AI LAW RADAR · Daily Last verified 19 Aug 2026

Jurisdiction dossier

Mauritius: AI regulation & deadlines

No AI-specific statute is in force, but Mauritius carries the fullest automated-decision regime of any Malabo Convention party — a GDPR-shaped bar, a three-place explanation duty and a criminal penalty that actually reaches it. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) gives every data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or significantly affects him. The s. 38(2) exceptions are the GDPR three — contract necessity; authorisation by a law that itself lays down suitable safeguards; explicit consent — and s. 38(5) confines the controller's own safeguard duty to the contract and consent limbs, leaving the legal-authorisation route to be policed by the authorising law. Section 38(3) goes beyond GDPR art. 22(4): automated processing intended to evaluate certain personal aspects relating to an individual shall not be based on special categories of personal data at all, with no consent or public-interest escape. The explanation duty runs proactively at s. 23(1)(g) — the existence of automated decision making including profiling, information about the logic involved, and the significance and envisaged consequences — reactively at s. 37(2)(h) inside the right of access, and again at s. 38(4), which requires the s. 23 information to state the existence of processing for a decision of the kind at s. 38(1) and its envisaged effects whenever an exception is relied on. Section 34(2)(a) makes a data protection impact assessment mandatory before systematic and extensive evaluation of personal aspects based on automated processing on which such decisions are based. Section 3(1) binds the State and s. 3(2) treats each Ministry as separate from every other, so public-sector automated decisions are in scope on the same terms as private ones; the exclusions at s. 3(4) are limited to need-to-know inter-departmental exchanges and purely personal or household activity. The penalty comes from s. 43(1), which reaches «any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act» — a fine not exceeding 200,000 rupees and imprisonment for a term not exceeding 5 years, drafted with «and» rather than «or» between them, plus forfeiture and stop-the-contravention orders under s. 43(2). In force since 15 January 2018 by Proclamation No. 3 of 2018; passed 8 December 2017, assented 22 December 2017, gazetted 23 December 2017, and repealing the Data Protection Act 2004 under s. 56. Mauritius deposited its instrument of ratification of the Malabo Convention on 14 March 2018, the earliest of the four parties added in this pass, so art. 14(5) has also bound since 8 June 2023 — a bar with no exceptions running behind a statute with three. 1 obligation tracked — 1 in force.

Binding — Binding sectoral Flagship law: Data Protection Act 2017 s. 38

No AI-specific statute is in force, but Mauritius carries the fullest automated-decision regime of any Malabo Convention party — a GDPR-shaped bar, a three-place explanation duty and a criminal penalty that actually reaches it. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) gives every data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or significantly affects him. The s. 38(2) exceptions are the GDPR three — contract necessity; authorisation by a law that itself lays down suitable safeguards; explicit consent — and s. 38(5) confines the controller's own safeguard duty to the contract and consent limbs, leaving the legal-authorisation route to be policed by the authorising law. Section 38(3) goes beyond GDPR art. 22(4): automated processing intended to evaluate certain personal aspects relating to an individual shall not be based on special categories of personal data at all, with no consent or public-interest escape. The explanation duty runs proactively at s. 23(1)(g) — the existence of automated decision making including profiling, information about the logic involved, and the significance and envisaged consequences — reactively at s. 37(2)(h) inside the right of access, and again at s. 38(4), which requires the s. 23 information to state the existence of processing for a decision of the kind at s. 38(1) and its envisaged effects whenever an exception is relied on. Section 34(2)(a) makes a data protection impact assessment mandatory before systematic and extensive evaluation of personal aspects based on automated processing on which such decisions are based. Section 3(1) binds the State and s. 3(2) treats each Ministry as separate from every other, so public-sector automated decisions are in scope on the same terms as private ones; the exclusions at s. 3(4) are limited to need-to-know inter-departmental exchanges and purely personal or household activity. The penalty comes from s. 43(1), which reaches «any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act» — a fine not exceeding 200,000 rupees and imprisonment for a term not exceeding 5 years, drafted with «and» rather than «or» between them, plus forfeiture and stop-the-contravention orders under s. 43(2). In force since 15 January 2018 by Proclamation No. 3 of 2018; passed 8 December 2017, assented 22 December 2017, gazetted 23 December 2017, and repealing the Data Protection Act 2004 under s. 56. Mauritius deposited its instrument of ratification of the Malabo Convention on 14 March 2018, the earliest of the four parties added in this pass, so art. 14(5) has also bound since 8 June 2023 — a bar with no exceptions running behind a statute with three.

checked 19 Aug 2026 primary source ↗

The Register

1 obligation
Mauritius Binding

Data Protection Act 2017 s. 38 — the African automated-decision bar that a criminal penalty actually backs

Binds Every controller and processor within the Act's reach. Section 3(1) binds the State expressly and s. 3(2) treats each Ministry or Government department as separate from every other, so a public-sector automated decision is in scope on the same terms as a private one — a drafting choice worth noting, because the Convention's own machinery assumes a national authority policing both. Section 3(3) applies the Act to processing of personal data wholly or partly by automated means, and to non-automated processing where the data form or are intended to form part of a filing system. The exclusions at s. 3(4) are narrow: exchanges of information between Ministries, Government departments and public sector agencies on a need-to-know basis, and processing by an individual in the course of a purely personal or household activity. There is no size, sector or turnover threshold, so the bar reaches enterprise, SME, public body and — Mauritius being a substantial offshore financial centre — the management companies and global-business licensees the Data Protection Office has issued separate registration advice to. Hiring is in scope through the s. 2 definition of profiling, which names «performance at work» among the personal aspects it covers, and credit, insurance and AML/CFT screening decisions fall the same way; the s. 38(2)(b) legal-authorisation limb is the one most likely to be reached for by a regulated financial institution, and it is the limb that requires the authorising law itself to lay down safeguards. The s. 5(i) function of the Commissioner is the tell that this was drafted with automated decisions in mind: the Commissioner is to «examine any proposal for automated decision making or data linkage that may involve an interference with, or may otherwise have an adverse effect, on the privacy of individuals and ensure that any adverse effect of the proposal on the privacy of individuals is minimised».. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) provides that «every data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or significantly affects him». Mauritius passed the Act on 8 December 2017, three days before the GDPR's own application date was a year away, and the transposition is close: s. 38(2) carries the three exceptions in GDPR order — (a) necessary for entering into, or performing, a contract between the data subject and a controller; (b) authorised by a law to which the controller is subject «and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests»; (c) based on the data subject's explicit consent. Two refinements distinguish it from the Zambian and Francophone rows. Section 38(3) bars any automated processing intended to evaluate certain personal aspects relating to an individual from being based on special categories of personal data — an outright prohibition rather than a consent-gated permission, and stricter on its face than GDPR art. 22(4), which allows special-category automated decisions on explicit consent or substantial public interest. And s. 38(5) narrows the safeguard duty to the contract and explicit-consent limbs at s. 38(2)(a) and (c), leaving the s. 38(2)(b) legal-authorisation route to be policed by the safeguards the authorising law itself must lay down. Mauritius also has the fullest explanation limb of the four Malabo parties added in this pass, and it runs in three places. Section 23(1)(g), the information duty at collection, requires the controller to give «the existence of automated decision making, including profiling, and information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject» — proactive, not on request. Section 37(2)(h) repeats the same item inside the right of access, so it is available reactively too. And s. 38(4) adds a specific overlay: where an exception at s. 38(2) is relied on, the s. 23 information «shall include information as to the existence of processing for a decision of the kind referred to in subsection (1) and the envisaged effects of such processing on the data subject». Section 34(2)(a) then makes a data protection impact assessment mandatory before «a systematic and extensive evaluation of personal aspects relating to individuals which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the individual or significantly affect the individual».

In force since 15 January 2018, by proclamation. Section 58(1) provides that the Act «shall come into operation on a date to be fixed by Proclamation» and s. 58(2) allows different dates for different sections; the header of the official Data Protection Office text records «Proclaimed by [Proclamation No. 3 of 2018] w.e.f. 15 January 2018», with no sectional split, so the whole Act including s. 38 has run from that date. The surrounding dates are all distinct and none of them is the operative one: passed by the National Assembly on 8 December 2017, assented by President Bibi Ameenah Firdaus Gurib-Fakim on 22 December 2017, published in the Government Gazette of Mauritius No. 120 of 23 December 2017. The Act is not a first-generation instrument — s. 56 repeals the Data Protection Act 2004, and s. 57 carries transitional provisions, so a Mauritian automated-decision rule of some kind predates 2018; the 2017 rewrite is what put the GDPR-shaped s. 38 in place and that is the date carried here. Mauritius ratified the Malabo Convention on 6 March 2018 and deposited on 14 March 2018 — the earliest deposit of the four parties added in this pass, and eight weeks after its own Act commenced — so from 8 June 2023 both instruments bind. Where they diverge the statute is the operative rule and the treaty runs behind it, because art. 14(5) of the Convention admits no contract, consent or legal-authorisation exception while s. 38(2) admits all three. Mauritius is also the only one of the four whose national law goes further than the Convention in the other direction: art. 16 and art. 17 of the Convention carry no logic item at all, while ss. 23(1)(g), 37(2)(h) and 38(4) carry three overlapping ones. So the Mauritian position is a bar with more exits than the treaty allows, guarded by an explanation duty the treaty never imposed.

Stated maximum penalty — A fine not exceeding 200,000 rupees and imprisonment for a term not exceeding 5 years, under s. 43(1) — and unlike Zambia, the route to it is explicit on the face of the section. Part VII (rights of data subjects, ss. 37-41) contains no penalty of its own, but s. 43(1) is drafted to sweep: «Any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding 200,000 rupees and to imprisonment for a term not exceeding 5 years». The words «or who otherwise contravenes this Act» are what carry a s. 38 breach into the penalty; without them the Mauritian position would be the Zambian one. Note the conjunction: the subsection reads «and» rather than «or» between fine and imprisonment, which on a literal reading makes both cumulative on conviction rather than alternative — an unusual drafting result, recorded as it stands rather than softened. Section 43(2) adds that the Court may order forfeiture of any equipment or article used or connected with the offence, and may order or prohibit the doing of any act to stop a continuing contravention. Separately, s. 42 creates a specific unlawful-disclosure offence, with s. 42(5) reaching a person who offers to sell personal data obtained in breach of it and s. 42(6) treating an advertisement indicating that personal data is or may be for sale as an offer to sell. Enforcement short of prosecution runs through the Commissioner: s. 6 investigation of complaints, s. 7 power to require information, s. 8 preservation order and s. 9 enforcement notice, with a right of appeal under s. 51 and the special jurisdiction of the Tribunal under s. 52. Impact tier: all entities.

In force · 15 Jan 2018 checked 19 Aug 2026 Data Protection Act 2017 s. 38 ↗ high confidence

Questions & answers

From the data

When does Data Protection Act 2017 s. 38 take effect in Mauritius?

Data Protection Act 2017 s. 38 is already in force, with obligations live since January 15, 2018. No AI-specific statute is in force, but Mauritius carries the fullest automated-decision regime of any Malabo Convention party — a GDPR-shaped bar, a three-place explanation duty and a criminal penalty that actually reaches it. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) gives every data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or significantly affects him. The s. 38(2) exceptions are the GDPR three — contract necessity; authorisation by a law that itself lays down suitable safeguards; explicit consent — and s. 38(5) confines the controller's own safeguard duty to the contract and consent limbs, leaving the legal-authorisation route to be policed by the authorising law. Section 38(3) goes beyond GDPR art. 22(4): automated processing intended to evaluate certain personal aspects relating to an individual shall not be based on special categories of personal data at all, with no consent or public-interest escape. The explanation duty runs proactively at s. 23(1)(g) — the existence of automated decision making including profiling, information about the logic involved, and the significance and envisaged consequences — reactively at s. 37(2)(h) inside the right of access, and again at s. 38(4), which requires the s. 23 information to state the existence of processing for a decision of the kind at s. 38(1) and its envisaged effects whenever an exception is relied on. Section 34(2)(a) makes a data protection impact assessment mandatory before systematic and extensive evaluation of personal aspects based on automated processing on which such decisions are based. Section 3(1) binds the State and s. 3(2) treats each Ministry as separate from every other, so public-sector automated decisions are in scope on the same terms as private ones; the exclusions at s. 3(4) are limited to need-to-know inter-departmental exchanges and purely personal or household activity. The penalty comes from s. 43(1), which reaches «any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act» — a fine not exceeding 200,000 rupees and imprisonment for a term not exceeding 5 years, drafted with «and» rather than «or» between them, plus forfeiture and stop-the-contravention orders under s. 43(2). In force since 15 January 2018 by Proclamation No. 3 of 2018; passed 8 December 2017, assented 22 December 2017, gazetted 23 December 2017, and repealing the Data Protection Act 2004 under s. 56. Mauritius deposited its instrument of ratification of the Malabo Convention on 14 March 2018, the earliest of the four parties added in this pass, so art. 14(5) has also bound since 8 June 2023 — a bar with no exceptions running behind a statute with three.

Who must comply with AI rules in Mauritius?

Current obligations bind, among others, Every controller and processor within the Act's reach. Section 3(1) binds the State expressly and s. 3(2) treats each Ministry or Government department as separate from every other, so a public-sector automated decision is in scope on the same terms as a private one — a drafting choice worth noting, because the Convention's own machinery assumes a national authority policing both. Section 3(3) applies the Act to processing of personal data wholly or partly by automated means, and to non-automated processing where the data form or are intended to form part of a filing system. The exclusions at s. 3(4) are narrow: exchanges of information between Ministries, Government departments and public sector agencies on a need-to-know basis, and processing by an individual in the course of a purely personal or household activity. There is no size, sector or turnover threshold, so the bar reaches enterprise, SME, public body and — Mauritius being a substantial offshore financial centre — the management companies and global-business licensees the Data Protection Office has issued separate registration advice to. Hiring is in scope through the s. 2 definition of profiling, which names «performance at work» among the personal aspects it covers, and credit, insurance and AML/CFT screening decisions fall the same way; the s. 38(2)(b) legal-authorisation limb is the one most likely to be reached for by a regulated financial institution, and it is the limb that requires the authorising law itself to lay down safeguards. The s. 5(i) function of the Commissioner is the tell that this was drafted with automated decisions in mind: the Commissioner is to «examine any proposal for automated decision making or data linkage that may involve an interference with, or may otherwise have an adverse effect, on the privacy of individuals and ensure that any adverse effect of the proposal on the privacy of individuals is minimised».. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Mauritius?

Stated statutory maxima include: Data Protection Act 2017 s. 38 — A fine not exceeding 200,000 rupees and imprisonment for a term not exceeding 5 years, under s. 43(1) — and unlike Zambia, the route to it is explicit on the face of the section. Part VII (rights of data subjects, ss. 37-41) contains no penalty of its own, but s. 43(1) is drafted to sweep: «Any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding 200,000 rupees and to imprisonment for a term not exceeding 5 years». The words «or who otherwise contravenes this Act» are what carry a s. 38 breach into the penalty; without them the Mauritian position would be the Zambian one. Note the conjunction: the subsection reads «and» rather than «or» between fine and imprisonment, which on a literal reading makes both cumulative on conviction rather than alternative — an unusual drafting result, recorded as it stands rather than softened. Section 43(2) adds that the Court may order forfeiture of any equipment or article used or connected with the offence, and may order or prohibit the doing of any act to stop a continuing contravention. Separately, s. 42 creates a specific unlawful-disclosure offence, with s. 42(5) reaching a person who offers to sell personal data obtained in breach of it and s. 42(6) treating an advertisement indicating that personal data is or may be for sale as an offer to sell. Enforcement short of prosecution runs through the Commissioner: s. 6 investigation of complaints, s. 7 power to require information, s. 8 preservation order and s. 9 enforcement notice, with a right of appeal under s. 51 and the special jurisdiction of the Tribunal under s. 52. Impact tier: all entities.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.