Law note · Mongolia
Law on Protection of Personal Data, enforcement
What it requires
- An app processing Mongolian personal data may be investigated by a designated National Human Rights Commission member or the state digital-development and communications body, and a person may complain to either, with a further court appeal available. Fines and criminal penalties sit in the separate Law on Violations and Criminal Law, neither confirmed in this research; a general damages-and-rights-protection remedy exists at Art. 16.2, though it is not framed as a dedicated statutory cause of action.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
Oversight is split between two institutions, both read directly. A designated member of the National Human Rights Commission (Art. 24.2) is specially responsible for information-protection activity, violations, and implementation of owner rights; the state digital-development and communications body (Art. 25) separately implements the Law, approves security requirements for sensitive, genetic, and biometric information processing, and receives breach notifications.
Art. 26 gives other state bodies continuing oversight within their existing competencies. Art. 28, read in extract, lets a complaint go to the competent authority or the National Human Rights Commission, with a further court appeal available. Art. 30, read in full, defers penalties to the Public Service Law or Labor Law for officials, and to the Criminal Law or the Law on Violations for persons and legal entities, none of which was read in this pass. No standalone private right of action distinct from Art. 16.2's damages-and-rights-protection clause was found.