Skip to the content
Global Data RulesData governance rules, country by country

Mongolia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Mongolia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

You mostly cannot send personal data out of Mongolia. The rule is a ban, with two ways out. Either the person agrees, or a law says you can. On top of that, a 2023 ministry order covers sensitive data. Any server handling it must sit in Mongolia, and must be reachable only from inside Mongolia. Sensitive data is defined very widely. It includes health records and the content of messages.

Data governance in Mongolia

The eight things that decide how you handle data about people in Mongolia. Same eight on every country page, so you can compare.

Who has to follow these rules

Probably not, if you have no presence in Mongolia at all. The privacy law covers how people, companies and unincorporated bodies collect, handle and use personal data. It does not say it reaches organisations outside the country. There is no revenue or size cut-off, and no duty to appoint a local representative. The rules usually reach you through your Mongolian company, your Mongolian server or your Mongolian licence, not through long-arm reach.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Only sometimes, and for a lot of data the answer is a flat no. The general rule bans sending personal data to a person, company or international body abroad. There are two ways out. A law or a treaty allows it, or the person the data is about has agreed. A separate ministry order then puts some data out of reach entirely. That covers health data, biometrics, genetic data, criminal records, digital signature keys, and the content of letters, e-mail and messages. For those, the server has to be in Mongolia and reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.

What you have to do here:
Keep the data in the country
Ways to send data out:
Explicit consent

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round. The transfer is banned. The only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light tick box. You must name every recipient before you collect the data. You must be able to prove the consent. And the person can withdraw it at any time.

What you have to do here:
Get consent · Put a transfer safeguard in place
Ways to send data out:
Explicit consent

The regulator, and whether it actually acts

Nobody owns privacy on its own. The law splits the job three ways. The National Human Rights Commission handles complaints and supervision. The Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports. Other state bodies police their own industries. The ministry is clearly working. It has issued binding orders and keeps a live register of 49 licensed information security auditors. We could not find any published privacy fine or decision. So treat the privacy side as switched on but not yet enforced.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

Mongolia is unusual. The privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds. Deleting it on any other ground is forbidden. Pulling the other way, there are minimums. Payment businesses must keep their records for at least 15 years. Anyone handling sensitive data must keep a history log of every change, deletion and restoration. Organisations running shared information systems must keep activity logs for a period fixed by government rules.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are three deadlines, and none is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them. You tell the ministry immediately if your system's security failed or you were attacked. If you run critical national infrastructure, you tell the national response centre immediately too. Once a year, every January, you also send the human rights commission a register of your incidents and what you did about them.

What you have to do here:
Tell affected people · Report breaches to the regulator · Report cyber incidents · Keep records of how you use data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. First, fingerprint scanners at work are illegal for private employers. An employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages. That drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive. But a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia, you need a telecoms licence.

What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

One big thing is in motion. On 13 May 2026 the government decided to build the legal rules for putting data into economic circulation and reuse. It also decided to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation. The minister can rewrite the server and storage rules with a simple order, without parliament and without consultation.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health and social care data must stay in the country

Official name: Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам · Minister of Digital Development and Communications order A/90 of 11 September 2023, clause 3.2 · Government rules

In forceNo — it stays put

Any organisation that handles sensitive, genetic or biometric personal data must keep the server inside Mongolia. That server must be reachable only from Mongolia. Consent does not get you out of this. Sensitive data is defined widely. It covers health records, criminal records, biometrics and the content of letters, e-mail and messages.

In force since 11 September 2023

Enforced by Ministry of Digital Development, Innovation and Communications

How this country controls where data goes: Not allowed

Government

Government data must stay in the country

Official name: Нийтийн мэдээллийн ил тод байдлын тухай хууль · Law on Public Information Transparency, 17 December 2021, articles 18.12, 27.7 and 33.2 · Act of parliament

In forceNo — it stays put

One rule covers government bodies, state-owned and part-state-owned companies, the public broadcaster and political parties. It also covers anyone carrying out a state function under a law or a contract. The core state data exchange system, and all foundational and sector-specific public databases, must stay inside Mongolia and be held at the National Data Centre.

In force since 1 May 2022

Enforced by Ministry of Digital Development, Innovation and Communications

How this country controls where data goes: Not allowed

Mapping and location

Mapping and location data must stay in the country

Official name: Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл · Law on Public Information Transparency, articles 27.3 and 27.7, read with the Law on Geodesy and Cartography article 9 and the General Law on State Registration articles 6 to 8 · Act of parliament

In forceNo — it stays put

Mongolia's national mapping database and its civil, property and company registration databases are named as foundational databases. By law they must be located inside the country. If your product depends on a live feed from any of them, the source cannot be mirrored abroad.

In force since 1 May 2022

Enforced by Ministry of Digital Development, Innovation and Communications

How this country controls where data goes: Not allowed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Government data rules

Official name: Хүний хувийн мэдээлэл хамгаалах тухай хууль · Law on Protection of Personal Information, 17 December 2021, article 14 · Act of parliament

In forceYes, with paperwork

Personal data may not be sent to anyone abroad unless a law or treaty allows it or the person has consented in writing. There is no approved-country list, no standard contract and no government approval route.

In force since 1 May 2022

Enforced by National Human Rights Commission of Mongolia

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent

Biometric data rules

Official name: Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл · Law on Protection of Personal Information, articles 10 and 31 · Act of parliament

In forceNo — it stays put

Only five named state bodies may collect fingerprints or genetic data, and only for five named purposes. A private employer may use other biometrics with the worker's consent for identity checks. It may never use fingerprints. It may not pass that data to anyone else. Fingerprints collected before 1 May 2022 had to be destroyed.

In force since 1 May 2022

Enforced by National Human Rights Commission of Mongolia

How this country controls where data goes: Not allowed

Who you would hear from

  • Монгол Улсын Хүний эрхийн Үндэсний Комисс

    Supervision of the personal data law, complaints, recommendations, review of impact assessments, annual receipt of controllers' breach registers

    A long-standing, staffed national human rights body. The personal data law requires one named Commission member to hold the data protection portfolio. We found no published data protection decision, fine or recommendation. Treat its privacy enforcement as untested rather than absent.

  • Цахим хөгжил, инновац, харилцаа холбооны яам

    Technical rules for personal data security and storage technology, registration of public databases, receipt of cyber incident notifications, licensing of information security auditors, host of the Public Cyber Attack Response Centre and the National Data Centre

    Clearly active. It issued order A/90 in 2023, which set the server-in-Mongolia rule. It issued the joint risk assessment methodology A/30 and A/148 in 2024. It issued a joint health software order with the Ministry of Health in April 2025. It keeps a live register of 49 licensed information security auditors, with permissions running to 2029.

  • Харилцаа холбооны зохицуулах хороо

    Licensing of telecoms and information network services, including data storage infrastructure and content delivery networks; sector procedures

    It publishes a maintained set of numbered procedures and runs an online licensing portal. The most recent listed procedure is dated 16 December 2024. We found no rule in its published procedures that data must stay in the country.

  • Монголбанк

    Licensing and supervision of payment systems, payment service providers and credit information; payment record retention

    A fully working central bank, with published licensing rules under the Law on the National Payment System. We did not read every one of its internal regulations. So we cannot rule out a must-stay-in-Mongolia condition for payments hidden inside a Bank of Mongolia procedure.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • How broadly the Ministry actually reads order A/90's server rule, given that 'sensitive data' includes the content of letters, e-mail and messages

    Read literally, clause 3.2 would put an ordinary hosted company mailbox under the server-in-Mongolia rule. We found no published guidance narrowing it, and no enforcement testing it. We confirmed the text. We could not confirm how it is applied. Ask the ministry before you host company mail abroad.

  • Whether the National Human Rights Commission has issued any data protection decision, recommendation or demand since 1 May 2022

    We could not read the Commission's website or its report archive. We can show what powers it has by law. We could not confirm what cases it has handled.

  • The exact log retention period for information system activity logs under the Law on Cyber Security

    Articles 17.1.3 and 19.2.9 leave the period to the general cyber security procedure approved by the Government. We could not find the text of that resolution. Ask the ministry for it before you set your log policy.

  • Whether any Bank of Mongolia or Financial Regulatory Commission regulation imposes a banking, insurance or securities where data has to be stored rule

    The laws themselves contain no such rule. But we read only the laws and the regulators' index pages, not every internal procedure. So this is 'we found no rule, checked 18 August 2026', not 'no rule exists'. Check with your regulator.

  • The content and status of the joint order A/130 and A/58 of 16 April 2025 on health service software

    The Ministry's own page lists it, but we could not download the linked document. It may add further storage or integration requirements for health services. Ask the Ministry for a copy if you build health software here.

  • The contents, bill number and consultation deadline of the draft Data Law

    The Ministry's home page carries the consultation notice and the Government meeting minute of 13 May 2026. We could not open the linked detail page, and no draft text is published on the site.

  • Reports that the UN Special Rapporteur on the right to privacy criticised Mongolia's fragmented supervision in February 2026 and recommended a dedicated independent data protection authority

    A professional source reported this. We could not read the United Nations document itself, and the Mongolian government has not published it. Treat it as a pointer only.

  • Whether the Law on Protection of Personal Information reaches a foreign company with no establishment or server in Mongolia

    Article 3 is silent on territory. There is no case law, no regulator guidance and no local representative duty. So the honest answer is that Mongolia has not resolved the question.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.