Law note · Mongolia
Law on Protection of Personal Data, biometric information definition and legacy fingerprint destruction
What it requires
- An app that captures a fingerprint, iris scan, faceprint, voiceprint, or body-movement identifier from a Mongolian data subject is processing biometric information under the Law's own definition, which explicitly names voice and face. An identifier extracted from a recording via technical means or software falls squarely within this definition. An app or its predecessor that collected fingerprint data before 1 May 2022 must destroy it unless separately authorized by law.
When LexLint raises it
processes_biometricsprocesses_voice
- Excludes recording-derived identifiers
- No
What we found
Art. 4.1.1, read in full, defines biometric information as unique bodily data allowing identification of a person with the help of equipment, technical means, or software, and explicitly lists fingerprint pattern, iris, face, voice, and body-movement characteristics as examples, the only jurisdiction in this batch whose statute names a voice or face modality.
Art. 31 (Transitional provisions), read in full, requires destruction of fingerprint data collected by an information controller before the Law entered into force, except as authorized by law, with a government-organized working group to oversee that destruction, a concrete retroactive remediation duty with no parallel found elsewhere in this batch.