Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
MongoliaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
In one paragraph
Mongolia is not an open country for data. As a rule you may not send personal data abroad at all unless the person agrees or a law says you can. On top of that, a 2023 ministry order says that any server handling sensitive data must sit in Mongolia and must be reachable only from inside Mongolia. Sensitive data is defined very widely and includes health records and the content of messages.
The catch
Do not read 'depends on your industry' as 'open in general'. The baseline is already a ban with a consent exception. The hard walls are drawn by data type as much as by industry: health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages all fall inside the server-in-Mongolia rule, whatever business you are in. Government bodies, state-owned and state-part-owned companies, and any company running a government service under a law or contract face a second wall over their databases.
Does this apply to me?
Probably not, if you have no presence in Mongolia at all. The privacy law says it governs how people, companies and unincorporated bodies collect, process and use personal data, but it does not say it reaches organisations outside the country. There is no revenue or size threshold, and there is no duty to appoint a local representative. In practice the rules bite through your Mongolian company, your Mongolian server, or your Mongolian licence rather than through long-arm reach.Medium confidence
Can the data leave the country?
Only sometimes, and for a lot of data the answer is a flat no. The general rule is that sending personal data to a person, company or international body abroad is banned unless a law or a treaty allows it, or the person the data is about has agreed. Then a separate ministry order takes health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages out of reach entirely: the server has to be in Mongolia and has to be reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.High confidence
What do I have to do to send it abroad?
There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round: the transfer is banned, and the only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light-touch tick box. You must name every recipient before you collect the data, you must be able to prove the consent, and the person can withdraw it at any time.High confidence
Who enforces this — and are they actually working?
Nobody owns privacy on its own. The law splits the job three ways: the National Human Rights Commission handles complaints and supervision, the Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports, and other state bodies police their own sectors. The ministry is clearly working: it has issued binding orders and it keeps a live register of 49 licensed information security auditors. What we could not find is any published privacy fine or decision, so treat the privacy side as switched on but not yet biting.Medium confidence
How long must I keep it, and when must I delete it?
Mongolia is unusual: the privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds, and deleting it on any other ground is forbidden. Pulling the other way, payment businesses must keep their records for at least 15 years, anyone handling sensitive data must keep a history log of every change, deletion and restoration, and organisations running shared information systems must keep activity logs for a period fixed by government rules.High confidence
What happens when something goes wrong?
There are three clocks and none of them is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them, you tell the ministry immediately if your system's security failed or you were attacked, and if you run critical national infrastructure you tell the national response centre immediately as well. Once a year, every January, you also send the human rights commission a register of the incidents you had and what you did about them.High confidence
What's the trap?
Five things catch people out. First, fingerprint scanners at work are illegal for private employers: an employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that biometric data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages, which drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive, but a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia you need a telecoms licence.High confidence
What's about to change?
One big thing is in motion. The government decided on 13 May 2026 to build a legal framework for putting data into economic circulation and reuse, and to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation at all: the minister can rewrite the server and storage rules by a simple order, without parliament and without consultation.Medium confidence
Hardest industry wall
  • Health and social care Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам
  • Government Нийтийн мэдээллийн ил тод байдлын тухай хууль
  • Mapping and location Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл
  • All industries Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл
ArgentinaChecked 18 August 2026
Yes, with paperworkWork: MediumEnforcement: Active
In one paragraph
Argentina lets personal data leave the country, but only on paper terms it sets. You either send it to a country the regulator has approved, or you sign the regulator's own model contract with the receiver. No industry has to keep data inside Argentina. Fines are tiny in dollars, but the regulator can order a database shut down, and some misuse is a crime.
The catch
There is no data-residency wall in Argentina, but four sector rules still catch people out. Banks and payment firms must run their technology and security management from inside Argentina, must tell the banking supervisor before they outsource, and must report a cyber incident within one hour. Government bodies must have a working backup data centre by late 2026. And nobody may publish a map showing Argentine territory without the national mapping agency's prior approval.
Does this apply to me?
The main privacy law is Ley 25.326, passed in 2000. It covers personal data held in any file or database in Argentina, public or private. There is no size threshold, no revenue threshold, and no duty to appoint a local representative. The law does not clearly say it reaches a foreign company with no presence in Argentina, and in practice the regulator has acted against local subsidiaries of global firms rather than against foreign entities directly.High confidence
Can the data leave the country?
Yes, with paperwork. The rule is that personal data may not go to a country that does not protect it well enough. The regulator publishes a list of countries it accepts, and for everywhere else you sign its model contract with the receiver. We looked for industries that must keep data inside Argentina - banking, payments, insurance, securities, health, telecoms, government cloud and mapping - and found none as of 18 August 2026.High confidence
What do I have to do to send it abroad?
The model is an approved-destinations list, and it is populated today with about a dozen places, including the whole European Union. If your destination is not on it, use the regulator's published model contract - two versions, one for handing data to another company that decides how to use it and one for a supplier processing it for you. Using the published wording needs no permission. If you change the wording, you must file the contract with the regulator within 30 days of signing.High confidence
Who enforces this — and are they actually working?
The Agency for Access to Public Information, known by its Spanish initials AAIP, enforces both privacy and freedom of information. It is real and working: it has a named head, it publishes a register of final penalties that was updated on 3 July 2026, it opened a public investigation into debt-collection calls in April 2026, and it chaired an international data-protection committee in July 2026. Its 244 final penalties are mostly small, and more than half are for calling people on the do-not-call list.High confidence
How long must I keep it, and when must I delete it?
Argentina has strong floors and one hard ceiling. Anti-money-laundering rules make banks, insurers, crypto firms, accountants and estate agents keep transaction records and customer files for at least ten years. Clinical records must be kept ten years from the last entry. Banks must keep audit and accounting support data six years and produce it immediately on demand. The ceiling: credit-reporting data may only show the last five years, dropping to two years once the debt is paid.High confidence
What happens when something goes wrong?
There is no general duty to report a data breach in Argentina, checked on 18 August 2026 - the privacy law has no deadline and the regulator's security rules are recommendations, not commands. Finance is the exception and the clock is brutal: banks and registered payment firms must tell the banking supervisor within one hour of an incident happening or being spotted, keep sending updates, and file a closing report within five days.High confidence
What's the trap?
Five things bite people. Answer times are very short: ten days for an access request and five working days to correct or delete. The maximum fine is one hundred thousand pesos, about seventy US dollars, so the real risk is a shutdown order or a criminal case, not the fine. Databases still have to be registered. Publishing a map of Argentina needs government approval first. And a bank cannot run its technology and security management from abroad.High confidence
What's about to change?
Nothing is scheduled to replace the privacy law. A reform bill went to Congress in 2023 and never became law; the regulator is still campaigning for a new one. The dated thing to watch is government cybersecurity: public bodies have about 180 days from 13 May 2026 to have contingency plans and a working alternative data centre, which lands around November 2026, and a new national cybersecurity centre started issuing rules in 2026.Medium confidence
Hardest industry wall
None found.