Data Security & Breach Notification
Federal Law on the Protection of Personal Data Held by Private Parties (2025) — security breaches
Mexico · March 21, 2025
Verify detailsMexico's duty runs to the individual, not the regulator. Where a security breach significantly affects a data subject's patrimonial or moral rights, the controller must notify the affected data subject without delay, telling them the nature of the breach, the personal data involved, the steps they can take to protect themselves, and the corrective measures the controller has taken. There is no general duty to report to the supervisory authority — the function now sits with the Secretaria Anticorrupcion y Buen Gobierno (SABG) following INAI's dissolution — which makes Mexico an outlier among the regimes in this dataset and a live risk of over-notification for businesses reusing a GDPR playbook. Marked 'check': the 2025 law is recent, implementing regulations and SABG guidance are still developing, and mandatory authority reporting has been publicly floated for a future regulatory cycle. Confirm current position before relying on the absence of an authority-notification duty.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.