WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Federal Law on the Protection of Personal Data Held by Private Parties (2025) — security breaches

LFPDPPP (2025) breach duty

Mexico · March 21, 2025

Verify details

Mexico's duty runs to the individual, not the regulator. Where a security breach significantly affects a data subject's patrimonial or moral rights, the controller must notify the affected data subject without delay, telling them the nature of the breach, the personal data involved, the steps they can take to protect themselves, and the corrective measures the controller has taken. There is no general duty to report to the supervisory authority — the function now sits with the Secretaria Anticorrupcion y Buen Gobierno (SABG) following INAI's dissolution — which makes Mexico an outlier among the regimes in this dataset and a live risk of over-notification for businesses reusing a GDPR playbook. Marked 'check': the 2025 law is recent, implementing regulations and SABG guidance are still developing, and mandatory authority reporting has been publicly floated for a future regulatory cycle. Confirm current position before relying on the absence of an authority-notification duty.

Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares, published in the Diario Oficial de la Federacion March 20, 2025Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.