Data protection · August 2026

The Data Protection Act 2017 and AI in Mauritius

Discussion of AI regulation in Mauritius has focused on the National AI Strategy and the FAIR guidelines since their launch in April 2026. For most organisations, though, the instrument that actually creates enforceable obligations is older and less discussed: the Data Protection Act 2017.

If your AI system touches personal data, this is the law that applies to you today, irrespective of what any strategy document says.

Why the DPA is the operative instrument

The Act came into force on 15 January 2018 and aligns Mauritius closely with the European General Data Protection Regulation. It is overseen by the Data Protection Office under the Data Protection Commissioner, which operates independently, and it applies to private organisations and public sector bodies alike.

The GDPR alignment matters practically: it means the concepts are familiar, the international guidance is broadly transferable, and a firm that has done GDPR work for European clients has already done much of the thinking.

Where AI meets the Act: impact assessments

The provision that bites hardest on AI is the requirement for an impact assessment where processing is high-risk, which expressly includes profiling and automated decision-making. A great many AI deployments are one or both of those without their owners having framed them that way.

A scoring model that ranks clients by risk is profiling. A system that triages applications is automated decision-making even if a human signs the result, if in practice the human follows the system.

What a DPIA actually involves

Done properly it is a design exercise, not a form. It should establish:

  • What personal data enters the system and why each field is necessary. This question alone tends to shrink systems, because a surprising amount of collected data turns out to serve no decision.
  • What the system decides or influences, and for whom.
  • What happens to a person the system gets wrong, and how they would find out.
  • Where the data is processed and stored, including every sub-processor. For AI this often means a foreign model provider, which is a transfer question.
  • How long data is retained and what happens at the end.
  • What the residual risk is after mitigations, stated plainly.

The reason to do this before building rather than after is that the answers change the design. A DPIA produced to document a finished system is a compliance artefact; one produced during design is an engineering input.

The question most firms get wrong

Whether client data is used to train a model. Many organisations assume that because they did not intend it, it is not happening. Whether it happens depends on the terms of the tools they use, and for general-purpose AI services the default is not always in your favour.

For any firm holding confidential or privileged material this belongs in the contract rather than in an email. We wrote about the firm-level version of this decision in an AI use policy for a Mauritian law firm, and about the shadow adoption that usually precedes it in what your staff are already doing with AI.

A workable starting position

  1. List every AI system or feature touching personal data. Include the tools staff use that were never formally adopted.
  2. For each, decide whether it involves profiling or automated decision-making. If either, a DPIA is indicated.
  3. For each, establish in writing whether the provider trains on your data.
  4. Identify where processing physically happens, including sub-processors.
  5. Name an accountable person per system. Not a committee.

This is general commentary rather than legal advice, and the Act itself together with guidance from the Data Protection Office should be consulted for any specific question.

Common questions

Does the Data Protection Act 2017 apply to AI?

It contains no AI-specific chapter, but it applies fully to AI systems that process personal data. The provisions that bite hardest are the requirement for an impact assessment where processing is high-risk, which expressly includes profiling and automated decision-making, together with the general obligations on lawfulness, minimisation, retention and transfers.

When do we need a DPIA for an AI system?

Where the processing is high-risk. Profiling and automated decision-making are expressly within that category, so a scoring model that ranks people, or a system that triages applications, will generally indicate one. If a human nominally signs the output but in practice follows the system, treat it as automated decision-making rather than assuming the signature removes it.

Is the Mauritian regime the same as GDPR?

It is closely aligned rather than identical. The Act came into force on 15 January 2018 and follows GDPR concepts and structure, which means international guidance is broadly transferable and prior GDPR work carries over. Differences in detail remain, so the Mauritian text governs.

Can we use an overseas AI provider?

Generally yes, but it is a transfer question and belongs in your impact assessment. You need to know which sub-processors touch the data, which jurisdiction it is processed and stored in, whether it is used for training, and what happens to it at the end of the relationship. Get those answers in the contract.

Who enforces data protection in Mauritius?

The Data Protection Office, headed by the Data Protection Commissioner. It operates independently and is not subject to the direction of any other authority in discharging its functions. Its remit covers public sector bodies as well as private organisations.

General commentary, not legal, regulatory or financial advice. · All notes