Data Protection Act 2017
What is Data Protection Act 2017?
Mauritius Data Protection Act 2017 (Act No. 20 of 2017), as amended by the Data Protection (Amendment) Act 2022, a GDPR-aligned data protection law administered by the Data Protection Office and the Data Protection Commissioner; repealed the Data Protection Act 2004. It comprises 22 controls organised across 7 domains, and applies in Mauritius.
How Data Protection Act 2017 maps to other frameworks
All 22 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains Data Protection Act 2017 groups its controls into
Frameworks that share controls with Data Protection Act 2017
Each of these has at least one control mapped to a control in Data Protection Act 2017. The number is how many Data Protection Act 2017 controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap Data Protection Act 2017
Training on frameworks that overlap Data Protection Act 2017
There is no course on Data Protection Act 2017 itself. These cover frameworks that share controls with it, so the material carries across even though the standard named is different.
Where Data Protection Act 2017 overlaps with the standards you already hold
What Data Protection Act 2017 means in your sector
What Data Protection Act 2017 means for your job
Questions people ask about Data Protection Act 2017
What is Data Protection Act 2017?
How many controls does Data Protection Act 2017 have?
Where does Data Protection Act 2017 apply?
What frameworks does Data Protection Act 2017 map to?
How do I get started with Data Protection Act 2017 compliance?
Query Data Protection Act 2017 programmatically
Data Protection Act 2017, its 22 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
Data Protection Act 2017 API reference and MCP config →What Data Protection Act 2017 requires, control by control
Each page carries the requirement text for one Data Protection Act 2017 control and what an assessor expects to see as evidence.
- MU-DPA17-S21 Principles relating to processing of personal data
- MU-DPA17-S22-23 Duties of controller and collection of personal data
- MU-DPA17-S24 Conditions for consent
- MU-DPA17-S28 Lawful processing
- MU-DPA17-S29 Special categories of personal data
- MU-DPA17-S30 Personal data of a child
- MU-DPA17-S31 Security of processing
- MU-DPA17-S36 Transfer of personal data outside Mauritius
- MU-DPA17-S37 Right of access
- MU-DPA17-S38 Automated individual decision making
How ready are you for Data Protection Act 2017?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.