Law note · Mongolia

Law on Protection of Personal Data, breach notification

cite Law on Protection of Personal Data (17 December 2021), Art. 25.1.3; Art. 10.5 stage IN FORCE in force since 2022-05-01 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that suffers a security breach of, or cyberattack on, an information system holding Mongolian personal data must submit a notification to the state digital-development and communications body, which must act on it in the shortest possible time. Whether the Act sets its own numeric deadline for the app's initial notification was not confirmed in this research.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

What we found

Art. 25.1.3, read in full, has the state digital-development and communications body receive and register notifications submitted by information controllers regarding a security breach of, or cyberattack on, information systems, and take necessary measures immediately, "immediately" itself being a defined term at Art. 4.1.3 meaning the shortest possible period of time, a qualitative rather than numeric standard.

This establishes the regulator's own immediate-action duty on receiving a notification; whether the Act imposes its own numeric deadline on a controller's initial notification was not confirmed in what was read (Arts. 18-23 were not read in this pass). Art. 10.5, read in extract, separately provides that meeting the Art. 25.1.2 security requirements is not grounds for exemption from liability arising from information loss.

← Back to the example  ·  Lint your app →