Speaker

Shayne Brasse

About The Speaker

Shayne has been approved by regulators in Mauritius, the United Arab Emirates (Dubai – DIFC) and Luxembourg for Compliance roles at Board and Senior Management Level.

He spent some time in Dubai where he was approved by the regulator as Senior Manager – Compliance Officer and MLRO for an Investment Manager in the DIFC and MLRO for a DNFBP (Company Service Provider). He later moved to a compliance consultancy firm in the DIFC as Senior GRC Consultant where Shayne was approved by the regulator to act as outsourced Compliance Officer and MLRO for several Authorised Firms. Shayne was appointed as Director on two Investment Firms domiciled and regulated in Luxembourg (including a UCITS) where he was responsible for overseeing compliance matters.

Prior to going to Dubai, Shayne was managing ADS Consulting Ltd and ADS Learning Ltd, a leading compliance consultancy firm and training institution in Mauritius. Shayne is currently Director of Scentia Consulting, a compliance consultancy firm with offices in Vivea Business Park, Moka. Scentia specializes in the offering of tailor-made compliance and training solutions to financial institutions (banking and non-banking) and non-financial entities which includes DNFBPs (Real Estate Agents/Land Promoter/Property Developer, Lawyers, Notaries, Company Service Providers, Accountants etc) and entities operating in non-financial industries.

Upcoming Event

Data Protection Essentials

COURSE CONTENT

1. Foundations of Data Protection

Enable participants to understand the legal architecture of data protection in Mauritius, situate it against the EU GDPR, and correctly identify roles, actors and material/territorial scope within their own organisation.

  • Why data protection matters: privacy as a fundamental right; reputational, regulatory and commercial drivers.
  • The Mauritian framework: the Data Protection Act 2017, its amendments, and subsidiary regulations.
  • The Data Protection Office: mandate, powers of investigation, enforcement and sanction.
  • The EU GDPR at a glance: extraterritorial reach (Article 3) and why Mauritian entities with EU-facing clients are caught.
  • Key definitions and distinction

2. Core Obligations: Principles, Lawful Basis and Data Subject Rights

Equip participants to apply the data protection principles and lawful bases to day to- day processing, and to handle a data subject rights request from receipt to response within the statutory timeline.

  • The processing principles (section 21, DPA 2017 / Article 5, GDPR) and what each means operationally.
  • Lawful bases for processing (section 28, DPA 2017 / Article 6, GDPR): consent, contract, legal obligation, vital interests, public interest and legitimate interests.
  • Consent: the required standard, withdrawal, and why it is the weakest basis in a client-services context. •Legitimate interests: applying the balancing test. •Special category data: the additional condition requirement (section 29, DPA 2017 / Article 9, GDPR).
  • Data subject rights and response deadlines: access, rectification, erasure, restriction, objection, portability, and rights in relation to automated decision-making. Fees, exemptions, identity verification and grounds for refusal.
  • Transparency obligations: privacy notices content, layering and timing

3. The Data Protection Regulations 2026 and the Compliance Framework in Practice

Ensure participants understand what has changed under the Data Protection Regulations 2026, what new obligations attach to their entity, and how to build the documentation and governance infrastructure a regulator will actually ask to see.

The Data Protection Regulations 2026 — what is new

  • Formalisation and status of the Data Protection Officer role: appointment criteria, independence, reporting line, and notification to the Data Protection Office.
  • Qualification, competence and conflict-of-interest requirements.
  • Tasks of the DPO and the obligation to resource the function adequately.
  • Record-keeping, registration and renewal mechanics.
  • Practical implications for outsourced or shared DPO arrangements, and for group entities.
 

Building the compliance framework

  • Record of Processing Activities (ROPA) — the foundation document.
  • Data Protection Impact Assessments: when mandatory, assessment methodology, residual risk and prior consultation.

4. Security, Breach Management, Enforcement and Embedding Compliance

Enable participants to respond to a personal data breach within the statutory timeline, understand the consequences of non-compliance, and leave with a concrete action plan for their function.

  • Security of processing: organisational and technical measures access control,
  • The human factor: phishing, misdirected email, insider risk and unsecured physical files.
  • Personal data breach management
  • Enforcement: powers of the Commissioner, enforcement notices, offences and penalties under the DPA 2017; supervisory action; civil liability and reputational exposure.
  • Interaction with adjacent regimes: AML/CFT record-keeping versus erasure; FATCA/CRS reporting; sectoral regulator expectations.