Law note · Mongolia
Law on Protection of Personal Data, breach notification
What it requires
- An app that suffers a security breach of, or cyberattack on, an information system holding Mongolian personal data must submit a notification to the state digital-development and communications body, which must act on it in the shortest possible time. Whether the Act sets its own numeric deadline for the app's initial notification was not confirmed in this research.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
What we found
Art. 25.1.3, read in full, has the state digital-development and communications body receive and register notifications submitted by information controllers regarding a security breach of, or cyberattack on, information systems, and take necessary measures immediately, "immediately" itself being a defined term at Art. 4.1.3 meaning the shortest possible period of time, a qualitative rather than numeric standard.
This establishes the regulator's own immediate-action duty on receiving a notification; whether the Act imposes its own numeric deadline on a controller's initial notification was not confirmed in what was read (Arts. 18-23 were not read in this pass). Art. 10.5, read in extract, separately provides that meeting the Art. 25.1.2 security requirements is not grounds for exemption from liability arising from information loss.