Mongolia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Mongolia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You mostly cannot send personal data out of Mongolia. The rule is a ban, with two ways out. Either the person agrees, or a law says you can. On top of that, a 2023 ministry order covers sensitive data. Any server handling it must sit in Mongolia, and must be reachable only from inside Mongolia. Sensitive data is defined very widely. It includes health records and the content of messages.
Data governance in Mongolia
The eight things that decide how you handle data about people in Mongolia. Same eight on every country page, so you can compare.
Who has to follow these rules
Probably not, if you have no presence in Mongolia at all. The privacy law covers how people, companies and unincorporated bodies collect, handle and use personal data. It does not say it reaches organisations outside the country. There is no revenue or size cut-off, and no duty to appoint a local representative. The rules usually reach you through your Mongolian company, your Mongolian server or your Mongolian licence, not through long-arm reach.
The Law on Protection of Personal Information, article 3.1, defines who is covered by activity, not by territory and not by who you target. It covers what happens when a person, a company or an organisation without legal personality collects, handles, uses and secures personal data. Article 3.2 extends the same rules to work done with technical means and software. There is no equivalent of the European test of 'offering goods or services to people in the territory'. There is no registration duty and no representative duty anywhere in the Act. The real reach comes from three other places. Order A/90 of 2023 requires the server that handles sensitive data to be in Mongolia, which is a physical hook. The Law on Public Information Transparency binds anyone carrying out a state function under a law or a contract. And the Law on Telecommunications, article 19-1, treats data storage infrastructure and content delivery networks as licensed 'information network' activity. So building a point of presence in Mongolia needs a licence from the Communications Regulatory Commission.
Sources
- Official sourceLegal Information Unified System, Ministry of Justice and Home AffairsLaw on Protection of Personal Information, 17 December 2021, article 3 (scope)
legalinfo.mn
“3.1. This law regulates relations connected with the collection, processing, use and securing of a person's private information by a person, a legal entity, or an organisation without the rights of a legal entity.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Telecommunications, 18 October 2001, article 19-1 (information network)
legalinfo.mn
Link checked 18 August 2026
Where the data is allowed to live
Only sometimes, and for a lot of data the answer is a flat no. The general rule bans sending personal data to a person, company or international body abroad. There are two ways out. A law or a treaty allows it, or the person the data is about has agreed. A separate ministry order then puts some data out of reach entirely. That covers health data, biometrics, genetic data, criminal records, digital signature keys, and the content of letters, e-mail and messages. For those, the server has to be in Mongolia and reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.
- What you have to do here:
- Keep the data in the country
- Ways to send data out:
- Explicit consent
Three layers stack up. (1) The national base rule. Article 14.1 of the Law on Protection of Personal Information is a ban with two ways out: a legal or treaty basis, or the person's consent. Consent must be written, on paper or electronically. It must be verified electronically or against an identity document. It must list every recipient (articles 8.2.6, 8.3, 8.4, 8.11). (2) The data-type wall. Order A/90 of the Minister of Digital Development and Communications is dated 11 September 2023. Its clause 3.2 applies to every organisation handling sensitive, genetic or biometric data. The server must be in Mongolia and reachable only from Mongolia. It must sit in a purpose-built technical room. It must be able to exchange data through the state 'KHUR' exchange. It must be synchronised to the Communications Regulatory Commission's time server, protected by a certificate and backed up regularly. Article 4.1.12 of the Act treats correspondence data as sensitive. That means letters, parcels, e-mail and anything exchanged over telecommunications and information technology. So on its face A/90 reaches unusually far. (3) The public-sector wall. The rule is in Law on Public Information Transparency articles 18.12 and 27.7. The core state exchange system, and every foundational and sector-specific public database, must be located in Mongolia. Article 33.2 requires them to be held at the National Data Centre. Foundational databases include the civil registration databases and the geodesy and cartography database (article 27.3). We found no storage-location rule of their own for banking and payments, insurance and securities, telecommunications, education or online gaming. For those, the national base rule and A/90 still apply.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, article 14 (transfer to persons and organisations in a foreign state)
legalinfo.mn
“14.1. Except as provided by law or by an international treaty of Mongolia, or except where the data subject has given consent, it is prohibited to transfer information to a person, a legal entity or an international organisation in a foreign state.”
Link checked 18 August 2026
- Official sourceMinister of Digital Development and CommunicationsOrder A/90 of 11 September 2023: Technological security requirements and procedure for processing sensitive, genetic and biometric personal data, clause 3.2
legalinfo.mn
“3.2. The server processing the information shall meet the following conditions and requirements: 3.2.1. be located in the territory of Mongolia; 3.2.2. be accessible only from Mongolia.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Public Information Transparency, 17 December 2021, articles 18.12, 27.3, 27.7 and 33.2
legalinfo.mn
“27.7. Foundational and sectoral databases shall be located in the territory of Mongolia.”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round. The transfer is banned. The only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light tick box. You must name every recipient before you collect the data. You must be able to prove the consent. And the person can withdraw it at any time.
- What you have to do here:
- Get consent · Put a transfer safeguard in place
- Ways to send data out:
- Explicit consent
There is no approved-country list. There are no standard contract clauses, no company-wide rules, no certification route and no case-by-case government permission. That is true for every transfer under the Law on Protection of Personal Information. The only routes are the legal or treaty basis in article 14.1, and consent. Consent must be given in writing, on paper or electronically (article 8.3). An electronic consent is valid only if the person was identified and checked by a means set by law, or one they accepted (article 8.4). Silence or the passing of time is expressly not consent (article 8.6). You must be able to prove consent (article 8.9). You need consent again for any new purpose (article 8.10). And you need separate consent to pass data on, unless your original notice already listed the recipients (articles 8.2.6 and 8.11). Consent can be withdrawn at any time, and you must make withdrawal easy (articles 8.7 and 18.4). Note the mismatch. For sensitive data, consent gets you past article 14 but not past order A/90. That order fixes where the server may sit, whatever anyone agreed.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 8 and 14
legalinfo.mn
“8.6. Where the data subject has not replied to a request for consent to collect information, the expiry of the period set for a reply, or of a normally reasonable period, shall not be a ground for treating consent as given.”
Link checked 18 August 2026
- Official sourceMinister of Digital Development and CommunicationsOrder A/90 of 11 September 2023, clause 3.2 (server conditions)
legalinfo.mn
Link checked 18 August 2026
The regulator, and whether it actually acts
Nobody owns privacy on its own. The law splits the job three ways. The National Human Rights Commission handles complaints and supervision. The Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports. Other state bodies police their own industries. The ministry is clearly working. It has issued binding orders and keeps a live register of 49 licensed information security auditors. We could not find any published privacy fine or decision. So treat the privacy side as switched on but not yet enforced.
The Law on Protection of Personal Information, article 24, gives the National Human Rights Commission the supervisory role. It monitors compliance. It receives and investigates complaints, and can act on its own initiative. It issues demands and recommendations. It receives companies' annual incident registers every January. It reviews impact assessments. And it reports on data protection in its annual report on the state of human rights. Article 24.2 requires one named Commission member to hold this portfolio. Article 25 gives the Ministry of Digital Development, Innovation and Communications the rule-making role in the digital world. It approves technology security requirements for sensitive, genetic and biometric data. It receives and registers reports of security failures and cyber attacks. Article 26 leaves every other state body to supervise within its own remit. Fines are not in the privacy law at all. They sit in the Law on Infringements, article 6.27, and are applied by inspectors, the police and the courts. The visible evidence of activity is on the ministry's side: order A/90 in 2023, the joint risk assessment methodology A/30 and A/148 in 2024, and a register of 49 companies allowed to carry out information security audits, with permissions running from 2026 to 2029. The National Human Rights Commission is a long-standing, staffed national human rights body. But its website is a JavaScript application whose content we could not read, and we found no published data protection decision.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 24, 25 and 26 (powers of the National Human Rights Commission, the ministry and other state bodies)
legalinfo.mn
“24.2. One member of the National Human Rights Commission shall be specially responsible for the functions set out in article 24.1 of this law.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsRegister of legal entities permitted to carry out information security audits (49 entities, permissions valid 2026 to 2029)
mddic.gov.mn
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsLegal framework page listing ministerial orders A/90 (2023) and A/30 and A/148 (2024)
mddic.gov.mn
Link checked 18 August 2026
How long you must keep it — and when to delete it
Mongolia is unusual. The privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds. Deleting it on any other ground is forbidden. Pulling the other way, there are minimums. Payment businesses must keep their records for at least 15 years. Anyone handling sensitive data must keep a history log of every change, deletion and restoration. Organisations running shared information systems must keep activity logs for a period fixed by government rules.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs · Keep records of how you use data
The maximum side is article 15 of the Law on Protection of Personal Information. You delete at the person's request where you collected or used the data unlawfully. You delete where a law, a treaty or a final court judgment orders it. And you delete where the original purpose has been achieved, or the contract or agreement says so. Article 15.2 then forbids deletion on any other ground, unless another law allows it. That turns the usual 'delete when you no longer need it' instinct on its head. It makes routine clear-outs legally risky without a written ground. The minimum side is scattered. Law on the National Payment System, article 30.1: operators, participants and payment service providers must keep documents from payment system activity for at least 15 years from receipt or creation. Order A/90 clause 3.1.6: keep a historical register of every change, deletion and restoration of sensitive data. Law on Cyber Security articles 17.1.3 and 19.2.9: keep information system activity logs for the period set in the general cyber security procedure approved by the Government. We could not confirm that period. One oddity worth knowing. Article 13.2 of the privacy law allows sensitive data about a dead person to be used without consent once 70 years have passed since death.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 13.2, 15 and 18.2.12
legalinfo.mn
“15.2. Unless otherwise provided by law, it is prohibited to delete information on grounds other than those set out in article 15.1 of this law.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on the National Payment System, article 30.1 (15-year document retention)
legalinfo.mn
“30.1. An operator, participant, payment service provider or person entitled to carry out activities related to the provision of payment services shall keep documents created in the course of payment system activity for not less than 15 years from the date of receipt or creation.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Cyber Security, articles 17.1.3 and 19.2.9 (activity log retention)
legalinfo.mn
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are three deadlines, and none is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them. You tell the ministry immediately if your system's security failed or you were attacked. If you run critical national infrastructure, you tell the national response centre immediately too. Once a year, every January, you also send the human rights commission a register of your incidents and what you did about them.
- What you have to do here:
- Tell affected people · Report breaches to the regulator · Report cyber incidents · Keep records of how you use data
DEADLINE ONE, to the person. The duty is in article 22.2 of the Law on Protection of Personal Information. Tell the person immediately where a breach may harm their rights or lawful interests. Article 22.3 sets out what the notice must say: who and what was affected, your name and contact details, the possible consequences, and the steps you took to fix it. A supplier who spots the breach must tell you immediately (article 22.1). DEADLINE TWO, to the ministry. Article 25.1.3 makes the ministry receive and register reports of security failures and cyber attacks on information systems used for personal data. The ministry must act immediately. DEADLINE THREE, to the cyber response centres. Law on Cyber Security article 17.1.2 covers information technology service providers. They must report a cyber attack to the relevant response centre immediately. If they cannot stop it, they must ask for help. Article 17.1.9 makes them tell affected users immediately. Article 19.2.14 makes critical information infrastructure organisations report immediately once normal operation is lost. Article 4.1.3 of the privacy law defines 'immediately' as the shortest possible period. So there is no set number of hours to plan against. The annual filing is article 22.6. The register of breaches and your responses goes to the National Human Rights Commission every January, and on demand at any time. There are two centres to choose between. The National Centre sits inside the intelligence agency and covers state-owned critical infrastructure and bodies on the unified state network. The Public Centre sits under the ministry and covers everyone else.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 4.1.3, 22 and 25.1.3
legalinfo.mn
“22.2. Where a breach under article 22.1 of this law may cause harm to the rights and lawful interests of the data subject, the controller shall notify the data subject immediately.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Cyber Security, articles 17.1.2, 17.1.9, 19.2.14, 20, 21 and 22 (response centres)
legalinfo.mn
“21.1. The National Centre shall operate within the structure of the intelligence organisation.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. First, fingerprint scanners at work are illegal for private employers. An employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages. That drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive. But a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia, you need a telecoms licence.
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
(1) Article 10.1 of the Law on Protection of Personal Information covers fingerprints and genetic data. Only five named state bodies may collect them, and only for five named purposes. Article 10.2 lets an employer use biometric data other than fingerprints, with the employee's consent, to make identity checks easier under its internal labour rules. Article 10.3 then forbids the employer from changing that data or passing it to anyone else. That rules out an offshore biometric access control supplier. Article 31.1 required fingerprints collected before the law started to be destroyed. (2) Article 4.1.12 lists correspondence among sensitive data. Article 4.1.4 defines correspondence data as letters, parcels, e-mail and anything exchanged using telecommunications or information technology. Read literally with clause 3.2 of order A/90, that puts an ordinary hosted mailbox under a server-in-Mongolia duty. We found no guidance narrowing this and no enforcement testing it. (3) Property, education, membership and digital identifiers are ordinary personal data under article 4.1.11. Health, correspondence, genetic and biometric data, digital signature private keys, criminal record, sexual orientation, gender identity and sexual life are sensitive under article 4.1.12. Money is not on the sensitive list. Biometric log-in is. (4) Article 30.2 says people and companies that break the law are liable under the Criminal Code or the Law on Infringements. The Law on Infringements article 6.27 covers unlawfully getting, handling, transferring or disclosing sensitive data. It costs a person 2 million tugrik, about 600 US dollars. It costs a company 20 million tugrik, about 5,700 US dollars. Using data outside the original purpose costs a person 500,000 tugrik (about 140 US dollars) and a company 5 million tugrik (about 1,400 US dollars). (5) Article 19-1 of the Law on Telecommunications covers four things. They are internet protocol interconnection, data storage infrastructure, content delivery networks, and virtual networks between demarcation points. All count as licensed information network activity. So a local point of presence needs a licence from the Communications Regulatory Commission. A sixth, for critical infrastructure. If a foreign national or foreign company carries out your cyber risk assessment, you must first get the opinion of the intelligence agency.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 4.1.4, 4.1.11, 4.1.12, 10, 30 and 31
legalinfo.mn
“10.2. An employer may, with the employee's consent, use biometric data other than non-duplicable bodily data (fingerprints) in order to simplify the identification and verification of the employee in accordance with its internal labour rules.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, 11 May 2017, articles 3.1 (one unit equals 1,000 tugrik) and 6.27 (breach of the Law on Protection of Personal Information)
legalinfo.mn
“3. Unlawfully obtaining, processing, transferring to others or disclosing a person's sensitive information, where it does not attract criminal liability, shall be punished by a fine of 2,000 units for a person and 20,000 units for a legal entity.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Cyber Security, article 19.2.12 (intelligence agency opinion where a foreign party carries out the risk assessment)
legalinfo.mn
Link checked 18 August 2026
What's changing next
One big thing is in motion. On 13 May 2026 the government decided to build the legal rules for putting data into economic circulation and reuse. It also decided to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation. The minister can rewrite the server and storage rules with a simple order, without parliament and without consultation.
Featured on the ministry's own home page on 18 August 2026: 'Give your feedback on the draft primary Data Law'. It cites minute 18 of the Government meeting of 13 May 2026. At that meeting the Government ordered steps to create the legal conditions for putting data into economic circulation and reuse. It also ordered preparations for an energy-efficient green data centre in Mongolia. No text, no bill number and no consultation deadline appeared on the page we read, and the linked detail page returned an error. Powers already in someone's hand, fastest first. (1) Article 20.2 of the Law on Protection of Personal Information lets the ministry act by order alone. It can set the security requirements, the assessment methodology and the requirements for storage technology. That is exactly the power used to create the server-in-Mongolia rule in 2023, and it can be widened the same way. (2) Article 25.1.2 lets the ministry approve technology security requirements for sensitive, genetic and biometric data. (3) Article 27.9 of the Law on Public Information Transparency lets the Government act by resolution. It sets the conditions for creating and registering foundational and sector-specific databases. That decides how much data is pulled into the National Data Centre. (4) Article 18.5.9 lets the Government name any further system a 'support system', which then falls under the state infrastructure rules. None of these needs a bill. The privacy law itself has not been changed since it was adopted on 17 December 2021. The Law on Cyber Security was changed on 6 January 2023, to add licensing for audit and risk assessment firms.
Sources
- Official sourceMinistry of Digital Development, Innovation and CommunicationsFeatured news: 'Give your feedback on the draft primary Data Law', citing minute 18 of the Government meeting of 13 May 2026
mddic.gov.mn
“Монгол Улсын Засгийн газрын 2026 оны 05 дугаар сарын 13-ны өдрийн 18 дугаар хуралдааны тэмдэглэлээр "Өгөгдлийг эдийн засгийн эргэлтэд оруулах, дахин ашиглах талаар эрх зүйн орчныг бүрдүүлэх, Монгол Улсад эрчим хүчний хэмнэлттэй ногоон дата төв байгуулах бэлтгэл ажлыг хангах" чиглэлээр холбогдох арга хэмжээ авч хэрэгжүүлэхийг үүрэг болгосон.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 20.2 and 25.1.2 (ministerial power to set storage technology requirements)
legalinfo.mn
“20.2. The requirements for securing information during collection, processing and use, the instructions for carrying out assessments, and the requirements for storage technology shall be set by the central state administrative body in charge of digital development and communications.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Health and social care data must stay in the country
Official name: Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам · Minister of Digital Development and Communications order A/90 of 11 September 2023, clause 3.2 · Government rules
Any organisation that handles sensitive, genetic or biometric personal data must keep the server inside Mongolia. That server must be reachable only from Mongolia. Consent does not get you out of this. Sensitive data is defined widely. It covers health records, criminal records, biometrics and the content of letters, e-mail and messages.
Enforced by Ministry of Digital Development, Innovation and Communications
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe server must be located in Mongolia and reachable only from Mongolia. It must sit in a purpose-built technical room. It must connect to the state KHUR exchange and to the telecoms regulator's time server.
- Independent audit — 1 yearAnnual information security audit, plus an audit after every security failure.
- Assess high-risk projects — 2 yearsInformation security risk assessment every two years, or whenever needed.
- Appoint a data protection officerA unit or a named officer responsible for information security is required.
- Keep logsA historical register of every change, deletion and restoration of the data must be kept.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: 20,000,000 tugrik for a legal entity — about $6 thousandUnlawful processing or disclosure of sensitive data under the Law on Infringements article 6.27(3)
Sources
- Official sourceMinister of Digital Development and CommunicationsOrder A/90 of 11 September 2023: Technological security requirements and procedure for processing sensitive, genetic and biometric personal data
legalinfo.mn
“3.2.1. be located in the territory of Mongolia; 3.2.2. be accessible (reachable) only from Mongolia.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 4.1.12 and 9 (definition and restriction of sensitive data) and 20.2 (power to set storage technology requirements)
legalinfo.mn
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsMinistry legal framework page listing order A/90 and the joint health software order A/130 and A/58 of 16 April 2025
mddic.gov.mn
Link checked 18 August 2026
Government data must stay in the country
Official name: Нийтийн мэдээллийн ил тод байдлын тухай хууль · Law on Public Information Transparency, 17 December 2021, articles 18.12, 27.7 and 33.2 · Act of parliament
One rule covers government bodies, state-owned and part-state-owned companies, the public broadcaster and political parties. It also covers anyone carrying out a state function under a law or a contract. The core state data exchange system, and all foundational and sector-specific public databases, must stay inside Mongolia and be held at the National Data Centre.
Enforced by Ministry of Digital Development, Innovation and Communications
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe core state data exchange system, and every foundational and sector-specific public database, must be located in Mongolia and held at the National Data Centre.
- Register or notifyArticle 27.8: you must register every creation, structural change or shutdown of a foundational or sector-specific database with the ministry.
- Written vendor contractArticle 18.16: a private company using the core or support systems to deliver services must sign a contract with the ministry.
- Keep logsArticle 34.1.3: the body responsible must keep and protect an activity log of its information system.
What it costs if you get it wrong
- Fixed maximum fine: 5,000,000 tugrik for a legal entity that fails to publish information required to be open; 1,000,000 tugrik for unlawful use or disclosure of restricted information — about $1 thousandLaw on Infringements article 15.34
Sources
- Official sourceLegal Information Unified SystemLaw on Public Information Transparency, 17 December 2021, articles 6, 18, 27, 33 and 34
legalinfo.mn
“18.12. The core system shall be located in the territory of Mongolia.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, article 15.34 (breach of the Law on Public Information Transparency)
legalinfo.mn
Link checked 18 August 2026
Mapping and location data must stay in the country
Official name: Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл · Law on Public Information Transparency, articles 27.3 and 27.7, read with the Law on Geodesy and Cartography article 9 and the General Law on State Registration articles 6 to 8 · Act of parliament
Mongolia's national mapping database and its civil, property and company registration databases are named as foundational databases. By law they must be located inside the country. If your product depends on a live feed from any of them, the source cannot be mirrored abroad.
Enforced by Ministry of Digital Development, Innovation and Communications
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe national mapping database and the civil, property and legal-entity registration databases are foundational databases and must sit in Mongolia.
Sources
- Official sourceLegal Information Unified SystemLaw on Public Information Transparency, articles 27.3 and 27.7
legalinfo.mn
“27.3. Foundational databases include the databases provided for in articles 6, 7 and 8 of the General Law on State Registration and article 9 of the Law on Geodesy and Cartography.”
Link checked 18 August 2026
Payment data rules
Official name: Кибер аюулгүй байдлын тухай хууль · Law on Cyber Security, 17 December 2021 (amended 6 January 2023), articles 9-1, 17 and 19 · Act of parliament
Seventeen categories of organisation count as critical information infrastructure. They include banks running the unified payment and settlement systems, second and third-level hospitals, dominant telecoms and IT providers, data centres, energy, water, transport and border control. They face yearly risk assessments and two-yearly security audits. They must report incidents immediately. And if a foreign firm does the assessment, the intelligence agency must sign off.
Enforced by Ministry of Digital Development, Innovation and Communications
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Assess high-risk projects — 1 yearCritical infrastructure: cyber risk assessment every year, and after every change to the system or network. Ordinary IT service providers: every two years.
- Independent audit — 2 yearsCritical infrastructure: information security audit every two years. Ordinary IT service providers: every year. An audit to an international standard counts.
- Report cyber incidentsNotify the relevant cyber attack response centre immediately; notify affected users immediately. Send the audit and assessment reports to the centre within one month of receiving them.
- Appoint a data protection officerA unit or a named officer responsible for cyber security is required.
- Keep logsKeep information system and network activity logs for the period set in the general cyber security procedure approved by the Government.
- Hold a security certificateArticle 19.2.3 requires critical infrastructure organisations to adopt information security standards.
- Do not hand data to foreign authorities on demandArticle 19.2.12: if a foreign national or foreign company carries out the cyber risk assessment, the intelligence agency's opinion must be obtained first.
What it costs if you get it wrong
- Fixed maximum fine: 10,000,000 tugrik (10,000 units) for a critical infrastructure legal entity — about $3 thousandFailing to comply with a requirement of the competent authority on cyber security; also 10,000 units for disclosing an audit or risk assessment report
- Fixed maximum fine: 2,000,000 tugrik (2,000 units) — about $570Having no system to detect, record and stop cyber attacks, or not being connected to a compliant response centre
Sources
- Official sourceLegal Information Unified SystemLaw on Cyber Security, 17 December 2021, articles 9-1, 17, 19, 20 to 23 and 25
legalinfo.mn
“19.2.12. Where a foreign national or a foreign legal entity is to carry out the cyber security risk assessment, the opinion of the intelligence organisation shall be obtained.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, article 14.13 (breach of the Law on Cyber Security)
legalinfo.mn
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsRegister of 49 legal entities permitted to carry out information security audits
mddic.gov.mn
Link checked 18 August 2026
Payment data rules (Payments)
Official name: Үндэсний төлбөрийн системийн тухай хууль · Law on the National Payment System, 31 May 2017, articles 11.3.7 and 30 · Act of parliament
We found no Mongolian rule that payment data must stay in the country. But there is an unusually long minimum. Payment operators, participants and service providers must keep payment records for at least 15 years. Licence applications to the central bank must set out how transaction data is protected when handled and stored.
Enforced by Bank of Mongolia
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent
What you have to do
- Keep data for a minimum period — 15 yearsDocuments arising from payment system activity must be kept for at least 15 years from receipt or creation.
- Register or notifyOperating a payment system or providing payment services needs permission from the Bank of Mongolia. The application must describe the IT system and how transaction data is protected when handled and stored.
- Secure the data
Sources
- Official sourceLegal Information Unified SystemLaw on the National Payment System, articles 11.3.7 and 30
legalinfo.mn
“30.1. ... shall keep documents created in the course of activity related to the payment system for not less than 15 years from the date of receipt or creation.”
Link checked 18 August 2026
- Official sourceBank of MongoliaPayment system laws and legal acts
mongolbank.mn
Link checked 18 August 2026
Telecoms rules
Official name: Харилцаа холбооны тухай хууль, 19-1 дүгээр зүйл · Law on Telecommunications, 18 October 2001, article 19-1 (added by the law of 6 January 2023), read with the Law on Permits article 8.1(9.3) · Act of parliament
We found no rule requiring telecoms subscriber data to stay in Mongolia, checked on 18 August 2026. But building data storage infrastructure or a content delivery network inside Mongolia is itself a licensed telecoms activity. So a local point of presence needs a licence from the Communications Regulatory Commission.
Enforced by Communications Regulatory Commission of Mongolia
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyRunning data storage infrastructure, a content delivery network, internet protocol interconnection or a virtual network between demarcation points is a licensed information network activity.
- Secure the dataArticle 25.2.4: operators must keep and protect the secrecy of all information passing over their network.
What it costs if you get it wrong
- Loss of your licenceArticle 15.1.2: disclosing the secrecy of communications and correspondence
Sources
- Official sourceLegal Information Unified SystemLaw on Telecommunications, articles 15.1.2, 19-1 and 25.2.4
legalinfo.mn
“19-1.1. The activity of using an information network and providing services under article 8.1(9.3) of the Law on Permits includes internet protocol interconnection and data storage infrastructure, content delivery networks and virtual networks between demarcation points.”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Commission of MongoliaProcedures, terms and requirements approved by the Communications Regulatory Commission (reviewed for data residency rules; none found)
crc.gov.mn
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Government data rules
Official name: Хүний хувийн мэдээлэл хамгаалах тухай хууль · Law on Protection of Personal Information, 17 December 2021, article 14 · Act of parliament
Personal data may not be sent to anyone abroad unless a law or treaty allows it or the person has consented in writing. There is no approved-country list, no standard contract and no government approval route.
Enforced by National Human Rights Commission of Mongolia
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent
What you have to do
- Put a transfer safeguard in placeSending data abroad is banned, unless a law or an international treaty allows it, or the person agrees.
- Get consentConsent must be written, on paper or electronically. You must be able to prove it. It must list the recipients. And you must get it again for a new purpose.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhereArticle 16.1.9: the person can have a copy of their data sent to a company of their choosing.
- Keep records of how you use dataArticle 18.2.12: keep a register of what you collect, how you handle it and how you use it.
What it costs if you get it wrong
- Fixed maximum fine: 20,000,000 tugrik (20,000 units) for a legal entity; 2,000,000 tugrik for an individual — about $6 thousandUnlawfully obtaining, processing, transferring or disclosing sensitive personal data
- Fixed maximum fine: 5,000,000 tugrik (5,000 units) for a legal entity; 500,000 tugrik for an individual — about $1 thousandUsing personal data for a purpose other than the legal ground or the original consent
- Criminal liabilityArticle 30.2 routes serious breaches to the Criminal Code rather than to administrative fines
- Claims by individualsArticle 16.2 gives the data subject a right to compensation for loss and for non-material harm
Sources
- Official sourceLegal Information Unified System, Ministry of Justice and Home AffairsLaw on Protection of Personal Information, 17 December 2021, articles 8, 14, 16, 18, 30 and 32
legalinfo.mn
“32.1. This law shall be followed from 1 May 2022.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, article 6.27 (penalties for breach of the personal data law)
legalinfo.mn
Link checked 18 August 2026
Biometric data rules
Official name: Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл · Law on Protection of Personal Information, articles 10 and 31 · Act of parliament
Only five named state bodies may collect fingerprints or genetic data, and only for five named purposes. A private employer may use other biometrics with the worker's consent for identity checks. It may never use fingerprints. It may not pass that data to anyone else. Fingerprints collected before 1 May 2022 had to be destroyed.
Enforced by National Human Rights Commission of Mongolia
How this country controls where data goes: Not allowed
What you have to do
- Get consentAn employer needs the worker's consent, and even then may not use fingerprints.
- Keep the data in the countryArticle 10.3 bars the employer from passing employee biometric data to anyone else at all. That rules out an offshore biometric supplier.
- Secure the dataArticle 10.5: meeting the ministry's security requirements does not excuse liability if the data is lost.
What it costs if you get it wrong
- Fixed maximum fine: 20,000,000 tugrik for a legal entity — about $6 thousandUnlawfully collecting, processing, transferring or disclosing biometric or genetic data
- Criminal liabilityArticle 30.2 routes serious cases to the Criminal Code
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 10 and 31
legalinfo.mn
“31.1. Non-duplicable bodily data (fingerprints) collected by a controller before this law is followed, other than those permitted by law, shall be destroyed.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
How broadly the Ministry actually reads order A/90's server rule, given that 'sensitive data' includes the content of letters, e-mail and messages
Read literally, clause 3.2 would put an ordinary hosted company mailbox under the server-in-Mongolia rule. We found no published guidance narrowing it, and no enforcement testing it. We confirmed the text. We could not confirm how it is applied. Ask the ministry before you host company mail abroad.
Whether the National Human Rights Commission has issued any data protection decision, recommendation or demand since 1 May 2022
We could not read the Commission's website or its report archive. We can show what powers it has by law. We could not confirm what cases it has handled.
The exact log retention period for information system activity logs under the Law on Cyber Security
Articles 17.1.3 and 19.2.9 leave the period to the general cyber security procedure approved by the Government. We could not find the text of that resolution. Ask the ministry for it before you set your log policy.
Whether any Bank of Mongolia or Financial Regulatory Commission regulation imposes a banking, insurance or securities where data has to be stored rule
The laws themselves contain no such rule. But we read only the laws and the regulators' index pages, not every internal procedure. So this is 'we found no rule, checked 18 August 2026', not 'no rule exists'. Check with your regulator.
The content and status of the joint order A/130 and A/58 of 16 April 2025 on health service software
The Ministry's own page lists it, but we could not download the linked document. It may add further storage or integration requirements for health services. Ask the Ministry for a copy if you build health software here.
The contents, bill number and consultation deadline of the draft Data Law
The Ministry's home page carries the consultation notice and the Government meeting minute of 13 May 2026. We could not open the linked detail page, and no draft text is published on the site.
Reports that the UN Special Rapporteur on the right to privacy criticised Mongolia's fragmented supervision in February 2026 and recommended a dedicated independent data protection authority
A professional source reported this. We could not read the United Nations document itself, and the Mongolian government has not published it. Treat it as a pointer only.
Whether the Law on Protection of Personal Information reaches a foreign company with no establishment or server in Mongolia
Article 3 is silent on territory. There is no case law, no regulator guidance and no local representative duty. So the honest answer is that Mongolia has not resolved the question.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.