What Is Law on Personal Data Protection (revised edition)?
Mongolia’s operative statute is the revised Law on Personal Data Protection, enacted on 17 December 2021 and effective on 1 May 2022 under Article 32.1. Legalinfo marks the Mongolian text valid, and the reviewed Ministry legal-framework page shows no amendment entry. A 2026 Legalinfo proposal mentioning “data intermediaries” is expressly marked draft and is not operative law. The primary oversight and complaint authority is the National Human Rights Commission of Mongolia (NHRC), an unusual institutional structure for a personal-data regime. The NHRC supervises implementation and accepts, investigates, and resolves complaints concerning protected-rights violations. A separate digital-development and communications administrative body handles implementation, technical safety, and incident-notification functions. The law provides extensive Article 16 rights, but erasure is notably restricted: Article 15 requires erasure only on enumerated grounds, and erasure outside those grounds is generally prohibited. No Mongolia-specific complaint or deletion route directed at data brokers, people-search sites, or public-record aggregators was located under the current law.
At a glance
- Full name
- Law on Personal Data Protection (revised edition)
- Short code
- Law on Personal Data Protection
- Jurisdiction
- Mongolia
- Enacted
- 2021
- Last major update
- Enacted 17 December 2021 and effective 1 May 2022; no amendment entry was shown on the reviewed Ministry legal-framework page; a 2026 Data Law proposal mentioning data intermediaries remains a draft
- Regulator
- National Human Rights Commission of Mongolia (NHRC)
- Private right of action
- Yes
- Statutory citation
- Law on Personal Data Protection (revised edition), effective 1 May 2022
Scope, who Law on Personal Data Protection covers
Protected data
Data subject rights
Right to give or refuse consent
Right to know whether data was collected, processed, or used
Right to receive the information required by Article 8.2
Right to know which third party received or will receive data
Right to request correction, amendment, or supplementation
Right to request erasure only on legally enumerated grounds
Right to demand compliance where collection is prohibited or erasure is legally required
Right to obtain a paper or electronic copy and transfer it to a subject-selected controller
Right to request cancellation of collection, processing, or use, with written notice
Right to complain or provide an explanation regarding a processing-resulting decision, submit additional information, and demand reprocessing
Right to protection and compensation for unlawful material or non-pecuniary harm
Right to complain to the NHRC
Notable features
Mongolia places primary privacy oversight with the National Human Rights Commission rather than a dedicated data-protection agency. The law contains broad Article 16 rights, but Article 15 limits erasure to enumerated legal grounds. Cross-border transfers generally require Mongolian-law permission, an applicable treaty, or subject consent, and no adequacy list, standard contractual clause mechanism, or regulator-preapproval mechanism was located in the Personal Data Protection Law itself.
Enforcement & penalties
Regulator: National Human Rights Commission of Mongolia (NHRC)
Penalties: Administrative Offences Law Article 6.27 provides fines of 500 units for individuals and 5,000 units for legal entities for unlawful purpose-different use or adverse automated-decision processing. Unlawful acquisition, processing, transfer, or disclosure of sensitive data may attract 2,000 units for individuals and 20,000 units for legal entities. Criminal Code Article 13.10 provides a fine of 450-5,400 units, community service, or travel restriction for unlawful acquisition or transfer of protected private information; aggravated conduct may attract 5,400-27,000 units, travel restriction, or 1-5 years’ imprisonment. Article 13.11 provides a fine of 1,350-10,000 units, travel restriction, or 6 months-2 years’ imprisonment for unauthorized disclosure. Figures are reported as stated in units and are not currency-converted.
Private right of action: Article 16.2 provides rights protection and compensation for unlawful material and non-pecuniary harm, alongside the NHRC complaint route; no separate general private-action procedure was identified.
Relevance to data brokers
No Mongolia-specific complaint/deletion route expressly directed at data brokers, people-search sites, or public-record aggregators was located. General controller routes exist for information, correction, Article 15-conditioned erasure, permitted cancellation, and complaints under Article 18.2. A separate 2026 “Data Law” proposal defines “data intermediary” and proposes intermediary obligations, but it is confirmed as a draft, not current law.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Who oversees personal-data protection in Mongolia?+
The National Human Rights Commission of Mongolia is the primary oversight and complaint authority under Article 24. A separate digital-development and communications administrative body handles implementation, technical safety, and incident-notification functions.
Does Mongolia provide a general right to erase personal data?+
Not generally. Article 15 requires erasure only on enumerated grounds, including unlawful processing, legal or court obligations, achievement of the original purpose in specified circumstances, or another legal ground. Erasure outside those grounds is generally prohibited.
Does Mongolia have a dedicated data-broker deletion route?+
Not located. The current law provides general controller information, correction, legally conditioned erasure, cancellation, and complaint routes, but no named data-broker, people-search, or public-record procedure.
Official sources & citations
Other international privacy regimes
Law on Personal Data Protection sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
