Insights

The Data Protection Act 2017 and AI: the six sections that apply to your systems

Mauritius does not yet have an AI-specific statute. The National AI Strategy 2025 to 2029 and the FAIR Guidelines set direction, but the FAIR Guidelines are non-binding: they state that they create no legal obligations, and they address public and private organisations alike, applied proportionately to size. Some directors conclude from this that AI is unregulated in Mauritius until Parliament says otherwise. It is not.

The Data Protection Act 2017 (Act 20 of 2017, in force since 15 January 2018) applies to the processing of personal data “wholly or partly, by automated means” (section 3(3)). Almost every commercial AI use involves personal data: the CV a screening tool reads, the history a credit model scores, the complaint a member of staff pastes into a public generative AI tool. If your AI system touches information about an identifiable person, the Act applies, and it was drafted with automated processing and profiling in mind.

This article groups the relevant provisions into six areas and shows what each means for five common uses: CV screening, credit scoring, customer chatbots, staff using public generative AI tools with customer data, and analytics on customer data. Paragraphs are labelled Legal requirement (what the Act says), Best practice (Data Protection Office guidance or accepted professional practice) or Consultaix recommendation (our view).

Disclaimer. This is general information, not legal advice. The Data Protection Office, headed by the Data Protection Commissioner, is the authority on the Act. Section references were checked against the published text of the Act. Where a decision turns on a provision, read the section itself and, if the stakes justify it, take legal advice.

1. Scope and definitions: why the Act reaches most AI

Legal requirement. “Personal data” means “any information relating to a data subject”, and a data subject is an identified or identifiable individual, including by reference to a name, an identification number, location data or an online identifier (section 2). “Processing” covers any operation on personal data “whether or not by automated means”, expressly including collection, storage, adaptation, retrieval, use, disclosure by transmission, alignment or combination, and erasure (section 2). “Profiling” means automated processing that evaluates personal aspects of an individual, “in particular to analyse or predict aspects concerning that individual’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements” (section 2).

Legal requirement. The Act binds a controller or processor established in Mauritius that processes personal data in the context of that establishment (section 3(5)(a)). A controller determines the purposes and means of processing; a processor acts on the controller’s behalf (section 2). No person may act as either unless registered with the Commissioner (section 14).

What it means for AI. Training, inference, scoring and summarising are all processing. Sending a customer record to a third-party AI service is disclosure by transmission. The vendor running the model is usually your processor; you remain the controller because you decided why and how the data is used. The profiling definition, with its reference to performance at work and economic situation, maps directly onto CV screening and credit scoring.

Consultaix recommendation. Inventory every AI tool in use, including free consumer accounts, before any policy work; the inventory belongs inside the section 33 record of processing.

2. Lawful basis, purpose limitation and consent

Legal requirement. Section 28(1) sets out the grounds for processing: consent for specified purposes; necessity for a contract with the data subject or for pre-contractual steps at the data subject’s request; a legal obligation; vital interests; public interest tasks; the legitimate interests of the controller or a third party, “except if the processing is unwarranted in any particular case having regard to the harm and prejudice to the rights and freedoms or legitimate interests of the data subject”; and historical, statistical or scientific research. Processing without a ground is an offence carrying a fine of up to 100,000 rupees and up to five years’ imprisonment (section 28(2)).

Legal requirement. Section 21 requires personal data to be processed lawfully, fairly and transparently; collected for explicit, specified and legitimate purposes and not further processed incompatibly with them; limited to what is necessary; accurate; and kept no longer than necessary. Where consent is relied on, the controller must prove it, the data subject may withdraw it at any time, and consent is unlikely to be “freely given” if a service is conditional on consent to unnecessary processing (section 24). Special categories of personal data (including health, ethnicity, religion, biometric data and criminal matters) may be processed only where a section 28 ground applies and a further condition in section 29(1) is met.

What it means for AI. Purpose limitation is the provision AI most often breaks by accident. Order data was collected to fulfil orders; using it to train a churn model or build marketing profiles is a new purpose that must be compatible with the original or supported by a fresh ground and notice. For CV screening, the pre-contractual ground in section 28(1)(b)(i) is the natural fit; for credit scoring, contract or legitimate interests with the balancing test written down; for a chatbot, answering the question sits within contract or legitimate interests, but keeping transcripts to train the model is a separate purpose. For staff using public generative AI tools there is usually no ground at all, because nobody decided. Consent is rarely right in employment or lending: it is hard to show it was freely given and it can be withdrawn.

Consultaix recommendation. Treat further processing as a gate. Before data collected for one purpose is used to train or tune a model, a named senior person confirms in writing that the new use is compatible, or that a new ground and notice are in place.

3. Transparency: what a person must be told

Legal requirement. When collecting personal data directly from a person, a controller must at that time inform them of the matters in section 23(2): the controller’s identity and contact details; the purpose; intended recipients; whether supply is voluntary or mandatory; the right to withdraw consent; the rights of access, rectification, restriction, erasure and objection; “the existence of automated decision making, including profiling, and information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject” (section 23(2)(g)); the storage period; the right to complain to the Commissioner; and, where applicable, any intended transfer abroad and the protection available there. Where data are not collected directly, the controller must still ensure the person is informed (section 23(4)), subject to the exceptions in section 23(3).

Legal requirement. The same information about automated decision making is owed on an access request (section 37(2)(h)), “in an intelligible form, using clear and plain language” (section 37(3)). Where a solely automated decision falls within a permitted exception, the notice must include the existence of that processing and its envisaged effects (section 38(4)). The right to object, including to profiling for direct marketing, must be “explicitly brought to the attention of the data subject” (section 40(4)).

What it means for AI. If a recruitment portal ranks applicants with a model, the applicant notice must say so, explain the logic in terms a layperson can follow (the factors weighed, not the code) and state the consequence, for example that low-ranked applications may not be read by a person. A lender owes the same for scoring. A chatbot should say it is automated and what happens to the conversation. Marketing analytics must disclose profiling and the right to object.

Best practice. Write the plain-language explanation once and reuse it in the notice, access responses and staff scripts. The UK Information Commissioner’s Office publishes guidance on explaining AI decisions; it is not authority in Mauritius, but it is a useful comparator for phrasing.

4. Solely automated decisions and profiling

Legal requirement. Every data subject has “the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or significantly affects him” (section 38(1)). The right does not apply where the decision is necessary for entering into or performing a contract with the data subject, is authorised by a law that provides suitable safeguards, or is based on explicit consent (section 38(2)). Under the contract and consent exceptions the controller must still “implement suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests” (section 38(5)). Separately, automated processing intended to evaluate personal aspects of an individual “shall not be based on special categories of personal data” (section 38(3)); that prohibition is not qualified by the subsection (2) exceptions.

When is a decision “solely automated”?

The Act does not define “solely”. On a plain reading, a decision is solely automated when no person exercises real judgement between the system’s output and the outcome. “Significantly affects” is a second test: refusing a job application, declining a loan or setting a premium plainly qualifies; ordering a recommendation list does not.

Best practice. The safe working assumption, consistent with how supervisory authorities elsewhere read the equivalent concept, is that human involvement takes a decision outside “solely automated” only when the reviewer has the authority, the information and the time to change it, and actually considers the case. Approving every recommendation unread is not meaningful involvement; nor is review only on complaint.

What it means for AI. CV screening that auto-rejects below a threshold, with nobody reading the rejected CVs, is a solely automated decision that significantly affects the applicant. It is lawful only under a section 38(2) exception, and the contract argument weakens the further the tool goes beyond checking stated minimum requirements. Auto-decline in credit scoring is in the same position. A chatbot that issues refunds mechanically is arguably deciding; one that routes to a human is not. Marketing segmentation is profiling, which customers may object to under section 40(2), but rarely “significantly affects” anyone. Section 38(3) matters for any model that could use, or infer, health, ethnicity, religion or biometric data.

Consultaix recommendation. For anything affecting employment, credit, insurance or access to a service, design the workflow so the system recommends and a named person decides. Where full automation is a genuine requirement, document the exception relied on, the safeguards and how a person contests the outcome.

5. DPIA and prior consultation: what you must do before switching on

Legal requirement. Where processing “is likely to result in a high risk to the rights and freedoms of data subjects by virtue of their nature, scope, context and purposes, every controller or processor shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data” (section 34(1)). The operations concerned include “a systematic and extensive evaluation of personal aspects relating to individuals which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the individual or significantly affect the individual” (section 34(2)(a)), large-scale processing of special categories (34(2)(b)), large-scale monitoring of public areas (34(2)(c)) and any operation for which consultation with the Office is required (34(2)(d)). A DPIA must contain a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to data subjects, and the measures to address them (section 34(3)); where appropriate, data subjects’ views must be sought (section 34(4)). Performing a DPIA is also a listed duty of every controller (section 22(2)(c)).

Legal requirement. Where the DPIA indicates a high risk, the controller or processor must consult the Office before processing (section 35(2)(a)); the Office may also require consultation on its own initiative (35(2)(b)). If risks are “insufficiently identified or mitigated”, the Office “shall prohibit the intended processing” and propose remedies (section 35(3)). The DPIA must be provided to the Office (section 35(5)).

Best practice. The Office publishes nine criteria for high-risk processing, drawn from the EU Article 29 Working Party: evaluation or scoring including profiling; automated decisions with significant effects; systematic monitoring; sensitive data; large scale; matching datasets; vulnerable persons; innovative technology, for which the Office’s own example is “Using Artificial Intelligence (AI) based systems”; and processing that denies a right or service. Its rule of thumb: two or more criteria means likely high risk and a DPIA is required; one criterion, where the controller considers the risk high, means a DPIA is recommended. The Office’s examples of automated decision-making include credit-scoring databases and “automated selection of candidates for job interviews based on forecasted productivity”.

What it means for AI. Because AI use is itself a criterion, any AI system on personal data starts with one, and a second is easy to find: profiling for screening, scoring and analytics; automated decisions for auto-reject; large scale for a chatbot across a customer base. On the Office’s method, a DPIA is required before deployment for each of the five uses here, with the possible exception of small-scale analytics that do not profile.

Best practice. The Office’s DPIA form (QMS 32) runs in seven steps from general information through risk scoring and mitigation to sign-off, and DPIAs can be submitted online through its eDPO system. Whether every DPIA must be lodged, or only those that trigger prior consultation under section 35, is a point to confirm with the Office for your own case.

Consultaix recommendation. Run the DPIA as a project gate. The companion article on AI impact assessment or DPIA gives a one-week method and shows how one document can serve section 34 and ISO/IEC 42001.

6. Security, processors, records, breaches and transfers

Legal requirement. A controller or processor must, when deciding the means of processing and during it, implement security and organisational measures against unauthorised access, alteration, disclosure, accidental loss and destruction, proportionate to the harm and the nature of the data (section 31(1)). The measures “shall include” pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience, timely restoration after an incident, and regular testing (section 31(2)(a)). Employees must be made aware of and comply with the measures (section 31(6)). A controller using a processor must choose one giving “sufficient guarantees” and enter into a written contract under which the processor acts only on instructions and is bound by the controller’s security obligations (section 31(4)); a processor acting outside instructions becomes a controller for that processing (section 31(5)).

Legal requirement. Every controller or processor must keep a record of processing operations covering purposes, data categories, recipients, transfers and safeguards, retention and verification mechanisms, and produce it to the Office on request (section 33). Every controller must designate an officer responsible for data protection compliance (section 22(2)(e)). A personal data breach must be notified to the Commissioner without undue delay and, where feasible, within 72 hours (section 25(1)); a processor must notify the controller without undue delay (section 25(2)); and where the breach is likely to result in high risk to a person, that person must be told (section 26).

Legal requirement. Personal data may leave Mauritius only under a section 36(1) condition: proof to the Commissioner of appropriate safeguards; explicit consent after being informed of the risks; necessity for a contract with or in the interest of the data subject, for public interest reasons provided by law, for a legal claim or for vital interests; a narrow compelling legitimate interests ground for non-repetitive transfers concerning few data subjects, again with proof of safeguards; or transfer from a public register. The Commissioner may demand proof that safeguards work and may prohibit, suspend or condition a transfer (section 36(4)).

What it means for AI. This group catches staff use of public generative AI tools. Pasting a customer’s name, account details and complaint into a consumer AI account is a disclosure to a third party under terms you have not negotiated, to servers usually abroad. That engages section 31(4) (no processor contract), section 36 (no documented transfer basis) and section 31(6) (staff unaware of the rules). The same provisions apply, more manageably, to any AI vendor hosted abroad: it needs a section 31(4) contract, a section 36 basis, a section 33 entry and a place in the breach plan, because an incident at the vendor is your breach to notify.

Best practice. Use enterprise tiers that contractually exclude training on your data and allow retention to be set, and include AI vendors in the periodic testing of measures that section 31(2)(a)(iv) contemplates.

Consultaix recommendation. Publish a short acceptable-use rule for generative AI first: approved tools, what may never be entered (customer and employee personal data, special categories, anything under NDA) and who to ask. The companion AI acceptable-use policy template gives a starting draft.

Five common AI uses and the provisions they trigger

A starting map, not a substitute for analysis of the specific system. “Likely” reflects the Office’s two-criteria rule of thumb.

AI use Lawful basis and purpose (ss. 21, 24, 28, 29) Transparency (ss. 23, 37, 40) Solely automated decisions (s. 38) DPIA and consultation (ss. 34, 35) Security, processors, transfers, breach (ss. 25, 26, 31, 33, 36)
CV screening or ranking Pre-contractual ground; minimise inputs; s. 38(3) bars evaluation on special categories Tell applicants profiling exists, the logic and the consequences (s. 23(2)(g)) Auto-reject with no human review is solely automated; needs a s. 38(2) exception plus safeguards Required: profiling plus AI use; the Office cites automated interview selection Processor contract; transfer basis if hosted abroad; record of processing
Credit scoring Contract or legitimate interests with a written balancing test; reuse must be purpose-compatible Tell customers scoring occurs and what it means; same on access requests (s. 37(2)(h)) Auto-decline is solely automated; contract exception may apply, with safeguards and a review route Required: scoring plus automated decisions; consultation likely if high risk remains As above; FSC and Bank of Mauritius rules may add duties for licensees
Customer-facing chatbot Contract or legitimate interests for answering queries; training on transcripts is a separate purpose Tell customers the system is automated and what happens to the conversation Usually not a significant decision, unless the bot settles claims, refunds or eligibility alone Likely where the bot serves the whole customer base (AI use plus large scale) Vendor contract; transfer basis; customers may volunteer special categories, so retention matters
Staff using public generative AI tools with customer data Often no ground for the disclosure; likely incompatible with the original purpose Customers have not been told Not usually a decision Not usually planned; applies if the tool is formally adopted at scale Main exposure: no processor contract (s. 31(4)), undocumented transfer (s. 36), staff unaware (s. 31(6)), breach risk (s. 25)
Analytics and segmentation Purpose compatibility is the main test; legitimate interests common; marketing profiling can be objected to (s. 40(2)) Notice must mention profiling and the right to object (s. 40(4)) Rarely a significant decision unless segments set pricing or access Likely where profiling meets matching datasets or large scale Security of the combined dataset; record of processing; retention limits

Registration (section 14), the compliance officer (section 22(2)(e)) and the record of processing (section 33) apply to the organisation as a whole.

A note on the GDPR

The Office’s introductory guide states that the Act “has been designed to align with the key principles found in international laws namely the EU General Data Protection Regulation”. That makes GDPR-era commentary on AI useful reading. It does not make GDPR article numbers authority in Mauritius: cite the Act’s sections, and where the Act is worded differently, as section 38(3) is, the Act governs.

Where Consultaix fits

Consultaix’s AI Governance Advisory helps organisations map their AI uses against the Data Protection Act 2017, ISO/IEC 42001 and relevant sector guidance, and build the records, notices and decision workflows described above at a scale that suits an organisation without a compliance department. Earlier in the journey, the AI Readiness Assessment scores governance alongside strategy, data, capability and execution and shows which of these provisions your current AI use already engages.

Sources