Skip to the content
Global Data RulesData governance rules, country by country

Mongolia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Waking up

Mongolia is not an open country for data. As a rule you may not send personal data abroad at all unless the person agrees or a law says you can. On top of that, a 2023 ministry order says that any server handling sensitive data must sit in Mongolia and must be reachable only from inside Mongolia. Sensitive data is defined very widely and includes health records and the content of messages.

Eight questions about Mongolia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Mongolia's rules apply to my company?

Probably not, if you have no presence in Mongolia at all. The privacy law says it governs how people, companies and unincorporated bodies collect, process and use personal data, but it does not say it reaches organisations outside the country. There is no revenue or size threshold, and there is no duty to appoint a local representative. In practice the rules bite through your Mongolian company, your Mongolian server, or your Mongolian licence rather than through long-arm reach.

Medium confidenceNational rulesAll industries

Can I store my users' data outside Mongolia?

Only sometimes, and for a lot of data the answer is a flat no. The general rule is that sending personal data to a person, company or international body abroad is banned unless a law or a treaty allows it, or the person the data is about has agreed. Then a separate ministry order takes health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages out of reach entirely: the server has to be in Mongolia and has to be reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.

High confidenceDepends on your industryApproval each timeExplicit consentKeep the data in the country

What do I need in place before data leaves Mongolia?

There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round: the transfer is banned, and the only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light-touch tick box. You must name every recipient before you collect the data, you must be able to prove the consent, and the person can withdraw it at any time.

High confidenceApproval each timeExplicit consentGet consentPut a transfer safeguard in place

Who enforces the rules in Mongolia, and what can they do?

Nobody owns privacy on its own. The law splits the job three ways: the National Human Rights Commission handles complaints and supervision, the Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports, and other state bodies police their own sectors. The ministry is clearly working: it has issued binding orders and it keeps a live register of 49 licensed information security auditors. What we could not find is any published privacy fine or decision, so treat the privacy side as switched on but not yet biting.

Medium confidenceWaking upRegulator

How long do I have to keep the data?

Mongolia is unusual: the privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds, and deleting it on any other ground is forbidden. Pulling the other way, payment businesses must keep their records for at least 15 years, anyone handling sensitive data must keep a history log of every change, deletion and restoration, and organisations running shared information systems must keep activity logs for a period fixed by government rules.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsKeep records of processing

What happens if there is a breach?

There are three clocks and none of them is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them, you tell the ministry immediately if your system's security failed or you were attacked, and if you run critical national infrastructure you tell the national response centre immediately as well. Once a year, every January, you also send the human rights commission a register of the incidents you had and what you did about them.

High confidenceTell affected peopleReport breaches to the regulatorReport cyber incidentsKeep records of processing

What trips people up in Mongolia?

Five things catch people out. First, fingerprint scanners at work are illegal for private employers: an employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that biometric data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages, which drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive, but a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia you need a telecoms licence.

High confidenceBiometric dataEmployee dataCriminal liabilityFixed maximum fineRegister or notify

What is changing soon in Mongolia?

One big thing is in motion. The government decided on 13 May 2026 to build a legal framework for putting data into economic circulation and reuse, and to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation at all: the minister can rewrite the server and storage rules by a simple order, without parliament and without consultation.

Medium confidenceProposedDraft law

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules2 rules

Хүний хувийн мэдээлэл хамгаалах тухай хууль

Act of parliament · Law on Protection of Personal Information, 17 December 2021, article 14

In forceYes, with paperwork

Personal data may not be sent to anyone abroad unless a law or treaty allows it or the person has consented in writing. There is no approved-country list, no standard contract and no government approval route.

In force since 1 May 2022

Enforced by National Human Rights Commission of Mongolia

Transfer model: Approval each time · Accepted routes: Explicit consent

High confidence

Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл

Act of parliament · Law on Protection of Personal Information, articles 10 and 31

In forceNo — it stays put

Only five named state bodies may collect fingerprints or genetic data, and only for five named purposes. A private employer may use other biometrics with the worker's consent for identity checks, but never fingerprints, and may not pass that data to anyone else. Fingerprints collected before 1 May 2022 had to be destroyed.

In force since 1 May 2022

Enforced by National Human Rights Commission of Mongolia

Transfer model: Not allowed

High confidence

Industry rules6 rules

Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам

Government rules · Minister of Digital Development and Communications order A/90 of 11 September 2023, clause 3.2 · Health and social care

In forceNo — it stays put

Any organisation that handles sensitive, genetic or biometric personal data must keep the server that processes it inside Mongolia, and that server must be reachable only from Mongolia. Consent does not get you out of this. Sensitive data is defined widely and covers health records, criminal records, biometrics and the content of letters, e-mail and messages.

In force since 11 September 2023

Enforced by Ministry of Digital Development, Innovation and Communications

Transfer model: Not allowed

High confidence

Нийтийн мэдээллийн ил тод байдлын тухай хууль

Act of parliament · Law on Public Information Transparency, 17 December 2021, articles 18.12, 27.7 and 33.2 · Government

In forceNo — it stays put

Government bodies, state-owned and state-part-owned companies, anyone carrying out a state function under a law or a contract, the public broadcaster and political parties must keep the core state data exchange system and all foundational and sectoral public databases inside Mongolia, held at the National Data Centre.

In force since 1 May 2022

Enforced by Ministry of Digital Development, Innovation and Communications

Transfer model: Not allowed

High confidence

Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл

Act of parliament · Law on Public Information Transparency, articles 27.3 and 27.7, read with the Law on Geodesy and Cartography article 9 and the General Law on State Registration articles 6 to 8 · Mapping and location

In forceNo — it stays put

Mongolia's national mapping database and its civil, property and company registration databases are named as foundational databases, so by law they must be located inside the country. If your product depends on a live feed from any of them, the source cannot be mirrored abroad.

In force since 1 May 2022

Enforced by Ministry of Digital Development, Innovation and Communications

Transfer model: Not allowed

High confidence

Who you would hear from

  • Монгол Улсын Хүний эрхийн Үндэсний Комисс

    Supervision of the personal data law, complaints, recommendations, review of impact assessments, annual receipt of controllers' breach registers

    A long-standing, staffed national human rights institution, and the personal data law requires one named Commission member to carry the data protection portfolio. We could not retrieve any content from its website, which is a JavaScript application, and we found no published data protection decision, fine or recommendation. Treat its privacy enforcement as untested rather than absent.

  • Цахим хөгжил, инновац, харилцаа холбооны яам

    Technical rules for personal data security and storage technology, registration of public databases, receipt of cyber incident notifications, licensing of information security auditors, host of the Public Cyber Attack Response Centre and the National Data Centre

    Demonstrably active: issued order A/90 in 2023 setting the server-in-Mongolia rule, the joint risk assessment methodology A/30 and A/148 in 2024, and a joint health software order with the Ministry of Health in April 2025. Maintains a live register of 49 licensed information security auditors with permissions running to 2029.

  • Харилцаа холбооны зохицуулах хороо

    Licensing of telecoms and information network services, including data storage infrastructure and content delivery networks; sector procedures

    Publishes a maintained body of numbered procedures and an online licensing portal; most recent listed procedure dated 16 December 2024. We found no data residency requirement in its published procedures.

  • Монголбанк

    Licensing and supervision of payment systems, payment service providers and credit information; payment record retention

    Fully operational central bank with a published licensing regime under the Law on the National Payment System. We did not review every one of its internal regulations, so a payments residency condition sitting inside a Bank of Mongolia procedure cannot be ruled out.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • How broadly the Ministry actually reads order A/90's server rule, given that 'sensitive data' includes the content of letters, e-mail and messages

    Taken literally, clause 3.2 would put an ordinary hosted company mailbox inside a server-in-Mongolia obligation. We found no published guidance narrowing it and no enforcement action testing it. The text is verified; the practice is not.

  • Whether the National Human Rights Commission has issued any data protection decision, recommendation or demand since 1 May 2022

    The Commission's website is a JavaScript application; neither its pages nor its backend interface could be retrieved, and its report archive returned an error. We can evidence its legal powers but not its casework.

  • The exact log retention period for information system activity logs under the Law on Cyber Security

    Articles 17.1.3 and 19.2.9 delegate the period to the general cyber security procedure approved by the Government. We could not locate that resolution's text.

  • Whether any Bank of Mongolia or Financial Regulatory Commission regulation imposes a banking, insurance or securities data residency rule

    The statutes contain none, but we reviewed only the statutes and the regulators' index pages, not every internal procedure. Rated 'no rule found, checked 18 August 2026', not 'no rule exists'.

  • The content and status of the joint order A/130 and A/58 of 16 April 2025 on health service software

    The Ministry's legal framework page lists it, but the linked PDF on the Ministry's own server redirects to itself and cannot be downloaded. It may add further health-sector storage or integration requirements.

  • The contents, bill number and consultation deadline of the draft Data Law

    The Ministry's home page carries the consultation notice and the Government meeting minute of 13 May 2026, but the linked detail page returns a 404 error and no draft text is published on the site.

  • Reports that the UN Special Rapporteur on the right to privacy criticised Mongolia's fragmented supervision in February 2026 and recommended a dedicated independent data protection authority

    Reported by a professional source. We could not reach the United Nations document itself, and there is no Mongolian government publication of it. Treated as indicative only.

  • Whether the Law on Protection of Personal Information reaches a foreign company with no establishment or server in Mongolia

    Article 3 is silent on territory. There is no case law, no regulator guidance and no local representative duty, so the honest answer is that the question has not been resolved in Mongolia.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.