Mauritius

Data Protection Act 2017

22 controls. 2 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

22 controls 2 frameworks share controls with it Mauritius verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

Mauritius Data Protection Act 2017 Evidence & Implementation Kit

22 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
MU-DPA17-s14-20Registration of controllers and processors0
MU-DPA17-s21Principles relating to processing of personal data1
MU-DPA17-s22-23Duties of controller and collection of personal data1
MU-DPA17-s24Conditions for consent1
MU-DPA17-s25-26Notification and communication of a personal data breach0
MU-DPA17-s27Duty to destroy personal data0
MU-DPA17-s28Lawful processing1
MU-DPA17-s29Special categories of personal data1
MU-DPA17-s30Personal data of a child1
MU-DPA17-s31Security of processing1
MU-DPA17-s33Record of processing operations0
MU-DPA17-s34-35Data protection impact assessment and prior consultation0
MU-DPA17-s36Transfer of personal data outside Mauritius1
MU-DPA17-s37Right of access1
MU-DPA17-s38Automated individual decision making1
MU-DPA17-s39Rectification, erasure or restriction of processing1
MU-DPA17-s4-5Data Protection Office and functions of the Commissioner0
MU-DPA17-s40-41Right to object and exercise of rights0
MU-DPA17-s42-43Offences and penalties (unlawful disclosure)0
MU-DPA17-s44Exceptions and restrictions0
MU-DPA17-s45-48Annual report, compliance audit, codes and certification0
MU-DPA17-s6-13Investigation, enforcement notices and powers of the Commissioner0

Tell me when Data Protection Act 2017 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Record of the lawful basis relied on per processing
  • Consent records
  • Lawful-basis register
  • Lawful-basis determination recorded per processing activity
  • Consent records where consent is the basis
  • Contract or legal-obligation references supporting processing
  • Breach response procedure covering notification to the Commissioner and to data subjects
  • Breach register with timelines
  • Breach detection, recording and notification procedure (under Law 124/2024)
  • Breach detection & notification to the AAIP

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Data Protection Act 2017, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition