Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
MongoliaChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
In one paragraph
Mongolia is not an open country for data. As a rule you may not send personal data abroad at all unless the person agrees or a law says you can. On top of that, a 2023 ministry order says that any server handling sensitive data must sit in Mongolia and must be reachable only from inside Mongolia. Sensitive data is defined very widely and includes health records and the content of messages.
The catch
Do not read 'depends on your industry' as 'open in general'. The baseline is already a ban with a consent exception. The hard walls are drawn by data type as much as by industry: health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages all fall inside the server-in-Mongolia rule, whatever business you are in. Government bodies, state-owned and state-part-owned companies, and any company running a government service under a law or contract face a second wall over their databases.
Does this apply to me?
Probably not, if you have no presence in Mongolia at all. The privacy law says it governs how people, companies and unincorporated bodies collect, process and use personal data, but it does not say it reaches organisations outside the country. There is no revenue or size threshold, and there is no duty to appoint a local representative. In practice the rules bite through your Mongolian company, your Mongolian server, or your Mongolian licence rather than through long-arm reach.Medium confidence
Can the data leave the country?
Only sometimes, and for a lot of data the answer is a flat no. The general rule is that sending personal data to a person, company or international body abroad is banned unless a law or a treaty allows it, or the person the data is about has agreed. Then a separate ministry order takes health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages out of reach entirely: the server has to be in Mongolia and has to be reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.High confidence
What do I have to do to send it abroad?
There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round: the transfer is banned, and the only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light-touch tick box. You must name every recipient before you collect the data, you must be able to prove the consent, and the person can withdraw it at any time.High confidence
Who enforces this — and are they actually working?
Nobody owns privacy on its own. The law splits the job three ways: the National Human Rights Commission handles complaints and supervision, the Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports, and other state bodies police their own sectors. The ministry is clearly working: it has issued binding orders and it keeps a live register of 49 licensed information security auditors. What we could not find is any published privacy fine or decision, so treat the privacy side as switched on but not yet biting.Medium confidence
How long must I keep it, and when must I delete it?
Mongolia is unusual: the privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds, and deleting it on any other ground is forbidden. Pulling the other way, payment businesses must keep their records for at least 15 years, anyone handling sensitive data must keep a history log of every change, deletion and restoration, and organisations running shared information systems must keep activity logs for a period fixed by government rules.High confidence
What happens when something goes wrong?
There are three clocks and none of them is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them, you tell the ministry immediately if your system's security failed or you were attacked, and if you run critical national infrastructure you tell the national response centre immediately as well. Once a year, every January, you also send the human rights commission a register of the incidents you had and what you did about them.High confidence
What's the trap?
Five things catch people out. First, fingerprint scanners at work are illegal for private employers: an employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that biometric data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages, which drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive, but a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia you need a telecoms licence.High confidence
What's about to change?
One big thing is in motion. The government decided on 13 May 2026 to build a legal framework for putting data into economic circulation and reuse, and to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation at all: the minister can rewrite the server and storage rules by a simple order, without parliament and without consultation.Medium confidence
Hardest industry wall
  • Health and social care Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам
  • Government Нийтийн мэдээллийн ил тод байдлын тухай хууль
  • Mapping and location Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл
  • All industries Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл
United StatesChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Active
In one paragraph
In general the United States lets data go anywhere. There is no national privacy law and no permit is needed to move data abroad. Two things bite hard. Six countries are effectively off limits for large amounts of sensitive data, with prison sentences attached. And anything connected to government work must physically stay on American soil.
The catch
The open headline stops the moment you touch one of six areas: government contracting, police records, federal tax records, defence technical data, telecom licences, and bulk sensitive data flowing to China, Russia, Iran, North Korea, Cuba or Venezuela. Also note that the rule that actually binds you is almost always a state law or an industry regulator's rule, not a national privacy act. There isn't one.
Does this apply to me?
Yes. American rules reach a foreign company with no office in the country. California's privacy law applies to any for-profit business that 'does business in California' and crosses one of three thresholds, and physical presence is not one of them. The children's rule covers foreign websites aimed at American children. No state and no federal law requires you to appoint a local representative — a real difference from Europe.High confidence
Can the data leave the country?
It depends entirely on your industry, so the single national answer is misleading. For ordinary consumer or employee data, yes — send it anywhere, no paperwork. But six sectors have hard walls. Government contracting, police data, federal tax data and defence work require the data to physically stay in the United States. Telecom licences restrict which foreign staff may even look at records. And for anyone, sending large volumes of sensitive data to six named countries is now a crime.High confidence
What do I have to do to send it abroad?
For ordinary data, nothing. No standard contract, no government approval, no destination approval list. The model is a blocklist and it is now populated: six countries are named. Before you move large volumes of sensitive data, your only real job is to work out whether a country of concern, or a company or person they control, could end up with access — including through a vendor, an investor or an employee.High confidence
Who enforces this — and are they actually working?
Nobody, and everybody. There is no national privacy regulator. Instead the consumer protection regulator, the health department, the securities regulator, the communications regulator, the Justice Department, all fifty state attorneys general and one dedicated state privacy agency each enforce a slice. Almost all of them are visibly working right now. The one exception is the new national data transfer programme: it is staffed and issuing guidance but has published no enforcement action yet.High confidence
How long must I keep it, and when must I delete it?
There is a strong floor and a weak but growing ceiling. Investment firms must keep some books for six years and most others for three, with the first two years easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now force you to publish how long you keep each type of data and to stop keeping it longer than you said, and since April 2026 children's data may no longer be kept indefinitely. Where a keep-it rule and a delete-it rule collide, the keep-it rule wins: every state law carves out data you are required by law to retain.High confidence
What happens when something goes wrong?
Count the clocks — there are at least seven, and they disagree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator, and you may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to disclose a material incident. The overlap, not any single deadline, is what people fail.High confidence
What's the trap?
Five that cost people their weekend. One: the national data transfer programme carries prison — up to twenty years for a deliberate breach. Two: Illinois lets individuals sue over fingerprints and face scans with fixed damages per person, no proof of harm needed, and that is where the largest privacy payouts happen. Three: the children's rule uses under 13, but several state laws use under 18, so a single age gate will not do. Four: government work means American soil, and police data allows only the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still be unenforceable, because a court has blocked it.High confidence
What's about to change?
Four things in the next twelve months. The national critical infrastructure reporting rule should be finalised in late 2026, which will switch on a 72-hour incident clock and a 24-hour ransom-payment clock for a very wide range of businesses. California's rules on automated decision-making bite on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a federal privacy bill is moving in Congress, but it is only a bill and binds nobody.High confidence
Hardest industry wall
  • Government Criminal Justice Information Services (CJIS) Security Policy
  • Government Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies
  • Defence Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services
  • Telecoms National security agreement / letter of assurance conditioning a section 214 authorisation, reviewed by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector