Law note · Mongolia

Law on Protection of Personal Data, biometric information definition and legacy fingerprint destruction

cite Law on Protection of Personal Data (17 December 2021), Art. 4.1.1; Art. 31 stage IN FORCE in force since 2022-05-01 kind Biometric privacy binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that captures a fingerprint, iris scan, faceprint, voiceprint, or body-movement identifier from a Mongolian data subject is processing biometric information under the Law's own definition, which explicitly names voice and face. An identifier extracted from a recording via technical means or software falls squarely within this definition. An app or its predecessor that collected fingerprint data before 1 May 2022 must destroy it unless separately authorized by law.

When LexLint raises it

  • processes_biometrics
  • processes_voice
Excludes recording-derived identifiers
No

What we found

Art. 4.1.1, read in full, defines biometric information as unique bodily data allowing identification of a person with the help of equipment, technical means, or software, and explicitly lists fingerprint pattern, iris, face, voice, and body-movement characteristics as examples, the only jurisdiction in this batch whose statute names a voice or face modality.

Art. 31 (Transitional provisions), read in full, requires destruction of fingerprint data collected by an information controller before the Law entered into force, except as authorized by law, with a government-organized working group to oversee that destruction, a concrete retroactive remediation duty with no parallel found elsewhere in this batch.

← Back to the example  ·  Lint your app →