Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
MongoliaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- Mongolia is not an open country for data. As a rule you may not send personal data abroad at all unless the person agrees or a law says you can. On top of that, a 2023 ministry order says that any server handling sensitive data must sit in Mongolia and must be reachable only from inside Mongolia. Sensitive data is defined very widely and includes health records and the content of messages.
- The catch
- Do not read 'depends on your industry' as 'open in general'. The baseline is already a ban with a consent exception. The hard walls are drawn by data type as much as by industry: health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages all fall inside the server-in-Mongolia rule, whatever business you are in. Government bodies, state-owned and state-part-owned companies, and any company running a government service under a law or contract face a second wall over their databases.
- Does this apply to me?
- Probably not, if you have no presence in Mongolia at all. The privacy law says it governs how people, companies and unincorporated bodies collect, process and use personal data, but it does not say it reaches organisations outside the country. There is no revenue or size threshold, and there is no duty to appoint a local representative. In practice the rules bite through your Mongolian company, your Mongolian server, or your Mongolian licence rather than through long-arm reach.Medium confidence
- Can the data leave the country?
- Only sometimes, and for a lot of data the answer is a flat no. The general rule is that sending personal data to a person, company or international body abroad is banned unless a law or a treaty allows it, or the person the data is about has agreed. Then a separate ministry order takes health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages out of reach entirely: the server has to be in Mongolia and has to be reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.High confidence
- What do I have to do to send it abroad?
- There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round: the transfer is banned, and the only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light-touch tick box. You must name every recipient before you collect the data, you must be able to prove the consent, and the person can withdraw it at any time.High confidence
- Who enforces this — and are they actually working?
- Nobody owns privacy on its own. The law splits the job three ways: the National Human Rights Commission handles complaints and supervision, the Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports, and other state bodies police their own sectors. The ministry is clearly working: it has issued binding orders and it keeps a live register of 49 licensed information security auditors. What we could not find is any published privacy fine or decision, so treat the privacy side as switched on but not yet biting.Medium confidence
- How long must I keep it, and when must I delete it?
- Mongolia is unusual: the privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds, and deleting it on any other ground is forbidden. Pulling the other way, payment businesses must keep their records for at least 15 years, anyone handling sensitive data must keep a history log of every change, deletion and restoration, and organisations running shared information systems must keep activity logs for a period fixed by government rules.High confidence
- What happens when something goes wrong?
- There are three clocks and none of them is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them, you tell the ministry immediately if your system's security failed or you were attacked, and if you run critical national infrastructure you tell the national response centre immediately as well. Once a year, every January, you also send the human rights commission a register of the incidents you had and what you did about them.High confidence
- What's the trap?
- Five things catch people out. First, fingerprint scanners at work are illegal for private employers: an employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that biometric data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages, which drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive, but a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia you need a telecoms licence.High confidence
- What's about to change?
- One big thing is in motion. The government decided on 13 May 2026 to build a legal framework for putting data into economic circulation and reuse, and to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation at all: the minister can rewrite the server and storage rules by a simple order, without parliament and without consultation.Medium confidence
- Hardest industry wall
- Health and social care — Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам
- Government — Нийтийн мэдээллийн ил тод байдлын тухай хууль
- Mapping and location — Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл
- All industries — Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл
United Arab EmiratesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
- In one paragraph
- The national privacy law has been in force since January 2022, but the rules that make it work were never written, so almost none of it can be enforced. Meanwhile the industries that matter have hard walls: health records, payment data, insurance data and identity-check reports must stay inside the country. Two financial districts run their own separate privacy systems, and those regulators do issue penalties.
- The catch
- The relaxed national picture is false the moment you touch health, payments, insurance, credit and identity checks, or government data. The national law expressly does not cover health data, banking data, government data, or companies inside the financial free zones. For most regulated businesses the national law is not the rule that binds them.
- Does this apply to me?
- Yes. The national privacy law reaches a company with no office in the country, as long as it handles the personal data of people inside the country. There is no revenue or headcount threshold to hide under. But the law carves out huge areas: government bodies, government data, health data, banking and credit data, and companies inside the financial free zones that have their own privacy laws.High confidence
- Can the data leave the country?
- It depends entirely on your industry. Under the national law data can leave once you have the right paperwork, and in practice nobody is checking. But four industries have real walls. Health records may not be stored or sent abroad at all. Payment data must be stored inside the country. Insurance data must be stored inside the country. And since April 2026 the national identity-check report may not be taken out of the country at all.High confidence
- What do I have to do to send it abroad?
- On paper the model is an approved-destinations list. The regulator is supposed to name countries whose protection is good enough, and no list has ever been published. So in practice everyone uses the fallback route: a contract with the recipient promising equivalent protection, or the person's explicit consent, or a narrow necessity exception. No government permission is needed and no filing is made, because the rules that would create those steps were never written.High confidence
- Who enforces this — and are they actually working?
- On paper the UAE Data Office. In practice it has never enforced anything: it has no public website, it has published no approved-destinations list, and the government decision that would set the fines has not been made. The regulators that really bite are elsewhere — the central bank fined a foreign bank branch about 5.4 million dollars in June 2026, and the data protection commissioner in the Abu Dhabi financial district has issued published penalty notices.Medium confidence
- How long must I keep it, and when must I delete it?
- The floors are long and they are set by industry, not by the privacy law. Health records must be kept for at least 25 years after the last treatment. Payment data must be kept for 5 years with a separate backup. Identity-check reports must be kept for at least 5 years. There is no working national deletion deadline, because the detailed rules that would set one were never issued.High confidence
- What happens when something goes wrong?
- There is no national deadline in hours today. The privacy law says you must tell the regulator as soon as you discover a breach, and leaves the actual timing and the wording of the notice to detailed rules that were never issued. So the clocks that really run are the ones set by your own regulator: the central bank for financial firms, and the separate data protection offices in the two financial districts. The national cyber incident reporting service is aimed at government bodies, not at private companies.Medium confidence
- What's the trap?
- Five things that cost people their weekend. One: the national privacy law does not cover health data, banking data, government data, or companies in the financial free zones, so most regulated firms are not governed by it at all. Two: health data may not leave the country, ever, and the fine is up to about 190 thousand dollars. Three: since April 2026 the national identity-check report may not be sent abroad. Four: a child is anyone under 18, but the parental consent line is drawn at 13. Five: there are two extra legal systems inside the country, and their regulators actually issue penalties.High confidence
- What's about to change?
- The single biggest thing is a rule that could appear on any Tuesday. When the government finally publishes the detailed rules under the privacy law, every company gets six months to comply and the law switches from decorative to real. Nothing signals when that will happen. In the meantime the new child safety law needs its penalty schedule, and the national identity-check platform is being rolled out across banks.Medium confidence
- Hardest industry wall
- Health and social care — Federal Law No. (2) of 2019 Concerning the Use of the Information and Communications Technology in Health Fields
- Payments — Retail Payment Services and Card Schemes Regulation
- Insurance — Insurance Authority Board of Directors' Resolution No. (18) of 2020 Concerning the Electronic Insurance Regulations
- Banking — Cabinet Resolution No. (55) of 2026 Promulgating the Executive Regulations of Federal Decree-Law No. (30) of 2024 Regarding the "Know Your Customer" Digital Platform