en mn jp
09:00 ~ 18:00
(+976)7704-1414
contact@akp.mn

The duties and liabilities of organizations in relation to the protection of personal data

Posted by: Alison&Kate Partners
Date: 2026-05-26
The duties and liabilities of organizations in relation to the protection of personal data

Author: Paralegal A. Nomin-Erdene

Hello, we are pleased to meet you again with our regular blog from AKP Law Firm, which aims to deliver legal knowledge in a simple and understandable way.

In this blog, we will introduce the obligations and responsibilities of organizations regarding the protection of personal data.

This article will cover the following topics: 

  1. What is Personal Data?

  2. Organizational Activities and Personal Data

  3. The Obligations and Responsibilities of Organizations in Protecting Personal Data

 

  1. What is Personal Data?

When we wake up in the morning and unlock our phones, our name, photo, location, and many other details about us instantly appear on the screen. Even when making an online purchase, we are asked for our age, address, and phone number. While these might seem ordinary, in reality, they represent one of the most valuable aspects of a person — personal data.

Personal data is the key to identifying who you are. Your name, date of birth, home address, even the kind of music you listen to or the stores you frequent, all become part of your identity. That is why personal data is not just a collection of numbers and letters, but a vital value that safeguards your freedom, privacy, and security.

Each country defines what constitutes personal data through its own legislation. Mongolia has also set out a legal definition in its law.

According to Article 4.1.11 of the Law on the Protection of Personal Data of Mongolia:

"Personal data refers to sensitive information of an individual, as well as the person's patronymic name, given name, date and place of birth, residential address, location, civil registration number, property, education, membership, electronic identifiers, and any other information that directly or indirectly identifies, or makes it possible to identify, a person."

1)      Electronic identifiers refer to information used to identify a person in the digital environment, such as system login names, email addresses, social media accounts, telecommunication addresses (wired or wireless), other devices, or information within information systems. For example, a person's email address, Facebook account, banking app login, or IP address are considered part of their personal data.

2)      Information that directly identifies a person is information that allows the identification of a specific individual using that information alone. Examples include a civil registration number, email address, etc.

3)      Information that indirectly identifies a person is information that can be used to identify an individual by combining data from multiple sources. Examples include an employee ID number, vehicle registration number, etc.

4)      Sensitive information refers to data about a person's ethnicity, ancestry, religion, beliefs, health, correspondence, genetic and biometric information, personal cryptographic keys, criminal record (whether serving or having served a sentence), sexual and gender orientation, expressions, and information about sexual activity.

i)      Genetic information – Unique information that reflects a person's body, health, and inherited traits, determined through biological sample analysis. For example, DNA.

ii)     Biometric information – Physical data related to a person that can be used to identify them through devices, equipment, or software, such as fingerprints, iris patterns, facial features, voice, and unique body movement characteristics.

iii)    Health information- Information about a person's physical or mental health, as well as details about health services or treatments received.

From this, it is clear that personal data is not limited to official records like names or civil registration numbers; it encompasses a broad range of information, from digital traces we leave online to the unique physical characteristics of our bodies. Since all of this makes a person unique and irreplaceable, protecting and properly using it is of utmost importance.

In the next section, we will examine what types of personal data organizations and businesses can collect, process, and use.

  1. Organizational Activities and Personal Data

 Businesses and organizations may collect, process, and use personal data in the following cases:

 1)    Based on legal grounds- When the law allows the collection, use, or processing of personal data.

2)    In labor relations- When necessary to exercise rights or fulfill duties in the course of employment, as permitted by law.

3)    For contract purposes- To establish a contract and ensure its proper execution.

4)    Publicly disclosed information- When the information has been made public in accordance with the law.

5)    Anonymized or non-identifiable data- For purposes such as historical research, scientific studies, art, literature, open data, or statistical reporting, where personal identification is not possible.

6)     With the consent of the data subject- In cases not covered by the above grounds, personal data may only be collected, processed, and used with the explicit consent of the data owner.

 Thus, organizations are obligated to use personal data only within the legal framework and for specific purposes. Violating this duty can lead to liability under the Law on Violations and the Criminal Code.

  1. Organizational Responsibilities and Liabilities Regarding Personal Data Protection

 Protecting personal data is not merely an ethical issue but involves strict legal liability. Every organization has a duty to strictly observe the individual's consent and legal grounds when collecting, storing, and using information. In case of a violation of this duty, liabilities specified in the Law on Infringement and the Criminal Code are imposed.

 According to Article 6.27 of the Law on Infringement:

  • If personal data is used for purposes other than what was initially consented to, a fine of 500,000 MNT shall be imposed on individuals and 5,000,000 MNT on organizations.

·         If information is improperly processed electronically without human intervention, resulting in a decision that may negatively affect human rights and freedoms, the same fine as above shall be imposed.

·         However, if the illegal acquisition, processing, transfer, or disclosure of a person's sensitive information does not reach the level of criminal liability, a higher fine is imposed: 2,000,000 MNT for individuals and 20,000,000 MNT for organizations.

Under Articles 13.10 and 13.11 of the Criminal Code of Mongolia, violations with more severe consequences, extremely serious negative impacts on society, or massive damages are considered criminal offenses. Liabilities are particularly stricter if the offense is committed using telecommunications or electronic devices, or if an official breaches personal privacy while performing their duties.

For example, the Criminal Code stipulates the following penalties:

·         A fine ranging from 450,000 to 27,000,000 MNT.

·         Restriction of the right to travel for a period of 1 month to 5 years.

·         Imprisonment for a period of 6 months to 5 years.

     Therefore, when protecting personal data, organizations must take the following measures:

·         Approve and enforce internal regulations related to data collection and processing.

·         Have internal control policies and information security evaluated and audited once a year by a professional organization or individual.

·         Regularly provide training to employees regarding information confidentiality and internal regulations.

By doing so, the organization not only reduces legal risks but also protects the trust of its consumers and clients. However, since adapting every law and regulation to fit your specific operational characteristics is complex, consulting a professional lawyer is the best solution.

If you want to receive detailed advice and information related to this article,  

 please contact us at the address below.   

 

Phone: +976 77041414 

Email: Contact@akp.mn