Law / Mongolia

Mongolia

privacy

Mongolia's Law on Protection of Personal Data of a Person (17 December 2021, in force 1 May 2022) is the richest, most modern instrument in this batch.

Art. 4.1.1's biometric-information definition explicitly names fingerprint, iris, face, and voice as illustrative examples, technology-mediated by its own terms, the only jurisdiction in this batch whose statute names a voice or face modality at all, and Art. 4.1.12 folds biometric and genetic information directly into the definition of a person's sensitive information rather than treating it as a separate track.

Art. 14 requires a default prohibition on transferring personal data abroad, lifted only by a statutory basis, an international treaty, or the subject's consent, with no adequacy-assessment mechanism and no additional public-order, health, or defense fallback grounds of the kind Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan all carry; this document records cross_border_restriction as strict rather than the corpus seed's moderate for that reason, though the Act imposes no localization or domestic-storage requirement at all.

Art. 25.1.3 gives Mongolia the batch's clearest breach-notification mechanism, requiring the digital-development regulator to act immediately (a defined qualitative standard, not a numeric deadline) on receiving a controller's notification of a security breach or cyberattack, and Art. 31 imposes a real, retroactive duty to destroy fingerprint data collected before the Law took effect unless separately authorized.

Oversight is split between a designated member of the National Human Rights Commission and the state digital-development body, with penalties deferred to the separate Criminal Law and Law on Violations, neither read in this pass. Chapter 7 (Art. 27) separately regulates the physical placement of audio, video, and audio-video recording devices, a rule not slotted into any registered attribute and noted here in prose only.

12 instruments named 7 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Law on Protection of Personal Data, biometric information definition and legacy fingerprint destruction

cite Law on Protection of Personal Data (17 December 2021), Art. 4.1.1; Art. 31 stage IN FORCE in force since 2022-05-01 binds public and private bodies source official text, legalinfo.mn, Mongolia's official legal-information portal
What it requires

Art. 4.1.1, read in full, defines biometric information as unique bodily data allowing identification of a person with the help of equipment, technical means, or software, and explicitly lists fingerprint pattern, iris, face, voice, and body-movement characteristics as examples, the only jurisdiction in this batch whose statute names a voice or face modality.

Art. 31 (Transitional provisions), read in full, requires destruction of fingerprint data collected by an information controller before the Law entered into force, except as authorized by law, with a government-organized working group to oversee that destruction, a concrete retroactive remediation duty with no parallel found elsewhere in this batch.

Breach notification

Law on Protection of Personal Data, breach notification

cite Law on Protection of Personal Data (17 December 2021), Art. 25.1.3; Art. 10.5 stage IN FORCE in force since 2022-05-01 binds public and private bodies source official text, legalinfo.mn, Mongolia's official legal-information portal
What it requires

Art. 25.1.3, read in full, has the state digital-development and communications body receive and register notifications submitted by information controllers regarding a security breach of, or cyberattack on, information systems, and take necessary measures immediately, "immediately" itself being a defined term at Art. 4.1.3 meaning the shortest possible period of time, a qualitative rather than numeric standard.

This establishes the regulator's own immediate-action duty on receiving a notification; whether the Act imposes its own numeric deadline on a controller's initial notification was not confirmed in what was read (Arts. 18-23 were not read in this pass). Art. 10.5, read in extract, separately provides that meeting the Art. 25.1.2 security requirements is not grounds for exemption from liability arising from information loss.

Comprehensive regime

Law on Protection of Personal Data, comprehensive regime

cite Law on Protection of Personal Data (17 December 2021), in force 1 May 2022, Arts. 1-4 stage IN FORCE in force since 2022-05-01 binds public and private bodies source official text, legalinfo.mn, Mongolia's official legal-information portal
What it requires

The Law, read in full for Arts. 1-4, applies to persons, legal entities, and organizations without legal-entity status that collect, process, use, or secure personal information, including via technical devices and software.

It exempts purely personal or household-family processing that does not infringe the person's own privacy, placing recording devices to protect one's own property or the life or health of oneself or family members, using one's own biometric information for the same purpose, and information legally required to be made public.

Arts. 6-8, the Act's general lawful-basis articles, are cross-referenced by Art. 9.2.1 but were not read in this pass, so this document does not assert their specific content.

Cross border transfer

Law on Protection of Personal Data, cross-border transfer

cite Law on Protection of Personal Data (17 December 2021), Art. 14 stage IN FORCE in force since 2022-05-01 binds public and private bodies source official text, legalinfo.mn, Mongolia's official legal-information portal
What it requires

Art. 14, read in full, is a one-paragraph default prohibition: transferring information to a person, legal entity, or international organization in a foreign country is prohibited except as provided by law or an international treaty of Mongolia, or with the information owner's consent.

There is no adequacy-assessment mechanism and no localization or domestic-storage requirement of the kind Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan all carry; nothing in the Act requires a Mongolian database to exist at all. This is a structurally different, narrower-gateway approach than the rest of the batch, which is why this document records cross_border_restriction as strict rather than moderate.

Data subject rights

Law on Protection of Personal Data, data subject rights

cite Law on Protection of Personal Data (17 December 2021), Art. 16; Art. 15 stage IN FORCE in force since 2022-05-01 binds public and private bodies source official text, legalinfo.mn, Mongolia's official legal-information portal
What it requires

Art. 16, read in full, is the richest rights list in this batch: consent to or refuse collection and transfer, know whether one's data has been collected or processed, know third-party recipients, correct errors, request deletion, demand enforcement of a legal prohibition on collection, obtain a copy of one's own data, transmit that copy to a controller of one's own choosing (a genuine data-portability right), withdraw from an ongoing processing activity, and object to and demand reprocessing of a decision resulting from data processing.

Art. 16.2 separately gives the subject a right to have unlawful material or moral damage remedied. Art. 15 sets the general deletion grounds: unlawfully collected data, court or treaty-ordered deletion, purpose achieved, or another statutory ground.

Enforcement supervision

Law on Protection of Personal Data, enforcement

cite Law on Protection of Personal Data (17 December 2021), Arts. 24-26, 28, 30 stage IN FORCE in force since 2022-05-01 binds public and private bodies source official text, legalinfo.mn, Mongolia's official legal-information portal
What it requires

Oversight is split between two institutions, both read directly. A designated member of the National Human Rights Commission (Art. 24.2) is specially responsible for information-protection activity, violations, and implementation of owner rights; the state digital-development and communications body (Art. 25) separately implements the Law, approves security requirements for sensitive, genetic, and biometric information processing, and receives breach notifications.

Art. 26 gives other state bodies continuing oversight within their existing competencies. Art. 28, read in extract, lets a complaint go to the competent authority or the National Human Rights Commission, with a further court appeal available. Art. 30, read in full, defers penalties to the Public Service Law or Labor Law for officials, and to the Criminal Law or the Law on Violations for persons and legal entities, none of which was read in this pass. No standalone private right of action distinct from Art. 16.2's damages-and-rights-protection clause was found.

Sensitive categories

Law on Protection of Personal Data, sensitive personal information

cite Law on Protection of Personal Data (17 December 2021), Arts. 4.1.12, 9 stage IN FORCE in force since 2022-05-01 binds public and private bodies source official text, legalinfo.mn, Mongolia's official legal-information portal
What it requires

Art. 4.1.12 defines a person's sensitive information to include origin or ethnicity, religion, belief, health, correspondence, genetic and biometric information together, the private key of a digital signature, criminal-sentence status, sexual orientation, gender identity and expression, and sexual-relations information, folding biometric and genetic data directly into the sensitive-information definition rather than treating it as a separate track.

Art. 9, read in extract, confirms this status carries elevated protection and prohibits collection, processing, or use except under the Act's general lawful-basis articles (Arts. 6-7, not independently read here), a health worker's legal duty, or evidence required by law in response to a legal claim; the extraction was cut off after this third ground.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.