Law note · Mongolia

Law on Protection of Personal Data, cross-border transfer

cite Law on Protection of Personal Data (17 December 2021), Art. 14 stage IN FORCE in force since 2022-05-01 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of a Mongolian data subject, including a voiceprint or other biometric identifier, to a person, legal entity, or organization in another country must have a statutory basis, an applicable international treaty, or the subject's consent; transfer is prohibited by default otherwise, and Mongolia imposes no separate domestic-storage requirement on the underlying data.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

What we found

Art. 14, read in full, is a one-paragraph default prohibition: transferring information to a person, legal entity, or international organization in a foreign country is prohibited except as provided by law or an international treaty of Mongolia, or with the information owner's consent.

There is no adequacy-assessment mechanism and no localization or domestic-storage requirement of the kind Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan all carry; nothing in the Act requires a Mongolian database to exist at all. This is a structurally different, narrower-gateway approach than the rest of the batch, which is why this document records cross_border_restriction as strict rather than moderate.

← Back to the example  ·  Lint your app →