Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
Art. 4.1.1, read in full, defines biometric information as unique bodily data allowing identification of a person with the help of equipment, technical means, or software, and explicitly lists fingerprint pattern, iris, face, voice, and body-movement characteristics as examples, the only jurisdiction in this batch whose statute names a voice or face modality.
Art. 31 (Transitional provisions), read in full, requires destruction of fingerprint data collected by an information controller before the Law entered into force, except as authorized by law, with a government-organized working group to oversee that destruction, a concrete retroactive remediation duty with no parallel found elsewhere in this batch.
Breach notification
What it requires →
Art. 25.1.3, read in full, has the state digital-development and communications body receive and register notifications submitted by information controllers regarding a security breach of, or cyberattack on, information systems, and take necessary measures immediately, "immediately" itself being a defined term at Art. 4.1.3 meaning the shortest possible period of time, a qualitative rather than numeric standard.
This establishes the regulator's own immediate-action duty on receiving a notification; whether the Act imposes its own numeric deadline on a controller's initial notification was not confirmed in what was read (Arts. 18-23 were not read in this pass). Art. 10.5, read in extract, separately provides that meeting the Art. 25.1.2 security requirements is not grounds for exemption from liability arising from information loss.
Comprehensive regime
What it requires →
The Law, read in full for Arts. 1-4, applies to persons, legal entities, and organizations without legal-entity status that collect, process, use, or secure personal information, including via technical devices and software.
It exempts purely personal or household-family processing that does not infringe the person's own privacy, placing recording devices to protect one's own property or the life or health of oneself or family members, using one's own biometric information for the same purpose, and information legally required to be made public.
Arts. 6-8, the Act's general lawful-basis articles, are cross-referenced by Art. 9.2.1 but were not read in this pass, so this document does not assert their specific content.
Cross border transfer
What it requires →
Art. 14, read in full, is a one-paragraph default prohibition: transferring information to a person, legal entity, or international organization in a foreign country is prohibited except as provided by law or an international treaty of Mongolia, or with the information owner's consent.
There is no adequacy-assessment mechanism and no localization or domestic-storage requirement of the kind Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan all carry; nothing in the Act requires a Mongolian database to exist at all. This is a structurally different, narrower-gateway approach than the rest of the batch, which is why this document records cross_border_restriction as strict rather than moderate.
Data subject rights
What it requires →
Art. 16, read in full, is the richest rights list in this batch: consent to or refuse collection and transfer, know whether one's data has been collected or processed, know third-party recipients, correct errors, request deletion, demand enforcement of a legal prohibition on collection, obtain a copy of one's own data, transmit that copy to a controller of one's own choosing (a genuine data-portability right), withdraw from an ongoing processing activity, and object to and demand reprocessing of a decision resulting from data processing.
Art. 16.2 separately gives the subject a right to have unlawful material or moral damage remedied. Art. 15 sets the general deletion grounds: unlawfully collected data, court or treaty-ordered deletion, purpose achieved, or another statutory ground.
Enforcement supervision
What it requires →
Oversight is split between two institutions, both read directly. A designated member of the National Human Rights Commission (Art. 24.2) is specially responsible for information-protection activity, violations, and implementation of owner rights; the state digital-development and communications body (Art. 25) separately implements the Law, approves security requirements for sensitive, genetic, and biometric information processing, and receives breach notifications.
Art. 26 gives other state bodies continuing oversight within their existing competencies. Art. 28, read in extract, lets a complaint go to the competent authority or the National Human Rights Commission, with a further court appeal available. Art. 30, read in full, defers penalties to the Public Service Law or Labor Law for officials, and to the Criminal Law or the Law on Violations for persons and legal entities, none of which was read in this pass. No standalone private right of action distinct from Art. 16.2's damages-and-rights-protection clause was found.
Sensitive categories
What it requires →
Art. 4.1.12 defines a person's sensitive information to include origin or ethnicity, religion, belief, health, correspondence, genetic and biometric information together, the private key of a digital signature, criminal-sentence status, sexual orientation, gender identity and expression, and sexual-relations information, folding biometric and genetic data directly into the sensitive-information definition rather than treating it as a separate track.
Art. 9, read in extract, confirms this status carries elevated protection and prohibits collection, processing, or use except under the Act's general lawful-basis articles (Arts. 6-7, not independently read here), a health worker's legal duty, or evidence required by law in response to a legal claim; the extraction was cut off after this third ground.