Section 43: Denial of access to personal data
repealed (no longer in force). juris shows the text as it was consolidated; it does not confirm that this is the law in force today. The records juris holds show this law as repealed.
43. Denial of access to personal data
(1) A data controller may refuse a request under section 41 where—
(a) he is not supplied with such information as he may reasonably
require in order to satisfy himself as to the identity of the person
making the request, and to locate the information which the person seeks;
D3 – 23 [Issue 5]
Data Protection Act
(b) compliance with such request will be in contravention of his confidentiality obligation imposed under any other enactment.
(2) Where a data controller cannot comply with a request under section 41 without disclosing personal data relating to another person, he may
refuse the request unless—
(a) the other individual has consented to the disclosure of his personal data to the person making the request; or
(b) he obtains the written approval of the Commissioner.
(3) In determining for the purposes of subsection (2) (b) whether it is
reasonable for the Commissioner to approve a request without the consent
of the other individual concerned, regard shall be had, in particular, to—
(a) any duty of confidentiality owed to the other individual;
(b) any steps taken by the data controller with a view to seeking the
consent of the other individual;
(c) whether the other individual is capable of giving consent; and
(d) any express refusal of consent by the other individual.
(4) (a) Where a data controller has previously complied with a request
made under section 41 by a data subject, the data controller is not obliged to
comply with a subsequent identical or similar request under that section by
that data subject unless a reasonable interval has elapsed between compliance with the previous request and the making of the current request.
(b) In determining, for the purposes of paragraph (a), whether
requests under section 41 are made at reasonable intervals, regard shall be
had to—
(i) the nature of the data;
(ii) the purpose for which the data are processed; and
(iii) the frequency with which the data are altered.
(5) A data controller shall not comply with a request under section 41
where—
(a) he is being requested to disclose information given or to be given
in confidence for the purposes of—
(i) the education, training or employment, or prospective education, training or employment, of the data subject;
(ii) the appointment, or prospective appointment, of the data
subject to any office; or
(iii) the provision, or prospective provision, by the data subject
of any service;
(b) the personal data requested consist of information recorded by
candidates during an academic, professional or other examination;
[Issue 5] D3 – 24
Revised Laws of Mauritius
(c) such compliance would, by revealing evidence of the commission of any offence other than an offence under this Act, expose
him to proceedings for that offence.
(S. 43 came into operation on 16 February 2009.)