With the introduction of the Mauritius Data Protection Act 2017, numerous companies have had to adjust their collecting, handling, use and storage of personal data. Issues such as misuse of data for fraud, blackmail and identity theft are only a few of the reasons why personal data should be protected. It is worth noting that the Mauritius Data Protection Act (“DPA 2017″) was introduced to give effect to the General Data Protection Regulation (GDPR). Regulation (EU) 2016/679 (“EU GDPR”). Both these legislations signal an era of increased accountability when it comes to how corporations treat personal data as well as the introduction of new rights for data subjects.
Companies in Mauritius are required to give effect to these legislations by incorporating data protection principles into their internal policies and procedures. These principles are the backbone that govern how sensitive personal information is exchanged and how it should be treated. So, what are they specifically?
Section 21 of the DPA 2017 identifies six data protection principles which are explained below in turn:
- Lawful, Fair and Transparent Processing
This seems an obvious concept, but the key is ensuring that the parameters for the use of the data being collected are properly set out in a company’s data protection policy. The policy has to be aligned to any applicable legislation.
The idea of transparency is also paramount. Details on how the data is being treated, whether there is any processing applicable, what information is being collected and for what purpose should be made available to data subjects, so they have a clear idea of what they are agreeing to.
- Collection for An Explicit, Specified and Legitimate Purpose
One of the core data protection principles is also that information should only be collected in a restricted manner. It has to be made clear from the outset what is the purpose of collecting data. The DPA 2017 states that data should not be “further processed in a manner incompatible with those purposes”. For example, in 2019, Google was fine a whopping 57 million USD by the French data protection authority, CNIL, for failing to acknowledge how its users’ data was processed.
- Limited to What Is Necessary in Relation To The Purposes For Which They Are Processed
Companies are also required to limit their data collection strictly to the information that is needed. The words “adequate, “relevant” are found in the DPA 2017 to describe what information is necessary. In the Google case mentioned above, the courts specifically highlighted that there was not enough clarity for users on the “plurality” of services” under the wider Google banner (e.g: Google, YouTube, Google Maps, Google Photos, etc.) and how information was being shared and combined across these platforms.
- Accurate and Up to Date
The DPA 2017 states that “every reasonable step [must be] taken to ensure that any inaccurate personal data are erased or rectified without delay”. With the requirement for accuracy, also arises the right for data subjects to access information held and ensure that it is not incorrect or misleading. Companies are required to take reasonable steps to ensure that any data held is accurate. This implies that the resources should be in place to verify accuracy, record in a manner than can be retrieved and that thought should be given to how often information held needs to be updated.
- Storage Limitation
The DPA 2017 states that data should be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed”. It is worth noting that in Mauritius, the statutory requirement for record-keeping is seven years per the Companies Act 2001. It is recommended that beyond that time frame, information that is retained should that subject to special circumstances (e.g: an ongoing investigation). Any information which no longer serves the purpose for which it was initially collected should be discarded even before the 7-year threshold.
- Processed in Accordance with The Rights of Data Subjects.
The underlying feature of data protection in our times is the acknowledgement that data is more than random pieces of information. We Iive in a world that can exploit and manipulate personal information for commercial gain should there be no controls in place. As seen in the case of the Facebook-Cambridge Analytica data scandal, the exploitation of personal information can have a direct impact on undermining not only personal human rights but can also lead to the wider manipulation of fundamental systems of our society such as democracy, if they are left to the mercy of commercial entities only.
Accordingly, the rights of data subjects which flow from the EU GDPR and the DPA 2017 include:
- The right to access
- The right to rectification and erasure
- The right to restrict processing
- The right to data portability
- The right to object to automated decision-making
Therefore, any company looking to give effect to the data protection legislations should not only incorporate the principles of data protection but also consider how to enable the rights of data subjects.
Temple Consulting is the regulatory compliance limb of the wider Temple Group. Our compliance consultants provide dedicated end-to-end data protection support to companies who are looking to align their systems. If any of the aspects mentioned in this article are of interest, we would be happy to help!
Recent Comments