Skip to content

Latest commit

 

History

History
176 lines (127 loc) · 10.3 KB

File metadata and controls

176 lines (127 loc) · 10.3 KB

LFPDPPP — Ley Federal de Protección de Datos Personales en Posesión de los Particulares

Metadata

Field Detail
Jurisdiction United Mexican States (Estados Unidos Mexicanos)
Law Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)
Current statute New LFPDPPP published March 20, 2025; effective March 21, 2025 — abrogates the 2010 law
Prior statute Original LFPDPPP enacted July 5, 2010 (effective July 6, 2010); Reglamento de la LFPDPPP (December 21, 2011)
Regulator Secretaría Anticorrupción y Buen Gobierno (SABG) — assumed the data-protection mandate after INAI was dissolved in the 2025 reform
Official Text diputados.gob.mx

⚠️ 2025 Reform — Read First

Mexico replaced the 2010 LFPDPPP with a new statute published in the Diario Oficial de la Federación on March 20, 2025 (effective the following day). The autonomous regulator INAI was dissolved, and its data-protection functions were transferred to the Secretaría Anticorrupción y Buen Gobierno (SABG) within the federal executive branch.

Most substantive obligations carry forward — the data-protection principles, ARCO rights, the Aviso de Privacidad requirement, and the sensitive-data regime remain the backbone of the law. Notable additions in the 2025 reform include an express right to object to automated decision-making that significantly affects a data subject, explicit data-retention / deletion duties, and reinforced confidentiality obligations surviving termination of the processing relationship.

Sections below describing INAI's role should be read as referring to its successor authority (SABG). References to specific articles reflect the law's long-standing structure; confirm the exact article numbering against the current consolidated text before relying on it in filings.


Overview

The LFPDPPP is Mexico's primary private-sector personal data protection law. The original 2010 statute was the first comprehensive data protection law in Latin America; it was abrogated and replaced by a new LFPDPPP in March 2025 (see the reform note above). The law remains the primary framework governing how private companies (particulares) in Mexico collect, use, store, and share personal data.

The law applies to any natural person or private legal entity (persona física o moral) that processes personal data, regardless of where they are located, if they target individuals in Mexico or process data collected in Mexico.


Core Data Protection Principles (Art. 6)

Principle (Principio) Description
Legality (Licitud) Data must be obtained lawfully and not through deception
Consent (Consentimiento) Processing requires consent unless a legal exception applies
Information / Notice (Información) Data subjects must be informed via Aviso de Privacidad before collection
Quality (Calidad) Data must be accurate, complete, and up to date
Purpose (Finalidad) Data may only be used for the stated purposes in the Aviso
Loyalty (Lealtad) No processing that harms data subjects' interests
Proportionality (Proporcionalidad) Only data necessary for the stated purpose may be collected
Responsibility (Responsabilidad) The responsable (controller) must ensure compliance throughout the data lifecycle

ARCO Rights (Art. 22–36)

ARCO rights (derechos ARCO) are the four fundamental rights of data subjects under the LFPDPPP:

Right Spanish Description Response Deadline
Access Acceso Obtain a copy of personal data held and how it is being processed 20 business days
Rectification Rectificación Correct inaccurate or incomplete data 20 business days
Cancellation Cancelación Request deletion of data when no longer necessary or lawfully held 20 business days
Opposition Oposición Object to processing for specific purposes 20 business days

ARCO Exercise Procedure

  1. Data subject submits written request to the responsable identifying themselves and specifying the right they wish to exercise
  2. Responsable has 20 business days to respond (extendable by another 20 days with justification)
  3. If request is granted, action must be taken within 15 business days of the decision
  4. If denied, data subject may file a complaint with INAI (recurso de revisión)
  5. INAI has authority to order compliance and impose sanctions

Aviso de Privacidad — Privacy Notice Requirements (Art. 15–17)

The Aviso de Privacidad (Privacy Notice) must be provided to data subjects before or at the time of data collection. It must contain:

Element Requirement
Identity and address of responsable Legal name, address, and if applicable, representative
Purposes (finalidades) Primary and secondary purposes for which data is collected
Transfer information Whether data will be transferred and to whom; purpose of transfer
ARCO procedure How data subjects can exercise ARCO rights
Consent mechanism How consent is obtained for sensitive data or secondary purposes
Changes to Aviso How data subjects will be notified of updates

The Aviso may be full, simplified, or short-form depending on how data is collected (in-person, digital, incidental). Simplified notices are permitted for digital contexts with a link to the full notice.


Sensitive Data (Datos Personales Sensibles) — Art. 3, 8–9

Sensitive data requires express, written consent (consentimiento expreso) — implied or tacit consent is insufficient.

Categories of sensitive data:

Category Examples
Racial or ethnic origin (origen racial o étnico) Ethnicity, indigenous identity
Present and future health condition (estado de salud) Medical history, diagnoses
Genetic information (información genética) DNA profiles
Religious, philosophical, or moral beliefs (creencias religiosas) Faith, ideology
Union membership (afiliación sindical) Trade union membership
Political opinions (opiniones políticas) Party affiliation, voting data
Sexual preference (preferencia sexual) Sexual orientation
Biometric data (datos biométricos) Fingerprints, facial recognition

Legal Bases for Processing (Art. 7–8)

Processing personal data generally requires consent unless one of the following exceptions applies:

  • Required by law (obligación legal)
  • Necessary for a contractual relationship with the data subject
  • Vital interests of the data subject (life/safety)
  • Publicly available information (datos de acceso público)
  • Listed in registers established by public authority
  • Necessary for medical treatment or prevention
  • Rights and obligations in a legal proceeding

Cross-Border Data Transfers (Art. 36–37)

International data transfers (transferencias internacionales) to third parties abroad are permitted only when:

  1. The recipient provides equivalent data protection guarantees
  2. Data subjects have consented to the transfer
  3. An exception applies (contractual necessity, legal obligation, vital interests, public interest)

Transfers may be formalized through:

  • Standard Contractual Clauses (cláusulas contractuales) approved by INAI
  • Binding corporate rules (reglas corporativas vinculantes) for intragroup transfers
  • Adequacy determination (Mexico does not maintain a formal adequacy list; equivalence is assessed case-by-case)

Enforcement (formerly INAI, now SABG)

Until the 2025 reform, the LFPDPPP was enforced by INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales), an autonomous constitutional body. The 2025 reform dissolved INAI and transferred its data-protection enforcement mandate to the Secretaría Anticorrupción y Buen Gobierno (SABG). The enforcement powers below carry over to the successor authority.

Powers

  • Investigate complaints from data subjects
  • Conduct audits and inspections (verificaciones)
  • Issue binding resolutions
  • Impose administrative fines

Penalties

Violation Fine Range
Failure to provide Aviso de Privacidad MXN 100 to 160,000 days of minimum wage
Processing without consent where required MXN 100 to 320,000 days
Failure to comply with ARCO requests MXN 100 to 160,000 days
Failing to maintain security measures MXN 100 to 320,000 days
Criminal liability (repeat/intentional) Imprisonment 3 months to 3 years

INAI enforcement priorities include: financial services, healthcare, telecommunications, and large-scale data brokers.


Relationship to Other Frameworks

Framework Relationship
Reglamento LFPDPPP (2011) Implementing regulations; detailed procedures for ARCO requests, security measures, transfers
NOM-151-SCFI-2016 Technical standard for electronic message preservation; relevant for compliance records
Ley Federal de Protección de Datos en Posesión de Sujetos Obligados Separate law for public sector; not covered by LFPDPPP
GDPR No formal adequacy relationship; Mexico-EU data transfers require SCCs or consent

Key Takeaways for Enterprise Buyers

  1. Aviso de Privacidad is non-negotiable — it must be presented before or at collection; missing it is the most commonly sanctioned violation
  2. ARCO requests have hard deadlines — 20 business days to respond; build this into your customer support workflow
  3. Sensitive data requires express written consent — any product handling health, biometric, or belief data needs documented consent chains
  4. The regulator is active (now SABG, formerly INAI) — enforcement has targeted major brands across retail, financial services, and HR platforms; the 2025 reform moved this mandate from INAI to the Secretaría Anticorrupción y Buen Gobierno
  5. Cross-border transfers need a legal mechanism — BYOC deployment keeps data in Mexico, eliminating the transfer question entirely
  6. B2B contracts must include data protection clauses — the Responsable/Encargado (controller/processor) relationship must be formalized contractually