Personal data protection: what applies to your website

If your site has a contact form, a newsletter, a client area or a shop, you are processing personal data. This article explains what that means in Mozambique, what is expected of you, and where our part ends and yours begins.

We are not lawyers. This is practical guidance from people who host websites, written to help you ask the right questions. For a decision with legal consequences — a contract, a fine, a formal request — talk to a lawyer.

What counts as personal data

It is any information that identifies a person, directly or by cross-referencing. The list is wider than intuition suggests:

Category Examples
The obvious Name, ID number, tax number, phone, address, e-mail address
The less obvious IP address, cookies, location, photographs where the person is recognisable, buying habits
The kind needing extra care Health, ethnic origin, political or religious convictions, sexual life, biometric data

“Processing” is also more than collecting: it includes storing, consulting, altering, sharing with third parties and deleting. A form that lands in your inbox and stays there for years is data processing.

Mozambique does not yet have a law just for this

It is the most common question and the answer is unusual: Mozambique has, to this day, no standalone personal data protection act. That does not mean there are no rules — it means they are spread across several instruments.

What already applies What it says
Constitution, article 71 Forbids using computer systems to record and process individually identifiable data on political convictions, religious faith and party affiliation, among others
Lei n.º 3/2017, of 9 January The Electronic Transactions Act. It defines the data processor — whoever collects, processes or stores personal data electronically — and the duties that come with it
Sector rules Banking, health and telecoms have their own confidentiality rules on top of the general ones
A bill is under way. A Personal Data Protection Act is being prepared that would create the ANPD — a national authority with regulatory, supervisory and sanctioning powers, along the lines of what exists elsewhere. Until it is approved and published, it is not law. We will update this article when it is.
This is not a licence to be careless. No specific law does not erase the Constitution, nor the Electronic Transactions Act, nor the reputational damage of a leak. And if you sell abroad — into the European Union, say — it is their rules that reach you, whatever applies here.

What to do on your site, concretely

1 Make the list. What data you collect, in which forms, where it is stored, who has access to it and for how long. Without that list, the rest is guesswork.
2 Publish a privacy policy in language people understand, saying what you collect, what for, who you share it with and how someone asks to be deleted. Link it in the footer and next to every form.
3 Ask only for what you need. If the contact form does not need a postal address, remove the field. Every extra field is one more risk and one fewer conversion.
4 Treat subscription as consent. An unticked box, never pre-ticked, and separate from the send button. And keep a record of when and how they consented.
5 Close the door. Active SSL certificate, strong passwords, two-factor authentication where available, and a review of who has access to the panel — see how to enable two-factor authentication.
6 Know how to go back. A backup is not only against failures: it is what lets you prove what was there and recover after an incident — see how to restore your data with JetBackup.

Mind what leaves your house

Many sites hand data to third parties without noticing: the form that posts to a newsletter service abroad, the embedded map, the share button, the analytics tool, the support chat.

And artificial intelligence tools. Pasting your client list, a contract or a patient’s details into an AI assistant is sharing with a third party — even if nobody reads it on the other side. If you use AI at work, see what makes sense to send in which AI tool suits which task.

What we do and what is yours

Ours Yours
Keeping the server updated and protected Deciding what data you collect and what for
Storing the data on the server and taking backups Writing and publishing the privacy policy
Providing SSL, firewall and access logs Answering people who ask for access, correction or deletion
Warning and helping if there is an incident on our side Controlling who on your team has the panel password

The full line between what we fix and what stays on your side is in how far our support goes.

Need to know where your site’s data is stored, or need an access log?

Ask us
  • 0 Users Found This Useful
Was this answer helpful?