Base juridique africaine
Loi · n° 20/2017

The Data Protection Act 2017

Autre · Act 20/2017 · Adoption : 22 décembre 2017

The Data Protection Act 2017 establishes a comprehensive legal framework for the protection of personal data in Mauritius. It creates the Data Protection Office and the position of Data Protection Commissioner to oversee compliance. The Act requires data controllers and processors to register with the Commissioner and sets out their obligations regarding the lawful processing of personal data. It provides the Commissioner with investigative and enforcement powers, including the ability to…

Act 20/2017

Proclaimed by [Proclamation No. 3 of 2018]w.e.f. 15 January 2018

Government Gazette of Mauritius No. 120 of 23 December 2017

I assent

BIBI AMEENAH FIRDAUS GURIB-FAKIM

22 December 2017

President of the Republic

ARRANGEMENT OF SECTIONS

Section

PART I PRELIMINARY

Short title 2. Interpretation 3. Application of Act

PART II DATA PROTECTION OFFICE

Sub-Part A Establishment of Data Protection Office

  1. Establishment of Office

Sub-Part B - Functions and Powers of Commissioner

  1. Functions of Commissioner
  2. Investigation of complaints
  3. Power to require information
  4. Preservation Order
  5. Enforcement notice
  6. Power to seek assistance

Sub-Part C - Powers of Authorised Officers

  1. Power of entry and search
  2. Obstruction of Commissioner or authorised officer

Sub-Part D Delegation of Power

  1. Delegation of power by Commissioner

PART III REGISTRATION OF CONTROLLERS AND PROCESSORS

  1. Controller and Processor
  2. Application for registration
  3. Issue of registration certificate
  4. Change in particulars
  5. Renewal of registration certificate
  6. Cancellation or variation of terms and conditions of registration certificate
  7. Register of controllers and processors

PART IV OBLIGATIONS ON CONTROLLERS AND PROCESSORS

  1. Principles relating to processing of personal data

Duties of controller Collection of personal data 4. Conditions for consent 25. Notification of personal data breach 26. Communication of personal data breach to data subject 27. Duty to destroy personal data 28. Lawful processing 9. Special categories of personal data 30. Personal data of child 3Security of processing Prior security check Record of processing operations

PART V PROCESSING OPERATIONS LIKELY TO

PRESENT RISK

34.Data protection impact assessment .Prior authorisation and consultation

PART VI TRANSFER OF PERSONAL DATA OUTSIDE MAURITIUS

36.Transfer of personal data outside Mauritius

PART VII RIGHTS OF DATA SUBJECTS

  1. Right of access
  2. Automated individual decision making
  3. Rectification, erasure or restriction of processing
  4. Right to object
  5. Exercise of rights

PART VIII OTHER OFFENCES AND PENALTIES

Unlawful disclosure of personal data Offence for which no specific penalty provided

PART IX MISCELLANEOUS

  1. Exceptions and restrictions
  2. Annual report
  3. Compliance audit
  4. Codes and guidelines
  5. Certification
  6. Confidentiality and oath
  7. Protection from liability
  8. Right of appeal
  9. Special jurisdiction of Tribunal
  10. Prosecution and jurisdiction
  11. Certificate issued by Commissioner
  12. Regulations
  13. Repeal
  14. Transitional provisions
  15. Commencement SCHEDULE

An Act

To provide for new legislation to strengthen the control and personal autonomy of data subjects over their personal data, in line with current relevant international standards, and for matters related thereto

ENACTED by the Parliament of Mauritius, as follows

PART I PRELIMINARY

1. Short title

This Act may be cited as the Data Protection Act 2017.

2. Interpretation

In this Act

"authorised officer" means an officer to whom the Commissioner has delegated his powers under section 13;

Texte intégral

Lisez l'intégralité de ce texte

Créez un compte gratuit pour lire le texte complet et interroger l'assistant IA sur ce document.

Lire l'intégralité gratuitement
Gratuit, sans carte bancaire Jetons de bienvenue offerts

Déjà un compte ? Se connecter