Mauritius has put its data protection officer regime on a statutory footing. The new regulations take effect on 1 January 2027, and on one key point, they reverse what the previous guidance allowed.
Key takeaways
- The Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 (GN No. 117 of 2026) come into force on 1 January 2027.
- A data protection officer (DPO) must now be an in-house staff member: outsourced or external DPOs will no longer satisfy the requirement.
- DPOs must hold a recognised certification from the Data Protection Office or an approved institution.
- Controllers must notify the Office within 14 days and publish the DPO’s contact details.
- Breaching the notification or publication duties is an offence carrying up to Rs 100,000 and 5 years’ imprisonment.
On 17 June 2026, the Minister made the Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 (Government Notice No. 117 of 2026) under section 55 of the Data Protection Act 2017. The regulations come into operation on 1 January 2027, giving organisations a short window to adjust before compliance becomes mandatory.
For any organisation processing personal data in Mauritius, this is more than a tidy-up exercise. Until now, the DPO function rested on a single clause of the Act and a set of non-binding guidelines issued by the Data Protection Office in 2023. The new regulations replace that soft framework with enforceable obligations and, on one important point, they reverse what the earlier guidance permitted.
The regulations at a glance
| Instrument | Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 |
| Citation | Government Notice No. 117 of 2026 |
| Enabling power | Section 55, Data Protection Act 2017 |
| Made | 17 June 2026 |
| In force | 1 January 2027 |
| Who it binds | Every controller (with a lead DPO where more than one is appointed) |
| Maximum penalty | Rs 100,000 fine and 5 years’ imprisonment (regs 3(4) and 8(1)) |
From a single clause to a detailed code
The Act itself says very little about DPOs. Section 22(2)(e) simply requires a controller, as part of its general duty to demonstrate compliance, to designate an officer responsible for data protection compliance issues. Everything else about the role—independence, qualifications, how the officer should be treated—lived in the Office’s 2023 guidance, which borrowed heavily from the EU’s General Data Protection Regulation and the European guidance on DPOs.
The 2026 Regulations take that framework and give it legal force. They spell out how a DPO is appointed, what the officer must do, how the officer must be qualified, and how the controller must support and protect the role. Much of what was previously good practice is now law.
The headline change: your DPO must be on your payroll
The most significant shift concerns who may hold the role. Regulation 3(1) requires the controller to designate its DPO from a staff member of the organisation. That is a deliberate departure from the 2023 guidance, which expressly allowed organisations to outsource the DPO function to an external individual or firm under a service contract.
The practical consequence is clear: once the regulations are in force, an outsourced or external DPO will no longer satisfy the requirement. Organisations that currently rely on a consultant or external service provider for this role will need to bring it in-house—appointing and, where necessary, training an existing or newly recruited employee—before 1 January 2027.
Where an organisation appoints more than one DPO (which the regulations permit, having regard to organisational structure, size, scale, and the complexity and sensitivity of the processing), it must designate a lead data protection officer to act as the primary point of contact with the Data Protection Office and with data subjects.
A new certification requirement
Regulation 5 sets out the qualifications a DPO must have. Beyond the expected expert knowledge of Mauritian data protection law, a proven ability to perform the role, and an in-depth understanding of the organisation’s operations and regulatory environment, the regulations introduce something new: the DPO must hold evidence of certification.
That certification must come either from the Data Protection Office itself—following successful completion of the Office’s training and payment of the applicable fee—or from a registered and accredited training institution approved by the Office. There was no certification requirement under the previous guidance, so organisations should factor training lead times and costs into their planning now rather than close to the deadline.
Tell the Office and tell the public
The regulations impose two new transparency duties. First, under regulation 3(4), the controller must communicate the DPO’s (or lead DPO’s) particulars to the Data Protection Office within 14 days of designation, and must notify the Office of any change within 14 days of that change.
Second, under regulation 8, the controller must publish the DPO’s contact details in a conspicuous place on its premises or, where applicable, on its website. Data subjects are given an express right to contact the DPO about the processing of their personal data or the exercise of their rights under the Act.
What the DPO must actually do
Regulation 4 replaces vague expectations with a concrete task list. The DPO (or lead DPO) is responsible, among other things, for:
- ensuring personal data is processed in line with the data protection principles;
- protecting data subject rights and handling data protection impact assessments;
- ensuring security and organisational measures are in place, and maintaining the record of processing operations;
- notifying the Office of, and communicating to data subjects, any personal data breach;
- managing the organisation’s registration as a controller or processor;
- facilitating the Office’s investigations, compliance audits, security checks and inspections;
- informing and advising the organisation and its staff, and monitoring compliance through internal audits, awareness-raising and training; and
- acting as liaison with the Commissioner.
Crucially, in performing these duties the DPO must report to the highest management level of the organisation.
Independence and job security, now enforceable
The regulations put real weight behind the DPO’s independence. Under regulation 6, the controller must ensure that the DPO’s other duties do not create a conflict of interest, involve the DPO in a timely way in all data protection matters, provide the necessary resources and training, and allow the officer to work independently and free from unlawful interference. Pointedly, the controller must not dismiss, suspend or otherwise penalise a DPO for lawfully performing the duties set out in the regulations. What was a recommendation in 2023 is now a legal protection.
Liability: shielded from the State, accountable to the employer
Regulation 7 strikes a careful balance. The DPO is not personally liable for the controller’s failure to comply with the Act: responsibility for compliance remains, as it always has, with the controller or processor. But the same regulation makes clear that the organisation may hold the DPO accountable for failing to perform the specific tasks assigned to the role under regulation 4. In short, the DPO does not carry the organisation’s regulatory liability, but is answerable internally for doing the job.
Offences and penalties
Regulation 9 creates a specific offence for contravening the notification duty (regulation 3(4)) or the publication duty (regulation 8(1)). On conviction, the penalty is a fine of up to Rs 100,000 and imprisonment for up to 5 years, the maximum the Act’s regulation-making power allows.
It is worth noting what regulation 9 does not directly criminalise: failing to designate a DPO in the first place, or breaching the certification and support obligations, are not named offences under this regulation. That said, a failure to designate would still expose a controller through the Act’s general non-compliance provisions, so this should not be read as a safe harbour.
Who is affected and what to do before 1 January 2027
These regulations reach every controller in Mauritius, from banks, insurers and fintechs to retailers, healthcare providers, BPO operators and public bodies. Organisations that today rely on an external DPO, or that have never formally appointed one, face the largest gap. The following steps close it:
- Audit your current arrangement. If your DPO is external or outsourced, plan now to move the role in-house to a staff member.
- Identify and certify your DPO. Confirm who will hold the role and arrange Office-approved certification, allowing for training lead times.
- Check for conflicts of interest. Ensure the DPO’s other responsibilities do not involve determining the purposes and means of processing.
- Prepare your notifications. Put a process in place to inform the Data Protection Office of the designation, and of any future change, within 14 days.
- Publish contact details. Add the DPO’s contact information to your website and premises.
- Resource and protect the role. Ensure senior-management support, adequate resources, training, independence, and reporting lines to the highest management level.
FAQs
What are the Mauritius DPO Regulations 2026?
They are the Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 (Government Notice No. 117 of 2026), made under section 55 of the Data Protection Act 2017. They set out how a data protection officer must be appointed, qualified, supported and protected, and they take effect on 1 January 2027.
When do the 2026 DPO Regulations come into force?
The regulations were made on 17 June 2026 and come into operation on 1 January 2027. Compliance changes should be completed before that date.
Can a business in Mauritius use an external or outsourced DPO?
No. From 1 January 2027, regulation 3(1) requires the DPO to be designated from a staff member of the organisation. This reverses the 2023 guidance, which had allowed the role to be outsourced. Organisations using an external DPO must bring the role in-house.
Does a Mauritian data protection officer need a certification?
Yes. Regulation 5 requires the DPO to hold certification issued either by the Data Protection Office (after completing its training and paying the applicable fee) or by a registered and accredited training institution approved by the Office.
Who must appoint a data protection officer under Mauritian law?
Every controller must designate a DPO for the purpose of section 22(2)(e) of the Data Protection Act 2017. Where more than one DPO is appointed, the controller must designate a lead DPO as the primary contact with the Office and data subjects.
What is the penalty for breaching the 2026 DPO Regulations?
Regulation 9 makes it an offence to contravene the duty to notify the Office of the DPO’s particulars (regulation 3(4)) or to publish the DPO’s contact details (regulation 8(1)). On conviction, the penalty is a fine of up to Rs 100,000 and imprisonment for up to 5 years.
How ITLawCo can help. We advise on appointing and structuring the DPO function, managing conflicts of interest, meeting the new certification and notification requirements, and building the internal governance regulation 6 now demands. If your organisation needs to be ready by 1 January 2027, the time to start is now. Contact us.
This article is provided for general information only and does not constitute legal advice. It reflects the law at 2 July 2026. For advice tailored to your organisation’s circumstances, please contact ITLawCo.




