The long arm of GDPR in Africa: reflection on data privacy law reform and practice in Mauritius
Alex Boniface Makulilo
Abstract
Alex Boniface Makulilo
Abstract
The recently adopted General Data Protection Regulation (GDPR) in the European Union has certainly set the highest standards of all data privacy policies across the world. In theory such standards have provided more control to individuals over their personal data. Due to the strengthened third-party obligations in the GDPR for data export to non-European Union countries and fear of loss of foreign investment if such countries fail to provide adequate protection of personal data, the GDPR exerts profound influence on data privacy law reform and practice outside Europe. This article analyses the impact of the GDPR in Africa by using Mauritius as an intrinsic case study. Mauritius is selected in this analysis due to its leading role in the privacy policy reforms in Africa and the internationalisation of its data protection systems. Accordingly, the development of the data protection system in Mauritius from the repealed Data Protection Act 2004 to the current Data Protection Act 2017 is analysed in detail, drawing on the largest body of reported complaints, appeals and judicial decisions so far decided by courts.
OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The recently adopted General Data Protection Regulation (GDPR) in the European Union has certainly set the highest standards of all data privacy policies across the world. In theory such standards have provided more control to individuals over their personal data. Due to the strengthened third-party obligations in the GDPR for data export to non-European Union countries and fear of loss of foreign investment if such countries fail to provide adequate protection of personal data, the GDPR exerts profound influence on data privacy law reform and practice outside Europe. This article analyses the impact of the GDPR in Africa by using Mauritius as an intrinsic case study. Mauritius is selected in this analysis due to its leading role in the privacy policy reforms in Africa and the internationalisation of its data protection systems. Accordingly, the development of the data protection system in Mauritius from the repealed Data Protection Act 2004 to the current Data Protection Act 2017 is analysed in detail, drawing on the largest body of reported complaints, appeals and judicial decisions so far decided by courts.
Key concepts: General Data Protection Regulation, Data Protection Act 1998, Information privacy law, European union, Privacy policy, Information privacy, FTC Fair Information Practice, Data Protection Directive