Law / Mongolia

Mongolia

13 of 16 named instruments researched to a stage, across five of the six areas of law we track: 13 in force. As of 15 September 2026.

  1. AI law none researched
  2. Privacy law 7
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 2

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law7 instruments, 7 in force

Research summary (275 words)

Mongolia's Law on Protection of Personal Data of a Person (17 December 2021, in force 1 May 2022) is the richest, most modern instrument in this batch.

Art. 4.1.1's biometric-information definition explicitly names fingerprint, iris, face, and voice as illustrative examples, technology-mediated by its own terms, the only jurisdiction in this batch whose statute names a voice or face modality at all, and Art. 4.1.12 folds biometric and genetic information directly into the definition of a person's sensitive information rather than treating it as a separate track.

Art. 14 requires a default prohibition on transferring personal data abroad, lifted only by a statutory basis, an international treaty, or the subject's consent, with no adequacy-assessment mechanism and no additional public-order, health, or defense fallback grounds of the kind Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan all carry; the cross-border restriction here is strict rather than moderate for that reason, though the Act imposes no localization or domestic-storage requirement at all.

Art. 25.1.3 gives Mongolia the batch's clearest breach-notification mechanism, requiring the digital-development regulator to act immediately (a defined qualitative standard, not a numeric deadline) on receiving a controller's notification of a security breach or cyberattack, and Art. 31 imposes a real, retroactive duty to destroy fingerprint data collected before the Law took effect unless separately authorized.

Oversight is split between a designated member of the National Human Rights Commission and the state digital-development body, with penalties deferred to the separate Criminal Law and Law on Violations, neither read. Chapter 7 (Art. 27) separately regulates the physical placement of audio, video, and audio-video recording devices, a rule not slotted into any registered attribute and noted here in prose only.

Biometric privacy

Law on Protection of Personal Data, biometric information definition and legacy fingerprint destruction

Law on Protection of Personal Data (17 December 2021), Art. 4.1.1; Art. 31official text, legalinfo.mn, Mongolia's official legal-information portal

In force since 1 May 2022. Binds public and private bodies.

What this law does

Art. 4.1.1, read in full, defines biometric information as unique bodily data allowing identification of a person with the help of equipment, technical means, or software, and explicitly lists fingerprint pattern, iris, face, voice, and body-movement characteristics as examples, the only jurisdiction in this batch whose statute names a voice or face modality.

Art. 31 (Transitional provisions), read in full, requires destruction of fingerprint data collected by an information controller before the Law entered into force, except as authorized by law, with a government-organized working group to oversee that destruction, a concrete retroactive remediation duty with no parallel found elsewhere in this batch.

What it requires

Breach notification

Law on Protection of Personal Data, breach notification

Law on Protection of Personal Data (17 December 2021), Art. 25.1.3; Art. 10.5official text, legalinfo.mn, Mongolia's official legal-information portal

In force since 1 May 2022. Binds public and private bodies.

What this law does

Art. 25.1.3 has the state digital-development and communications body receive and register notifications submitted by information controllers regarding a security breach of, or cyberattack on, information systems, and take necessary measures immediately, "immediately" itself being a defined term at Art. 4.1.3 meaning the shortest possible period of time, a qualitative rather than numeric standard.

This establishes the regulator's own immediate-action duty on receiving a notification; whether the Act imposes its own numeric deadline on a controller's initial notification is not established here (Arts. 18-23). Art. 10.5 separately provides that meeting the Art. 25.1.2 security requirements is not grounds for exemption from liability arising from information loss.

What it requires

Comprehensive regime

Law on Protection of Personal Data, comprehensive regime

Law on Protection of Personal Data (17 December 2021), in force 1 May 2022, Arts. 1-4official text, legalinfo.mn, Mongolia's official legal-information portal

In force since 1 May 2022. Binds public and private bodies.

What this law does

The Law applies to persons, legal entities, and organizations without legal-entity status that collect, process, use, or secure personal information, including via technical devices and software.

It exempts purely personal or household-family processing that does not infringe the person's own privacy, placing recording devices to protect one's own property or the life or health of oneself or family members, using one's own biometric information for the same purpose, and information legally required to be made public. Arts. 6-8, the Act's general lawful-basis articles, are cross-referenced by Art. 9.2.1 and are not summarised here.

What it requires

Cross border transfer

Law on Protection of Personal Data, cross-border transfer

Law on Protection of Personal Data (17 December 2021), Art. 14official text, legalinfo.mn, Mongolia's official legal-information portal

In force since 1 May 2022. Binds public and private bodies.

What this law does

Art. 14, read in full, is a one-paragraph default prohibition: transferring information to a person, legal entity, or international organization in a foreign country is prohibited except as provided by law or an international treaty of Mongolia, or with the information owner's consent.

There is no adequacy-assessment mechanism and no localization or domestic-storage requirement of the kind Kazakhstan, Uzbekistan, Tajikistan, and Turkmenistan all carry; nothing in the Act requires a Mongolian database to exist at all. This is a structurally different, narrower-gateway approach than the rest of the batch, which is why the cross-border restriction here is strict rather than moderate.

What it requires

Data subject rights

Law on Protection of Personal Data, data subject rights

Law on Protection of Personal Data (17 December 2021), Art. 16; Art. 15official text, legalinfo.mn, Mongolia's official legal-information portal

In force since 1 May 2022. Binds public and private bodies.

What this law does

Art. 16, read in full, is the richest rights list in this batch: consent to or refuse collection and transfer, know whether one's data has been collected or processed, know third-party recipients, correct errors, request deletion, demand enforcement of a legal prohibition on collection, obtain a copy of one's own data, transmit that copy to a controller of one's own choosing (a genuine data-portability right), withdraw from an ongoing processing activity, and object to and demand reprocessing of a decision resulting from data processing.

Art. 16.2 separately gives the subject a right to have unlawful material or moral damage remedied. Art. 15 sets the general deletion grounds: unlawfully collected data, court or treaty-ordered deletion, purpose achieved, or another statutory ground.

What it requires

Enforcement supervision

Law on Protection of Personal Data, enforcement

Law on Protection of Personal Data (17 December 2021), Arts. 24-26, 28, 30official text, legalinfo.mn, Mongolia's official legal-information portal

In force since 1 May 2022. Binds public and private bodies.

What this law does

Oversight is split between two institutions. A designated member of the National Human Rights Commission (Art. 24.2) is specially responsible for information-protection activity, violations, and implementation of owner rights; the state digital-development and communications body (Art. 25) separately implements the Law, approves security requirements for sensitive, genetic, and biometric information processing, and receives breach notifications.

Art. 26 gives other state bodies continuing oversight within their existing competencies. Art. 28, read in extract, lets a complaint go to the competent authority or the National Human Rights Commission, with a further court appeal available. Art. 30, read in full, defers penalties to the Public Service Law or Labor Law for officials, and to the Criminal Law or the Law on Violations for persons and legal entities, none of which was read. No standalone private right of action distinct from Art. 16.2's damages-and-rights-protection clause was found.

What it requires

Sensitive categories

Law on Protection of Personal Data, sensitive personal information

Law on Protection of Personal Data (17 December 2021), Arts. 4.1.12, 9official text, legalinfo.mn, Mongolia's official legal-information portal

In force since 1 May 2022. Binds public and private bodies.

What this law does

Art. 4.1.12 defines a person's sensitive information to include origin or ethnicity, religion, belief, health, correspondence, genetic and biometric information together, the private key of a digital signature, criminal-sentence status, sexual orientation, gender identity and expression, and sexual-relations information, folding biometric and genetic data directly into the sensitive-information definition rather than treating it as a separate track.

Art. 9 confirms this status carries elevated protection and prohibits collection, processing, or use except under the Act's general lawful-basis articles (Arts. 6-7), a health worker's legal duty, or evidence required by law in response to a legal claim.

What it requires

Scraping law2 instruments, 2 in force

Research summary (227 words)

Mongolia's Law on Copyright (Revised edition, promulgated 6 May 2021) is the clearest instrument reaching scraping-adjacent activity: it protects a database as a creative compilation and prohibits reproducing, systematically uploading, or otherwise developing a database's information inconsistent with the rights and legitimate interests of the person who created it, while its general quotation, news, research, and library exceptions create no dedicated text-and-data-mining exception for training on scraped text.

The Law on Cybersecurity (adopted 2021, in force 1 May 2022), read in full, runs to organizations with critical information infrastructure and entities connected to the state information consolidated network rather than to an ordinary web crawler or aggregator, so it does not bind a private scraping operator on the text read.

A computer-misuse-specific criminal provision could not be confirmed here: legalinfo.mn hosts a Criminal Code text headed with a 3 January 2002 adoption date whose Chapter 25 (Arts. 226-229) criminalizes unauthorized alteration of computer data or programs, unlawful acquisition of computer information, and creating or distributing malicious software, but a later Criminal Code that other Mongolian amendment acts cite as adopted 3 December 2015 could not be located as its own consolidated text on legalinfo.mn, so which text presently governs computer-misuse offences is not confirmed.

Personal data scraped from a Mongolian source falls under the Law on Protection of Personal Data, already researched under this jurisdiction's privacy topic.

Cybersecurity law1 instrument, 1 in force

Research summary (660 words)

Mongolia's cyber-resilience law is the Law of Mongolia on Cyber Security (Кибер аюулгүй байдлын тухай), adopted by the State Great Khural of Mongolia on 17 December 2021 and in force since 1 May 2022; a February 2025 Oxford Global Cyber Security Capacity Centre review and a 15 September 2026 search found no subsequent repeal or substantive amendment to the Law itself, though Mongolia's Criminal Code and its Laws on Communications, Violations, and Criminal Procedure were amended alongside the Law's original enactment to align cybercrime definitions with the Council of Europe's Budapest Convention, a change already reflected in this jurisdiction's scraping row rather than repeated here.

The Law binds four separate classes of legal person, and only one of the four reaches a declared LexLint activity.

A state-owned legal person (Art. 16, drawing its definition of 'state-owned legal person' from Article 13 of the Law on State and Local Properties) and a legal person providing information technology services in the processing, storing, distributing, computer-analytics, and shared-information-system-hosting sense of Article 17.1, both, like an organization with critical information infrastructure under Article 19 (a Government-adopted list spanning 17 named categories of business from power and water utilities to banks, fuel importers, strategic-mineral miners, and border-crossing control systems), are classifications this corpus's activity vocabulary cannot express: Article 17.1's shared-information-system hosting, processing and analytics description falls on the browser-or-API side of the line distributes_software_product's own definition draws, and none of the three classes names a specific digital-service category the way NIS2 names social networking platforms, marketplaces or search engines, so all three are recorded here rather than raised against a guessed activity, the same treatment this profile gives Singapore's five Cybersecurity Act bound-party classes and DORA's financial entities.

Article 17.1's duties for the class it does reach, an internal procedure, an officer or unit for cyber security, biennial risk assessments, annual information-security audits, a check on new information-technology products and their updates, and immediate notification of both the relevant center and affected users on a cyber-attack, and Article 19's parallel and heavier set for a critical-information-infrastructure operator, annual risk assessments, biennial audits, an action plan, a detection-and-termination system, and notification within one month of receiving a risk-assessment or audit report, are both real, substantial law, unreached by this topic's export for the same activity-vocabulary reason.

The fourth class, 'legal persons other than that stipulated in article 17.1' (Art. 17.3), is the residual catch-all that reaches every other legal person conducting activity in Mongolia's cyberspace, extended by Article 3.2 to a foreign or foreign-invested legal person operating through Mongolia's information systems and networks; it is the row raised as this jurisdiction's one security-topic instrument, flagged inclusively across this topic's baseline activity set because the duty carries no sector or personal-data gate at all.

The Law sets no security requirement a software product or connected device must meet to be placed on the market and no support-period or update duty running with a product once sold; the nearest text, Article 17.1.8's duty for an information-technology-service legal person to check its own new products and updates, is an operational duty on that narrower class rather than a market-placement regime, and it too sits inside the Article 17.1 deferral.

Enforcement of the Law runs through Article 24, which imposes an official's liability under the Law on Public Service or the Labor Law for non-criminal conduct (Art. 24.1) and a violator's liability under the Criminal Law or the Law on Violations (Art. 24.2, covering both an individual and a legal person) without stating a specific offense or a penalty figure in the Law's own text; the Criminal Law and the Law on Violations are not described here, so no penalty_structure is recorded for the instrument below.

Mongolia's breach-notification duty for personal data sits in the Law on Protection of Personal Data, already this jurisdiction's privacy row; an unauthorized-access or computer-misuse offense sits in the Criminal Code's Chapter 25/26 computer-crime provisions, already this jurisdiction's scraping row, and neither is repeated here.

Vulnerability and incident reporting

Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal Persons

Law of Mongolia on Cyber Security, adopted 17 December 2021, in force 1 May 2022, Art. 17.3Unofficial English translation, legalinfo.mn (Mongolia's national legal-information portal, operated by the Legal Institute)

In force since 1 May 2022. Binds private bodies.

What this law does

Article 17.3 binds every legal person in Mongolia other than one providing information technology processing, storage, distribution, computer-analytics or shared-information-system hosting services under Article 17.1, a narrower duty-bearer this jurisdiction's summary records rather than flags here.

That legal person must abide by the Government's common procedure for ensuring cyber security once adopted, notify the relevant center against cyber-attacks and violations of a cyber-attack or violation against it and obtain assistance where necessary, and comply with the recommendations and requirements the relevant authorities issue.

The Law extends this duty, like the rest of the Law, to a foreign or foreign-invested legal person operating through Mongolia's information systems and networks unless the Law states otherwise. The Public center, which receives this notification for a legal person outside the state information network and critical infrastructure, operates under the state central administrative organization in charge of digital development and communications.

The text sets no numeric clock for this notice, unlike the immediate-notification duty Articles 16.1.3, 17.1.2 and 19.2.14 place on a state-owned legal person, an information-technology-service legal person, and a critical-information-infrastructure operator. A violator faces liability under the Criminal Law or the Law on Violations, on Article 24.2's own cross-reference; the Law's own text names neither statute's specific offense or maximum penalty.

What it requires

Age gating law1 instrument, 1 in force

Research summary (188 words)

Mongolia's Law on Child Protection (5 February 2016, in force 1 September 2016) requires a citizen or legal entity possessing rights in the internet environment to maintain a special service package for children and, when concluding a service contract, to ask whether children under 18 are in the customer's care and agree whether adult-channel services will be used (art. 8.6).

The same Law separately bars publicizing, through newspapers, television, radio, or a digital network, the identity of a child reported to have committed or been the victim of a crime or violation (art. 8.4), a duty that runs to identifying disclosure rather than to age verification or gating, so it is described here rather than landed as a separate instrument.

The Law on Cybersecurity (adopted 2021, in force 1 May 2022), read in full for this jurisdiction's ai topic, contains no provision addressing a minor's access to a service. The Law on the Rights of the Child (2016), the Law on Broadcasting (2019), and the Law on Combating Cybercrime (2021) are not described here, and the Communications Regulatory Commission's own site (crc.gov.mn) renders only a client-side navigation shell.

Adult content age verification (AV)

Law on Child Protection, Internet-Service Child Package and Age Inquiry Duty

Law of Mongolia on Child Protection, 5 February 2016 (in force 1 September 2016), art. 8.6Unofficial English translation (translated 2023-07-20), National Legal Institute of Mongolia (legalinfo.mn)

In force since 1 September 2016. Binds private bodies.

What this law does

A citizen or legal entity possessing rights in the internet environment must maintain a special package of services devoted to children. When concluding a service contract, that citizen or legal entity must ask whether there are children under the age of 18 in the customer's care, and agree with the customer whether to use special channel services for adults.

The duty is part of the Law's original 2016 text; unlike the neighbouring paragraphs of the same article, it carries no later amendment note. Liability for a breach of the Law's child-protection duties is left to a separate Law on Violations, and, for conduct that amounts to a crime, to the Criminal Code; this Law states no fine or penalty figure of its own for art. 8.6.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (145 words)

Mongolia's Law on Copyright (Revised edition, promulgated 6 May 2021) permits quoting and republishing parts of a work for a press review or already-published press and broadcast content on public-interest topics, subject to attribution, a non-profit purpose, a fair-use extent, and no market harm to the original, so snippet and headline reproduction for news reporting has a general free-use ground rather than a dedicated exemption of its own.

The same Law separately names aggregators (defined as a person who collects and delivers content and offers it to the public) among the intermediaries that must not violate copyright on their networks and must act on infringement reports, and lists an unauthorized internet or digital link to a work as its own form of infringement.

No press-publisher neighbouring right, compelled platform-to-publisher bargaining regime, or hot-news misappropriation doctrine distinct from the copyright provisions above appears in the text.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.