Law note · Mongolia
Law on Protection of Personal Data, cross-border transfer
What it requires
- An app transferring the personal data of a Mongolian data subject, including a voiceprint or other biometric identifier, to a person, legal entity, or organization in another country must have a statutory basis, an applicable international treaty, or the subject's consent; transfer is prohibited by default otherwise, and Mongolia imposes no separate domestic-storage requirement on the underlying data.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Art. 14, read in full, is a one-paragraph default prohibition: transferring information to a person, legal entity, or international organization in a foreign country is prohibited except as provided by law or an international treaty of Mongolia, or with the information owner's consent.
There is no adequacy-assessment mechanism and no localization or domestic-storage requirement of the kind Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan all carry; nothing in the Act requires a Mongolian database to exist at all. This is a structurally different, narrower-gateway approach than the rest of the batch, which is why this document records cross_border_restriction as strict rather than moderate.