Not publishable as-is. 1 of 5 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Mozambique
MZschema gdpri-v2trajectory: not yet assessedunregulated gapoverlaps: FIM, WPM
Last updated · 10 categories · 0
claims · 13 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No red categories; 50 sub-modules are flagged red.
Jurisdiction lead brief
Standing brief, as of 25 August 2026.
Lead Signal
Mozambique's data-protection and cyber-governance framework moved on two fronts this cycle, with the more advanced movement occurring in adjacent cybersecurity law rather than in the core data-protection bill itself. The Assembly of the Republic approved the Cyber Security Act and the Cybercrimes Act around 17 April 2026, establishing a National Cyber Security Council and designating INTIC as the National Cyber Security Authority. This is a high-confidence finding corroborated across two independent T3 sources, and it is now in force. The substantive Personal Data Protection Bill, by contrast, remains pending: it was approved by the Council of Ministers in early 2026 and forwarded to the Assembly of the Republic for debate, but has not itself been enacted. The result is a transitional state in which enforceable cyber-governance authority now exists ahead of the comprehensive data-protection regime that would eventually govern lawful processing, data subject rights, and cross-border transfers.
Other Developments
INTIC positioned for a dual regulatory role. Under the draft Personal Data Protection Bill, INTIC is designated to assume the role of the National Authority for Protection of Personal Data (ANPD), a proposed rather than enacted designation. INTIC's parallel, already-in-force role as National Cyber Security Authority under the Cyber Security Act means the same institution is positioned as the eventual anchor for both cyber-governance and data-protection oversight in Mozambique, pending the Bill's enactment.
Escalating administrative sanctions proposed for the future ANPD. The draft Bill would empower the ANPD with escalating administrative sanctions ranging from warnings to fines, blocking or deletion of data, and partial or total prohibition of processing activities, subject to a fair administrative process. These powers exist only in bill form; the ANPD is not yet operational and INTIC's current enforcement authority runs through the Cyber Security and Cybercrimes Acts rather than a data-protection-specific rulebook.
Cross-Monitor Connections
The Cyber Security Act and Cybercrimes Act, and the pending Personal Data Protection Bill's cross-border transfer-authorisation requirement, carry direct relevance to the financial-integrity monitor, which has separately flagged the draft Bill's AML/KYC data-sharing implications for obliged entities in its own regulatory-horizon tracking. The world-payments monitor's coverage of Mozambique's National Financial Inclusion Strategy, which foresees future data-protection and cybersecurity obligations for banks, is a related forward-looking thread that will intersect with INTIC's eventual ANPD role once the Bill is enacted.
Outlook
The principal item to watch is whether the Assembly of the Republic debates and enacts the Personal Data Protection Bill, which per its own terms would trigger implementing regulations within 180 days of publication. Until enactment, INTIC's operative authority runs through the Cyber Security Act and Cybercrimes Act rather than a data-protection-specific mandate, and the ANPD's proposed sanctions powers remain non-binding.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Constitutional and sectoral fragments plus an active legislative pipeline exist, but no comprehensive enacted statute or dedicated regulator is in force.
Traffic-light rationale — AmberConstitutional and sectoral fragments plus an active legislative pipeline exist, but no comprehensive enacted statute or dedicated regulator is in force.
Sub-modules (5)
Regulator And AuthorityRed
There is no independent dedicated data protection authority in Mozambique; oversight functions are fragmented across sectoral bodies and INTIC for ICT policy.
Claims (1):
CLM-MZ-11a2b3c4 (claim on file)
Act And InstrumentsAmber
No comprehensive data protection act is in force. Constitutional Article 71, the Electronic Transactions Law, Law 34/2014, the Cybersecurity/Cybercrime Laws, and the pending draft Personal Data Protection Law together form the current patchwork.
Claims (5):
CLM-MZ-22b3c4d5 (claim on file)
CLM-MZ-33c4d5e6 (claim on file)
CLM-MZ-44d5e6f7 (claim on file)
CLM-MZ-55e6f708 (claim on file)
CLM-MZ-66f70819 (claim on file)
Material ScopeRed
No comprehensive material scope for 'personal data' or 'processing' has been enacted; only narrow sectoral categories (public-entity records, electronic transactions data) are addressed.
Claims (1):
CLM-MZ-7708192a (claim on file)
Territorial ScopeRed
No territorial-scope rule (e.g., extraterritorial application to non-established controllers) exists absent a comprehensive statute.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique proteção de dados pessoais lei.
Regulator Registration And FilingRed
No controller registration or filing regime exists in the absence of a dedicated regulator.
Claims (1):
CLM-MZ-8819293b (claim on file)
Category narrative77 words
Mozambique has no comprehensive data protection statute and no independent dedicated data protection authority. The framework rests on Article 71 of the Constitution (general basis only), sectoral instruments (Electronic Transactions Law 3/2017; Law 34/2014 on confidentiality of personal data held by public entities), and the newly approved Cybersecurity and Cybercrime Laws (April 2026). A draft Personal Data Protection Law (sixth version released Nov 2025) was reported submitted to Parliament in March 2026 but is not yet enacted.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Only a non-binding draft addresses this module; nothing is currently in force.
Traffic-light rationale — Not assessedOnly a non-binding draft addresses this module; nothing is currently in force.
Sub-modules (4)
Lawful BasesRed
The draft Personal Data Protection Law reportedly establishes principles and rules for data processing, but this is not yet in force.
Claims (1):
CLM-MZ-99293a4c (claim on file)
Consent ThresholdsRed
No enacted consent standard exists.
Absence provenance: unavailable. Searched: Mozambique proteção de dados pessoais lei, Mozambique data protection law 2026.
Special CategoriesRed
No enacted special/sensitive-category regime exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique proteção de dados pessoais lei.
Pseudonymisation And AnonymisationRed
No enacted pseudonymisation/anonymisation definitions or safe-harbours exist.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Category narrative30 words
No enacted lawful-basis framework, consent standard, special-category regime, or pseudonymisation/anonymisation safe-harbour exists. The pending draft Personal Data Protection Law (6th version, Nov 2025) reportedly proposes comprehensive principles but remains unenacted.
Only a general constitutional principle exists; no operative rights mechanism or deadlines are in force.
Traffic-light rationale — Not assessedOnly a general constitutional principle exists; no operative rights mechanism or deadlines are in force.
Sub-modules (5)
Access RightRed
No enacted subject-access-request mechanism exists.
Claims (1):
CLM-MZ-a3a4b5c6 (claim on file)
Rectification And ErasureRed
No enacted rectification/erasure right exists.
Claims (1):
CLM-MZ-a3a4b5c6 (claim on file)
Restriction And ObjectionRed
No enacted restriction/objection right exists.
Claims (1):
CLM-MZ-a3a4b5c6 (claim on file)
Data PortabilityRed
No enacted portability right exists.
Claims (1):
CLM-MZ-a3a4b5c6 (claim on file)
Deadlines And Response WindowsRed
No statutory response-window requirement exists absent a comprehensive law.
Claims (1):
CLM-MZ-a3a4b5c6 (claim on file)
Category narrative28 words
Beyond the general constitutional guarantee in Article 71, Mozambique has no enacted framework granting enumerated data subject rights (access, rectification, erasure, restriction, objection, portability) or statutory response deadlines.
A narrow public-sector confidentiality duty is in force; general controller/processor obligations remain unenacted.
Traffic-light rationale — AmberA narrow public-sector confidentiality duty is in force; general controller/processor obligations remain unenacted.
Sub-modules (7)
Accountability And DpiaRed
No enacted accountability principle or DPIA trigger exists; the draft law would reportedly introduce one.
Claims (1):
CLM-MZ-c5c6d7e8 (claim on file)
Dpo RequirementsRed
No DPO appointment threshold exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Ropa RequirementsRed
No records-of-processing obligation exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Joint Controller ArrangementsRed
No joint-controller regime exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Security MeasuresAmber
Law 34/2014 requires confidentiality of personal data held by public entities, with sanctions for unauthorised sharing.
Claims (1):
CLM-MZ-b4b5c6d7 (claim on file)
Breach NotificationRed
No breach-notification requirement (to regulator or subjects) exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique Cybersecurity Law 2026 INTIC personal data provisions.
Retention And DisposalRed
No general retention-limit or disposal duty exists outside sector-specific rules.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Category narrative52 words
Law 34/2014 imposes a confidentiality duty on public entities holding personal data, with fines and potential criminal prosecution for unauthorised disclosure, but there is no general accountability, DPIA, DPO, ROPA, joint-controller, breach-notification, or retention regime applicable across sectors. The pending draft Personal Data Protection Law would reportedly introduce such obligations if enacted.
Treaty ratification exists as a cross-border commitment, but no operative domestic transfer mechanism, adequacy status, or localisation rule has been verified.
Traffic-light rationale — AmberTreaty ratification exists as a cross-border commitment, but no operative domestic transfer mechanism, adequacy status, or localisation rule has been verified.
Sub-modules (6)
Transfer MechanismsAmber
Mozambique ratified the AU Malabo Convention in 2020, but no domestic implementing statute operationalising cross-border transfer mechanisms has been verified.
Claims (2):
CLM-MZ-d6d7e8f9 (claim on file)
CLM-MZ-e7e8f90a (claim on file)
Adequacy ReceivedRed
No adequacy decision received from another regime has been identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Adequacy GrantedRed
No adequacy decision granted to another regime has been identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Sccs And BcrsRed
No SCC or BCR framework exists under Mozambican law.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Transfer Impact AssessmentRed
No TIA requirement exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Data LocalisationRed
No general data-localisation mandate has been identified.
Absence provenance: unavailable. Searched: Mozambique Banco de Moçambique bank secrecy customer data telecommunications INCM data protection.
Category narrative48 words
Mozambique signed and ratified the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), but there is no evidence of domestic transposing legislation giving it direct effect, and no adequacy decisions (received or granted), SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate under any comprehensive statute.
Some sectoral coverage is referenced (finance, telecoms/e-transactions) but underlying instruments are not independently confirmed at statute level; other sectors show no coverage.
Traffic-light rationale — AmberSome sectoral coverage is referenced (finance, telecoms/e-transactions) but underlying instruments are not independently confirmed at statute level; other sectors show no coverage.
Sub-modules (7)
Financial Sector OverlayAmber
Mozambique's financial sector is reported to maintain its own legal framework safeguarding sector data, but the specific instrument(s) were not independently verified.
Claims (1):
CLM-MZ-f8f90a1b (claim on file)
Health Sector OverlayRed
No health-sector data-protection overlay identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Telecoms And EprivacyAmber
The Electronic Transactions Law (Law 3/2017) contains provisions relevant to e-commerce and electronic transactions with implications for data protection and privacy.
Claims (1):
CLM-MZ-091a2b3c (claim on file)
Employment DataRed
No employment-data-specific overlay identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Credit And ScoringRed
No credit-scoring-specific data rules identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
EducationRed
No education-sector data rules identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
InsuranceRed
No insurance-sector data rules identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Category narrative43 words
The financial and telecommunications sectors reportedly maintain their own legal frameworks for safeguarding sector data, though specific instruments were not independently verified. The Electronic Transactions Law (3/2017) addresses e-commerce data implications. No health, employment, credit-scoring, education, or insurance sector-specific data-protection overlays were identified.
No comprehensive or sectoral instrument addressing adtech/commercial privacy was located.
Traffic-light rationale — Not assessedNo comprehensive or sectoral instrument addressing adtech/commercial privacy was located.
Sub-modules (6)
Cookies And TrackersRed
No cookie/tracker consent regime identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique proteção de dados pessoais lei.
Dark PatternsRed
No dark-pattern prohibition identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Opt Out SignalsRed
No recognition of opt-out signals (e.g., GPC) identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room rules identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Cross Context AdvertisingRed
No cross-context-advertising ('sale'/'share') regime identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Direct MarketingRed
No direct-marketing consent/suppression regime identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Category narrative22 words
No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rules, cross-context-advertising regime, or direct-marketing consent/suppression framework has been identified in Mozambican law.
Only a criminal-law privacy-intrusion offence exists; no positive algorithmic, biometric, or genetic data governance regime is in force.
Traffic-light rationale — Not assessedOnly a criminal-law privacy-intrusion offence exists; no positive algorithmic, biometric, or genetic data governance regime is in force.
Sub-modules (6)
Profiling RestrictionsRed
No profiling restriction analogous to GDPR Art. 22 exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Automated Decision Making TransparencyRed
No ADM transparency/explanation right exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Ai Risk AssessmentsRed
No AI-specific risk-assessment requirement exists.
Absence provenance: unavailable. Searched: Mozambique Cybersecurity Law 2026 INTIC personal data provisions.
Biometric RegimeRed
No biometric-data-specific regime exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Genetic DataRed
No genetic-data-specific regime exists.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
State Surveillance CarveoutsAmber
Article 252 of the Penal Code criminalises unauthorised privacy intrusion, including communications interception and image capture, functioning as the operative surveillance-related provision.
Claims (1):
CLM-MZ-1a2b3c4d (claim on file)
Category narrative45 words
Mozambique's Penal Code (Law 24/2019, Article 252) criminalises unauthorised interference with privacy including interception of communications, image capture, and sharing of private information, functioning as a narrow surveillance carve-out/offence. No profiling restrictions, ADM transparency rules, AI-specific risk-assessment requirements, or biometric/genetic data regimes have been identified.
No comprehensive or sectoral instrument addressing children's or vulnerable-groups' data was located.
Traffic-light rationale — Not assessedNo comprehensive or sectoral instrument addressing children's or vulnerable-groups' data was located.
Sub-modules (5)
Age VerificationRed
No age-verification requirement identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Parental ConsentRed
No parental-consent mechanism identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Minor Profiling BansRed
No minor-profiling ban identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Education SettingsRed
No education-setting-specific data rule identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Dependent AdultsRed
No dependent-adult data protection provision identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Category narrative17 words
No age-of-consent, parental-consent mechanism, minor-profiling ban, education-setting-specific rule, or dependent-adult protection has been identified in Mozambican law.
No dedicated DP enforcement regime, but material legislative activity occurred within the reporting window.
Traffic-light rationale — AmberNo dedicated DP enforcement regime, but material legislative activity occurred within the reporting window.
Sub-modules (6)
Regulator Powers And PenaltiesRed
No dedicated DP regulator or DP-specific penalty schedule exists; only sectoral/criminal sanctions apply.
Claims (1):
CLM-MZ-2b3c4d5e (claim on file)
Enforcement Activity IndexRed
No DP-specific enforcement activity exists absent a dedicated regulator.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Regulator Funding And CapacityRed
Not applicable; no dedicated DP regulator exists to fund or staff.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Collective Redress And Class ActionsRed
No DP-specific collective-redress mechanism identified.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Private Right Of ActionRed
No DP-specific private right of action identified beyond general criminal/civil recourse.
Absence provenance: unavailable. Searched: Mozambique data protection law 2026.
Recent Developments 180DAmber
The Assembly approved the Cybersecurity Law and Cybercrime Law (reported April 2026), and INTIC reported the draft Personal Data Protection Law's submission to Parliament (reported March 2026) — both within the 180-day window.
Claims (2):
CLM-MZ-3c4d5e6f (claim on file)
CLM-MZ-4d5e6f70 (claim on file)
Category narrative71 words
No dedicated data-protection regulator exists, so there are no data-protection-specific investigative/enforcement powers, fine schedules, or enforcement-activity index. Sanctions for privacy-related violations arise only under sectoral/criminal law (Law 34/2014 fines and possible prosecution; Penal Code Art. 252). Recent developments within the last 180 days include the Assembly's approval of the Cybersecurity and Cybercrime Laws (April 2026) and INTIC's report of the draft Personal Data Protection Law being submitted to Parliament (March 2026).
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 1 failing check(s).
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
15.38
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Mozambique
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s) (0 category placement(s)), 13 source(s) in the cumulative register.
All 10 modules were researched. Coverage is thin across the board given the jurisdiction's unregulated-gap status: only regulator_and_framework, controller_processor_duties (security_measures), cross_border_and_adequacy (transfer_mechanisms), sectoral_watch (telecoms_and_eprivacy), algorithmic_biometric_and_surveillance_governance (state_surveillance_carveouts) and enforcement_and_redress (recent_developments_180d) carry substantive claims, all sourced to T3 secondary reporting (OneTrust DataGuidance) or T2/T1 anchors (Boletim da República text host, mz.gov.mz portal). lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, children_and_vulnerable_groups, and most sectoral_watch sub-modules carry only absent_field_provenance narratives, consistent with the seed's characterization of Mozambique as lacking a comprehensive data-protection statute and dedicated DPA. No T1 primary-legislative-text URL (e.g., Boletim da República gazette page for a specific law) was independently fetched beyond a hosted PDF copy of the Electronic Transactions Law.
Unresolved questions (5):
What is the current legislative status/timeline of the draft Personal Data Protection Law after its reported March 2026 submission to Parliament?
Has the AU Convention on Cyber Security and Personal Data Protection (Malabo Convention) been transposed into Mozambican domestic law via an implementing instrument?
Are there specific Banco de Moçambique or INCM (telecommunications regulator) regulations imposing customer data confidentiality or localisation obligations?
What are the precise entry-into-force date and full text of the Cybersecurity and Cybercrime Laws approved in April 2026, and do they contain personal-data-specific provisions?
Does Law No. 34/2014 apply only to public entities, or does it extend to private-sector controllers processing data on behalf of the state?