🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
MZ v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing6 sources retrieved model claude-sonnet-5 · 2026-08-07

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Mozambique

MZ schema gdpri-v2 trajectory: not yet assessedunregulated gapoverlaps: FIM, WPM

Last updated · 10 categories · 0 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 50 sub-modules are flagged red.

Jurisdiction lead brief

Standing brief, as of 25 August 2026.

Lead Signal

Mozambique's data-protection and cyber-governance framework moved on two fronts this cycle, with the more advanced movement occurring in adjacent cybersecurity law rather than in the core data-protection bill itself. The Assembly of the Republic approved the Cyber Security Act and the Cybercrimes Act around 17 April 2026, establishing a National Cyber Security Council and designating INTIC as the National Cyber Security Authority. This is a high-confidence finding corroborated across two independent T3 sources, and it is now in force. The substantive Personal Data Protection Bill, by contrast, remains pending: it was approved by the Council of Ministers in early 2026 and forwarded to the Assembly of the Republic for debate, but has not itself been enacted. The result is a transitional state in which enforceable cyber-governance authority now exists ahead of the comprehensive data-protection regime that would eventually govern lawful processing, data subject rights, and cross-border transfers.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Constitutional and sectoral fragments plus an active legislative pipeline exist, but no comprehensive enacted statute or dedicated regulator is in force.

Traffic-light rationale — AmberConstitutional and sectoral fragments plus an active legislative pipeline exist, but no comprehensive enacted statute or dedicated regulator is in force.

Sub-modules (5)

Regulator And AuthorityRed

There is no independent dedicated data protection authority in Mozambique; oversight functions are fragmented across sectoral bodies and INTIC for ICT policy.

Claims (1):

  • CLM-MZ-11a2b3c4 (claim on file)

Act And InstrumentsAmber

No comprehensive data protection act is in force. Constitutional Article 71, the Electronic Transactions Law, Law 34/2014, the Cybersecurity/Cybercrime Laws, and the pending draft Personal Data Protection Law together form the current patchwork.

Claims (5):

  • CLM-MZ-22b3c4d5 (claim on file)
  • CLM-MZ-33c4d5e6 (claim on file)
  • CLM-MZ-44d5e6f7 (claim on file)
  • CLM-MZ-55e6f708 (claim on file)
  • CLM-MZ-66f70819 (claim on file)

Material ScopeRed

No comprehensive material scope for 'personal data' or 'processing' has been enacted; only narrow sectoral categories (public-entity records, electronic transactions data) are addressed.

Claims (1):

  • CLM-MZ-7708192a (claim on file)

Territorial ScopeRed

No territorial-scope rule (e.g., extraterritorial application to non-established controllers) exists absent a comprehensive statute.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique proteção de dados pessoais lei.

Regulator Registration And FilingRed

No controller registration or filing regime exists in the absence of a dedicated regulator.

Claims (1):

  • CLM-MZ-8819293b (claim on file)
Category narrative77 words

Mozambique has no comprehensive data protection statute and no independent dedicated data protection authority. The framework rests on Article 71 of the Constitution (general basis only), sectoral instruments (Electronic Transactions Law 3/2017; Law 34/2014 on confidentiality of personal data held by public entities), and the newly approved Cybersecurity and Cybercrime Laws (April 2026). A draft Personal Data Protection Law (sixth version released Nov 2025) was reported submitted to Parliament in March 2026 but is not yet enacted.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

Only a non-binding draft addresses this module; nothing is currently in force.

Traffic-light rationale — Not assessedOnly a non-binding draft addresses this module; nothing is currently in force.

Sub-modules (4)

Lawful BasesRed

The draft Personal Data Protection Law reportedly establishes principles and rules for data processing, but this is not yet in force.

Claims (1):

  • CLM-MZ-99293a4c (claim on file)

Special CategoriesRed

No enacted special/sensitive-category regime exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique proteção de dados pessoais lei.

Pseudonymisation And AnonymisationRed

No enacted pseudonymisation/anonymisation definitions or safe-harbours exist.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Category narrative30 words

No enacted lawful-basis framework, consent standard, special-category regime, or pseudonymisation/anonymisation safe-harbour exists. The pending draft Personal Data Protection Law (6th version, Nov 2025) reportedly proposes comprehensive principles but remains unenacted.

#

Only a general constitutional principle exists; no operative rights mechanism or deadlines are in force.

Traffic-light rationale — Not assessedOnly a general constitutional principle exists; no operative rights mechanism or deadlines are in force.

Sub-modules (5)

Access RightRed

No enacted subject-access-request mechanism exists.

Claims (1):

  • CLM-MZ-a3a4b5c6 (claim on file)

Rectification And ErasureRed

No enacted rectification/erasure right exists.

Claims (1):

  • CLM-MZ-a3a4b5c6 (claim on file)

Restriction And ObjectionRed

No enacted restriction/objection right exists.

Claims (1):

  • CLM-MZ-a3a4b5c6 (claim on file)

Data PortabilityRed

No enacted portability right exists.

Claims (1):

  • CLM-MZ-a3a4b5c6 (claim on file)

Deadlines And Response WindowsRed

No statutory response-window requirement exists absent a comprehensive law.

Claims (1):

  • CLM-MZ-a3a4b5c6 (claim on file)
Category narrative28 words

Beyond the general constitutional guarantee in Article 71, Mozambique has no enacted framework granting enumerated data subject rights (access, rectification, erasure, restriction, objection, portability) or statutory response deadlines.

#

A narrow public-sector confidentiality duty is in force; general controller/processor obligations remain unenacted.

Traffic-light rationale — AmberA narrow public-sector confidentiality duty is in force; general controller/processor obligations remain unenacted.

Sub-modules (7)

Accountability And DpiaRed

No enacted accountability principle or DPIA trigger exists; the draft law would reportedly introduce one.

Claims (1):

  • CLM-MZ-c5c6d7e8 (claim on file)

Dpo RequirementsRed

No DPO appointment threshold exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Ropa RequirementsRed

No records-of-processing obligation exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Joint Controller ArrangementsRed

No joint-controller regime exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Security MeasuresAmber

Law 34/2014 requires confidentiality of personal data held by public entities, with sanctions for unauthorised sharing.

Claims (1):

  • CLM-MZ-b4b5c6d7 (claim on file)

Breach NotificationRed

No breach-notification requirement (to regulator or subjects) exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique Cybersecurity Law 2026 INTIC personal data provisions.

Retention And DisposalRed

No general retention-limit or disposal duty exists outside sector-specific rules.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Category narrative52 words

Law 34/2014 imposes a confidentiality duty on public entities holding personal data, with fines and potential criminal prosecution for unauthorised disclosure, but there is no general accountability, DPIA, DPO, ROPA, joint-controller, breach-notification, or retention regime applicable across sectors. The pending draft Personal Data Protection Law would reportedly introduce such obligations if enacted.

#

Treaty ratification exists as a cross-border commitment, but no operative domestic transfer mechanism, adequacy status, or localisation rule has been verified.

Traffic-light rationale — AmberTreaty ratification exists as a cross-border commitment, but no operative domestic transfer mechanism, adequacy status, or localisation rule has been verified.

Sub-modules (6)

Transfer MechanismsAmber

Mozambique ratified the AU Malabo Convention in 2020, but no domestic implementing statute operationalising cross-border transfer mechanisms has been verified.

Claims (2):

  • CLM-MZ-d6d7e8f9 (claim on file)
  • CLM-MZ-e7e8f90a (claim on file)

Adequacy ReceivedRed

No adequacy decision received from another regime has been identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Adequacy GrantedRed

No adequacy decision granted to another regime has been identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Sccs And BcrsRed

No SCC or BCR framework exists under Mozambican law.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Transfer Impact AssessmentRed

No TIA requirement exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Data LocalisationRed

No general data-localisation mandate has been identified.

Absence provenance: unavailable. Searched: Mozambique Banco de Moçambique bank secrecy customer data telecommunications INCM data protection.

Category narrative48 words

Mozambique signed and ratified the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), but there is no evidence of domestic transposing legislation giving it direct effect, and no adequacy decisions (received or granted), SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate under any comprehensive statute.

#

Some sectoral coverage is referenced (finance, telecoms/e-transactions) but underlying instruments are not independently confirmed at statute level; other sectors show no coverage.

Traffic-light rationale — AmberSome sectoral coverage is referenced (finance, telecoms/e-transactions) but underlying instruments are not independently confirmed at statute level; other sectors show no coverage.

Sub-modules (7)

Financial Sector OverlayAmber

Mozambique's financial sector is reported to maintain its own legal framework safeguarding sector data, but the specific instrument(s) were not independently verified.

Claims (1):

  • CLM-MZ-f8f90a1b (claim on file)

Health Sector OverlayRed

No health-sector data-protection overlay identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Telecoms And EprivacyAmber

The Electronic Transactions Law (Law 3/2017) contains provisions relevant to e-commerce and electronic transactions with implications for data protection and privacy.

Claims (1):

  • CLM-MZ-091a2b3c (claim on file)

Employment DataRed

No employment-data-specific overlay identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Credit And ScoringRed

No credit-scoring-specific data rules identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

EducationRed

No education-sector data rules identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

InsuranceRed

No insurance-sector data rules identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Category narrative43 words

The financial and telecommunications sectors reportedly maintain their own legal frameworks for safeguarding sector data, though specific instruments were not independently verified. The Electronic Transactions Law (3/2017) addresses e-commerce data implications. No health, employment, credit-scoring, education, or insurance sector-specific data-protection overlays were identified.

#

No comprehensive or sectoral instrument addressing adtech/commercial privacy was located.

Traffic-light rationale — Not assessedNo comprehensive or sectoral instrument addressing adtech/commercial privacy was located.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent regime identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026, Mozambique proteção de dados pessoais lei.

Dark PatternsRed

No dark-pattern prohibition identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Opt Out SignalsRed

No recognition of opt-out signals (e.g., GPC) identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') regime identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Direct MarketingRed

No direct-marketing consent/suppression regime identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Category narrative22 words

No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rules, cross-context-advertising regime, or direct-marketing consent/suppression framework has been identified in Mozambican law.

#

Only a criminal-law privacy-intrusion offence exists; no positive algorithmic, biometric, or genetic data governance regime is in force.

Traffic-light rationale — Not assessedOnly a criminal-law privacy-intrusion offence exists; no positive algorithmic, biometric, or genetic data governance regime is in force.

Sub-modules (6)

Profiling RestrictionsRed

No profiling restriction analogous to GDPR Art. 22 exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Automated Decision Making TransparencyRed

No ADM transparency/explanation right exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Ai Risk AssessmentsRed

No AI-specific risk-assessment requirement exists.

Absence provenance: unavailable. Searched: Mozambique Cybersecurity Law 2026 INTIC personal data provisions.

Biometric RegimeRed

No biometric-data-specific regime exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Genetic DataRed

No genetic-data-specific regime exists.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

State Surveillance CarveoutsAmber

Article 252 of the Penal Code criminalises unauthorised privacy intrusion, including communications interception and image capture, functioning as the operative surveillance-related provision.

Claims (1):

  • CLM-MZ-1a2b3c4d (claim on file)
Category narrative45 words

Mozambique's Penal Code (Law 24/2019, Article 252) criminalises unauthorised interference with privacy including interception of communications, image capture, and sharing of private information, functioning as a narrow surveillance carve-out/offence. No profiling restrictions, ADM transparency rules, AI-specific risk-assessment requirements, or biometric/genetic data regimes have been identified.

#

No comprehensive or sectoral instrument addressing children's or vulnerable-groups' data was located.

Traffic-light rationale — Not assessedNo comprehensive or sectoral instrument addressing children's or vulnerable-groups' data was located.

Sub-modules (5)

Age VerificationRed

No age-verification requirement identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Minor Profiling BansRed

No minor-profiling ban identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Education SettingsRed

No education-setting-specific data rule identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Dependent AdultsRed

No dependent-adult data protection provision identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Category narrative17 words

No age-of-consent, parental-consent mechanism, minor-profiling ban, education-setting-specific rule, or dependent-adult protection has been identified in Mozambican law.

#

No dedicated DP enforcement regime, but material legislative activity occurred within the reporting window.

Traffic-light rationale — AmberNo dedicated DP enforcement regime, but material legislative activity occurred within the reporting window.

Sub-modules (6)

Regulator Powers And PenaltiesRed

No dedicated DP regulator or DP-specific penalty schedule exists; only sectoral/criminal sanctions apply.

Claims (1):

  • CLM-MZ-2b3c4d5e (claim on file)

Enforcement Activity IndexRed

No DP-specific enforcement activity exists absent a dedicated regulator.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Regulator Funding And CapacityRed

Not applicable; no dedicated DP regulator exists to fund or staff.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Collective Redress And Class ActionsRed

No DP-specific collective-redress mechanism identified.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Private Right Of ActionRed

No DP-specific private right of action identified beyond general criminal/civil recourse.

Absence provenance: unavailable. Searched: Mozambique data protection law 2026.

Recent Developments 180DAmber

The Assembly approved the Cybersecurity Law and Cybercrime Law (reported April 2026), and INTIC reported the draft Personal Data Protection Law's submission to Parliament (reported March 2026) — both within the 180-day window.

Claims (2):

  • CLM-MZ-3c4d5e6f (claim on file)
  • CLM-MZ-4d5e6f70 (claim on file)
Category narrative71 words

No dedicated data-protection regulator exists, so there are no data-protection-specific investigative/enforcement powers, fine schedules, or enforcement-activity index. Sanctions for privacy-related violations arise only under sectoral/criminal law (Law 34/2014 fines and possible prosecution; Penal Code Art. 252). Recent developments within the last 180 days include the Assembly's approval of the Cybersecurity and Cybercrime Laws (April 2026) and INTIC's report of the draft Personal Data Protection Law being submitted to Parliament (March 2026).

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct15.38
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Mozambique
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s) (0 category placement(s)), 13 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were researched. Coverage is thin across the board given the jurisdiction's unregulated-gap status: only regulator_and_framework, controller_processor_duties (security_measures), cross_border_and_adequacy (transfer_mechanisms), sectoral_watch (telecoms_and_eprivacy), algorithmic_biometric_and_surveillance_governance (state_surveillance_carveouts) and enforcement_and_redress (recent_developments_180d) carry substantive claims, all sourced to T3 secondary reporting (OneTrust DataGuidance) or T2/T1 anchors (Boletim da República text host, mz.gov.mz portal). lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, children_and_vulnerable_groups, and most sectoral_watch sub-modules carry only absent_field_provenance narratives, consistent with the seed's characterization of Mozambique as lacking a comprehensive data-protection statute and dedicated DPA. No T1 primary-legislative-text URL (e.g., Boletim da República gazette page for a specific law) was independently fetched beyond a hosted PDF copy of the Electronic Transactions Law.

Unresolved questions (5):

  • What is the current legislative status/timeline of the draft Personal Data Protection Law after its reported March 2026 submission to Parliament?
  • Has the AU Convention on Cyber Security and Personal Data Protection (Malabo Convention) been transposed into Mozambican domestic law via an implementing instrument?
  • Are there specific Banco de Moçambique or INCM (telecommunications regulator) regulations imposing customer data confidentiality or localisation obligations?
  • What are the precise entry-into-force date and full text of the Cybersecurity and Cybercrime Laws approved in April 2026, and do they contain personal-data-specific provisions?
  • Does Law No. 34/2014 apply only to public entities, or does it extend to private-sector controllers processing data on behalf of the state?

Escalate to primary-source review: yes