Skip to content

Evidence request lists

Mauritius DPA

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border Transfer - Mauritius DPA

MU-DPA-Cross-Border-Transfer-Section-36-Adequacy-SCC-BCR-Mauritius-Global-Business-IBC-Financial-Services
Mauritius DPA Cross-Border + Section 36 + Adequacy + SCC + BCR + Mauritius Global Business + Financial Services

Govern cross-border transfers under Section 36 particularly significant due to Mauritius as cross-border financial services hub. Section 36 transfers prohibited outside Mauritius unless: (a) adequacy decision by Data Protection Commissioner; (b) Standard Contractual Clauses (SCC) approved by Commissioner; (c) Binding Corporate Rules (BCR) approved by Commissioner; (d) explicit consent after being informed of risks; (e) necessary for performance of contract; (f) necessary for important public interest; (g) necessary for establishment exercise or defence of legal claims; (h) necessary for vital interests; (i) made from public register. Adequacy decisions issued by Commissioner via Government Notices. Convention 108+ member states automatic adequacy. EU GDPR adequacy assessment ongoing. Mauritius as Mauritius International Business Companies (IBC) + Mauritius Global Business Companies (GBC)

Artefacts an auditor will ask for
  • Section 36 cross-border transfer register
  • Adequacy decisions list from Commissioner (Government Notices)
  • Mauritius-Commissioner-approved SCC executed
  • BCR documentation submitted to Commissioner
  • Mauritius IBC + GBC offshore business cross-border data flow documentation
  • FSC Conduct of Business Rules + BoM outsourcing intersection mapping
  • EU-Mauritius EPA + Mauritius-India CECPA + AfCFTA Digital Protocol mapping
Where this commonly fails
  • Section 36 transfers without proper lawful basis
  • Commissioner-approved SCC not in use (relying on EU SCC alone)
  • Mauritius IBC/GBC offshore data flows not papered for Section 36
  • FSC + BoM cross-border outsourcing parallel obligations missed

Data Subject Rights - Mauritius DPA

MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection
Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection

Provide and operate channels for data subjects to exercise statutory rights under Sections 26-33. Section 26 right of access within 1 month extendable by 2 months for complex requests + free of charge first request per year. Section 27 right of rectification of inaccurate or incomplete data. Section 28 right of erasure (right to be forgotten) where data no longer necessary + consent withdrawn + objected + unlawful processing + legal obligation + child data collected with parental consent now adult. Section 29 right to restriction of processing during accuracy dispute or lawful-basis contestation. Section 30 right to be informed (transparency obligations). Section 31 right of data portability in structured commonly-used machine-readable format where based on consent or contract and processed automatically. Section 32 right to object including absolute right to object to direct marketing +

Artefacts an auditor will ask for
  • Subject rights request register with 1-month SLA (Section 26)
  • Identity authentication procedure
  • Right of erasure workflow with Section 28 grounds documentation
  • Data portability technical capability (structured + machine readable)
  • DPO Mauritius complaint mechanism preparedness + ICT Appeal Tribunal preparedness
  • Marketing opt-out infrastructure
  • Solely automated decision-making safeguards (human intervention)
Where this commonly fails
  • No 1-month SLA tracking
  • Right of erasure refused without Section 28 grounds documentation
  • ICT Appeal Tribunal 21-day appeal not anticipated
  • Automated decision-making safeguards missing

Enforcement Sanctions and Remedies - Mauritius DPA

MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court
Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court

Manage Data Protection Commissioner enforcement under Sections 41-43. Commissioner powers under Section 41 include investigation + information notices + enforcement notices + variation orders + compliance orders + warnings + reprimands + cease processing orders. Section 41 complaint mechanism free of charge with 6-month response target. ICT Appeal Tribunal (under ICT Act 2001) appeal under Section 47 within 21 days of Commissioner decision + 3-member panel + de novo review. Supreme Court of Mauritius appeal on points of law within 21 days. Section 43 administrative fines up to MUR 200,000 (approximately USD 4,400) per offence + 5 years imprisonment + may be increased by Court for serious cases + restitution + remediation orders. Civil claim under Tort Law for material and non-material damage. Commissioner public censure + decision publication + annual report to National Assembly. African

Artefacts an auditor will ask for
  • DPO Mauritius enforcement notice tracking and remediation evidence
  • Section 43 penalty exposure assessment (MUR 200K per offence + 5 year prison)
  • ICT Appeal Tribunal 21-day appeal preparedness
  • Supreme Court 21-day points-of-law appeal escalation
  • Tort civil claim preparedness under Section 45
  • RAPDP cooperation documentation (African DPA network)
  • Convention 108+ Committee mutual assistance
  • Bilateral MoU coordination with South Africa Information Regulator + Morocco CNDP + Senegal CDP + Kenya ODPC + Rwanda NCPDP + Madagascar CNPD
Where this commonly fails
  • MUR 200K + 5 year prison exposure not flagged to legal
  • ICT Appeal Tribunal 21-day SLA missed
  • Cybercrime Act 2003 + ICAC + FIU coordination not mapped
  • African network cooperation not engaged for cross-border investigations

Governance DPO ROPA DPIA - Mauritius DPA

MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration
Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration

Operate Mauritius DPA governance structure including DPO designation + ROPA + DPIA + sectoral Codes of Conduct + Commissioner registration. Section 25-DPO mandatory Data Protection Officer designation for public authorities + bodies whose core activities consist of large-scale regular and systematic monitoring + bodies whose core activities consist of large-scale processing of sensitive data + bodies whose processing is likely to result in high risk to rights and freedoms. DPO independent + reports to highest management + contact published + DPO Mauritius notification. ROPA (Records of Processing Activities) under Section 22 in English or French covering controller and processor activities including identity + purposes + categories of data subjects + categories of personal data + categories of recipients + cross-border transfers + retention + technical and organisational measures. DPIA (

Artefacts an auditor will ask for
  • DPO designation letter + reporting line + DPO Mauritius notification (Section 25-DPO)
  • ROPA in English or French + Section 22 completeness
  • DPIA register under Section 34 + Commissioner consultation Section 35 records for unmitigated high residual risk
  • Section 38 Codes of Conduct registered with Commissioner adherence (banking + insurance + offshore + ICT)
  • Section 39 certification mechanism evidence
  • Public register of DPOs cross-walk
Where this commonly fails
  • No DPO despite Section 25-DPO triggers (public authority + large-scale sensitive + systematic monitoring)
  • DPIA not conducted for AI/ML + profiling
  • Codes of Conduct claimed but not Section 38-registered
  • Commissioner consultation Section 35 skipped for high-residual-risk

Scope and Authority - Mauritius DPA

MU-DPA-Scope-Act-20-2017-Assent-18-December-2017-Effective-15-January-2018-DPO-Mauritius-Convention-108
Mauritius DPA Scope + Act 20 of 2017 + Assent 18 December 2017 + Effective 15 January 2018 + DPO Mauritius + Convention 108+

Establish the legal foundation of Mauritius Data Protection Act 2017 (Act No. 20 of 2017) enacted by National Assembly + assented by President Ameenah Gurib-Fakim 18 December 2017 + Government Notice 219 of 2017 + effective 15 January 2018. Replaced Data Protection Act 2004. Foundational Mauritian data protection statute aligned with EU GDPR Regulation 2016/679 + Council of Europe Convention 108+ (Mauritius first non-European state to ratify Convention 108 in 2016 + ratified Convention 108+ Protocol 2018) + AU Malabo Convention on Cyber Security and Personal Data Protection 2014. Data Protection Office (DPO) Mauritius independent supervisory authority + headquartered Port Louis + Data Protection Commissioner appointed by Public Service Commission for 5-year term + reports to National Assembly. Constitution of Mauritius Section 9 (protection of privacy of home and other property) + Sectio

Artefacts an auditor will ask for
  • Mauritius DPA Act 20 of 2017 applicability assessment
  • Section 4 extraterritorial scope analysis
  • Convention 108+ + AU Malabo Convention adherence evidence
  • DPO Mauritius correspondence records
  • Sectoral coordination memoranda (BoM + FSC + MRA + ICTA)
Where this commonly fails
  • No Section 4 extraterritorial analysis for global business sector
  • Constitution Section 9/12 anchor not documented
  • Convention 108+ ratification not leveraged for cross-border

Security and Breach Notification - Mauritius DPA

MU-DPA-Security-Breach-Notification-Section-25-BREACH-72-Hour-Commissioner-Cyber-Security-Strategy
Mauritius DPA Security + Breach Notification + Section 25-BREACH + 72 Hour + Commissioner + Cyber Security Strategy

Implement technical and organisational security measures + breach notification process aligned with GDPR Articles 32-34 + Mauritius National Cyber Security Strategy. Section 31 (security) requires controller and processor implementation of appropriate technical and organisational measures including encryption + access controls + activity logging + secure development + supplier security + business continuity + workforce training. DPO Mauritius Security Standards Guidance Note 3/2018 prescribes baseline measures. Section 25-BREACH 72-hour breach notification to Data Protection Commissioner for any personal data breach + concurrent affected data subject notification without undue delay where high risk to rights and freedoms + breach register maintenance + breach response plan + post-incident review. Coordination with CERT-Mu (Computer Emergency Response Team Mauritius) under National Comput

Artefacts an auditor will ask for
  • DPO Mauritius Security Standards Guidance Note 3/2018 compliance evidence
  • Section 31 security measures (admin + technical + physical)
  • Section 25-BREACH 72-hour Commissioner notification procedure + breach register + breach response plan
  • Affected data subject notification template + high-risk threshold determination
  • CERT-Mu dual-notification protocol for critical infrastructure
  • BoM Cybersecurity Guidelines 2019 (banking) + FSC Circulars (offshore) compliance
  • Tabletop exercise records
Where this commonly fails
  • No Section 25-BREACH 72-hour notification capability
  • CERT-Mu dual notification not mapped for critical infrastructure
  • DPO Mauritius Security Standards 3/2018 baseline not implemented
  • Sectoral cybersecurity (BoM + FSC) parallel obligations not coordinated

Sensitive Data and Children - Mauritius DPA

MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16
Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16

Process sensitive personal data and children data under enhanced conditions in Sections 24 and 25. Sensitive Personal Data definition (Section 2) includes racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data + data concerning health + data concerning sex life or sexual orientation + criminal convictions and offences. Section 24 sensitive data processing prohibited unless one of the lawful conditions applies: explicit consent + employment + social security or social protection law + vital interests where subject incapable of consent + non-profit body with appropriate safeguards + manifestly public + legal claims + reasons of substantial public interest + healthcare provided by professional bound by secrecy + public health + archiving/scientific/historical research or statistical purposes with safeguards.

Artefacts an auditor will ask for
  • Sensitive data inventory under Section 2 definition with Section 24 lawful condition mapping
  • Explicit consent records or other Section 24 condition documentation
  • Children below 16 parental consent records (Section 25)
  • DPO Mauritius Biometric Data Guidance Note 1/2018 compliance for biometric processing
  • Ministry of Health Hospital Information Systems data sharing controls (health)
Where this commonly fails
  • Section 24 lawful conditions not invoked correctly (implied consent for sensitive processing)
  • Children age verification absent for online services
  • Biometric workplace surveillance without DPO Guidance Note 1/2018 compliance

Seven Data Protection Principles - Mauritius DPA

MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability
Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability

Implement the seven foundational Data Protection Principles under Section 21 of the Act (GDPR Article 5 alignment). (1) Lawfulness fairness and transparency - processing must have lawful basis + be fair to data subject + transparent in operation. (2) Purpose limitation - collected for specified explicit legitimate purposes + not further processed incompatibly. (3) Data minimisation - adequate + relevant + limited to what is necessary. (4) Accuracy - accurate + kept up to date + reasonable steps to erase or rectify inaccuracies. (5) Storage limitation - kept in identifiable form only as long as necessary. (6) Integrity and confidentiality - appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction + damage. (7) Accountability - data controller responsible for and able to demonstrate compliance with Section 21 principles (GDPR-sty

Artefacts an auditor will ask for
  • Section 21 seven principles implementation matrix
  • Lawful basis register per processing under Section 23
  • Bilingual privacy notices (English + French) where required
  • ROPA under Section 22 in English or French
  • DPO Mauritius Guidance Notes 2018/2020/2024 implementation
Where this commonly fails
  • Accountability principle (Section 21(7)) not demonstrable through records
  • English-only notices despite mixed-language workforce/customer base
  • ROPA incomplete or not maintained
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Mauritius DPA framework page.