Data Protection Act 2017
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Mauritius DPA 2017: Part II - Data Protection Office and Commissioner
Establishes the Data Protection Office and sets the functions of the Data Protection Commissioner, the independent supervisory authority that ensures compliance with the Act.
- Awareness of the Commissioner's jurisdiction and points of cooperation
- Records of interaction with the Data Protection Office
- No designated contact for the Commissioner
Empowers the Commissioner to investigate complaints, require information, issue preservation and enforcement notices, enter and search premises, and act against obstruction.
- Procedure to respond to Commissioner information requests, preservation and enforcement notices
- Cooperation with entry/search where lawful
- Failure to comply with an enforcement or preservation notice
- Obstructing the Commissioner
Mauritius DPA 2017: Part III - Registration of Controllers and Processors
Requires every controller and processor to be registered with the Commissioner, with application, issue, renewal, change of particulars, and cancellation/variation of the registration certificate, recorded in the public register.
- Valid registration certificate as controller/processor
- Records of renewals and notified changes in particulars
- Operating as an unregistered controller/processor
- Failing to notify a change in particulars or renew
Mauritius DPA 2017: Part IV - Obligations on Controllers and Processors
Sets the core data protection principles: lawful, fair and transparent processing; purpose limitation; minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
- Documentation demonstrating each principle (lawfulness, minimisation, accuracy, storage limitation, security, accountability)
- Records of processing
- No demonstrable accountability for the principles
- Excessive collection or indefinite retention
Sets the duties of the controller and the conditions for collecting personal data, including providing the data subject with the prescribed information at the point of collection.
- Collection notices containing the required information
- Controller accountability records
- Collecting data without the required notice
Where processing is based on consent, the controller must be able to demonstrate that the data subject has consented, the request must be clearly distinguishable and in plain language, and consent may be withdrawn at any time.
- Consent records demonstrating valid, informed consent
- Withdrawal mechanism
- No record of consent
- Bundled or unclear consent requests
Requires the controller to notify the Commissioner of a personal data breach without undue delay (and within the prescribed time), and to communicate the breach to affected data subjects where it is likely to result in a high risk to their rights and freedoms.
- Breach response procedure covering notification to the Commissioner and to data subjects
- Breach register with timelines
- No breach notification process
- Late or omitted notification to the Commissioner
Requires the controller to destroy or erase personal data as soon as it is reasonable to assume that the purpose for which it was collected is no longer being served by its retention.
- Retention schedule and secure-destruction procedures tied to purpose
- Indefinite retention beyond the collection purpose
Processing is lawful only where at least one of the specified conditions is met (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
- Record of the lawful basis relied on per processing
- Legitimate-interests assessment where relied on
- No documented lawful basis
Prohibits the processing of special categories of personal data (such as racial or ethnic origin, political opinions, religious beliefs, health, sex life, genetic and biometric data) save where a specified condition applies.
- Identification of special-category processing and the specific condition relied on
- Heightened safeguards
- Processing special categories without a valid condition
Sets specific protections for the processing of a child's personal data, including requirements for the consent of a parent or guardian.
- Age-verification and parental-consent mechanism for children's data
- Processing a child's data without parental consent where required
Requires the controller and processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing.
- Documented technical and organisational security measures
- Risk-based justification
- No documented security measures
- Security not adjusted to risk
Requires controllers and processors to maintain a record of their processing operations containing the prescribed information.
- Up-to-date record of processing operations (RoPA)
- No record of processing operations
- Incomplete RoPA
Mauritius DPA 2017: Part V - Risk Processing (DPIA)
Requires a prior security check and a data protection impact assessment for processing likely to present a high risk, and prior authorisation or consultation with the Commissioner where required.
- DPIA records for high-risk processing
- Evidence of prior consultation/authorisation with the Commissioner where required
- No DPIA for high-risk processing
Mauritius DPA 2017: Part VI - Transfer Outside Mauritius
Restricts transfers of personal data to another country to cases where the Commissioner is satisfied of adequate safeguards, or a specified condition (such as consent or contract necessity) applies.
- Transfer mechanism records (adequacy/safeguards/conditions)
- Transfer risk assessment
- Transfers without adequate safeguards or a valid condition
Mauritius DPA 2017: Part VII - Rights of Data Subjects
Entitles a data subject to obtain confirmation of, and access to, their personal data and prescribed information about the processing.
- Access-request handling procedure and logs
- Identity verification of requesters
- No access-request process
Gives the data subject the right not to be subject to a decision based solely on automated processing that significantly affects them, save in specified cases with safeguards.
- Inventory of solely automated decisions and safeguards
- Human-intervention mechanism
- Solely automated significant decisions without safeguards
Entitles the data subject to obtain rectification of inaccurate data, erasure, or restriction of processing in specified circumstances.
- Procedures for rectification, erasure and restriction requests
- Logs of requests and responses
- No erasure/rectification workflow
Provides the right to object to processing (including for direct marketing) and sets the procedure and timeframes for exercising data subject rights.
- Objection-handling procedure incl direct-marketing opt-out
- Adherence to statutory response timeframes
- No objection mechanism
- Exceeding response timeframes
Mauritius DPA 2017: Part VIII-IX - Offences, Enforcement and Miscellaneous
Creates offences including the unlawful disclosure of personal data, and provides penalties (fines and imprisonment) for breaches of the Act.
- Confidentiality controls preventing unlawful disclosure
- Risk assessment of offence exposure (fines and imprisonment)
- Unlawful disclosure of personal data
- Underestimating criminal exposure
Sets the exemptions from, and restrictions on, the application of the Act, including for national security, defence, prevention of crime and journalistic, literary or artistic purposes.
- Documented basis for any exemption relied on
- Over-broad reliance on exemptions
Provides for the Commissioner's annual report, compliance audits of controllers and processors, the issue of codes and guidelines, and certification mechanisms.
- Readiness for a compliance audit by the Commissioner
- Adoption of relevant codes/guidelines or certification
- No readiness for a compliance audit
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Data Protection Act 2017 framework page.