Skip to content

Evidence request lists

Data Protection Act 2017

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Mauritius DPA 2017: Part II - Data Protection Office and Commissioner

MU-DPA17-s4-5
Data Protection Office and functions of the Commissioner

Establishes the Data Protection Office and sets the functions of the Data Protection Commissioner, the independent supervisory authority that ensures compliance with the Act.

Artefacts an auditor will ask for
  • Awareness of the Commissioner's jurisdiction and points of cooperation
  • Records of interaction with the Data Protection Office
Where this commonly fails
  • No designated contact for the Commissioner
MU-DPA17-s6-13
Investigation, enforcement notices and powers of the Commissioner

Empowers the Commissioner to investigate complaints, require information, issue preservation and enforcement notices, enter and search premises, and act against obstruction.

Artefacts an auditor will ask for
  • Procedure to respond to Commissioner information requests, preservation and enforcement notices
  • Cooperation with entry/search where lawful
Where this commonly fails
  • Failure to comply with an enforcement or preservation notice
  • Obstructing the Commissioner

Mauritius DPA 2017: Part III - Registration of Controllers and Processors

MU-DPA17-s14-20
Registration of controllers and processors

Requires every controller and processor to be registered with the Commissioner, with application, issue, renewal, change of particulars, and cancellation/variation of the registration certificate, recorded in the public register.

Artefacts an auditor will ask for
  • Valid registration certificate as controller/processor
  • Records of renewals and notified changes in particulars
Where this commonly fails
  • Operating as an unregistered controller/processor
  • Failing to notify a change in particulars or renew

Mauritius DPA 2017: Part IV - Obligations on Controllers and Processors

MU-DPA17-s21
Principles relating to processing of personal data

Sets the core data protection principles: lawful, fair and transparent processing; purpose limitation; minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

Artefacts an auditor will ask for
  • Documentation demonstrating each principle (lawfulness, minimisation, accuracy, storage limitation, security, accountability)
  • Records of processing
Where this commonly fails
  • No demonstrable accountability for the principles
  • Excessive collection or indefinite retention
MU-DPA17-s22-23
Duties of controller and collection of personal data

Sets the duties of the controller and the conditions for collecting personal data, including providing the data subject with the prescribed information at the point of collection.

Artefacts an auditor will ask for
  • Collection notices containing the required information
  • Controller accountability records
Where this commonly fails
  • Collecting data without the required notice
MU-DPA17-s24
Conditions for consent

Where processing is based on consent, the controller must be able to demonstrate that the data subject has consented, the request must be clearly distinguishable and in plain language, and consent may be withdrawn at any time.

Artefacts an auditor will ask for
  • Consent records demonstrating valid, informed consent
  • Withdrawal mechanism
Where this commonly fails
  • No record of consent
  • Bundled or unclear consent requests
MU-DPA17-s25-26
Notification and communication of a personal data breach

Requires the controller to notify the Commissioner of a personal data breach without undue delay (and within the prescribed time), and to communicate the breach to affected data subjects where it is likely to result in a high risk to their rights and freedoms.

Artefacts an auditor will ask for
  • Breach response procedure covering notification to the Commissioner and to data subjects
  • Breach register with timelines
Where this commonly fails
  • No breach notification process
  • Late or omitted notification to the Commissioner
MU-DPA17-s27
Duty to destroy personal data

Requires the controller to destroy or erase personal data as soon as it is reasonable to assume that the purpose for which it was collected is no longer being served by its retention.

Artefacts an auditor will ask for
  • Retention schedule and secure-destruction procedures tied to purpose
Where this commonly fails
  • Indefinite retention beyond the collection purpose
MU-DPA17-s28
Lawful processing

Processing is lawful only where at least one of the specified conditions is met (consent, contract, legal obligation, vital interests, public task, or legitimate interests).

Artefacts an auditor will ask for
  • Record of the lawful basis relied on per processing
  • Legitimate-interests assessment where relied on
Where this commonly fails
  • No documented lawful basis
MU-DPA17-s29
Special categories of personal data

Prohibits the processing of special categories of personal data (such as racial or ethnic origin, political opinions, religious beliefs, health, sex life, genetic and biometric data) save where a specified condition applies.

Artefacts an auditor will ask for
  • Identification of special-category processing and the specific condition relied on
  • Heightened safeguards
Where this commonly fails
  • Processing special categories without a valid condition
MU-DPA17-s30
Personal data of a child

Sets specific protections for the processing of a child's personal data, including requirements for the consent of a parent or guardian.

Artefacts an auditor will ask for
  • Age-verification and parental-consent mechanism for children's data
Where this commonly fails
  • Processing a child's data without parental consent where required
MU-DPA17-s31
Security of processing

Requires the controller and processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing.

Artefacts an auditor will ask for
  • Documented technical and organisational security measures
  • Risk-based justification
Where this commonly fails
  • No documented security measures
  • Security not adjusted to risk
MU-DPA17-s33
Record of processing operations

Requires controllers and processors to maintain a record of their processing operations containing the prescribed information.

Artefacts an auditor will ask for
  • Up-to-date record of processing operations (RoPA)
Where this commonly fails
  • No record of processing operations
  • Incomplete RoPA

Mauritius DPA 2017: Part V - Risk Processing (DPIA)

MU-DPA17-s34-35
Data protection impact assessment and prior consultation

Requires a prior security check and a data protection impact assessment for processing likely to present a high risk, and prior authorisation or consultation with the Commissioner where required.

Artefacts an auditor will ask for
  • DPIA records for high-risk processing
  • Evidence of prior consultation/authorisation with the Commissioner where required
Where this commonly fails
  • No DPIA for high-risk processing

Mauritius DPA 2017: Part VI - Transfer Outside Mauritius

MU-DPA17-s36
Transfer of personal data outside Mauritius

Restricts transfers of personal data to another country to cases where the Commissioner is satisfied of adequate safeguards, or a specified condition (such as consent or contract necessity) applies.

Artefacts an auditor will ask for
  • Transfer mechanism records (adequacy/safeguards/conditions)
  • Transfer risk assessment
Where this commonly fails
  • Transfers without adequate safeguards or a valid condition

Mauritius DPA 2017: Part VII - Rights of Data Subjects

MU-DPA17-s37
Right of access

Entitles a data subject to obtain confirmation of, and access to, their personal data and prescribed information about the processing.

Artefacts an auditor will ask for
  • Access-request handling procedure and logs
  • Identity verification of requesters
Where this commonly fails
  • No access-request process
MU-DPA17-s38
Automated individual decision making

Gives the data subject the right not to be subject to a decision based solely on automated processing that significantly affects them, save in specified cases with safeguards.

Artefacts an auditor will ask for
  • Inventory of solely automated decisions and safeguards
  • Human-intervention mechanism
Where this commonly fails
  • Solely automated significant decisions without safeguards
MU-DPA17-s39
Rectification, erasure or restriction of processing

Entitles the data subject to obtain rectification of inaccurate data, erasure, or restriction of processing in specified circumstances.

Artefacts an auditor will ask for
  • Procedures for rectification, erasure and restriction requests
  • Logs of requests and responses
Where this commonly fails
  • No erasure/rectification workflow
MU-DPA17-s40-41
Right to object and exercise of rights

Provides the right to object to processing (including for direct marketing) and sets the procedure and timeframes for exercising data subject rights.

Artefacts an auditor will ask for
  • Objection-handling procedure incl direct-marketing opt-out
  • Adherence to statutory response timeframes
Where this commonly fails
  • No objection mechanism
  • Exceeding response timeframes

Mauritius DPA 2017: Part VIII-IX - Offences, Enforcement and Miscellaneous

MU-DPA17-s42-43
Offences and penalties (unlawful disclosure)

Creates offences including the unlawful disclosure of personal data, and provides penalties (fines and imprisonment) for breaches of the Act.

Artefacts an auditor will ask for
  • Confidentiality controls preventing unlawful disclosure
  • Risk assessment of offence exposure (fines and imprisonment)
Where this commonly fails
  • Unlawful disclosure of personal data
  • Underestimating criminal exposure
MU-DPA17-s44
Exceptions and restrictions

Sets the exemptions from, and restrictions on, the application of the Act, including for national security, defence, prevention of crime and journalistic, literary or artistic purposes.

Artefacts an auditor will ask for
  • Documented basis for any exemption relied on
Where this commonly fails
  • Over-broad reliance on exemptions
MU-DPA17-s45-48
Annual report, compliance audit, codes and certification

Provides for the Commissioner's annual report, compliance audits of controllers and processors, the issue of codes and guidelines, and certification mechanisms.

Artefacts an auditor will ask for
  • Readiness for a compliance audit by the Commissioner
  • Adoption of relevant codes/guidelines or certification
Where this commonly fails
  • No readiness for a compliance audit
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Data Protection Act 2017 framework page.