Data Protection in Mongolia

Security in Mongolia

Data Controllers must take the following measures for the purpose of maintaining data security:

  • Adopt internal data security rules and regulations;
  • Approve a plan in accordance with the law to take measures and deliver notice to the state authority and the Data Owner in the event of data loss;
  • Take all measures to ensure the integrity, confidentiality and accessibility of information technology system used for data collection, processing and use;
  • Adopt and follow procedures and instructions on restricting the use of data, deleting the data and making it impossible to identify the Data Owner; and
  • In the event of making decisions that affect the rights, freedom and legitimate interests of the Data Owner or regularly processing Sensitive Personal Data, the Data Controller must evaluate the situation in order to ensure the security of data processing activities. Guidelines and procedures for the evaluation will be adopted by the Ministry of Digital Development, Innovation and Communications as recommended by the National Human Rights Commission.

On 11 September 2023, the Ministry of Digital Development, Innovation and Communications adopted the procedure on "General requirement for maintaining information security during the collection, processing and use of Personal Data" ("Information Security Requirement"). As per the Information Security Requirement, the Data Controller must follow the below principles when collecting, processing and using the Sensitive Personal Data in addition to those provided under the Data Protection Law:

  • Transparency;
  • Fit for purpose;
  • Maintain storage limitations;
  • Responsible;
  • Based on risk evaluation; and
  • Have integrated information system.

According to the Information Security Requirement, the Data Controller must comply with certain technological security requirements, including:

  • Adopt and implement internal information security regulation;
  • Employ unit or personnel in charge of information security;
  • Use information processing program, network and equipment that are approved by the authorized entity;
  • Use licensed program in order to prevent information security risks and conduct an information security evaluation every two years or when necessary;
  • Conduct an information security audit on an annual basis;
  • Maintain historical records of information changes, deletions, and restorations; and
  • Monitor and ensure the integrity and confidentiality of the information.

The Information Security Requirement further requires that the information processing server of the Data Controller must:

  • be located in the territory of Mongolia;
  • be accessible only from Mongolia;
  • be placed in the dedicated technical room;
  • be able to increase the capacity of the server if necessary;
  • be able to exchange information through the state information exchange system "KHUR";
  • be connected to the network time server of the Communications Regulatory Commission of Mongolia;
  • be protected by "SSL" certificate; and
  • be able to be backed up on a regular basis.

The Cyber Security Law of Mongolia, adopted by the Parliament on 17 December 2021 regulates matters pertaining to the establishment of systems, principles and legal framework for ensuring cyber security. According to the Cyber Security Law, “cyber security system” that is responsible for ensuring cyber security includes the Government, intelligence agency, state-owned legal entities, police organization, citizens, legal entities and entities with critical information infrastructure, such as entities operating in the energy, health and payment sectors, as well as database operators and border ports. For instance, the Law provides that an individual person must be responsible for maintaining cyber security of himself and individuals under his or her care.

Continue reading

  • no results

Previous topic
Back to top