Data Protection

Protection of personal data across any organisation has become significantly crucial in today’s digital landscape. With the ever-increasing importance of data security and privacy, our comprehensive solutions aim to assist you in safeguarding your valuable data assets and ensuring compliance with data protection laws, both as controller and as processor.

The Data Protection Act of 2017 in Mauritius applies to both controllers and processors, encompassing entities established within Mauritius that process personal data within that context, as well as those not based in Mauritius but utilizing equipment within the country for personal data processing, excluding transit purposes.

See below the data protection services offered by CASS:

Our Service Suite

Registration or renewal as Controller and Processor

Certification with the Data Protection Office

Acting as Data Protection Officer

Drafting Data Protection Policies and Procedures

Implementation of a Data Protection Framework

Controllers and Processors of the personal data should mandatorily be registered with the Data Protection Office of Mauritius. This is provided for by Section 14 of the DPA 2017 whereby controllers and processors should firstly register and consequently renew their registration certificate every 3 years. We register and renew the registration of Controllers and Processors of personal data with the Data Protection Office of Mauritius and handle all the liaisons with the Data Protection Office allowing you to prioritise your business operations with full peace of mind.

Where a controller or processor wishes to apply for a certification under Section 48 of the DPA 2017, CASS provides the support needed for companies during their certification process including all necessary liaisons with the Data Protection Office.

Data Controllers and Processors have the obligation to designate a Data Protection Officer, under S.22(2)(e) of the DPA 2017, who is responsible for the following:
• Informing and advising the controller/processor and its employees about their obligations to comply with the DPA and other data protection laws;
• Monitoring compliance with the DPA and other data protection laws, including managing internal data protection activities, advise on data protection impact assessment, train staff and conduct internal audits; and
• Being the first point of contact for the DPO and for individuals whose data are processed (employees, customers amongst others).

Outsourcing your Data Protection Officer to us at a cost-effective rate means freeing up valuable resources for your core business activities and ensuring greater peace of mind

Every controller shall adopt policies and implement appropriate technical and organisational measures so as to ensure and be able to demonstrate that the processing of personal data is performed in accordance with this Act.

We draft data protection policies and procedures which are tailor-made to suit the intricacies of your business as well as your specific business needs.

• Data inventory & Mapping: We assist companies in conducting a comprehensive data inventory which involves identifying and documenting all types of data which they collect, process and store.

• Gap Analysis and Roadmap: We conduct a thorough assessment of the Company’s existing data security infrastructure, policies, and practices. This assessment will identify potential risks and areas for improvement allowing us to develop a tailored data protection strategy.

• Implementation: We will guide you through the necessary steps to ensure proper handling, storage and protection of personal data. We will assist to develop comprehensive data protection policies, procedures and documentation.

• Post Implementation Review: We will assist in assessing the overall effectiveness of the implemented data protection measures and determining the level of compliance with relevant laws.

• Employee Training and Awareness: We will conduct training sessions to educate your employees about data protection best practices and importance of safeguarding personal data.

 

Registration or renewal as Controller and Processor

Controllers and Processors of the personal data should mandatorily be registered with the Data Protection Office of Mauritius. This is provided for by Section 14 of the DPA 2017 whereby controllers and processors should firstly register and consequently renew their registration certificate every 3 years. We register and renew the registration of Controllers and Processors of personal data with the Data Protection Office of Mauritius and handle all the liaisons with the Data Protection Office allowing you to prioritise your business operations with full peace of mind.

Certification with the Data Protection Office

Where a controller or processor wishes to apply for a certification under Section 48 of the DPA 2017, CASS provides the support needed for companies during their certification process including all necessary liaisons with the Data Protection Office. 

Acting as Data Protection Officer

Data Controllers and Processors have the obligation to designate a Data Protection Officer, under S.22(2)(e) of the DPA 2017, who is responsible for the following:
• Informing and advising the controller/processor and its employees about their obligations to comply with the DPA and other data protection laws;
• Monitoring compliance with the DPA and other data protection laws, including managing internal data protection activities, advise on data protection impact assessment, train staff and conduct internal audits; and
• Being the first point of contact for the DPO and for individuals whose data are processed (employees, customers amongst others).

Outsourcing your Data Protection Officer to us at a cost-effective rate means freeing up valuable resources for your core business activities and ensuring greater peace of mind. 

Drafting Data Protection Policies and Procedures

Every controller shall adopt policies and implement appropriate technical and organisational measures so as to ensure and be able to demonstrate that the processing of personal data is performed in accordance with this Act.

We draft data protection policies and procedures which are tailor-made to suit the intricacies of your business as well as your specific business needs.

Implementation of a Data Protection Framework

• Data inventory & Mapping: We assist companies in conducting a comprehensive data inventory which involves identifying and documenting all types of data which they collect, process and store.

• Gap Analysis and Roadmap: We conduct a thorough assessment of the Company’s existing data security infrastructure, policies, and practices. This assessment will identify potential risks and areas for improvement allowing us to develop a tailored data protection strategy.

• Implementation: We will guide you through the necessary steps to ensure proper handling, storage and protection of personal data. We will assist to develop comprehensive data protection policies, procedures and documentation.

• Post Implementation Review: We will assist in assessing the overall effectiveness of the implemented data protection measures and determining the level of compliance with relevant laws.

• Employee Training and Awareness: We will conduct training sessions to educate your employees about data protection best practices and importance of safeguarding personal data.

Our IT Partner

Through collaboration with Techgenic, our IT experts, we deliver customised data privacy solutions:
• Information Security
• Cybersecurity Framework implementation
• Audits

EMAIL ADDRESS:

info@cass.mu

PHONE NUMBER:

+230 402 6860