, ask what its contract requires.

  • Health sector storage rules

    We found no health-specific rule on storing or transferring data. The Public Health Bill 2026 is at consultation stage and we could not find its text on a government site. If you work in health, check with the Ministry of Health before you rely on this.

  • Tax record retention periods under the Income Tax Act 1995 and the Value Added Tax Act 1998

    We could not confirm a tax record retention period from a government source. The Mauritius Revenue Authority overview page does not state one. The seven-year figure in this record comes from company law and anti-money-laundering rules, which we did verify. Check with your tax adviser before you set a tax retention period.

  • Whether the Cybersecurity and Cybercrime Act 2021 has been fully proclaimed

    We could not confirm the commencement date. The Act says it starts on a date fixed by Proclamation, and the consolidated copy we read does not carry that note. The 2026 critical information infrastructure regulations were made under the Act and are in force, which strongly suggests it has started.

  • That Mauritius has acceded to the Council of Europe data protection convention and its modernising protocol

    Widely reported and consistent with how the Act is written. The accession papers sit on a Council of Europe site rather than a Mauritius government site, so we treat this as background only.

  • Whether the six-month compliance moratorium reported by professional commentators for the 2026 data protection officer regulations exists

    The published text gives a start date of 1 January 2027 and says nothing about a transition period. Treat 1 January 2027 as a firm date.

  • Insurance-specific and securities-specific record location rules beyond the cloud guidelines

    We verified the Financial Services Commission cloud guidelines. We did not read the record-keeping sections of the Financial Services Act 2007 or the Insurance Act 2005, so those exact duties are unconfirmed. Check them if you are licensed under either Act.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.