Law / Mozambique

Mozambique

8 of 15 named instruments researched to a stage, across four of the six areas of law we track: 5 in force and 3 enacted but not yet in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 3
  3. Scraping law 1
  4. Cybersecurity law 3
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law3 instruments, 3 in force

Research summary (159 words)

Mozambique has no comprehensive, dedicated data-protection statute; a Draft Personal Data Protection Law approved by the Council of Ministers on 3 March 2026 remains before the Assembly of the Republic and is not yet enacted.

Chapter IX of the Electronic Transactions Law (Lei n.º 3/2017, de 9 de Janeiro) imposes a narrower, sectoral duty on any data controller or data processor who electronically collects, processes, or discloses personal data: the processing must be accurate, complete, and current, its purpose and the processor's identity disclosed before collection, and use limited to the stated purpose; a data subject may obtain confirmation of, access to, and correction of their own data, and the processor must designate a compliance officer and publish its data-handling policies and practices.

Chapter X makes violating this data-protection duty a punishable contravention alongside a list of computer-misuse contraventions, decided by the sector regulator, the National Institute of Information and Communication Technologies (INTIC), and appealable to the judicial courts.

Comprehensive regime

Electronic Transactions Law, Protection of Personal Electronic Data

Lei n.º 3/2017, de 9 de Janeiro, arts. 63(1)-(2), (5), 64, 65(1), (3) (dever de protecção de dados)Text of Lei n.º 3/2017, de 9 de Janeiro (Lei das Transacções Electrónicas), Boletim da República I Série, mirrored by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 2 applies the Law to natural and legal persons, public or private, that apply information and communication technologies in their activities, including electronic or commercial transactions and electronic government. Article 63(1) requires any data controller who electronically collects, processes, or discloses personal data to keep it accurate, complete, and up to date.

Article 63(2) requires the objectives for which personal data are collected and the data processor's identity to be specified before collection, and limits later use to those stated objectives. Article 63(5) requires the data processor to protect personal data against risk, loss, unauthorised access, destruction, use, modification, or disclosure.

Article 63(7) applies this chapter without prejudice to the article 40 rules on electronic advertising and marketing and to any specific legislation on electronic data protection, and article 63(8) exempts electronic collection, processing, or disclosure of personal data for journalism, artistic or literary expression, or when decided by the competent authorities to safeguard public security and national defence.

Article 64 bars accessing computerised archives, files, records, or databases to learn a third party's personal data, and bars transferring personal data between information systems belonging to distinct services or institutions, except where established by legal instrument or judicial decision. Article 65(1) requires the data processor to designate one or more individuals responsible for compliance with this chapter's principles.

Article 65(3) makes the data processor responsible for personal information in its possession or custody, including information transferred to a third party for processing, subject to the same article 40, journalism, artistic-expression, and public-security exemptions as article 63.

What it requires

Data subject rights

Electronic Transactions Law, data subject rights and information notice

Lei n.º 3/2017, de 9 de Janeiro, arts. 63(3)-(4), (6), 65(2) (direitos do titular dos dados)Text of Lei n.º 3/2017, de 9 de Janeiro (Lei das Transacções Electrónicas), Boletim da República I Série, mirrored by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 63(3) requires the data processor, where personal data was not collected from the data subject directly, to give the subject the reason for collecting it and the processor's identity by the time the data is first disclosed to a third party. Article 63(4) excuses that notice where it is impossible, involves a disproportionate effort, is permitted by law, or the data is registered for statistical, historical, or scientific purposes.

Article 63(6) gives every person the right to obtain confirmation from a data controller of whether it holds data about them, to be told about that data within a reasonable period on payment of a fee, to receive a reasoned refusal where a request under either of those points is denied, and, where they object to data concerning them and the objection is accepted, to have it removed, rectified, completed, or altered.

Article 65(2) requires the data processor to make available to any person specific information about its policies and practices for managing personal information, including who is responsible for those policies and to whom a complaint or question should be directed, how to obtain access to personal information the processor retains, and a description of the type of personal information retained, including a general report of its use.

What it requires

Enforcement supervision

Electronic Transactions Law, data protection contraventions and enforcement

Lei n.º 3/2017, de 9 de Janeiro, arts. 67(m), 68(c), 69-70 (contravenções e fiscalização)Text of Lei n.º 3/2017, de 9 de Janeiro (Lei das Transacções Electrónicas), Boletim da República I Série, mirrored by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 66 states that the contraventions in this chapter are punishable under the following articles, without prejudice to a more severe penalty under separate criminal legislation. Article 67(m) makes violating the data-protection duty, meaning the data processor's obligations under this Law, a punishable contravention alongside a list of computer-misuse contraventions.

Article 68(c) sets the fine for that contravention, along with five other listed contraventions, at 30 to 90 times the public-service minimum wage, unless a more severe penalty applies under separate criminal legislation.

Article 69(1) gives the entidade reguladora, identified by article 11(2) as the National Institute of Information and Communication Technologies (INTIC), the power to process and decide the contravention proceeding, and article 69(2) leaves the procedural regime for contraventions to be regulated by the Council of Ministers.

Article 70(1) lets a sanction from a contravention be appealed directly to the judicial court of the relevant jurisdiction, or challenged first by a complaint to the minister overseeing information technology, and article 70(2) sends an appeal from any other decision to the Administrative Court.

What it requires

Scraping law1 instrument, 1 in force

Research summary (129 words)

Mozambique has no scraping-specific statute. Chapter X of the Electronic Transactions Law (Lei n.º 3/2017, de 9 de Janeiro) makes illegal access to a computer system, illegal interception, data interference, system interference, and misuse of devices punishable contraventions; on a plain reading, each of these turns on defeating a security measure or intentionally damaging a system or data, so a scraper reading a public, unauthenticated page without doing either is not described by the text.

Two further named laws, a cybersecurity statute and a cybercrime statute, have not been located in an official gazette or regulator publication, so their content is not described here. Whether Mozambique's copyright statute (Lei n.º 9/2022) carries a text-and-data-mining exception, and whether a database right or a robots.txt-specific rule exists, is not addressed here.

Computer misuse

Electronic Transactions Law, Computer Misuse Contraventions

Lei n.º 3/2017, de 9 de Janeiro, arts. 67 e 68 (Transacções Electrónicas)Text of Lei n.º 3/2017, de 9 de Janeiro (Lei das Transacções Electrónicas), Boletim da República I Série, mirrored by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 2 applies the Law to natural and legal persons, public or private, that apply information and communication technologies in their activities.

Article 67 lists as contraventions: (a) illegal access to all or part of a computer system or computer network by violating security measures, with intent to obtain data or another dishonest intent; (b) illegal interception, by technical means, of private data transmissions to, from, or within a computer system or network; (c) data interference, meaning the intentional and undue damaging, deletion, deterioration, alteration, or suppression of data; (d) system interference, meaning intentionally affecting the functioning of a computer system or network through the introduction, transmission, damaging, deletion, deterioration, alteration, or suppression of data; and (e) misuse of devices, meaning intentionally and without permission causing another's loss of property through introducing, altering, deleting, or suppressing data or interfering with a computer system's or network's functioning.

Article 68(a) sets the fine for these five contraventions at 40 to 90 times the public-service minimum wage, without prejudice to a more severe penalty under separate criminal legislation. Article 69 gives the sector regulator jurisdiction to process and decide contravention cases, and Article 70 allows direct appeal to the competent judicial court.

On the text of Article 67(a), illegal access requires violating a security measure with an intent to obtain data or another dishonest intent; reading a public, unauthenticated page without defeating a security measure has not itself been held to violate this article.

What it requires

Cybersecurity law3 instruments, 3 enacted but not yet in force

Research summary (233 words)

Mozambique enacted a standalone Cybersecurity Law (Lei n.º 13/2026), approved by the Assembleia da República on 29 April 2026, promulgated by the President on 10 June 2026, and published in the Boletím da República on 1 July 2026; it enters into force on 29 September 2026, ninety days after publication.

The Law reaches the whole private sector and the public administration alike with no personal-data trigger, and separately names critical-infrastructure operators, essential-service operators, digital-service providers, digital-intermediary-service providers, data-centre operators, and cloud-computing-platform operators, each carrying its own minimum security requirements, an incident-notification duty to a sectoral and a National CSIRT, and a good-faith safe harbour for responsible vulnerability disclosure.

A companion Cybercrime Law (Lei n.º 14/2026) was passed and published the same day; it criminalises unauthorised access and related offences against a system rather than regulating an operator's own security posture, so it belongs to the scraping topic rather than here.

Mozambique has no comprehensive personal-data-protection statute of its own: the Electronic Transactions Law's narrower data-protection chapter is a privacy-topic instrument, and a Personal Data Protection Bill remains before the Assembleia da República.

Banco de Moçambique has issued Aviso n.º 6/GBM/2026 (18 August 2026) on data-processing and data-storage procedures and requirements for credit institutions and financial companies, a financial-sector regime the LexLint activity vocabulary cannot yet express as its own bound party, so it is named here rather than filed as its own instrument.

Sector security regimes

Cybersecurity Law, Sector-Specific Security Requirements for Critical Infrastructure, Essential Services and Digital Providers

Lei n.º 13/2026, arts. 51 a 56Official gazette text, Boletím da República I Série No. 123 (1 July 2026), hosted by INTIC

In force in 6 days, effective 29 September 2026. Binds public and private bodies.

What this law does

Articles 51 through 56 of Mozambique's Cybersecurity Law layer sector-specific security-measure duties onto six categories the Law defines: critical-infrastructure operators, essential-service operators, digital-service providers, digital-intermediary-service providers, data-centre operators, and cloud-computing-platform operators, each required to take technical and organisational measures proportionate to the risk their networks and information systems face.

A private critical-infrastructure operator must additionally establish an institutional CSIRT, and a data-centre or cloud-computing-platform operator must safeguard the integrity, confidentiality, and availability of the data it stores. Breach of these requirements shares the same fine as Articles 47 through 50: 90 to 160 times the minimum public-service wage.

What it requires

Security baseline statutes

Cybersecurity Law, General Security Requirements for the Public Administration and the Private Sector

Lei n.º 13/2026, arts. 47 a 50Official gazette text, Boletím da República I Série No. 123 (1 July 2026), hosted by INTIC

In force in 6 days, effective 29 September 2026. Binds public and private bodies.

What this law does

Articles 47 through 50 of Mozambique's Cybersecurity Law (Lei n.º 13/2026) set minimum cybersecurity requirements binding every entity the Law covers, with no sector or size gate, and Article 50 restates the duty specifically for the Public Administration and the Private Sector at large.

A covered entity must maintain an information-security policy, a cyber-risk-management methodology, incident-notification procedures, risk-prevention and mitigation mechanisms, backup and recovery infrastructure, internal security-audit and oversight mechanisms, a staff security-awareness programme, a named person responsible for information security, and an incident detection-and-response team, and the Public Administration and the Private Sector must additionally name an internal cybersecurity auditor and establish an institutional CSIRT.

Breach of these requirements is punishable by a fine of 90 to 160 times the minimum public-service wage.

What it requires

Vulnerability and incident reporting

Cybersecurity Law, Incident Notification and Responsible Vulnerability Disclosure

Lei n.º 13/2026, arts. 57 a 66Official gazette text, Boletím da República I Série No. 123 (1 July 2026), hosted by INTIC

In force in 6 days, effective 29 September 2026. Binds public and private bodies.

What this law does

Article 57 defines a cybersecurity incident of significant impact by five alternative tests: its assessed severity, whether it stops an essential service beyond its maximum tolerable outage, whether it disrupts another essential-service provider, whether it requires an extraordinary remediation measure, or whether it harms a critical infrastructure's own users.

Articles 58 through 64 require the Public Administration and Private Sector at large, and separately the critical-infrastructure, essential-service, digital-service, digital-intermediary-service, data-centre, and cloud-computing-platform categories, to notify such an incident to their sectoral CSIRT and the National CSIRT within a deadline the National Cybersecurity Authority sets rather than the Law itself, and to file a monthly report on the incident's causes, resolution time, and measures taken; a data-centre or cloud-platform operator must also notify its own subscribers of an incident affecting their content.

Article 66 gives a good-faith safe harbour to a person who discloses a security vulnerability, provided among other conditions that they give at least 90 calendar days' notice before publishing it. Breach of the notification duty is punishable by a fine of 80 to 100 times the minimum public-service wage.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (113 words)

Mozambique has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code. The Copyright and Related Rights Law (Lei n.º 9/2022, de 29 de Junho) excludes news of the day and reports of events of a merely informational character from copyright protection outright, alongside mere facts and data, so a bare news item is never a protected work regardless of who first published it.

The Law's chapter on limitations to authors' economic rights survives only as a heavily degraded scan in the located gazette copy, so a quotation or press-review free-use provision, if the Law carries one, is not described here; the same degradation affects the Law's moral and economic rights chapters generally.

Snippet reproduction

Copyright and Related Rights Law, Exclusion of News and Facts from Protection

Lei n.º 9/2022, de 29 de Junho (Direitos do Autor e Direitos Conexos), art. 7Text of Lei n.º 9/2022

In force. Binds public and private bodies.

What this law does

Article 7(1) excludes from copyright protection: official texts of a legislative, administrative, or judicial nature and their official translations; news of the day and reports of events of a merely informational character; mere facts and data; political speeches, unless collected in a volume by their authors; ideas, processes, operational methods, or mathematical concepts, principles, or discoveries; and titles that are a generic, necessary, or usual designation of the theme or object of a work of a given genre, or that consist exclusively of the names of historical or mythological characters or of living public figures.

Article 7(2) allows the official texts named in Article 7(1)(a) to incorporate protected works without the rightholder's prior consent and without any compensation for the incorporation. The Law repeals the prior copyright statute, Lei n.º 4/2001, de 27 de Fevereiro.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.