| Field | Detail |
|---|---|
| Jurisdiction | United Mexican States (Estados Unidos Mexicanos) |
| Law | Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) |
| Current statute | New LFPDPPP published March 20, 2025; effective March 21, 2025 — abrogates the 2010 law |
| Prior statute | Original LFPDPPP enacted July 5, 2010 (effective July 6, 2010); Reglamento de la LFPDPPP (December 21, 2011) |
| Regulator | Secretaría Anticorrupción y Buen Gobierno (SABG) — assumed the data-protection mandate after INAI was dissolved in the 2025 reform |
| Official Text | diputados.gob.mx |
Mexico replaced the 2010 LFPDPPP with a new statute published in the Diario Oficial de la Federación on March 20, 2025 (effective the following day). The autonomous regulator INAI was dissolved, and its data-protection functions were transferred to the Secretaría Anticorrupción y Buen Gobierno (SABG) within the federal executive branch.
Most substantive obligations carry forward — the data-protection principles, ARCO rights, the Aviso de Privacidad requirement, and the sensitive-data regime remain the backbone of the law. Notable additions in the 2025 reform include an express right to object to automated decision-making that significantly affects a data subject, explicit data-retention / deletion duties, and reinforced confidentiality obligations surviving termination of the processing relationship.
Sections below describing INAI's role should be read as referring to its successor authority (SABG). References to specific articles reflect the law's long-standing structure; confirm the exact article numbering against the current consolidated text before relying on it in filings.
The LFPDPPP is Mexico's primary private-sector personal data protection law. The original 2010 statute was the first comprehensive data protection law in Latin America; it was abrogated and replaced by a new LFPDPPP in March 2025 (see the reform note above). The law remains the primary framework governing how private companies (particulares) in Mexico collect, use, store, and share personal data.
The law applies to any natural person or private legal entity (persona física o moral) that processes personal data, regardless of where they are located, if they target individuals in Mexico or process data collected in Mexico.
| Principle (Principio) | Description |
|---|---|
| Legality (Licitud) | Data must be obtained lawfully and not through deception |
| Consent (Consentimiento) | Processing requires consent unless a legal exception applies |
| Information / Notice (Información) | Data subjects must be informed via Aviso de Privacidad before collection |
| Quality (Calidad) | Data must be accurate, complete, and up to date |
| Purpose (Finalidad) | Data may only be used for the stated purposes in the Aviso |
| Loyalty (Lealtad) | No processing that harms data subjects' interests |
| Proportionality (Proporcionalidad) | Only data necessary for the stated purpose may be collected |
| Responsibility (Responsabilidad) | The responsable (controller) must ensure compliance throughout the data lifecycle |
ARCO rights (derechos ARCO) are the four fundamental rights of data subjects under the LFPDPPP:
| Right | Spanish | Description | Response Deadline |
|---|---|---|---|
| Access | Acceso | Obtain a copy of personal data held and how it is being processed | 20 business days |
| Rectification | Rectificación | Correct inaccurate or incomplete data | 20 business days |
| Cancellation | Cancelación | Request deletion of data when no longer necessary or lawfully held | 20 business days |
| Opposition | Oposición | Object to processing for specific purposes | 20 business days |
- Data subject submits written request to the responsable identifying themselves and specifying the right they wish to exercise
- Responsable has 20 business days to respond (extendable by another 20 days with justification)
- If request is granted, action must be taken within 15 business days of the decision
- If denied, data subject may file a complaint with INAI (recurso de revisión)
- INAI has authority to order compliance and impose sanctions
The Aviso de Privacidad (Privacy Notice) must be provided to data subjects before or at the time of data collection. It must contain:
| Element | Requirement |
|---|---|
| Identity and address of responsable | Legal name, address, and if applicable, representative |
| Purposes (finalidades) | Primary and secondary purposes for which data is collected |
| Transfer information | Whether data will be transferred and to whom; purpose of transfer |
| ARCO procedure | How data subjects can exercise ARCO rights |
| Consent mechanism | How consent is obtained for sensitive data or secondary purposes |
| Changes to Aviso | How data subjects will be notified of updates |
The Aviso may be full, simplified, or short-form depending on how data is collected (in-person, digital, incidental). Simplified notices are permitted for digital contexts with a link to the full notice.
Sensitive data requires express, written consent (consentimiento expreso) — implied or tacit consent is insufficient.
Categories of sensitive data:
| Category | Examples |
|---|---|
| Racial or ethnic origin (origen racial o étnico) | Ethnicity, indigenous identity |
| Present and future health condition (estado de salud) | Medical history, diagnoses |
| Genetic information (información genética) | DNA profiles |
| Religious, philosophical, or moral beliefs (creencias religiosas) | Faith, ideology |
| Union membership (afiliación sindical) | Trade union membership |
| Political opinions (opiniones políticas) | Party affiliation, voting data |
| Sexual preference (preferencia sexual) | Sexual orientation |
| Biometric data (datos biométricos) | Fingerprints, facial recognition |
Processing personal data generally requires consent unless one of the following exceptions applies:
- Required by law (obligación legal)
- Necessary for a contractual relationship with the data subject
- Vital interests of the data subject (life/safety)
- Publicly available information (datos de acceso público)
- Listed in registers established by public authority
- Necessary for medical treatment or prevention
- Rights and obligations in a legal proceeding
International data transfers (transferencias internacionales) to third parties abroad are permitted only when:
- The recipient provides equivalent data protection guarantees
- Data subjects have consented to the transfer
- An exception applies (contractual necessity, legal obligation, vital interests, public interest)
Transfers may be formalized through:
- Standard Contractual Clauses (cláusulas contractuales) approved by INAI
- Binding corporate rules (reglas corporativas vinculantes) for intragroup transfers
- Adequacy determination (Mexico does not maintain a formal adequacy list; equivalence is assessed case-by-case)
Until the 2025 reform, the LFPDPPP was enforced by INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales), an autonomous constitutional body. The 2025 reform dissolved INAI and transferred its data-protection enforcement mandate to the Secretaría Anticorrupción y Buen Gobierno (SABG). The enforcement powers below carry over to the successor authority.
- Investigate complaints from data subjects
- Conduct audits and inspections (verificaciones)
- Issue binding resolutions
- Impose administrative fines
| Violation | Fine Range |
|---|---|
| Failure to provide Aviso de Privacidad | MXN 100 to 160,000 days of minimum wage |
| Processing without consent where required | MXN 100 to 320,000 days |
| Failure to comply with ARCO requests | MXN 100 to 160,000 days |
| Failing to maintain security measures | MXN 100 to 320,000 days |
| Criminal liability (repeat/intentional) | Imprisonment 3 months to 3 years |
INAI enforcement priorities include: financial services, healthcare, telecommunications, and large-scale data brokers.
| Framework | Relationship |
|---|---|
| Reglamento LFPDPPP (2011) | Implementing regulations; detailed procedures for ARCO requests, security measures, transfers |
| NOM-151-SCFI-2016 | Technical standard for electronic message preservation; relevant for compliance records |
| Ley Federal de Protección de Datos en Posesión de Sujetos Obligados | Separate law for public sector; not covered by LFPDPPP |
| GDPR | No formal adequacy relationship; Mexico-EU data transfers require SCCs or consent |
- Aviso de Privacidad is non-negotiable — it must be presented before or at collection; missing it is the most commonly sanctioned violation
- ARCO requests have hard deadlines — 20 business days to respond; build this into your customer support workflow
- Sensitive data requires express written consent — any product handling health, biometric, or belief data needs documented consent chains
- The regulator is active (now SABG, formerly INAI) — enforcement has targeted major brands across retail, financial services, and HR platforms; the 2025 reform moved this mandate from INAI to the Secretaría Anticorrupción y Buen Gobierno
- Cross-border transfers need a legal mechanism — BYOC deployment keeps data in Mexico, eliminating the transfer question entirely
- B2B contracts must include data protection clauses — the Responsable/Encargado (controller/processor) relationship must be formalized contractually