Mauritius' New DPO Regulations Change the Rules by 1 January 2027 - Here's How to Get Ahead of Them
For the first time, Mauritius has turned the Data Protection Act 2017's single-clause DPO requirement into a detailed, enforceable framework - one with no small-business exemption and a hard deadline. This guide explains what the Data Protection Office actually requires from registration through to your first in-house Data Protection Officer, and how ISECURION helps organizations across Mauritius get there.
What's Inside This Guide
- Data Protection in Mauritius: The DPA 2017 & DPO Regulations 2026 at a Glance
- The Data Protection Act 2017 Explained
- DPO Regulations 2026: What Changes by 1 January 2027
- Personal Data Breach Notification & Penalties
- VAPT & Security Assessment Services
- Compliance Audits, DPIA & Certification Support
- Sector-Wise Coverage Across Mauritius
- Compliance Roadmap to 1 January 2027
- Comprehensive FAQ
Data Protection in Mauritius at a Glance
These are the four pillars every organization processing personal data in Mauritius needs to understand - the foundation ISECURION builds every DPO engagement on:
DPA 2017
Mauritius' core data protection law, aligned with the GDPR and Convention 108+, administered by the Data Protection Office and Commissioner.
DPO Regulations 2026
Binding rules on how the Data Protection Officer must be designated, resourced, and positioned - in force from 1 January 2027.
Controller/Processor Registration
A mandatory, renewable registration with the Data Protection Office - not a one-time filing you can forget about for good.
Breach Notification
A 72-hour clock to the Commissioner once a personal data breach is discovered, with separate obligations to affected individuals.
The Compliance Gap Isn't the Law. It's Having Someone Own It.
Most organizations in Mauritius don't fall short of the DPA 2017 because their intentions are wrong - they fall short because no one internally is accountable for registration renewals, breach-response readiness, and now, a properly designated and trained in-house DPO. ISECURION's Data Protection Compliance model exists to close that gap: registration support, DPO training and certification, and a security program built to satisfy an actual Data Protection Office audit, not just a checklist.
What This Guide Covers:
- The Data Protection Act 2017 - scope, principles, and who must register as controller or processor
- DPO Regulations 2026 in full: designation, independence, resourcing, and the 1 January 2027 deadline
- Personal data breach notification timelines and the penalties for getting them wrong
- Cross-border data transfer rules for Global Business Companies and outsourcing operations
- VAPT and security assessments that demonstrate the technical safeguards the Act requires
- Data Protection Impact Assessments and voluntary certification support
- Sector-specific guidance for financial services, healthcare, hospitality, and BPO/ICT
- A phased roadmap to get compliant before the moratorium ends
Get Your Free DPO Readiness Assessment
Understand your organization's registration status, DPO obligations under the 2026 Regulations, and your path to 1 January 2027. Our team responds within 24 hours. No obligation.
The Data Protection Act 2017 Explained
The Data Protection Act 2017 (Act No. 20 of 2017) came into force on 15 January 2018, replacing the Data Protection Act 2004 and modernizing Mauritius' data protection framework to align with international standards, incorporating principles from the EU's General Data Protection Regulation 2016/679 (GDPR) and the Council of Europe's Convention 108+. The Act is administered by the Data Protection Office, headed by the Data Protection Commissioner, who is appointed by the President on the advice of the Prime Minister and exercises independent supervisory functions, including registration of data controllers and processors, investigation of complaints, conducting audits, issuing enforcement notices, and imposing penalties.
Who the Act Applies To
The DPA 2017 applies to every data controller established in Mauritius - a person or public body who alone, or jointly with others, determines the purposes and means of processing personal data and holds decision-making power over that processing. It also applies to entities that use equipment located in Mauritius to process personal data, even if the organization itself is based elsewhere. This reaches well beyond banks and telecoms: Global Business Companies licensed under the Financial Services Act, e-commerce platforms, hospitality groups, healthcare providers, BPO and ICT companies, and professional services firms are all commonly caught by the definition.
Core Obligations Under the Act
Registration of Controllers & Processors
Every controller (and, where applicable, processor) must register with the Data Protection Office before processing personal data. Registration is valid for three years and must be renewed before expiry, with fees set under the Data Protection (Fees) Regulations 2020.
Lawful Processing & Consent
Processing must have a legal basis - consent, contract, legal obligation, vital interest, public interest, or legitimate interest - and organizations must be able to demonstrate which basis applies to each processing activity.
Rights of Data Subjects
Individuals have rights of access, rectification, erasure, restriction of processing, and the right to object to decisions based solely on automated processing, including profiling, that significantly affect them.
Cross-Border Data Transfer Restrictions
Personal data may only be transferred outside Mauritius to countries the Commissioner recognizes as providing adequate protection, or under approved safeguards such as binding contractual clauses - a key consideration for GBCs and outsourcing arrangements.
Data Protection Impact Assessments
High-risk processing activities require a documented DPIA before processing begins, along with prior authorization or consultation with the Commissioner in specified cases.
Security of Processing
Controllers must adopt policies and implement appropriate technical and organizational security measures, and be able to demonstrate accountability for how personal data is actually protected in practice.
A Registration Isn't a One-Time Filing
Many organizations register once with the Data Protection Office and assume the obligation is discharged permanently. Registration is valid for three years under section 16(2) of the Act, and failing to renew it is treated the same as never registering at all - an offence punishable by a fine of up to MUR 200,000 and imprisonment for up to five years. Tracking renewal dates is one of the most common gaps ISECURION finds during compliance audits in Mauritius.
DPO Regulations 2026: What Changes by 1 January 2027
The Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, made under section 55 of the DPA 2017 and approved by Cabinet in mid-June 2026, close the gap between the Act's high-level DPO obligation and day-to-day reality. Where the previous framework rested on a single statutory clause supported by non-binding 2023 guidelines, the new Regulations set out precisely how a DPO must be appointed, qualified, resourced, and protected - and they apply to every controller of personal data, with no general exemption for small businesses, micro-enterprises, or low-volume processing.
What the Regulations Actually Require
In-House Designation Only
Effective: 1 January 2027
What Changes: Regulation 3(1) requires the DPO to be designated from among an organization's own staff members, reversing the earlier position under 2023 guidelines that allowed the role to be held by someone entirely outside the organization
Practical Impact: Organizations currently relying on an outsourced or purely external DPO need to identify and train a qualified internal staff member before the deadline
Notification & Publication Duties
Timeline: Notify the Data Protection Office within 14 days of designating a DPO
Publication: The DPO's contact details must be published on the organization's website and at its premises
Penalty for Breach: A fine of up to MUR 100,000 and imprisonment for up to five years
Independence & Reporting Line
Requirement: The DPO must have a direct reporting line to the organization's highest level of management
Structural Protection: The DPO cannot be placed in a position where instructions on how to carry out the role compromise their independence
Why It Matters: This is what separates a genuine compliance function from a title added to an unrelated job description
Resourcing, Training & Support
Requirement: Senior-management support, adequate resources, and ongoing training appropriate to the role
Scope of Duties: Advising on DPA 2017 obligations, monitoring compliance, coordinating breach response, and acting as the point of contact for the Data Protection Office and data subjects
ISECURION Role: Structured DPO training and certification for the staff member who will hold the role
DPA 2017 & DPO Regulations 2026 - Key Obligations at a Glance
Use this table to understand the core compliance clocks and obligations your organization is now working against:
| Obligation | Governing Provision | Timeline | Penalty for Non-Compliance |
|---|---|---|---|
| Controller/Processor Registration | DPA 2017, Section 30; Section 16(2) | Before processing begins; renew every 3 years | Fine up to MUR 200,000 + up to 5 years imprisonment |
| DPO Designation (In-House) | DPO Regulations 2026, Reg. 3(1) | By 1 January 2027 (6-month moratorium) | Fine up to MUR 100,000 + up to 5 years imprisonment |
| DPO Notification to the Office | DPO Regulations 2026 | Within 14 days of designation | Fine up to MUR 100,000 + up to 5 years imprisonment |
| Personal Data Breach Notification | DPA 2017, Breach Notification provisions | Without undue delay, within 72 hours where feasible | Enforcement action; case-dependent penalties |
| Failure to Comply with Enforcement Notice | DPA 2017 | By deadline set in the notice | Fine up to MUR 50,000 + up to 2 years imprisonment |
| Failure to Attend Hearing / Produce Documents | DPA 2017 | As required by the Commissioner | Fine up to MUR 50,000 + up to 2 years imprisonment |
Personal Data Breach Notification & Penalties
A personal data breach in Mauritius triggers obligations on a tight clock, and getting the sequence wrong compounds an already difficult situation with regulatory exposure. Understanding exactly who must be notified, when, and under what conditions is one of the most operationally important parts of DPA 2017 compliance.
NOTIFYING THE DATA PROTECTION COMMISSIONER
Timeline: Without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach
What Must Be Included: The nature of the breach, categories and approximate number of affected data subjects, and the measures taken or proposed to address it
Who Is Responsible: The data controller, even where a processor was the source of the incident
NOTIFYING AFFECTED DATA SUBJECTS
Trigger: Required where the breach is likely to result in a high risk to the rights and freedoms of affected individuals
Timeline: As soon as possible, generally after the Commissioner has been notified
Exceptions: May not be required where appropriate protective measures (e.g. encryption) were already applied, or where notification would involve disproportionate effort and a public communication achieves the same result
PROCESSOR-TO-CONTROLLER NOTIFICATION
Timeline: Without any undue delay once the processor becomes aware of a breach
What This Means Practically: Vendor and outsourcing contracts need explicit breach-notification clauses, since the controller's 72-hour clock to the Commissioner starts running regardless of how quickly a processor reports upstream
DOCUMENTATION & ACCOUNTABILITY
Requirement: Controllers and processors must document compliance measures, processing operations, risk assessments, and actions taken to address risks, and make records available to the Data Protection Office on request
Oversight: The Office carries out periodical audits of controllers and processors to verify compliance
Enforcement Powers of the Data Protection Commissioner
The Commissioner is empowered to investigate complaints, determine whether a breach of the DPA 2017 has occurred, issue enforcement notices requiring remedial action by a set deadline, and refer matters to the Police for prosecution where warranted.
Example: A Phishing-Driven Data Breach at a Mauritius-Based GBC Administrator
- Discovery: Security monitoring flags unauthorized access to a mailbox containing client onboarding documents and personal data
- Internal Escalation (Hours 0-24): Incident response team contains the account, and the DPO leads the impact assessment - this is exactly the coordination role the DPO Regulations 2026 formalize
- Commissioner Notification (Within 72 Hours): Controller notifies the Data Protection Office with the nature, scope, and remediation status of the incident
- Data Subject Notification (If High Risk): Affected clients notified where the exposed data creates a meaningful risk of harm
- Cross-Border Consideration: If the GBC's underlying beneficial owners or group entities sit outside Mauritius, notification obligations under other jurisdictions' laws may run in parallel
Why Preparation Matters: Every one of these steps is far faster and less error-prone when the DPO role, the breach-response plan, and the notification templates already exist - rather than being improvised for the first time during a live incident.
VAPT & Security Assessment Services in Mauritius
Vulnerability Assessment and Penetration Testing (VAPT) is the technical backbone of DPA 2017's "security of processing" requirement - it is one thing to write a security policy, and another to demonstrate to the Data Protection Office, an auditor, or a client that your systems actually withstand a realistic attack. ISECURION delivers VAPT and broader security assessments to organizations across Mauritius, supporting the technical evidence base your DPO and compliance program need.
VAPT Service Types Available Through ISECURION
Web Application Testing
OWASP Top 10 and Top 25 testing, authentication and session management review, business logic flaw identification for client portals and booking platforms.
Mobile Application Testing
iOS and Android testing per OWASP MASVS, local storage security, insecure data transmission, and reverse engineering resistance.
Network Penetration Testing
Internal and external network testing, lateral movement simulation, privilege escalation, and firewall/IDS/IPS evasion testing.
Cloud Security Assessment
AWS, Azure and GCP configuration review, IAM role analysis, and storage access control review - especially relevant where data is hosted outside Mauritius.
API Security Testing
REST, GraphQL and SOAP API testing, rate limiting, authentication, authorization, and OAuth/JWT vulnerability assessment.
Social Engineering & Phishing Simulation
Controlled phishing campaigns and awareness testing, feeding directly into the security-awareness component of a DPA 2017-aligned program.
Compliance Audits, DPIA & Certification Support
Compliance audits assess your organization's alignment against the DPA 2017 and the DPO Regulations 2026, identify control gaps, and provide a clear remediation path - work that ISECURION's Mauritius engagements typically structure around the DPO function itself, so the person accountable for compliance owns the resulting roadmap.
DPA 2017 Compliance Audit
Coverage: Registration status, lawful basis mapping, data subject rights processes, cross-border transfer review
Deliverable: Gap analysis and prioritized remediation roadmap
Timeline: 2-4 weeks depending on scope
DPO Training & Certification
Coverage: DPA 2017 obligations, DPO Regulations 2026 duties, breach-response coordination, DPIA methodology
Deliverable: A certified, internally designated DPO ready for the 1 January 2027 deadline
Format: Structured training with ongoing refresher support
Data Protection Office Registration
Coverage: Controller/processor registration filing, renewal tracking ahead of the 3-year expiry
Deliverable: Completed registration and a documented renewal calendar
Timeline: 1-2 weeks
Data Protection Impact Assessment
Coverage: Risk assessment for high-risk processing activities, prior authorization/consultation support where required
Deliverable: Documented DPIA satisfying Data Protection Office expectations
Timeline: 2-3 weeks depending on complexity
ISO 27001 Certification Support
Coverage: Gap assessment against ISO 27001 controls, internal audit, certification readiness
Deliverable: Certification-ready evidence package, often reused as DPA 2017 security evidence
Timeline: 3-4 months typical
Breach Response Plan Development
Coverage: 72-hour notification workflow, pre-drafted Commissioner and data-subject notification templates
Deliverable: Tested incident response and notification playbook
Validation: Tabletop exercise with the DPO and executive team
Sector-Wise Data Protection & Security Coverage Across Mauritius
ISECURION supports organizations across Mauritius with DPO services, VAPT, and compliance work, with particular depth in the following sectors.
Global Business Companies & Financial Services
Regulatory Focus: DPA 2017, DPO Regulations 2026, FSC licensing conditions, cross-border transfer restrictions for group structures
Industry Focus: Management companies, GBC administrators, fund administrators, wealth management, insurtech
Financial Services-Specific Services:
- Controller/Processor Determination: Clarifying which entity in a GBC structure holds decision-making power over processing, and who processes on their behalf
- In-House DPO Training: Preparing the staff member who will hold the DPO role once outsourced arrangements are no longer sufficient
- Cross-Border Transfer Review: Mapping data flows to group entities, custodians, and administrators outside Mauritius against the adequacy and safeguards requirements
- FSC-Aligned Security Controls: VAPT and control evidence supporting both DPA 2017 and Financial Services Commission expectations
- Client Due Diligence Data Handling: Security review of KYC/CDD data storage and access controls
Healthcare & Health Tech
Regulatory Focus: DPA 2017 special category data provisions, DPO Regulations 2026, breach notification for sensitive health data
Industry Focus: Private clinics, diagnostic centers, telehealth platforms, medical tourism operators
Healthcare-Specific Services:
- Sensitive Data Risk Assessment: DPIA support for processing health data, which carries elevated risk classification under the Act
- Access Control Review: Technical safeguards around patient records and diagnostic systems
- Breach Notification Readiness: 72-hour workflow design specific to health data incidents
- DPO Training for Clinical Environments: Practical training that accounts for clinical workflows, not just office-based data handling
Hospitality, Tourism & Real Estate
Regulatory Focus: DPA 2017 obligations around guest and buyer personal data, cross-border booking platform data flows
Industry Focus: Hotels and resorts, property developers, IRS/RES real estate schemes, travel agencies
Hospitality & Real Estate-Specific Services:
- Guest Data Inventory: Mapping personal data collected through booking platforms, loyalty programs, and payment processing
- Third-Party Booking Platform Review: Assessing data-sharing arrangements with international OTAs and payment providers
- Buyer Data Protection for Real Estate Schemes: Registration and DPO support for developers handling foreign buyer personal and financial data
- PCI-Aligned Payment Security: VAPT covering payment processing systems handling guest and buyer card data
BPO, ICT & Outsourcing
Regulatory Focus: DPA 2017 processor obligations, cross-border transfer where client data originates outside Mauritius, contractual security clauses
Industry Focus: Call centers, shared services centers, software development outsourcing, IT-enabled services
BPO & ICT-Specific Services:
- Processor Registration Support: Registration where the organization acts as a data processor on behalf of overseas clients
- Client Security Questionnaire Support: Evidence packages for enterprise clients' vendor security due diligence
- Contractual Security Clause Review: Ensuring outsourcing contracts reflect processor-to-controller breach notification duties
- ISO 27001/SOC 2 Readiness: Certification support that satisfies both local compliance and international client expectations
SMEs, E-Commerce & Public Sector Bodies
Regulatory Focus: DPA 2017 baseline obligations with no small-business exemption; e-commerce payment and customer data handling
Industry Focus: Retail and e-commerce platforms, professional services firms, public bodies, sole traders
SME & Public Sector-Specific Services:
- Right-Sized DPO Readiness: Practical, proportionate DPO training for organizations without a dedicated compliance function
- Registration & Renewal Management: Ensuring the 3-year registration cycle doesn't lapse unnoticed
- Customer Data Security Review: VAPT and access control review for e-commerce checkout and customer account systems
- Public Body Compliance Support: DPA 2017 alignment for government-linked entities and statutory bodies
Compliance Roadmap: From Registration Check to a Fully Operational DPO by 1 January 2027
Moving from an unclear compliance position to a fully operational, audit-ready DPO function requires a phased approach. Here's how ISECURION typically structures a Mauritius data protection engagement:
Phase 1: Assess & Classify (Weeks 1-3)
- Registration Status Check: Confirm whether your organization is registered as a controller or processor, and when the current registration expires
- Processing Activity Inventory: Map what personal data is collected, why, where it's stored, and who it's shared with, including any cross-border flows
- Current DPO Position Review: Assess whether an existing DPO arrangement (internal or outsourced) will satisfy the 2027 in-house requirement
- Gap Analysis: Score current practices against DPA 2017 and DPO Regulations 2026 requirements
Phase 2: Designate & Register (Weeks 3-8)
- Internal DPO Selection: Identify a suitable staff member with the standing, independence, and capacity to hold the role
- DPO Training & Certification: Structured training covering DPA 2017 obligations, breach coordination, DPIA methodology, and the specific duties under the 2026 Regulations
- Data Protection Office Notification: File the DPO designation within the required window and publish contact details on the website and premises
- Registration/Renewal Filing: Complete or renew controller/processor registration where needed
Phase 3: Build the Program (Months 2-4)
- Breach Response Plan: A tested 72-hour notification workflow with pre-drafted Commissioner and data-subject templates
- DPIA Process: A repeatable methodology for assessing high-risk processing activities before they launch
- Vendor & Processor Contracts: Security and breach-notification clauses reviewed across third-party arrangements
- Policy Framework: Written data protection policies covering lawful basis, retention, and data subject rights handling
Phase 4: Validate & Certify (Months 4-6)
- VAPT Validation: Technical testing of systems handling personal data to evidence the Act's security-of-processing requirement
- Compliance Audit: Full DPA 2017 and DPO Regulations 2026 audit ahead of the 1 January 2027 deadline
- Tabletop Exercise: Breach-response dry run with the DPO and executive team participating
- Optional Certification: ISO 27001 or SOC 2 readiness where international clients require it
Phase 5: Sustain (Ongoing)
- Registration Renewal Tracking: Calendar-based tracking ahead of the 3-year registration cycle
- DPO Refresher Training: Ongoing upskilling as the Data Protection Office issues further guidance
- Annual Reassessment: Refreshed processing inventory and DPIA reviews as the business evolves
- Advisory Retainer: Standing support for the DPO on complex processing decisions and incident response
Typical Engagement Scope by Organization Size
| Organization Profile | Typical Engagement | VAPT Cadence | Compliance Focus |
|---|---|---|---|
| Sole Trader / Micro-Business | Project-based DPO training + registration | As needed | Baseline DPA 2017 compliance |
| SME / E-Commerce | DPO training + light advisory retainer | Annual | Registration renewal, breach readiness |
| Mid-Market / Hospitality Group | DPO training + ongoing retainer | Annual + ad hoc | DPIA, vendor risk, payment security |
| GBC / Financial Services / BPO | Dedicated retainer + certification support | Continuous / quarterly | Cross-border transfer, FSC alignment, ISO 27001/SOC 2 |
The Moratorium Is a Runway, Not a Deadline to Wait For
The six-month moratorium after the DPO Regulations 2026 came into force exists to give organizations time to adjust - not to delay starting. Identifying and training the right internal staff member, restructuring reporting lines, and building a genuinely independent DPO function all take longer than most organizations expect. Contact ISECURION for a tailored proposal specific to your organization's size, sector, and current registration status in Mauritius.
Comprehensive FAQ: Data Protection & DPO Compliance in Mauritius
Answers to the most common questions from boards, founders, and compliance teams across Mauritius
Alignment: The Act incorporates principles from the EU's GDPR and the Council of Europe's Convention 108+, and is administered by the Data Protection Office, headed by the Data Protection Commissioner.
Who It Applies To: Every data controller established in Mauritius, including Global Business Companies licensed under the Financial Services Act, plus entities that use equipment located in Mauritius to process personal data - even if based elsewhere.
Practical Reach: This extends well beyond banks and telecoms to e-commerce platforms, hospitality groups, healthcare providers, BPO/ICT companies, and professional services firms.
Effective Date: 1 January 2027, with a six-month moratorium granted for organizations to adjust.
What Changes: The previously high-level, single-clause DPO obligation becomes a detailed, enforceable framework covering designation, independence, resourcing, and reporting lines.
Scope: No general exemption for small businesses, micro-enterprises, or low-volume processing - the rules apply to any entity determining the purposes and means of processing personal data.
What This Reverses: Earlier 2023 guidelines permitted the role to be held by someone entirely outside the organization - that option ends with the new Regulations.
What To Do Now: Organizations currently relying on an outsourced DPO need to identify and train a suitable internal staff member before the deadline.
Where External Support Still Fits: Advisors can continue to deliver DPO training, upskilling, audits, and ongoing compliance advisory - just not hold the statutory DPO title itself.
Validity: Registration is valid for three years under section 16(2) of the Act, and must be renewed before expiry.
Fees: Set out in the Data Protection (Fees) Regulations 2020, covering registration, renewal, and certified copies of register entries.
Penalty for Lapsing: Processing personal data without valid registration is an offence punishable by a fine of up to MUR 200,000 and imprisonment for up to five years.
Data Subject Notification: Required where the breach is likely to result in a high risk to affected individuals' rights and freedoms.
Processor Obligations: A processor that becomes aware of a breach must notify the controller without undue delay.
What to Include: Nature of the breach, categories and approximate number of affected data subjects, and measures taken or proposed to address it.
Non-Compliance with Enforcement Notice / False Information: Fine of up to MUR 50,000 and imprisonment of up to two years.
Breach of DPO Notification/Publication Duties: Fine of up to MUR 100,000 and imprisonment of up to five years under the new DPO Regulations 2026.
Beyond Fines: Criminal liability and reputational damage carry weight well beyond the monetary penalty, particularly for regulated entities and Global Business Companies.
Who This Affects Most: Global Business Companies and outsourcing operations that route data processing, storage, or support functions through group entities or vendors outside Mauritius.
Practical Step: Map every cross-border data flow - including cloud hosting and SaaS tools - before assuming a transfer is compliant by default.
DPIA Support: Supporting data protection impact assessments for high-risk processing activities.
Structural Requirements Under the 2026 Regulations: Independence, a direct reporting line to the highest level of management, adequate resourcing, and ongoing training.
What It's Not: A title added to an unrelated job description with no real authority or capacity to act.
Processor Determination: GBCs also need to determine who acts as processor where a management company or administrator processes data on their behalf.
DPO Decision: Now shaped directly by the DPO Regulations 2026's in-house staff requirement - an outsourced administrator can no longer simply hold the DPO title for the GBC.
Who Is Covered: Any entity that determines the purposes and means of processing personal data, including sole traders and very small organizations.
Practical Implication: The appointment and training obligations reach far beyond large regulated institutions - right down to single-owner businesses handling customer data.
DPO Training & Certification: Structured training for the internal staff member who will hold the DPO role from 1 January 2027.
Compliance Audits: Full assessment against the DPA 2017 and DPO Regulations 2026.
VAPT & Security Assessments: Technical evidence demonstrating the safeguards the Act requires.
Ongoing Advisory & Support: Standing support so the DPO function remains resourced and independent rather than becoming a compliance formality.
Regulatory Fluency: Working familiarity with the DPA 2017, DPO Regulations 2026, FSC licensing conditions, and cross-border transfer requirements.
Practical, Right-Sized Programs: Engagement scope that fits sole traders and SMEs as readily as GBCs and financial institutions.
Global Delivery Experience: Established presence across Mauritius, India, UAE, Qatar, the wider GCC, and the United States.
What We're NOT: Not a compliance checkbox vendor - our goal is a genuinely functioning DPO program, not just a certificate on the wall.