Section 35: Prior authorisation and consultation
as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.
35. Prior authorisation and consultation
(1) Every controller or processor shall obtain authorisation from
the Office prior to processing personal data in order to ensure compliance
of the intended processing with this Act and in particular to mitigate the
risks involved for the data subjects where a controller or processor cannot
provide for the appropriate safeguards referred to in section 36 in relation
to the transfer of personal data to another country.
(2) The controller or processor shall consult the Office prior to
processing personal data in order to ensure compliance of the intended
processing with this Act and in particular to mitigate the risks involved for
the data subjects where –
(a) a data protection impact assessment as provided for
in section 34 indicates that processing operations are
by virtue of their nature, scope or purposes, likely to
present a high risk; or
(b) the Office considers it necessary to carry out a prior
consultation on processing operations that are likely to
present a high risk to the rights and freedoms of data
subjects by virtue of their nature, scope or purposes.
(3) Where the Office is of the opinion that the intended processing
does not comply with this Act, in particular where risks are insufficiently
identified or mitigated, it shall prohibit the intended processing and make
appropriate proposals to remedy such non-compliance.
(4) The Office shall make public a list of the processing
operations which are subject to prior consultation in accordance with
subsection (2)(b).
500 Acts 2017 Acts 2017 501
(5) The controller or processor shall provide the Office with
the data protection impact assessment provided for in section 34 and, on
request, with any other information, so as to allow the Office to make
an assessment of the compliance of the processing and in particular of
the risks for the protection of personal data of the data subject and of the
related safeguards.
PART VI – TRANSFER OF PERSONAL
DATA OUTSIDE MAURITIUS