WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Americas

Mexico Privacy & Data Protection Laws

Every regime below can apply to a business handling Mexico residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

March 21, 2025 (repealing and replacing the 2010 law of the same name)
Federal Law on the Protection of Personal Data Held by Private Parties (2025)
LFPDPPP (2025)
Verify details

Mexico replaced its 2010 data protection law outright in March 2025. The new LFPDPPP keeps the ARCO rights framework (Access, Rectification, Cancellation, Opposition) and the privacy-notice regime, adds transparency duties around automated decision-making, and — the structural change — reassigns enforcement. The independent regulator INAI was dissolved; its data-protection functions transferred to the executive branch, to the Secretaria Anticorrupcion y Buen Gobierno (SABG). Territorial scope is a means/establishment test rather than a GDPR-style targeting test: it reaches private parties processing personal data in Mexican territory, controllers established in Mexico, and controllers not established in Mexico that use means located in Mexican territory (or where Mexican law applies under contract or international law) — so the trigger below is modeled on established presence only, and a foreign business with no Mexican establishment or infrastructure should get specific advice rather than assuming coverage or non-coverage. Fines run from 100 to 320,000 times the UMA, doubled for sensitive-data violations.

Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares, published in the Diario Oficial de la Federacion March 20, 2025Read regulation →

Cross-Border Data Transfer · 1

Mexico regulates transfers by consent rather than by destination. Every transfer — domestic or international, it makes no difference — requires the data subject's consent unless a statutory exception applies, must be disclosed in the privacy notice, and must stay within the purpose that justified it. The recipient assumes the SAME obligations as the controller that transferred the data, and the burden of proving the transfer was lawful falls on both the transferring party and the recipient. There is no adequacy list to consult and no standard clauses to sign; the privacy notice is the compliance artefact. Marked 'check': the statutory exceptions were numbered Art. 37 under the 2010 law and the 2025 renumbering was not confirmed against the primary text, implementing regulations under the new law were still developing, and enforcement now sits with the Secretaria Anticorrupcion y Buen Gobierno rather than the dissolved INAI.

Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares, published in the Diario Oficial de la Federacion March 20, 2025Read regulation →

Data Security & Breach Notification · 1

Mexico's duty runs to the individual, not the regulator. Where a security breach significantly affects a data subject's patrimonial or moral rights, the controller must notify the affected data subject without delay, telling them the nature of the breach, the personal data involved, the steps they can take to protect themselves, and the corrective measures the controller has taken. There is no general duty to report to the supervisory authority — the function now sits with the Secretaria Anticorrupcion y Buen Gobierno (SABG) following INAI's dissolution — which makes Mexico an outlier among the regimes in this dataset and a live risk of over-notification for businesses reusing a GDPR playbook. Marked 'check': the 2025 law is recent, implementing regulations and SABG guidance are still developing, and mandatory authority reporting has been publicly floated for a future regulatory cycle. Confirm current position before relying on the absence of an authority-notification duty.

Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares, published in the Diario Oficial de la Federacion March 20, 2025Read regulation →

Other Americas jurisdictions