Mongolia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Mongolia is not an open country for data. As a rule you may not send personal data abroad at all unless the person agrees or a law says you can. On top of that, a 2023 ministry order says that any server handling sensitive data must sit in Mongolia and must be reachable only from inside Mongolia. Sensitive data is defined very widely and includes health records and the content of messages.
Eight questions about Mongolia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Mongolia's rules apply to my company?
Probably not, if you have no presence in Mongolia at all. The privacy law says it governs how people, companies and unincorporated bodies collect, process and use personal data, but it does not say it reaches organisations outside the country. There is no revenue or size threshold, and there is no duty to appoint a local representative. In practice the rules bite through your Mongolian company, your Mongolian server, or your Mongolian licence rather than through long-arm reach.
Law on Protection of Personal Information, article 3.1, defines the scope by activity, not by territory or by targeting: it covers relations arising when a person, a legal entity or an organisation without legal personality collects, processes, uses and secures personal data. Article 3.2 extends the same rules to processing carried out with technical means and software. There is no equivalent of the European 'offering goods or services to people in the territory' test and no registration or representative obligation anywhere in the Act. Practical reach comes from three other places: order A/90 of 2023 requires the server that processes sensitive data to be in Mongolia, which is a physical hook; the Law on Public Information Transparency binds anyone carrying out a state function under a law or a contract; and the Law on Telecommunications, article 19-1, brings data storage infrastructure and content delivery networks inside the licensed 'information network' activity, so building a point of presence in Mongolia needs a licence from the Communications Regulatory Commission.
Sources
- Official sourceLegal Information Unified System, Ministry of Justice and Home AffairsLaw on Protection of Personal Information, 17 December 2021, article 3 (scope)
legalinfo.mn
“3.1. This law regulates relations connected with the collection, processing, use and securing of a person's private information by a person, a legal entity, or an organisation without the rights of a legal entity.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Telecommunications, 18 October 2001, article 19-1 (information network)
legalinfo.mn
Link checked 18 August 2026
Can I store my users' data outside Mongolia?
Only sometimes, and for a lot of data the answer is a flat no. The general rule is that sending personal data to a person, company or international body abroad is banned unless a law or a treaty allows it, or the person the data is about has agreed. Then a separate ministry order takes health data, biometrics, genetic data, criminal records, digital signature keys and the content of letters, e-mail and messages out of reach entirely: the server has to be in Mongolia and has to be reachable only from Mongolia. Government systems and the country's foundational databases must also stay in Mongolia.
Three layers stack up. (1) National baseline: article 14.1 of the Law on Protection of Personal Information is a prohibition with two exits, a legal or treaty basis, or the data subject's consent. Consent must be written, on paper or electronically, must be verified electronically or against an identity document, and must list every recipient (articles 8.2.6, 8.3, 8.4, 8.11). (2) Data-type wall: Minister of Digital Development and Communications order A/90 of 11 September 2023, clause 3.2, applies to every controller handling sensitive, genetic or biometric data and requires the processing server to be located in Mongolia and accessible only from Mongolia, sited in a purpose-built technical room, able to exchange data through the state 'KHUR' exchange, synchronised to the Communications Regulatory Commission's time server, protected by a certificate and regularly backed up. Because article 4.1.12 of the Act treats correspondence data, meaning letters, parcels, e-mail and anything exchanged over telecommunications and information technology, as sensitive, the reach of A/90 is unusually wide on its face. (3) Public-sector wall: Law on Public Information Transparency articles 18.12 and 27.7 require the core state exchange system and every foundational and sectoral public database to be located in Mongolia, and article 33.2 requires them to be held at the National Data Centre. Foundational databases include the civil registration databases and the geodesy and cartography database (article 27.3). Sectors with no residency rule of their own that we could find: banking and payments, insurance and securities, telecommunications, education and online gaming. For those the national baseline and A/90 still apply.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, article 14 (transfer to persons and organisations in a foreign state)
legalinfo.mn
“14.1. Except as provided by law or by an international treaty of Mongolia, or except where the data subject has given consent, it is prohibited to transfer information to a person, a legal entity or an international organisation in a foreign state.”
Link checked 18 August 2026
- Official sourceMinister of Digital Development and CommunicationsOrder A/90 of 11 September 2023: Technological security requirements and procedure for processing sensitive, genetic and biometric personal data, clause 3.2
legalinfo.mn
“3.2. The server processing the information shall meet the following conditions and requirements: 3.2.1. be located in the territory of Mongolia; 3.2.2. be accessible only from Mongolia.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Public Information Transparency, 17 December 2021, articles 18.12, 27.3, 27.7 and 33.2
legalinfo.mn
“27.7. Foundational and sectoral databases shall be located in the territory of Mongolia.”
Link checked 18 August 2026
What do I need in place before data leaves Mongolia?
There is no approval process, no standard contract and no list of approved countries. Mongolia works the other way round: the transfer is banned, and the only ways out are a law or treaty that allows it, or the written consent of the person concerned. Consent is not a light-touch tick box. You must name every recipient before you collect the data, you must be able to prove the consent, and the person can withdraw it at any time.
There is no adequacy list, no standard contractual clauses, no binding corporate rules, no certification route and no case-by-case government authorisation for transfers under the Law on Protection of Personal Information. The only mechanisms are the legal or treaty basis in article 14.1 and consent. Consent must be given in writing on paper or electronically (article 8.3); an electronic consent is valid only if the person was identified and authenticated by a means set by law or accepted by them (article 8.4); silence or a lapse of time is expressly not consent (article 8.6); the controller must be able to prove consent (article 8.9); consent is needed again for any new purpose (article 8.10); and separate consent is needed to pass data on unless the original notice already listed the recipients (articles 8.2.6 and 8.11). Consent can be withdrawn at any time and the controller must make withdrawal easy (articles 8.7 and 18.4). Note the mismatch: for sensitive data, consent gets you past article 14 but not past order A/90, which fixes where the server may sit regardless of what anyone agreed.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 8 and 14
legalinfo.mn
“8.6. Where the data subject has not replied to a request for consent to collect information, the expiry of the period set for a reply, or of a normally reasonable period, shall not be a ground for treating consent as given.”
Link checked 18 August 2026
- Official sourceMinister of Digital Development and CommunicationsOrder A/90 of 11 September 2023, clause 3.2 (server conditions)
legalinfo.mn
Link checked 18 August 2026
Who enforces the rules in Mongolia, and what can they do?
Nobody owns privacy on its own. The law splits the job three ways: the National Human Rights Commission handles complaints and supervision, the Ministry of Digital Development, Innovation and Communications writes the technical rules and takes cyber incident reports, and other state bodies police their own sectors. The ministry is clearly working: it has issued binding orders and it keeps a live register of 49 licensed information security auditors. What we could not find is any published privacy fine or decision, so treat the privacy side as switched on but not yet biting.
Law on Protection of Personal Information, article 24, gives the National Human Rights Commission the supervisory role: monitoring compliance, receiving and investigating complaints or acting on its own initiative, issuing demands and recommendations, receiving controllers' annual incident registers every January, reviewing impact assessments, and reporting on data protection in its annual report on the state of human rights. Article 24.2 requires one named Commission member to carry this portfolio. Article 25 gives the Ministry of Digital Development, Innovation and Communications the rule-making role in the digital environment: approving technology security requirements for sensitive, genetic and biometric data, and receiving and registering notifications of security failures and cyber attacks. Article 26 leaves every other state body to supervise within its own statutory remit. Fines are not in the privacy law at all; they sit in the Law on Infringements, article 6.27, and are applied by inspectors, the police and the courts. Observable evidence of activity is on the ministry side: order A/90 in 2023, the joint risk assessment methodology A/30 and A/148 in 2024, and a register of 49 legal entities permitted to carry out information security audits with permissions running from 2026 to 2029. The National Human Rights Commission is a long-standing, staffed national human rights institution, but its website is a JavaScript application whose content we could not retrieve, and we found no published data protection decision.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 24, 25 and 26 (powers of the National Human Rights Commission, the ministry and other state bodies)
legalinfo.mn
“24.2. One member of the National Human Rights Commission shall be specially responsible for the functions set out in article 24.1 of this law.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsRegister of legal entities permitted to carry out information security audits (49 entities, permissions valid 2026 to 2029)
mddic.gov.mn
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsLegal framework page listing ministerial orders A/90 (2023) and A/30 and A/148 (2024)
mddic.gov.mn
Link checked 18 August 2026
How long do I have to keep the data?
Mongolia is unusual: the privacy law tells you when you may delete, not just when you must. You may only erase personal data on four listed grounds, and deleting it on any other ground is forbidden. Pulling the other way, payment businesses must keep their records for at least 15 years, anyone handling sensitive data must keep a history log of every change, deletion and restoration, and organisations running shared information systems must keep activity logs for a period fixed by government rules.
The ceiling side is article 15 of the Law on Protection of Personal Information: you delete on the data subject's request where collection or use was unlawful, where a law, treaty or final court judgment orders it, or where the original purpose has been achieved or the contract or agreement says so. Article 15.2 then forbids deletion on any other ground unless another law provides for it, which turns the usual 'delete when you no longer need it' instinct on its head and makes routine data-minimisation purges legally risky without a documented ground. The floor side is scattered: Law on the National Payment System, article 30.1, requires operators, participants and payment service providers to keep documents arising from payment system activity for at least 15 years from receipt or creation; order A/90 clause 3.1.6 requires a historical register of every change, deletion and restoration of sensitive data; Law on Cyber Security articles 17.1.3 and 19.2.9 require information system activity logs to be kept for the period set in the general cyber security procedure approved by the Government, a period we could not verify. One oddity worth knowing: article 13.2 of the privacy law allows sensitive data of a dead person to be processed without consent once 70 years have passed since death.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 13.2, 15 and 18.2.12
legalinfo.mn
“15.2. Unless otherwise provided by law, it is prohibited to delete information on grounds other than those set out in article 15.1 of this law.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on the National Payment System, article 30.1 (15-year document retention)
legalinfo.mn
“30.1. An operator, participant, payment service provider or person entitled to carry out activities related to the provision of payment services shall keep documents created in the course of payment system activity for not less than 15 years from the date of receipt or creation.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Cyber Security, articles 17.1.3 and 19.2.9 (activity log retention)
legalinfo.mn
Link checked 18 August 2026
What happens if there is a breach?
There are three clocks and none of them is measured in hours. The word the laws use is 'immediately', which they define as the shortest possible time. You tell the affected person immediately if the problem could harm them, you tell the ministry immediately if your system's security failed or you were attacked, and if you run critical national infrastructure you tell the national response centre immediately as well. Once a year, every January, you also send the human rights commission a register of the incidents you had and what you did about them.
Clock one, to the individual: article 22.2 of the Law on Protection of Personal Information requires the controller to notify the data subject immediately where a breach may harm their rights or lawful interests, and article 22.3 sets the contents, namely who and what was affected, the controller's name and contact details, the possible consequences and the remedial steps taken. A supplier who spots the breach must tell the controller immediately (article 22.1). Clock two, to the ministry: article 25.1.3 requires the ministry to receive and register notifications from controllers that an information system used for personal data has suffered a security failure or a cyber attack, and to act immediately. Clock three, to the cyber response centres: Law on Cyber Security article 17.1.2 requires information technology service providers to notify the relevant response centre of a cyber attack immediately and to seek help if they cannot stop it, article 17.1.9 requires them to notify affected users immediately, and article 19.2.14 requires critical information infrastructure organisations to notify immediately once normal operation is lost. Article 4.1.3 of the privacy law defines 'immediately' as the shortest possible period, so there is no safe-harbour number of hours to plan against. The annual filing is article 22.6: the register of breaches and responses goes to the National Human Rights Commission every January, and on demand at any time. There are two centres to choose between: the National Centre sits inside the intelligence agency and covers state-owned critical infrastructure and bodies on the unified state network; the Public Centre sits under the ministry and covers everyone else.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 4.1.3, 22 and 25.1.3
legalinfo.mn
“22.2. Where a breach under article 22.1 of this law may cause harm to the rights and lawful interests of the data subject, the controller shall notify the data subject immediately.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Cyber Security, articles 17.1.2, 17.1.9, 19.2.14, 20, 21 and 22 (response centres)
legalinfo.mn
“21.1. The National Centre shall operate within the structure of the intelligence organisation.”
Link checked 18 August 2026
What trips people up in Mongolia?
Five things catch people out. First, fingerprint scanners at work are illegal for private employers: an employer may use other biometrics with the worker's consent, but never fingerprints, and may not pass that biometric data to anyone else. Second, 'sensitive data' includes the content of letters, e-mail and messages, which drags ordinary company mail systems towards the server-in-Mongolia rule. Third, financial and payment data is not classed as sensitive, but a fingerprint or face login for a banking app is, so banks land inside the strict rules by the back door. Fourth, breaking the privacy law can be a crime, not just a fine. Fifth, if you build data storage or a content delivery network inside Mongolia you need a telecoms licence.
(1) Article 10.1 of the Law on Protection of Personal Information reserves the collection of fingerprints and genetic data to five named state bodies for five named purposes. Article 10.2 lets an employer use biometric data other than fingerprints, with the employee's consent, to make identity checks easier under its internal labour rules. Article 10.3 then forbids the employer from altering that data or passing it to anyone else, which rules out an offshore biometric access control vendor. Article 31.1 required fingerprints collected before the law started to be destroyed. (2) Article 4.1.12 lists correspondence among sensitive data, and article 4.1.4 defines correspondence data as letters, parcels, e-mail and anything exchanged using telecommunications or information technology. Read literally with clause 3.2 of order A/90 that puts an ordinary hosted mailbox inside a server-in-Mongolia obligation. We have found no guidance narrowing this and no enforcement testing it. (3) Property, education, membership and digital identifiers are ordinary personal data under article 4.1.11; health, correspondence, genetic and biometric data, digital signature private keys, criminal record, sexual orientation, gender identity and sexual life are sensitive under article 4.1.12. Money is not on the sensitive list. Biometric authentication is. (4) Article 30.2 says individuals and legal entities that breach the law bear liability under the Criminal Code or the Law on Infringements. Under the Law on Infringements article 6.27, unlawfully obtaining, processing, transferring or disclosing sensitive data costs an individual 2 million tugrik (about $600) and a company 20 million tugrik (about $5,700), and using data outside the original purpose costs an individual 500,000 tugrik (about $140) and a company 5 million tugrik (about $1,400). (5) Article 19-1 of the Law on Telecommunications puts internet protocol interconnection, data storage infrastructure, content delivery networks and virtual networks between demarcation points inside the licensed information network activity, so a local point of presence needs a licence from the Communications Regulatory Commission. A sixth, for critical infrastructure: if a foreign national or foreign company performs your cyber risk assessment you must first obtain the opinion of the intelligence agency.
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 4.1.4, 4.1.11, 4.1.12, 10, 30 and 31
legalinfo.mn
“10.2. An employer may, with the employee's consent, use biometric data other than non-duplicable bodily data (fingerprints) in order to simplify the identification and verification of the employee in accordance with its internal labour rules.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, 11 May 2017, articles 3.1 (one unit equals 1,000 tugrik) and 6.27 (breach of the Law on Protection of Personal Information)
legalinfo.mn
“3. Unlawfully obtaining, processing, transferring to others or disclosing a person's sensitive information, where it does not attract criminal liability, shall be punished by a fine of 2,000 units for a person and 20,000 units for a legal entity.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Cyber Security, article 19.2.12 (intelligence agency opinion where a foreign party carries out the risk assessment)
legalinfo.mn
Link checked 18 August 2026
What is changing soon in Mongolia?
One big thing is in motion. The government decided on 13 May 2026 to build a legal framework for putting data into economic circulation and reuse, and to prepare for a green, energy-efficient data centre in Mongolia. The ministry is now consulting on a first Data Law. It is a draft, so nothing in it binds anyone yet. The bigger short-term risk is not new legislation at all: the minister can rewrite the server and storage rules by a simple order, without parliament and without consultation.
Featured on the ministry's own home page on 18 August 2026: 'Give your feedback on the draft primary Data Law', recording that by minute 18 of the Government meeting of 13 May 2026 the Government directed measures to create the legal environment for putting data into economic circulation and reuse and to prepare for establishing an energy-efficient green data centre in Mongolia. No text, no bill number and no consultation deadline were published on the page we retrieved, and the linked detail page returned an error. Dormant switches to watch, in order of how fast they could move: (1) article 20.2 of the Law on Protection of Personal Information lets the ministry set, by order alone, the security requirements, the assessment methodology and the requirements for storage technology, which is exactly the power used to create the server-in-Mongolia rule in 2023 and can be widened the same way; (2) article 25.1.2 lets the ministry approve technology security requirements for sensitive, genetic and biometric data; (3) article 27.9 of the Law on Public Information Transparency lets the Government set by resolution the conditions for creating and registering foundational and sectoral databases, which determines how much data is pulled into the National Data Centre; (4) article 18.5.9 lets the Government designate any further system as a 'support system', which then falls inside the state infrastructure regime. None of these needs a bill. The privacy law itself has not been amended since it was adopted on 17 December 2021; the Law on Cyber Security was amended on 6 January 2023 to add the licensing of audit and risk assessment firms.
Sources
- Official sourceMinistry of Digital Development, Innovation and CommunicationsFeatured news: 'Give your feedback on the draft primary Data Law', citing minute 18 of the Government meeting of 13 May 2026
mddic.gov.mn
“Монгол Улсын Засгийн газрын 2026 оны 05 дугаар сарын 13-ны өдрийн 18 дугаар хуралдааны тэмдэглэлээр "Өгөгдлийг эдийн засгийн эргэлтэд оруулах, дахин ашиглах талаар эрх зүйн орчныг бүрдүүлэх, Монгол Улсад эрчим хүчний хэмнэлттэй ногоон дата төв байгуулах бэлтгэл ажлыг хангах" чиглэлээр холбогдох арга хэмжээ авч хэрэгжүүлэхийг үүрэг болгосон.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 20.2 and 25.1.2 (ministerial power to set storage technology requirements)
legalinfo.mn
“20.2. The requirements for securing information during collection, processing and use, the instructions for carrying out assessments, and the requirements for storage technology shall be set by the central state administrative body in charge of digital development and communications.”
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
6 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules2 rules
Хүний хувийн мэдээлэл хамгаалах тухай хууль
Act of parliament · Law on Protection of Personal Information, 17 December 2021, article 14
Personal data may not be sent to anyone abroad unless a law or treaty allows it or the person has consented in writing. There is no approved-country list, no standard contract and no government approval route.
Enforced by National Human Rights Commission of Mongolia
Transfer model: Approval each time · Accepted routes: Explicit consent
What it makes you do
- Put a transfer safeguard in placeTransfer abroad is prohibited unless a law or an international treaty allows it, or the data subject consents.
- Get consentConsent must be written on paper or electronically, must be provable, must list the recipients, and must be re-obtained for a new purpose.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhereArticle 16.1.9: the person may have a copy of their data sent to a controller of their choosing.
- Keep records of processingArticle 18.2.12: keep a register of collection, processing and use.
What it costs if you get it wrong
- Fixed maximum fine: 20,000,000 tugrik (20,000 units) for a legal entity; 2,000,000 tugrik for an individual — about $6 thousandUnlawfully obtaining, processing, transferring or disclosing sensitive personal data
- Fixed maximum fine: 5,000,000 tugrik (5,000 units) for a legal entity; 500,000 tugrik for an individual — about $1 thousandUsing personal data for a purpose other than the legal ground or the original consent
- Criminal liabilityArticle 30.2 routes serious breaches to the Criminal Code rather than to administrative fines
- Claims by individualsArticle 16.2 gives the data subject a right to compensation for loss and for non-material harm
Sources
- Official sourceLegal Information Unified System, Ministry of Justice and Home AffairsLaw on Protection of Personal Information, 17 December 2021, articles 8, 14, 16, 18, 30 and 32
legalinfo.mn
“32.1. This law shall be followed from 1 May 2022.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, article 6.27 (penalties for breach of the personal data law)
legalinfo.mn
Link checked 18 August 2026
Хүний хувийн мэдээлэл хамгаалах тухай хууль, 10, 31 дүгээр зүйл
Act of parliament · Law on Protection of Personal Information, articles 10 and 31
Only five named state bodies may collect fingerprints or genetic data, and only for five named purposes. A private employer may use other biometrics with the worker's consent for identity checks, but never fingerprints, and may not pass that data to anyone else. Fingerprints collected before 1 May 2022 had to be destroyed.
Enforced by National Human Rights Commission of Mongolia
Transfer model: Not allowed
What it makes you do
- Get consentAn employer needs the worker's consent, and even then may not use fingerprints.
- Keep the data in the countryArticle 10.3 bars the employer from passing employee biometric data to anyone else at all, which rules out an offshore biometric vendor.
- Secure the dataArticle 10.5: meeting the ministry's security requirements does not excuse liability if the data is lost.
What it costs if you get it wrong
- Fixed maximum fine: 20,000,000 tugrik for a legal entity — about $6 thousandUnlawfully collecting, processing, transferring or disclosing biometric or genetic data
- Criminal liabilityArticle 30.2 routes serious cases to the Criminal Code
Sources
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 10 and 31
legalinfo.mn
“31.1. Non-duplicable bodily data (fingerprints) collected by a controller before this law is followed, other than those permitted by law, shall be destroyed.”
Link checked 18 August 2026
Industry rules6 rules
Хүний эмзэг мэдээлэл, генетик болон биометрик мэдээлэл боловсруулахад баримтлах технологийн аюулгүй байдлын шаардлага, журам
Government rules · Minister of Digital Development and Communications order A/90 of 11 September 2023, clause 3.2 · Health and social care
Any organisation that handles sensitive, genetic or biometric personal data must keep the server that processes it inside Mongolia, and that server must be reachable only from Mongolia. Consent does not get you out of this. Sensitive data is defined widely and covers health records, criminal records, biometrics and the content of letters, e-mail and messages.
Enforced by Ministry of Digital Development, Innovation and Communications
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe processing server must be located in Mongolia and be accessible only from Mongolia, in a purpose-built technical room, connected to the state KHUR exchange and to the telecoms regulator's time server.
- Independent audit — 1 yearAnnual information security audit, plus an audit after every security failure.
- Assess high-risk projects — 2 yearsInformation security risk assessment every two years, or whenever needed.
- Appoint a data protection officerA unit or a named officer responsible for information security is required.
- Keep logsA historical register of every change, deletion and restoration of the data must be kept.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: 20,000,000 tugrik for a legal entity — about $6 thousandUnlawful processing or disclosure of sensitive data under the Law on Infringements article 6.27(3)
Sources
- Official sourceMinister of Digital Development and CommunicationsOrder A/90 of 11 September 2023: Technological security requirements and procedure for processing sensitive, genetic and biometric personal data
legalinfo.mn
“3.2.1. be located in the territory of Mongolia; 3.2.2. be accessible (reachable) only from Mongolia.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Protection of Personal Information, articles 4.1.12 and 9 (definition and restriction of sensitive data) and 20.2 (power to set storage technology requirements)
legalinfo.mn
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsMinistry legal framework page listing order A/90 and the joint health software order A/130 and A/58 of 16 April 2025
mddic.gov.mn
Link checked 18 August 2026
Нийтийн мэдээллийн ил тод байдлын тухай хууль
Act of parliament · Law on Public Information Transparency, 17 December 2021, articles 18.12, 27.7 and 33.2 · Government
Government bodies, state-owned and state-part-owned companies, anyone carrying out a state function under a law or a contract, the public broadcaster and political parties must keep the core state data exchange system and all foundational and sectoral public databases inside Mongolia, held at the National Data Centre.
Enforced by Ministry of Digital Development, Innovation and Communications
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe core state data exchange system, and every foundational and sectoral public database, must be located in Mongolia and held at the National Data Centre.
- Register or notifyArticle 27.8: every creation, structural change or decommissioning of a foundational or sectoral database must be registered with the ministry.
- Written vendor contractArticle 18.16: a private company using the core or support systems to deliver services must sign a contract with the ministry.
- Keep logsArticle 34.1.3: the body responsible must keep and protect an activity log of its information system.
What it costs if you get it wrong
- Fixed maximum fine: 5,000,000 tugrik for a legal entity that fails to publish information required to be open; 1,000,000 tugrik for unlawful use or disclosure of restricted information — about $1 thousandLaw on Infringements article 15.34
Sources
- Official sourceLegal Information Unified SystemLaw on Public Information Transparency, 17 December 2021, articles 6, 18, 27, 33 and 34
legalinfo.mn
“18.12. The core system shall be located in the territory of Mongolia.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, article 15.34 (breach of the Law on Public Information Transparency)
legalinfo.mn
Link checked 18 August 2026
Нийтийн мэдээллийн ил тод байдлын тухай хууль, 27.3, 27.7 дугаар зүйл
Act of parliament · Law on Public Information Transparency, articles 27.3 and 27.7, read with the Law on Geodesy and Cartography article 9 and the General Law on State Registration articles 6 to 8 · Mapping and location
Mongolia's national mapping database and its civil, property and company registration databases are named as foundational databases, so by law they must be located inside the country. If your product depends on a live feed from any of them, the source cannot be mirrored abroad.
Enforced by Ministry of Digital Development, Innovation and Communications
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe national mapping database and the civil, property and legal-entity registration databases are foundational databases and must sit in Mongolia.
Sources
- Official sourceLegal Information Unified SystemLaw on Public Information Transparency, articles 27.3 and 27.7
legalinfo.mn
“27.3. Foundational databases include the databases provided for in articles 6, 7 and 8 of the General Law on State Registration and article 9 of the Law on Geodesy and Cartography.”
Link checked 18 August 2026
Кибер аюулгүй байдлын тухай хууль
Act of parliament · Law on Cyber Security, 17 December 2021 (amended 6 January 2023), articles 9-1, 17 and 19 · Finance
Seventeen categories of organisation count as critical information infrastructure, including banks running the unified payment and settlement systems, second and third-level hospitals, dominant telecoms and IT providers, data centres, energy, water, transport and border control. They face yearly risk assessments, two-yearly security audits, immediate incident reporting and intelligence agency sign-off if a foreign firm does the assessment.
Enforced by Ministry of Digital Development, Innovation and Communications
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Assess high-risk projects — 1 yearCritical infrastructure: cyber risk assessment every year, and after every change to the system or network. Ordinary IT service providers: every two years.
- Independent audit — 2 yearsCritical infrastructure: information security audit every two years. Ordinary IT service providers: every year. An audit to an international standard counts.
- Report cyber incidentsNotify the relevant cyber attack response centre immediately; notify affected users immediately. Send the audit and assessment reports to the centre within one month of receiving them.
- Appoint a data protection officerA unit or a named officer responsible for cyber security is required.
- Keep logsKeep information system and network activity logs for the period set in the general cyber security procedure approved by the Government.
- Hold a security certificateArticle 19.2.3 requires critical infrastructure organisations to adopt information security standards.
- Do not hand data to foreign authorities on demandArticle 19.2.12: if a foreign national or foreign company carries out the cyber risk assessment, the intelligence agency's opinion must be obtained first.
What it costs if you get it wrong
- Fixed maximum fine: 10,000,000 tugrik (10,000 units) for a critical infrastructure legal entity — about $3 thousandFailing to comply with a requirement of the competent authority on cyber security; also 10,000 units for disclosing an audit or risk assessment report
- Fixed maximum fine: 2,000,000 tugrik (2,000 units) — about $570Having no system to detect, record and stop cyber attacks, or not being connected to a compliant response centre
Sources
- Official sourceLegal Information Unified SystemLaw on Cyber Security, 17 December 2021, articles 9-1, 17, 19, 20 to 23 and 25
legalinfo.mn
“19.2.12. Where a foreign national or a foreign legal entity is to carry out the cyber security risk assessment, the opinion of the intelligence organisation shall be obtained.”
Link checked 18 August 2026
- Official sourceLegal Information Unified SystemLaw on Infringements, article 14.13 (breach of the Law on Cyber Security)
legalinfo.mn
Link checked 18 August 2026
- Official sourceMinistry of Digital Development, Innovation and CommunicationsRegister of 49 legal entities permitted to carry out information security audits
mddic.gov.mn
Link checked 18 August 2026
Үндэсний төлбөрийн системийн тухай хууль
Act of parliament · Law on the National Payment System, 31 May 2017, articles 11.3.7 and 30 · Payments
Mongolia has no payments localisation rule that we could find, but it does have an unusually long retention floor: payment operators, participants and service providers must keep payment records for at least 15 years. Licence applications to the central bank must set out how transaction data is protected in processing and storage.
Enforced by Bank of Mongolia
Transfer model: Approval each time · Accepted routes: Explicit consent
What it makes you do
- Keep data for a minimum period — 15 yearsDocuments arising from payment system activity must be kept for at least 15 years from receipt or creation.
- Register or notifyOperating a payment system or providing payment services needs a permission from the Bank of Mongolia, and the application must describe the IT system and how transaction data is protected while processed and stored.
- Secure the data
Sources
- Official sourceLegal Information Unified SystemLaw on the National Payment System, articles 11.3.7 and 30
legalinfo.mn
“30.1. ... shall keep documents created in the course of activity related to the payment system for not less than 15 years from the date of receipt or creation.”
Link checked 18 August 2026
- Official sourceBank of MongoliaPayment system laws and legal acts
mongolbank.mn
Link checked 18 August 2026
Харилцаа холбооны тухай хууль, 19-1 дүгээр зүйл
Act of parliament · Law on Telecommunications, 18 October 2001, article 19-1 (added by the law of 6 January 2023), read with the Law on Permits article 8.1(9.3) · Telecoms
We found no rule requiring telecoms subscriber data to stay in Mongolia, checked on 18 August 2026. But building data storage infrastructure or a content delivery network inside Mongolia is itself a licensed telecoms activity, so a local point of presence needs a licence from the Communications Regulatory Commission.
Enforced by Communications Regulatory Commission of Mongolia
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyRunning data storage infrastructure, a content delivery network, internet protocol interconnection or a virtual network between demarcation points is a licensed information network activity.
- Secure the dataArticle 25.2.4: operators must keep and protect the secrecy of all information passing over their network.
What it costs if you get it wrong
- Loss of your licenceArticle 15.1.2: disclosing the secrecy of communications and correspondence
Sources
- Official sourceLegal Information Unified SystemLaw on Telecommunications, articles 15.1.2, 19-1 and 25.2.4
legalinfo.mn
“19-1.1. The activity of using an information network and providing services under article 8.1(9.3) of the Law on Permits includes internet protocol interconnection and data storage infrastructure, content delivery networks and virtual networks between demarcation points.”
Link checked 18 August 2026
- Official sourceCommunications Regulatory Commission of MongoliaProcedures, terms and requirements approved by the Communications Regulatory Commission (reviewed for data residency rules; none found)
crc.gov.mn
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
How broadly the Ministry actually reads order A/90's server rule, given that 'sensitive data' includes the content of letters, e-mail and messages
Taken literally, clause 3.2 would put an ordinary hosted company mailbox inside a server-in-Mongolia obligation. We found no published guidance narrowing it and no enforcement action testing it. The text is verified; the practice is not.
Whether the National Human Rights Commission has issued any data protection decision, recommendation or demand since 1 May 2022
The Commission's website is a JavaScript application; neither its pages nor its backend interface could be retrieved, and its report archive returned an error. We can evidence its legal powers but not its casework.
The exact log retention period for information system activity logs under the Law on Cyber Security
Articles 17.1.3 and 19.2.9 delegate the period to the general cyber security procedure approved by the Government. We could not locate that resolution's text.
Whether any Bank of Mongolia or Financial Regulatory Commission regulation imposes a banking, insurance or securities data residency rule
The statutes contain none, but we reviewed only the statutes and the regulators' index pages, not every internal procedure. Rated 'no rule found, checked 18 August 2026', not 'no rule exists'.
The content and status of the joint order A/130 and A/58 of 16 April 2025 on health service software
The Ministry's legal framework page lists it, but the linked PDF on the Ministry's own server redirects to itself and cannot be downloaded. It may add further health-sector storage or integration requirements.
The contents, bill number and consultation deadline of the draft Data Law
The Ministry's home page carries the consultation notice and the Government meeting minute of 13 May 2026, but the linked detail page returns a 404 error and no draft text is published on the site.
Reports that the UN Special Rapporteur on the right to privacy criticised Mongolia's fragmented supervision in February 2026 and recommended a dedicated independent data protection authority
Reported by a professional source. We could not reach the United Nations document itself, and there is no Mongolian government publication of it. Treated as indicative only.
Whether the Law on Protection of Personal Information reaches a foreign company with no establishment or server in Mongolia
Article 3 is silent on territory. There is no case law, no regulator guidance and no local representative duty, so the honest answer is that the question has not been resolved in Mongolia.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Mongolia versus Argentina
- Mongolia versus Armenia
- Mongolia versus Australia
- Mongolia versus Austria
- Mongolia versus Azerbaijan
- Mongolia versus Brazil
- Mongolia versus Bulgaria
- Mongolia versus Cambodia
- Mongolia versus Canada
- Mongolia versus China
- Mongolia versus Croatia
- Mongolia versus Cyprus
- Mongolia versus Estonia
- Mongolia versus France
- Mongolia versus Georgia
- Mongolia versus Germany
- Mongolia versus Greece
- Mongolia versus Hong Kong SAR
- Mongolia versus Hungary
- Mongolia versus Iceland
- Mongolia versus India
- Mongolia versus Indonesia
- Mongolia versus Ireland
- Mongolia versus Israel
- Mongolia versus Italy
- Mongolia versus Japan
- Mongolia versus Latvia
- Mongolia versus Lithuania
- Mongolia versus Luxembourg
- Mongolia versus Malta
- Mongolia versus Mexico
- Mongolia versus Nepal
- Mongolia versus Netherlands
- Mongolia versus Poland
- Mongolia versus Russia
- Mongolia versus Saudi Arabia
- Mongolia versus Serbia
- Mongolia versus Singapore
- Mongolia versus Slovakia
- Mongolia versus Slovenia
- Mongolia versus South Korea
- Mongolia versus Spain
- Mongolia versus Sri Lanka
- Mongolia versus Sweden
- Mongolia versus Switzerland
- Mongolia versus Taiwan
- Mongolia versus Thailand
- Mongolia versus Turkey
- Mongolia versus Ukraine
- Mongolia versus United Arab Emirates
- Mongolia versus United Kingdom
- Mongolia versus United States
- Mongolia versus Uzbekistan