Cross-Border Data Transfer
Federal Law on the Protection of Personal Data Held by Private Parties (2025) — transfers of personal data
Mexico · March 21, 2025
Verify detailsMexico regulates transfers by consent rather than by destination. Every transfer — domestic or international, it makes no difference — requires the data subject's consent unless a statutory exception applies, must be disclosed in the privacy notice, and must stay within the purpose that justified it. The recipient assumes the SAME obligations as the controller that transferred the data, and the burden of proving the transfer was lawful falls on both the transferring party and the recipient. There is no adequacy list to consult and no standard clauses to sign; the privacy notice is the compliance artefact. Marked 'check': the statutory exceptions were numbered Art. 37 under the 2010 law and the 2025 renumbering was not confirmed against the primary text, implementing regulations under the new law were still developing, and enforcement now sits with the Secretaria Anticorrupcion y Buen Gobierno rather than the dissolved INAI.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.