Skip to the content
Global Data RulesData governance rules, country by country

Mauritius

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Personal data can leave Mauritius, but almost never without paperwork. You have to satisfy the privacy regulator that the data will still be protected, and in practice the regulator signs transfers off one at a time. Every organisation that handles personal data must also register with it. From January 2027 each one must name a trained, certified privacy officer from its own staff.

Data governance in Mauritius

The eight things that decide how you handle data about people in Mauritius. Same eight on every country page, so you can compare.

Who has to follow these rules

Only if you have a foothold on the island. The law catches you if you are set up in Mauritius, meaning you live there or run an office, branch or agency there. It also catches you if you are not set up there but use equipment inside Mauritius to handle the data. Selling to Mauritians from abroad, with no kit on the island, is not enough by itself. If you do use equipment there, you must name a representative based in Mauritius, and you must register with the privacy regulator before you start. There is no size or revenue floor to duck under.

High confidenceNational rulesAppoint a local representativeRegister or notify

Where the data is allowed to live

Yes, but you have to earn it. The general rule is that personal data may go abroad if you can show the privacy regulator that it will still be properly protected, or if a narrow exception applies such as the person's explicit informed consent. In practice the regulator handles this as an approval queue: it cleared 112 transfer requests in 2024. There is no list of pre-approved countries, so no destination is automatically safe. Several industries add their own gate on top, and company law adds a hard one that has nothing to do with privacy.

High confidenceYes, with paperworkApproval each timeBankingInsuranceSecuritiesOnline gamingKeep the data in the countryPut a transfer safeguard in place

Sending data out of the country

The model is case-by-case approval, not a country list. Before personal data leaves, you must put appropriate protections in place and file proof of them with the privacy regulator. If you cannot provide those protections, you must go and ask the regulator for permission first. Mauritius has published no list of approved destinations and no official standard contract template, so you cannot rely on where the data is going. Requests go through the regulator's online portal, and it approved 112 of them in 2024.

High confidenceApproval each timeGovernment sign-off neededExplicit consentNeeded for a contractImportant public interestLegal claimsSomeone's life is at riskPut a transfer safeguard in place

The regulator, and whether it actually acts

The Data Protection Office, headed by Commissioner Drudeisha Madhub, who has held the post since 2007. It is real and it is working: 209 published decisions up to November 2025, 179 new complaints and 65 site inspections in 2024, 105 breach reports received and 112 transfer approvals granted. But it is thinly staffed, with one officer in post against twelve requested, and its own report says enforcement action has been delayed by that. It issues no fines, because every penalty in the Act is a criminal one that a court must impose. Financial and gambling regulators enforce separately and are fully active.

High confidenceActiveCriminal liability

How long you must keep it — and when to delete it

Two forces pull against each other. The privacy law says delete: keep personal data only as long as you need it, and destroy it as soon as the purpose has gone. Company law and money-laundering rules say keep: seven years for company records, accounting records and customer due diligence files. The keep rules win where they apply, because the privacy law lets you process where a law requires it. In practice you set a seven-year clock on financial and corporate paperwork and a short, purpose-based clock on everything else.

High confidenceDelete data after a periodKeep data for a minimum periodKeep records of processing

If something goes wrong

One firm clock and several soft ones. A personal data breach must be reported to the Commissioner without undue delay and, where possible, within 72 hours of you finding out. If you miss that, you must explain why you were late. Where the breach is likely to seriously harm people, you must also tell them, without undue delay. A supplier who spots a breach must tell the organisation it works for straight away. Cyber incidents affecting critical national systems go to the national cyber team as well, and that route has no fixed deadline in the law.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsSecure the data

What catches people out

Five things that catch people out. One: suppliers must register too, not just the organisation in charge, and the certificate expires every three years. Two: from January 2027 every organisation must name a privacy officer from its own payroll, holding a certificate from the regulator or a school the regulator approves, with no exemption for tiny firms. Three: getting it wrong is a crime, not a fine, and a person can go to prison for up to five years. Four: your company paperwork must physically stay in Mauritius. Five: the telecoms regulator can order the internet shut off, and did in November 2024.

High confidenceRegister or notifyAppoint a data protection officerHold a security certificateExtra vendor secrecy termsKeep the data in the countryCriminal liabilityOrder to stop

What's changing next

One dated change dominates: on 1 January 2027 every organisation must have its certified in-house privacy officer in place, so the work has to start now. Owners of systems the government has labelled critical - banking, public service, technology and broadcasting, energy and water, transport - have until 1 June 2027 to comply with directions. Beyond that the government has announced a national cyber agency, a digital identity bill, artificial intelligence rules and social media responsibility measures, none of them law yet. Several powers already on the books could change the picture with no warning.

High confidencePassed, not yet fully in forceProposedAppoint a data protection officerHold a security certificate

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Guideline on the Use of Cloud Services, read with the Guidelines on Outsourcing by Financial Institutions

Regulator guideline · BOM/BSD 46/September 2022; Guidelines on Outsourcing revised 13 October 2020

In forceYes, with paperwork

Banks may host data outside Mauritius, but only with the Bank of Mauritius told in advance, given audit and seizure rights in the contract, and kept informed of exactly which countries hold the data. Banking secrecy sits on top and is enforced as a crime.

In force since 7 September 2022But only enforceable from 7 September 2023

Enforced by Bank of Mauritius

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed

High confidence
Finance

Guidelines on Cloud Computing Services

Regulator guideline · Financial Services Commission, issued 30 November 2023 under the Financial Services Act 2007

In forceYes, with paperwork

Insurers, fund managers, securities firms, management companies and global business entities may use offshore cloud, but must tell the Financial Services Commission 15 business days before anything material goes live, must know and disclose which countries hold the data, and must be able to pull any record back at any time.

In force since 30 November 2023But only enforceable from 30 May 2024

Enforced by Financial Services Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed

High confidence
Online gaming

Gambling Regulatory Authority Act 2007

Act of parliament · Act No. 9 of 2007 as at 16 June 2026, sections 28, 28B and 91A; section 91A added by Act 12 of 2023

In forceYes, with paperwork

Gambling operators cannot choose where their game servers sit. The regulator's board must approve the location and the Authority must get direct access to the server. It can also order internet providers to block offshore gambling sites and order banks to stop payments to them.

In force since 10 September 2007But only enforceable from 20 July 2023

Enforced by Gambling Regulatory Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Data Protection Act 2017

Act of parliament · Act No. 20 of 2017; proclaimed by Proclamation No. 3 of 2018

In forceYes, with paperwork

The general privacy law. It reaches you only if you are established in Mauritius or use equipment there, but if it does reach you, you must register, name a local representative if you are foreign, and get the regulator comfortable before personal data goes abroad. All penalties are criminal.

In force since 15 January 2018

Enforced by Data Protection Office

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026

Directly binding regulation · Government Notice No. 117 of 2026, made under section 55 of the Data Protection Act

Passed, not yet fully in forceYes — store it anywhere

From 1 January 2027 every organisation that decides how personal data is used must appoint a data protection officer from its own staff, certified by the regulator or a regulator-approved trainer, tell the regulator within 14 days and publish the contact details. This instrument does not restrict where data is stored; it restricts who can hold the job.

In force since 1 January 2027

Enforced by Data Protection Office

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Companies Act 2001

Act of parliament · Act No. 15 of 2001, sections 190, 191, 193 and 194; section 190 amended by Act 11 of 2018

In forceA copy must stay

Every Mauritius company must keep its constitution, share register, minutes, directors' certificates, financial statements and accounting records inside Mauritius. Accounting records may sit abroad only if summary accounts and returns are still sent back to and held at a place in Mauritius and the Registrar is told where.

In force since 1 December 2001

Enforced by Registrar of Companies (Corporate and Business Registration Department)

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Data Protection Office / Bureau de la protection des donnees

    General personal data protection, registration of controllers and processors, cross-border transfer authorisations

    Fully constituted and issuing decisions. Commissioner Mrs Drudeisha Madhub has held the post since August 2007. Published decision series reaches Decision No 209 dated 11 November 2025. In 2024 it recorded 179 new complaints, 65 site-visit inspections, 105 breach notifications, 3,076 registration certificates and 112 authorised cross-border transfers. Severely under-resourced: 1 data protection officer or senior officer in post against 12 requested, and its own annual report attributes delayed enforcement to that. It issues no fines because the Act creates only criminal offences; no completed prosecution was reported for 2024.

  • Ministry of Information Technology, Communication and Innovation

    Rule-making under the Data Protection Act and the Cybersecurity and Cybercrime Act; publisher of the official legislation set

    Active. Made the data protection officer regulations on 17 June 2026 and the critical information infrastructure designation regulations on 29 May 2026.

  • Bank of Mauritius / Banque de Maurice

    Banks and non-bank deposit takers: outsourcing, cloud, anti-money-laundering and banking confidentiality

    Active supervisor. Issues guidelines, public notices and enforcement action, and is rolling out a bank threat intelligence sharing platform announced in the 2026-2027 Budget.

  • Financial Services Commission, Mauritius

    Insurance, securities, funds, management companies, global business and fintech

    Active. Issued cloud computing guidelines in November 2023 and maintains a live circulars series.

  • ICT Authority

    Telecoms and internet licensing, network standards, content-related directions to internet service providers

    Active. Used its powers in November 2024 to order national blocking of social media platforms before the general election, then withdrew the order.

  • CERT-MU

    National cyber incident response and reporting for critical information infrastructure

    Active. Operates incident and vulnerability reporting channels and was funded in the 2026-2027 Budget to build a national fraud reporting and response mechanism.

  • Gambling Regulatory Authority

    Gaming and betting licensing, server approval and blocking directions

    Active. Published a consolidated Act as at 16 June 2026, licensing guidelines in February 2026 and technical standards regulations in 2024.

  • Registrar of Companies

    Company incorporation, registered office and company records requirements

    Active registry. Receives the statutory notices about where a company keeps its records.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the Data Protection Office publishes no adequacy list, no standard contractual clauses and no binding corporate rules scheme

    This is a negative. We searched the regulator's own site on 19 August 2026 and found only a portal-based transfer request route and no published mechanism library. Absence of evidence, not proof of absence.

  • Whether the Data Protection Office has issued any decision, or the Commissioner has changed, between November 2025 and 19 August 2026

    The published decisions page ends at Decision No 209 dated 11 November 2025 and the latest annual report on the site covers 2024. We cannot tell whether nothing was decided or nothing was published.

  • Whether there is any statutory or published service standard for how long a cross-border transfer authorisation takes

    No timeframe found in the Act or on the regulator's site. Plan for an open-ended wait.

  • Telecom-specific data retention or localisation obligations in licence conditions

    The Information and Communication Technologies Act 2001 contains no retention or localisation mandate that we could locate. Individual licence conditions issued by the ICT Authority are not published in full, so a licence-level obligation cannot be ruled out.

  • Any government cloud, public sector hosting or education data localisation policy

    No published instrument found on government domains, checked 19 August 2026. Government hosting is concentrated at the Government Online Centre in practice, but we found no rule requiring it.

  • Health sector storage rules

    No health-specific data storage or transfer instrument found. The Public Health Bill 2026 is at consultation stage only and its text is not published on a government domain we could reach.

  • Tax record retention periods under the Income Tax Act 1995 and the Value Added Tax Act 1998

    The Mauritius Revenue Authority overview page does not state a retention period and we did not reach the operative sections of the tax statutes. The seven-year figure in this record comes from company law and anti-money-laundering rules, which we did verify.

  • Whether the Cybersecurity and Cybercrime Act 2021 has been fully proclaimed

    The Act says it comes into operation on a date fixed by Proclamation and the consolidated copy we read does not carry the proclamation note. The 2026 critical information infrastructure regulations were made under it and are in force, which strongly implies commencement, but we could not open the proclamation itself.

  • That Mauritius has acceded to the Council of Europe data protection convention and its modernising protocol

    Widely reported and consistent with the shape of the Act, but the accession instruments sit on a Council of Europe domain, not a Mauritius government domain, so this is stated as background only.

  • Whether the six-month compliance moratorium reported by professional commentators for the 2026 data protection officer regulations exists

    The gazetted text contains only a commencement date of 1 January 2027 and no transitional provision. Treat 1 January 2027 as the hard date.

  • Insurance-specific and securities-specific record location rules beyond the cloud guidelines

    We verified the Financial Services Commission cloud guidelines but did not open the underlying record-keeping provisions of the Financial Services Act 2007 or the Insurance Act 2005.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Mauritius versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.