top of page

Cybercrime Law - Law No. 14/2026, of July 1

  • Writer: JLA advogados
    JLA advogados
  • 2 days ago
  • 7 min read


Law No. 14/2026, of July 1, was approved by the Assembly of the Republic of Mozambique, promulgated by the President of the Republic, Daniel Francisco Chapo, and published in the Official Gazette. This law aims to establish substantive and procedural criminal provisions, as well as provisions regarding international cooperation in criminal matters, in the field of cybercrime and the collection of electronic evidence.


The Law thus covers three essential areas: the criminalization of cybercrimes, specific procedural mechanisms for the collection and preservation of evidence in electronic form, and the framework for international cooperation in criminal matters in the field of cybercrime, in accordance with Article 1 of the Law.


  1. Objectives of the Law


The growing digitization of the economy, public administration, and relations between private entities that use electronic information systems has brought significant benefits to economic and social development. However, it has also increased the exposure of citizens, businesses, and public institutions to risks related to cybercrime.


In this context, the Law aims to criminalize offenses specifically related to computer systems, establish appropriate procedural mechanisms for obtaining and preserving electronic evidence, strengthen international cooperation in combating digital crime, and harmonize Mozambique’s legal framework with international best practices in the field of cybersecurity and the fight against cybercrime.


This legislative initiative comes amid a growing incidence of electronic fraud, unauthorized access to computer systems, cyberattacks against critical infrastructure, and the misuse of digital data.


  1. Main Crimes Covered by the Law


  The Law defines the acts that constitute cybercrimes, notably the following:


Unauthorized Access (Article 4): This consists of unauthorized access to another person’s device—whether fixed or mobile, and whether or not connected to a computer network—for the purpose of obtaining non-public information from private email or electronic communications, accessing private data, trade or industrial secrets, or gaining unauthorized remote access. The law also punishes the production, sale, distribution, or dissemination of devices, programs, or computer data intended for the commission of such acts. The prescribed penalty is imprisonment for 1 to 2 years and a fine of up to 1 year.     Pursuant to Article 4(3), criminal proceedings do not require a complaint, except when data relating to private life is involved;

 

Unlawful Interception (Article 5): This refers to the unauthorized capture or monitoring, by technical means, of computer data transmissions that take place within a computer system, are intended for that system, or originate from it. The production or distribution of programs or devices designed to carry out such interceptions is also punishable. The prescribed penalty is imprisonment for up to 3 years and a fine of up to 2 years;

 

Data Tampering (Article 6): This covers the unauthorized alteration, corruption, rendering unusable, erasure, deletion, or destruction of computer data. The prescribed penalty is imprisonment for 1 to 2 years and a corresponding fine. Pursuant to paragraph 2, the installation of vulnerabilities that intentionally cause damage to critical infrastructure or services is punishable by imprisonment for 3 years and a corresponding fine;

 

Interference with Systems (Article 7): This consists of the disruption, interruption, or serious impediment of the operation of a computer system through the introduction, transmission, deterioration, damage, alteration, deletion, denial of access, or suppression of computer programs or data, or through any other form of interference. The prescribed penalty is imprisonment for up to 2 years and a fine of up to 1 year. The law increases the penalty to imprisonment for up to 3 years when the act is committed against critical infrastructure or services (paragraph 2), and to imprisonment for 2 to 8 years when the conduct results in substantial damage, disruption of essential services, or significant harm to third parties (paragraph 3);

 

Misuse of Devices (Article 8): Criminalizes the production, sale, importation, or distribution of programs, codes, or devices intended for the commission of the unauthorized acts described in Articles 4 and 5 of the Law. The prescribed penalty is imprisonment for 1 to 2 years;

 

Computer Fraud (Article 9): Occurs when computer data is intentionally and unlawfully entered, modified, erased, or deleted, thereby producing false data or documents, with the intent that they be considered or used for legal purposes as if they were authentic (paragraph 1). Paragraph (2) imposes the same penalties on anyone who uses a document produced through the acts referred to in paragraph (1) with the intent to cause harm or obtain an unlawful benefit. Paragraph 3 of Article 9 provides for an aggravated penalty of imprisonment for a term of 2 to 8 years for anyone who imports, distributes, sells, or possesses for commercial purposes any device that allows access to a communications system or a conditional access service, on which the acts provided for in the preceding paragraphs have been committed. Paragraph 4 imposes the same penalties as those in paragraph 1 on anyone who, for the purpose of gaining an advantage, manipulates, falsifies, or misuses another person’s identity. The occurrence of moral or property damage constitutes an aggravating circumstance (paragraph 5). The penalty range under paragraph 1 is imprisonment for 1 to 5 years and a fine of up to 1 year; and

 

Computer and Communications Fraud (Article 10): This consists of obtaining unlawful enrichment, for oneself or for a third party, through interference with the results of data processing, the incorrect structuring of a computer program, the unauthorized use of data, or unauthorized intervention in processing, thereby causing financial loss to third parties. The prescribed penalty is imprisonment for up to 3 years and a corresponding fine. Paragraph 2 extends the same penalty to anyone who uses programs, electronic devices, or other means intended to reduce, alter, or prevent the normal functioning or operation of telecommunications services, with the intent to obtain unlawful gain.


The Law also introduced the following offenses, which were not included in the draft law originally approved by the Assembly of the Republic:

 

Cyber Espionage (Article 11): Punishes unlawful or unauthorized access to government computer systems to obtain classified or strategic information, for political, economic, or military reasons, for the purposes of foreign intelligence, with a prison term of 3 to 10 years (paragraph 1). Paragraph 2 punishes the intrusion into corporate networks to steal trade secrets or commercial strategies and to compromise critical infrastructure and services, with a prison term of 2 to 8 years;

 

Cyber Terrorism and Violent Extremism (Article 12): Anyone who attacks, threatens to attack, intrudes upon, destroys, or tampers with data or computer systems of critical infrastructure, thereby disrupting their operation or the provision of their services, is punishable by imprisonment for 2 to 8 years (paragraph 1). The same penalty applies to anyone who mobilizes, recruits, produces, or disseminates content through computer systems, for political, economic, or religious motives, with the intent to cause panic, fear, or terror (paragraph 2);

 

Cyber Extortion (Article 13): Any person who threatens to disclose compromising information, launch attacks on computer systems, or leak personal data in the digital space in exchange for payment is punishable by imprisonment for up to 2 years and a corresponding fine (paragraph 1). The penalty is increased to imprisonment for up to 3 years and a corresponding fine when the victim is the head of a sovereign body, a member of the government, the head of a public body, or the head of a judicial body (paragraph 2); and

 

Child Sexual Content in the Digital Environment (Article 15): Anyone who produces, offers, exchanges, makes available, transmits, or publishes, through a computer or telecommunications system, sexual or pornographic content involving minors is punishable by imprisonment for 6 months to 1 year and a fine of up to 1 year (paragraph 1). The penalty does not apply when the act is committed for the purpose of reporting the incident to the competent authorities (paragraph 2).


  1. New Digital Investigation Mechanisms


To strengthen investigative capacity and the collection of electronic evidence, the Law establishes specific procedural mechanisms. Under Articles 18 and 19, authorities may order the expedited preservation of computer data and traffic data, as well as the expedited disclosure of traffic data that is susceptible to alteration or deletion.


Furthermore, Article 20 provides for the possibility of ordering the submission or provision of computer data necessary for criminal investigations. In addition, Articles 21 and 22 regulate the search for and seizure of computer data, including the creation of forensic copies, the preservation of data integrity, and the seizure of electronic media.

 

The Law also provides for the interception of electronic communications (Article 23) and the conduct of undercover operations to investigate more serious cybercrimes (Article 24).


These measures seek to adapt traditional criminal investigation mechanisms to the digital reality, strengthening the authorities’ capacity to prevent, detect, and suppress cybercrime.


  1. Punishment for Attempts and Criminal Liability of Legal Entities


Under Article 14, an attempt to commit any of the offenses provided for in the law is punishable under the Penal Code. Article 16 expressly establishes the criminal liability of legal entities and equivalent entities for the crimes provided for in the law, under the terms and within the limits of the respective liability regime set forth in the Penal Code.


  1. International Cooperation


Chapter IV of the Law governs the framework for international cooperation regarding computer-related crime. Under Article 25, the competent national authorities cooperate with the competent foreign authorities for the purpose of investigating crimes related to computer systems or data, as well as for the collection of evidence in electronic form. Article 26 establishes a mechanism for spontaneous information sharing, allowing for the communication of information useful to criminal investigations in other States.


Article 27 requires the Public Prosecutor’s Office to maintain a permanent contact point available 24 hours a day, 7 days a week, to provide immediate assistance to investigations within the framework of international cooperation, including technical advice, expedited preservation of data in emergency situations, collection of evidence, and location of suspects.


Article 28 regulates the mechanism for the expedited preservation and disclosure of computer data in the context of international cooperation, stipulating that the data subject to preservation may only be provided under the conditions expressly provided for by law. The grounds for refusing cooperation are exhaustively listed in Article 29, namely when offenses of a political nature are involved, when cooperation would undermine national sovereignty, security, or public order, or when the requesting State does not provide adequate safeguards for the protection of personal data.


  1. Final Provisions


With regard to the final provisions, Article 34 expressly repeals: (i) in paragraph 1, Articles 256, 289, 336, 337, 338, and 339 of the Penal Code adopted by Law No. 24/2019, of December 24, as amended by Law No. 17/2020 of December 23; and (ii) in paragraph 2, Article 57 and paragraph 2 of Article 66 of Law No. 4/2016 of July 3 (Telecommunications Law). The Government is tasked with issuing regulations for the law within 180 days from the date of its publication in the Official Gazette (Article 35), and the law will enter into force 90 days after its publication (Article 36).


*


For more information, please contact us at maputo@jlaadvogados.com

Comments


bottom of page