Compliance
Data Protection Act 2017: What Your Mauritius Website Must Do
If your website has a contact form, a newsletter signup, a booking system, a login, or Google Analytics, you are processing personal data and the Data Protection Act 2017 applies to your business. Most Mauritian SME websites are not compliant, mainly because almost nothing has been written about this for business owners rather than lawyers. This guide covers what the Act actually asks of a website, what registration involves, and what changes in January 2027.
By Nexstack · Published · 8 min read
What the Act covers, and whether it applies to you
The Data Protection Act 2017 governs the processing of personal data in Mauritius. It is closely modelled on the European GDPR, which is why the vocabulary will look familiar if you have dealt with EU clients. Personal data means any information that can identify a living person: a name, an email address, a phone number, an IP address, a photograph, a customer order history.
In practice, your website is in scope if it does any of the following:
- Collects names, emails or phone numbers through a contact or quote form
- Runs a newsletter or mailing list
- Takes bookings, applications or online orders
- Has customer accounts or a login
- Uses analytics, advertising pixels or any tracking cookie
- Embeds third-party tools that receive visitor data
That is nearly every business website in Mauritius. The size of your company does not exempt you.
Do you need to register as a Data Controller?
Mauritius requires organisations that determine how and why personal data is processed, the controllers, to register with the Data Protection Office. This is a distinctive feature of the Mauritian regime and is the obligation most SMEs are unaware of.
Published registration fees are tiered by headcount. At the time of writing, guidance indicates Rs 1,000 for organisations with up to five employees, Rs 1,500 for six to twenty-five, and Rs 2,500 above that, with a certificate valid for three years.
| Number of employees | Indicative registration fee | Validity |
|---|---|---|
| 0 – 5 | Rs 1,000 | 3 years |
| 6 – 25 | Rs 1,500 | 3 years |
| More than 25 | Rs 2,500 | 3 years |
Applications are made to the Data Protection Office, which publishes application guides for controllers. Verify the current fee, form and payment method with the Office before you apply, since these details change.
Cookie consent: what is actually required
The consent standard under the Act is the strict one. Consent must be freely given, specific, informed and unambiguous, which has concrete consequences for how a cookie banner is built:
- No pre-ticked boxes and no implied consent. "By continuing to browse you accept cookies" is not consent.
- Non-essential cookies must not fire before the visitor agrees. This is where most banners fail: the banner appears, but Analytics and the advertising pixel have already loaded.
- Rejecting must be as easy as accepting. A prominent Accept button with Reject buried in a settings sub-menu does not meet the standard.
- Consent cannot be bundled into your terms and conditions. It has to be a separate, specific choice.
- Withdrawal must be straightforward. Visitors need a way to change their mind later, which means keeping the cookie settings reachable from the footer.
- Strictly necessary cookies are different. Session and security cookies your site cannot function without do not require consent, but you should still disclose them.
What a compliant privacy policy has to say
A privacy policy is not a formality to copy from another site. Copied policies routinely describe data flows that do not match the business, which is worse than a short and accurate one. Yours should state, in language a customer can follow:
- Who you are, with a real contact address and email
- What personal data you collect, itemised: form fields, account data, analytics, cookies
- Why you collect each type, and your lawful basis for doing so
- Who you share it with, naming the actual third parties: your email platform, hosting provider, analytics, payment gateway
- Whether data leaves Mauritius, which it does if you use most international cloud services
- How long you keep it, and what triggers deletion
- What rights individuals have, including access, correction, objection and erasure, and exactly how to exercise them
- How to complain to the Data Protection Office if they are not satisfied with your response
Keep it current. The moment you add a chat widget, a booking tool or a new pixel, the policy is out of date.
The Data Protection Officer rules arriving in January 2027
Mauritius has moved to formalise the Data Protection Officer role through binding regulations, reported as taking effect on 1 January 2027 after a compliance moratorium, with organisations required to notify the Data Protection Office of a designation within a short window of making it.
If you run a small business with a brochure website and a contact form, this is unlikely to change your day-to-day. If you process personal data at scale, handle sensitive categories such as health data, or operate in a regulated sector, this deserves attention now rather than in December 2026. Confirm the applicable requirements and dates with the Data Protection Office or your legal adviser, since regulations of this kind are refined as they come into force.
A practical compliance checklist for your website
- List every place your site collects personal data, including third-party embeds you may have forgotten.
- Publish a privacy policy that matches that list, linked from every page footer.
- Implement a cookie banner that genuinely blocks non-essential scripts until consent is given, with an equally easy reject option.
- Add a clear consent checkbox to forms, unticked, explaining what the person is agreeing to.
- Check whether your organisation must register as a Data Controller, and register if so.
- Serve the entire site over HTTPS, and make sure form submissions and any stored data are protected.
- Set a retention rule for form submissions and old accounts, and actually delete on schedule.
- Know who in your business responds to an access or deletion request, and how fast.
- Re-check the policy and banner each time you add a tool to the site.
Beyond avoiding penalties, this work builds trust. A visitor who sees a genuine cookie choice and a policy that names real third parties is more likely to hand over their details in the first place, which is the point of the form.
Want a website that is compliant from day one?
We build compliance into every site we deliver: consent-gated analytics, an honest cookie banner, a privacy policy that matches your actual data flows, and HTTPS everywhere. If you already have a site, we can audit and fix what is missing.
Frequently asked questions
Do I need a cookie banner on my Mauritius website?
If your site uses any non-essential cookies, including Google Analytics or advertising pixels, you need to obtain consent before those cookies are set. Consent under the Data Protection Act 2017 must be freely given, specific, informed and unambiguous, so pre-ticked boxes and implied consent from continued browsing are not sufficient.
How much does Data Controller registration cost in Mauritius?
Published guidance indicates tiered fees of Rs 1,000 for organisations with up to five employees, Rs 1,500 for six to twenty-five, and Rs 2,500 for more than twenty-five, with the certificate valid for three years. Confirm the current fee and process with the Data Protection Office before applying.
Does a small business in Mauritius need a Data Protection Officer?
Mauritius has formalised the Data Protection Officer role through regulations reported as taking effect on 1 January 2027, with notification to the Data Protection Office required after designation. Whether your organisation is caught depends on the nature and scale of your processing, so confirm your position with the Data Protection Office or a legal adviser rather than assuming a small business is exempt.
Does the Data Protection Act apply if my website only has a contact form?
Yes. A contact form collects names, email addresses and often phone numbers, which is personal data. You need a lawful basis for collecting it, a privacy policy explaining what happens to it, a retention rule, and a way for people to ask for their data to be corrected or deleted.
Is GDPR compliance enough for a Mauritian website?
The Data Protection Act 2017 is closely modelled on the GDPR, so a genuinely GDPR-compliant site meets most of the substance. The important difference is Mauritius-specific procedure, particularly registration with the Data Protection Office and local notification requirements, which GDPR compliance alone does not cover.
Keep reading
How Much Does a Website Cost in Mauritius in 2026?
Rupee-by-rupee breakdown of website pricing in Mauritius: what a landing page, a business site and an online store actually cost, which fees get left out of quotes, and how the SME Mauritius grant schemes can cover up to 80% of the bill.
The Best Payment Gateway for E-Commerce in Mauritius
A practical comparison of the payment options available to Mauritian online stores: what MIPS actually costs per month, how the MCB Juice and Peach Payments partnership works, what your bank needs from you, and how to choose without locking yourself in.