Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Mexico
MXschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 50
claims · 27 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
50Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction lead brief
Standing brief, as of 28 September 2026.
Lead Signal
Mexico's data-protection institutional architecture underwent its most consequential change in over two decades this cycle. The Instituto Nacional de Transparencia, Acceso a la Informacion y Proteccion de Datos Personales (INAI) was formally dissolved as of 21 March 2025, with its data-protection and transparency functions transferred to the Secretaria Anticorrupcion y Buen Gobierno, a federal-executive-branch body. This is a material reduction in institutional independence: unlike INAI, which held constitutionally autonomous status and the power to bring constitutional challenges, the new Secretariat sits within the executive branch and lacks that challenge-bringing authority. The transfer follows a constitutional reform, described by its proponents as "organic simplification," that the Mexican Senate approved to dissolve seven autonomous constitutional bodies altogether, of which INAI was one.
Notably, the substantive data-protection rights framework itself is reported by secondary sources to remain largely unchanged: the new LFPDPPP, which replaces the 2010 federal private-sector data-protection law and took effect the same date as INAI's dissolution, is understood to leave data-subject rights and controller obligations substantively intact. The change this cycle is institutional and structural rather than a rewriting of the rights themselves.
Other Developments
Specialised federal courts absorb data-protection litigation. Specialised Federal Judiciary courts for public-information and data-protection litigation began operating on 1 July 2025, absorbing all pending and new proceedings related to public information and data protection. This is part of the broader 2025 institutional transition following INAI's dissolution, and it represents a parallel reallocation of adjudicative authority alongside the executive-branch reallocation of regulatory authority.
Cross-Monitor Connections
The institutional transition described here has no identified direct overlap with financial-integrity, world-payments, advennt, artificial-intelligence or crypto developments this cycle; the dissolution of INAI is a domestic institutional-architecture matter specific to Mexico's transparency and data-protection oversight function.
Outlook
The open question this cycle is whether the new Secretaria Anticorrupcion y Buen Gobierno has yet exercised any enforcement power, such as fines or sanctions, under the LFPDPPP since assuming INAI's functions on 21 March 2025; no such action has been identified in open sources to date. Equally unresolved is the current operating status and caseload of the specialised Federal Judiciary courts created 1 July 2025. Both questions bear directly on whether Mexico's data-protection regime, formally unchanged in substance, is being enforced with comparable vigour under its new executive-branch home.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
A comprehensive statute remains in force and a named regulator exists, but the supervising authority itself is mid-transition, independence and procedural rules are unsettled, and mandated secondary regulation is overdue.
Primary frameworkLey Federal de Protección de Datos Personales en Posesión de los Particulares (NLFPDPPP, 2025), successor to the 2010 Federal Law
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno (Dirección General de Datos Personales en el Sector Privado)
Traffic-light rationale — AmberA comprehensive statute remains in force and a named regulator exists, but the supervising authority itself is mid-transition, independence and procedural rules are unsettled, and mandated secondary regulation is overdue.
Sub-modules (5)
Regulator And AuthorityAmber
INAI, the former autonomous DPA, was dissolved by constitutional reform; its private-sector data-protection function was transferred to the Secretaría Anticorrupción y Buen Gobierno, supplemented by two new decentralized bodies created May 2025.
Claims (3):
On 28 November 2024 the Mexican Senate approved the 'Simplificación Orgánica' constitutional reform dissolving seven autonomous constitutional bodies, including INAI.
The constitutional reform transfers access-to-information, transparency and personal-data-protection responsibilities to a body within the federal public administration responsible for personal data held by both private and public entities.
On 12 May 2025 the Ministry of Anticorruption and Good Governance announced creation of two new decentralized bodies, Transparencia para el Pueblo and the Personal Data Protection Unit, assuming roughly 80% of INAI's former functions, with a Specialized Court to be established under the judiciary.
Act And InstrumentsGreen
The operative private-sector instrument is the NLFPDPPP (DOF 20 Mar 2025, in force 21 Mar 2025), which repealed the 2010 FLPPDPP; a parallel General Law covers public-sector 'obligated parties'.
Claims (2):
The New Federal Law for the Protection of Personal Data in Possession of Private Parties (NLFPDPPP) was published in the DOF on 20 March 2025 and entered into force 21 March 2025, superseding and repealing the 2010 FLPPDPP.
The Executive Branch is mandated to issue updated implementing regulations within 90 days of the NLFPDPPP's entry into force to harmonize the regulatory framework, with the prior 2010 Regulations remaining only provisionally applicable in the interim.
Material ScopeGreen
The law governs legitimate, controlled and informed processing of personal data by private parties to guarantee privacy and informational self-determination; credit-reporting entities remain carved out under separate sectoral law.
Claims (1):
Credit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate sectoral regulation.
Territorial ScopeAmber
The private-sector law has historically applied on a territorial basis to processing by companies/persons established in Mexico regardless of data-subject residence; the new law preserves this structure.
Claims (1):
The private-sector data protection statute applies to processing of personal data by companies and persons on Mexican territory regardless of where the data subjects reside, requiring Mexican-based internet companies to comply even for non-Mexican users' data.
Regulator Registration And FilingRed
No dedicated national registry/filing obligation for controllers was identified in the sources reviewed for the private-sector regime.
Absence provenance: unavailable. Searched: Mexico LFPDPPP data controller registration filing requirement, NLFPDPPP registro responsables tratamiento datos.
Category narrative162 words
Mexico's private-sector data protection regime underwent a foundational institutional rupture between Nov 2024 and mid-2025. The Senate approved a constitutional 'organic simplification' reform dissolving seven autonomous bodies including INAI (the former DPA), with functions redistributed to the federal executive branch. A New Federal Law for the Protection of Personal Data Held by Private Parties (NLFPDPPP) was published 20 March 2025 (effective 21 March 2025), repealing the 2010 FLPPDPP, alongside a companion General Law for the public sector. The Secretaría Anticorrupción y Buen Gobierno, acting through its Dirección General de Datos Personales en el Sector Privado, now exercises the former INAI's private-sector functions; two decentralized administrative bodies (Transparencia para el Pueblo and the Personal Data Protection Unit) were stood up in May 2025 to absorb roughly 80% of INAI's functions, with a Specialized Court under the judiciary also contemplated. As of mid-2026 the new authority had not yet issued the harmonizing secondary regulation mandated within 90 days of the NLFPDPPP's entry into force.
no periodic updates on record for this sub-brief
Sources and claims (7)
ProbableIAPP — On 28 November 2024 the Mexican Senate approved the 'Simplificación Orgánica' constitutional reform dissolving seven autonomous constitutional bodies, including INAI.observed
ProbableIAPP — The constitutional reform transfers access-to-information, transparency and personal-data-protection responsibilities to a body within the federal public administration responsible for personal data held by both private and public entities.observed
ProbableOneTrust DataGuidance — On 12 May 2025 the Ministry of Anticorruption and Good Governance announced creation of two new decentralized bodies, Transparencia para el Pueblo and the Personal Data Protection Unit, assuming roughly 80% of INAI's former functions, with a Specialized Court to be established under the judiciary.observed
ProbableOneTrust DataGuidance — The New Federal Law for the Protection of Personal Data in Possession of Private Parties (NLFPDPPP) was published in the DOF on 20 March 2025 and entered into force 21 March 2025, superseding and repealing the 2010 FLPPDPP.observed
ProbableOneTrust DataGuidance — The Executive Branch is mandated to issue updated implementing regulations within 90 days of the NLFPDPPP's entry into force to harmonize the regulatory framework, with the prior 2010 Regulations remaining only provisionally applicable in the interim.observed
ProbableIAPP — Credit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate sectoral regulation.observed
ProbableIAPP — The private-sector data protection statute applies to processing of personal data by companies and persons on Mexican territory regardless of where the data subjects reside, requiring Mexican-based internet companies to comply even for non-Mexican users' data.observed
Core lawful-basis and sensitive-data structures exist and are GDPR-adjacent, but definitional gaps (research/journalistic carve-outs, anonymisation safe-harbour detail) remain unresolved pending new regulations.
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberCore lawful-basis and sensitive-data structures exist and are GDPR-adjacent, but definitional gaps (research/journalistic carve-outs, anonymisation safe-harbour detail) remain unresolved pending new regulations.
Sub-modules (4)
Lawful BasesAmber
The law sets out grounds for processing distinct from GDPR (e.g., legal mandate, public-source data, prior dissociation, contractual necessity) and does not address research or journalistic/artistic processing purposes.
Claims (2):
The Federal Law sets out grounds for processing personal data distinct from the GDPR and does not address processing for scientific or historical research purposes.
The Federal Law does not address matters such as processing for journalistic or artistic purposes, unlike the GDPR.
Consent ThresholdsAmber
Privacy-notice (aviso de privacidad) content requirements were revised by NLFPDPPP Art. 15, now requiring identification of data subject to processing and purposes, and distinguishing purposes requiring consent, while dropping the prior mandatory disclosure of intended transfers.
Claims (2):
NLFPDPPP Article 15 revises mandatory privacy-notice content, requiring identification of the data subject to the processing and its purposes and distinguishing purposes that require consent.
Unlike the prior law, the NLFPDPPP no longer lists disclosure of intended data transfers as a mandatory element of the privacy notice.
Special CategoriesGreen
The law imposes additional requirements for sensitive/special-category data akin to GDPR Art. 9, though with a narrower definitional scope than the European regime.
Claims (1):
The Federal Law provides additional requirements for processing sensitive data and defines conditions for consent, in ways broadly similar to the GDPR's special-category regime.
Pseudonymisation And AnonymisationAmber
The statute defines 'disociación' (dissociation) as a recognized legal mechanism/exception basis, but detailed anonymisation safe-harbour standards were not located in the sources reviewed.
'Disociación' (dissociation) of personal data is defined as a recognized legal element/exception basis under the private-sector data protection framework.
Category narrative63 words
Mexico's private-sector regime recognizes a privacy-notice-and-consent-centred model with enumerated exceptions to consent (public sources, legal mandate, prior dissociation, contractual necessity), plus enhanced conditions for 'sensitive' (special-category) data. The NLFPDPPP revises privacy-notice content requirements (Art. 15) but the underlying lawful-basis and consent architecture is substantially continuous with the 2010 law; the statute does not address processing for scientific/historical research or journalistic/artistic purposes, unlike GDPR.
Sources and claims (6)
ProbableOneTrust DataGuidance — The Federal Law sets out grounds for processing personal data distinct from the GDPR and does not address processing for scientific or historical research purposes.observed
ProbableOneTrust DataGuidance — The Federal Law does not address matters such as processing for journalistic or artistic purposes, unlike the GDPR.observed
ProbableIAPP — NLFPDPPP Article 15 revises mandatory privacy-notice content, requiring identification of the data subject to the processing and its purposes and distinguishing purposes that require consent.observed
ProbableIAPP — Unlike the prior law, the NLFPDPPP no longer lists disclosure of intended data transfers as a mandatory element of the privacy notice.observed
ProbableOneTrust DataGuidance — The Federal Law provides additional requirements for processing sensitive data and defines conditions for consent, in ways broadly similar to the GDPR's special-category regime.observed
ProbableIAPP — 'Disociación' (dissociation) of personal data is defined as a recognized legal element/exception basis under the private-sector data protection framework.observed
Core ARCO rights are well-established and enforceable, but data portability is confirmed absent from the new statute, and deadline/response-window specifics await the pending implementing regulations.
Primary frameworkNLFPDPPP Arts. 16-25 (ARCO rights procedure)
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberCore ARCO rights are well-established and enforceable, but data portability is confirmed absent from the new statute, and deadline/response-window specifics await the pending implementing regulations.
Sub-modules (5)
Access RightGreen
The new law broadens the access right beyond simply knowing processed data and the privacy notice, to include information on the general conditions of processing.
Claims (2):
ARCO rights (access, rectification, cancellation and opposition) form the procedural core of data-subject rights under the private-sector data protection law.
The New Law redefines the access right so that the data subject may access personal data and also know general conditions of the processing, expanding beyond the prior law's narrower formulation.
Rectification And ErasureGreen
Both GDPR and the Mexican Federal Law recognize a right to request cancellation/erasure of data in certain circumstances; deletion is also required once data is no longer necessary for the stated purpose.
Claims (2):
Both the GDPR and the Mexican Federal Law provide that data subjects may request cancellation or erasure of their data in certain circumstances for legitimate reasons.
Personal data must be deleted where it is no longer required for the purposes indicated in the privacy notice provided to data subjects.
Restriction And ObjectionAmber
Opposition (the 'O' in ARCO) is a recognized right; restriction as a distinct GDPR-style concept is not separately elaborated in the sources reviewed.
Absence provenance: unavailable. Searched: NLFPDPPP derecho de limitación del tratamiento.
Claims (1):
Opposition to processing is recognized as one of the four ARCO rights under the private-sector framework.
Data PortabilityRed
Practitioner review of the enacted NLFPDPPP text confirms the new law does not include a data portability right, despite general secondary summaries describing 'enhanced' rights.
Claims (1):
Practitioner analysis of the enacted NLFPDPPP text confirms the new law does not include a data portability right, among other omissions relative to GDPR-style frameworks.
Deadlines And Response WindowsAmber
Historically, data controllers/authorities operated under short compliance windows (e.g., 10 days to comply with an IFAI/INAI resolution); NLFPDPPP-specific response-window detail awaits the pending implementing regulation.
Claims (2):
Under the 2010-era framework, data collectors had 10 days to comply with a resolution issued by the data protection authority.
Against resolutions of the new Secretaría (replacing INAI), affected parties may now pursue amparo proceedings before specialized district and circuit courts, which were to be enabled within 120 calendar days of the reform decree's publication (i.e., by 19 June 2025).
Category narrative90 words
Mexico's rights framework centers on the ARCO rights (access, rectification, cancellation, opposition). The NLFPDPPP broadens the definition of the access right to include information about the conditions of processing, and replaces judicial review of regulator resolutions from nullity trials to amparo proceedings before newly created specialized federal courts. Critically, per detailed practitioner analysis of the enacted text, the new law does NOT include a data portability right, in contrast to a DataGuidance summary describing 'enhanced' data subject rights generally — this is flagged as an unresolved conflict pending primary-text confirmation.
Sources and claims (8)
ProbableIAPP — ARCO rights (access, rectification, cancellation and opposition) form the procedural core of data-subject rights under the private-sector data protection law.observed
ProbableIAPP — The New Law redefines the access right so that the data subject may access personal data and also know general conditions of the processing, expanding beyond the prior law's narrower formulation.observed
ProbableOneTrust DataGuidance — Both the GDPR and the Mexican Federal Law provide that data subjects may request cancellation or erasure of their data in certain circumstances for legitimate reasons.observed
ProbableIAPP — Personal data must be deleted where it is no longer required for the purposes indicated in the privacy notice provided to data subjects.observed
ProbableIAPP — Opposition to processing is recognized as one of the four ARCO rights under the private-sector framework.observed
ProbableIAPP — Practitioner analysis of the enacted NLFPDPPP text confirms the new law does not include a data portability right, among other omissions relative to GDPR-style frameworks.observed
ProbableIAPP — Under the 2010-era framework, data collectors had 10 days to comply with a resolution issued by the data protection authority.observed
ProbableIAPP — Against resolutions of the new Secretaría (replacing INAI), affected parties may now pursue amparo proceedings before specialized district and circuit courts, which were to be enabled within 120 calendar days of the reform decree's publication (i.e., by 19 June 2025).observed
Security and controller-liability principles exist and are enforceable, but DPO, DPIA, privacy-by-design and regulator-facing breach notification — all GDPR Art. 25/33/35/37-39 analogues — are confirmed absent from the current statute and Regulations.
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberSecurity and controller-liability principles exist and are enforceable, but DPO, DPIA, privacy-by-design and regulator-facing breach notification — all GDPR Art. 25/33/35/37-39 analogues — are confirmed absent from the current statute and Regulations.
Sub-modules (7)
Accountability And DpiaRed
The Regulations address a concept of accountability but neither the Federal Law nor Regulations define processor liabilities or require DPIAs/privacy-by-design; a general secondary summary claiming DPIA introduction conflicts with detailed practitioner review of the enacted text.
Claims (2):
Neither the Federal Law nor its Regulations address Data Protection Impact Assessments (DPIAs).
A general secondary summary describes the NLFPDPPP as imposing stricter obligations including the need for risk assessments and data protection impact evaluations, which conflicts with detailed practitioner review of the enacted text confirming DPIAs are not addressed; this discrepancy is unresolved pending primary-text confirmation.
Dpo RequirementsAmber
Neither the Federal Law nor its Regulations require formal DPO appointment or regulator notification of a DPO; historically the 2010 law required only designation of a responsible person/department (privacy officer).
Claims (2):
Neither the Federal Law nor the Regulations require organizations to designate a formal Data Protection Officer or notify the authority of a DPO appointment.
Under the 2010-era law, all data controllers and processors had to appoint a person or group responsible for personal-data-related requirements (a privacy officer), and employers had to appoint a person or department for employee data.
Ropa RequirementsRed
No explicit records-of-processing-activities (ROPA) obligation equivalent to GDPR Art. 30 was located in the sources reviewed.
Absence provenance: unavailable. Searched: NLFPDPPP registro de actividades de tratamiento obligación.
Joint Controller ArrangementsAmber
The Federal Law specifies controllers are liable for violations of its principles but does not define processor liabilities in GDPR Art. 28 style detail.
Claims (1):
The Federal Law specifies that data controllers are liable for violations of its principles, though neither the Law nor Regulations define the liabilities of data processors in detail.
Security MeasuresGreen
The Federal Law itself does not define security measures, but the (provisionally applicable) Regulations define 'technical security measures' and require risk-based administrative, technical and physical safeguards.
Claims (2):
The Federal Law does not itself define security measures, but Article 2(VII) of the Regulations defines 'technical security measures' as controls ensuring authorized, identified access to logical databases.
Mexico's data-protection regime imposes risk-based technical, administrative and physical safeguards on data processors under both the private-sector Federal Law and the public-sector General Law.
Breach NotificationAmber
The Federal Law does not specify a breach-notification requirement to the regulator; the Regulations (Art. 64) require the controller to inform the data subject without delay of breaches affecting their patrimonial or moral rights. Sector overlays impose separate regulator-facing notification (e.g., banks to CNBV).
Claims (2):
Under the current legislative framework there is no requirement to inform the data protection authority when a data breach occurs; the Federal Law/Regulations only impose notification obligations toward the affected data subject.
Banks must immediately notify the National Banking and Securities Commission (CNBV) of any qualifying information-security incident, and the chief information security officer must submit a monthly information-security management report.
Retention And DisposalGreen
Personal data must be deleted once no longer required for the purposes stated in the privacy notice.
Claims (1):
Personal data must be deleted if no longer required for the purposes indicated in the privacy notice provided to data subjects.
Category narrative79 words
Mexico's regime imposes accountability, security and (limited) breach-related duties on controllers, but critically diverges from GDPR by not requiring a formal Data Protection Officer appointment/notification, and by not requiring DPIAs or privacy-by-design/default under either the Federal Law or its Regulations — a gap the NLFPDPPP's practitioner review confirms was carried forward. Breach notification runs to affected data subjects, not to the regulator, under the current Regulations (Art. 64); sectoral overlays (e.g., banking) impose separate incident-notification duties to financial regulators.
Sources and claims (10)
ProbableOneTrust DataGuidance — Neither the Federal Law nor its Regulations address Data Protection Impact Assessments (DPIAs).observed
UncertainOneTrust DataGuidance — A general secondary summary describes the NLFPDPPP as imposing stricter obligations including the need for risk assessments and data protection impact evaluations, which conflicts with detailed practitioner review of the enacted text confirming DPIAs are not addressed; this discrepancy is unresolved pending primary-text confirmation.observed
ProbableOneTrust DataGuidance — Neither the Federal Law nor the Regulations require organizations to designate a formal Data Protection Officer or notify the authority of a DPO appointment.observed
ProbableIAPP — Under the 2010-era law, all data controllers and processors had to appoint a person or group responsible for personal-data-related requirements (a privacy officer), and employers had to appoint a person or department for employee data.observed
ProbableOneTrust DataGuidance — The Federal Law specifies that data controllers are liable for violations of its principles, though neither the Law nor Regulations define the liabilities of data processors in detail.observed
ProbableOneTrust DataGuidance — The Federal Law does not itself define security measures, but Article 2(VII) of the Regulations defines 'technical security measures' as controls ensuring authorized, identified access to logical databases.observed
ProbableIAPP — Mexico's data-protection regime imposes risk-based technical, administrative and physical safeguards on data processors under both the private-sector Federal Law and the public-sector General Law.observed
ProbableOneTrust DataGuidance — Under the current legislative framework there is no requirement to inform the data protection authority when a data breach occurs; the Federal Law/Regulations only impose notification obligations toward the affected data subject.observed
ProbableIAPP — Banks must immediately notify the National Banking and Securities Commission (CNBV) of any qualifying information-security incident, and the chief information security officer must submit a monthly information-security management report.observed
ProbableIAPP — Personal data must be deleted if no longer required for the purposes indicated in the privacy notice provided to data subjects.observed
A transfer mechanism exists in statute but enforcement reach is explicitly limited by the authority's own historical acknowledgment of extraterritorial enforcement gaps, and SCC/BCR/TIA/localisation specifics are largely undocumented in current secondary sources.
Primary frameworkNLFPDPPP Art. 36 (international transfer clause in privacy notice)
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberA transfer mechanism exists in statute but enforcement reach is explicitly limited by the authority's own historical acknowledgment of extraterritorial enforcement gaps, and SCC/BCR/TIA/localisation specifics are largely undocumented in current secondary sources.
Sub-modules (6)
Transfer MechanismsAmber
Transfers rely on a privacy-notice clause binding the receiving controller to the same purposes and obligations, contingent on data-subject acceptance.
Claims (2):
Under Article 36 of the private-sector law, a controller transferring personal data abroad must communicate the signed privacy notice to the new foreign controller so it remains bound by the same purposes and obligations, conditioned on a transfer clause having been included in the notice and accepted by the data subject.
The data protection authority has historically lacked international enforcement powers to compel foreign companies subject to a different legal order to comply with Mexican data protection obligations.
Adequacy ReceivedRed
No evidence found of Mexico having received a formal adequacy determination from another regime (e.g., EU) as of the research date.
Absence provenance: unavailable. Searched: Mexico EU adequacy decision received GDPR.
Adequacy GrantedAmber
Mexico's Federal Law/Regulations reference European adequacy decisions as a basis for enabling transfers, implying a form of unilateral recognition rather than a reciprocal adequacy-granting mechanism.
Claims (1):
The Federal Law and Regulations cite European Union adequacy decisions as a basis for enabling international data transfers out of Mexico.
Sccs And BcrsRed
No dedicated SCC or BCR certification/registration scheme for the private sector was identified in the sources reviewed.
No transfer-impact-assessment requirement analogous to post-Schrems II EU practice was identified for Mexico's private-sector regime.
Absence provenance: unavailable. Searched: Mexico transfer impact assessment requirement data protection.
Data LocalisationRed
No general data-localisation mandate was identified for the private-sector regime in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico data localisation requirement personal data private sector.
Category narrative75 words
Mexico's private-sector regime permits international transfers through privacy-notice-embedded transfer clauses binding the foreign recipient to the same purposes, and secondary commentary indicates the Federal Law/Regulations cite European adequacy decisions as a basis for enabling transfers. However, INAI (and now its successor) has historically lacked international enforcement powers to bind foreign controllers under other legal orders, limiting practical enforceability. No explicit SCC/BCR certification scheme, transfer-impact-assessment requirement, or general data-localisation mandate was identified for the private sector.
Sources and claims (3)
ProbableIAPP — Under Article 36 of the private-sector law, a controller transferring personal data abroad must communicate the signed privacy notice to the new foreign controller so it remains bound by the same purposes and obligations, conditioned on a transfer clause having been included in the notice and accepted by the data subject.observed
ProbableIAPP — The data protection authority has historically lacked international enforcement powers to compel foreign companies subject to a different legal order to comply with Mexican data protection obligations.observed
ProbableOneTrust DataGuidance — The Federal Law and Regulations cite European Union adequacy decisions as a basis for enabling international data transfers out of Mexico.observed
Financial-sector overlay is well documented; health, telecoms, education and insurance overlays are thinly evidenced or absent in the sources reviewed.
Supervisory authorityComisión Nacional Bancaria y de Valores (CNBV)
Traffic-light rationale — AmberFinancial-sector overlay is well documented; health, telecoms, education and insurance overlays are thinly evidenced or absent in the sources reviewed.
Sub-modules (7)
Financial Sector OverlayGreen
Banks must immediately notify CNBV of qualifying information-security incidents, with monthly CISO reporting to the CEO/board; credit-reporting entities are exempt from the general law and governed by separate legislation.
Claims (2):
Banks in Mexico must immediately notify the Comisión Nacional Bancaria y de Valores (CNBV) of any qualifying information-security incident.
The chief information security officer at Mexican banks must submit a monthly information-security management report to the CEO and, when required, to the board or relevant committees.
Health Sector OverlayAmber
Secondary commentary notes the existence of sector-specific laws in the health and pharmaceutical sectors distinct from the general Federal Law, but granular detail was not found in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico health sector data protection law pharmaceutical overlay detail.
Claims (1):
Sector-specific laws exist in the financial services and health/pharmaceutical sectors distinct from the general private-sector Federal Law and Regulations.
Telecoms And EprivacyRed
No dedicated telecoms/ePrivacy-style overlay (e.g., cookie consent, electronic communications confidentiality specific to the sector) was identified.
Historically, employers were required to appoint a person or department responsible for employee personal data and to promote its protection.
Claims (1):
Employers must appoint a person or establish a personal data department to handle employees' personal data and promote its protection.
Credit And ScoringAmber
Credit-reporting entities (sociedades de información crediticia) are exempt from the general Federal Law and governed by separate credit-bureau legislation.
Claims (1):
Credit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate regulation.
EducationRed
No education-sector-specific data protection overlay was identified in the sources reviewed.
Mexico layers sector-specific rules atop the general private-sector data protection statute, most notably in financial services (credit-reporting carve-out, CNBV incident-notification duties for banks) and health/pharmaceutical sectors. No dedicated telecoms/ePrivacy, education, or insurance-specific data protection overlays were identified in the sources reviewed.
Sources and claims (5)
ProbableIAPP — Banks in Mexico must immediately notify the Comisión Nacional Bancaria y de Valores (CNBV) of any qualifying information-security incident.observed
ProbableIAPP — The chief information security officer at Mexican banks must submit a monthly information-security management report to the CEO and, when required, to the board or relevant committees.observed
ProbableOneTrust DataGuidance — Sector-specific laws exist in the financial services and health/pharmaceutical sectors distinct from the general private-sector Federal Law and Regulations.observed
ProbableIAPP — Employers must appoint a person or establish a personal data department to handle employees' personal data and promote its protection.observed
ProbableIAPP — Credit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate regulation.observed
No dedicated adtech/commercial-privacy regime exists; only the general opposition right within ARCO offers any traction for direct-marketing objections.
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — RedNo dedicated adtech/commercial-privacy regime exists; only the general opposition right within ARCO offers any traction for direct-marketing objections.
Sub-modules (6)
Cookies And TrackersRed
The Mexican private-sector law does not specifically address internet cookies.
Claims (1):
The Mexican federal data protection law does not specifically address topics such as internet cookies, employee monitoring, or collection of personal data in connection with credit-card transactions.
Dark PatternsRed
No dark-pattern prohibition was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico dark patterns prohibition consumer data law.
Opt Out SignalsRed
No recognition of universal opt-out signals (e.g., Global Privacy Control, DAA) was identified.
Absence provenance: unavailable. Searched: Mexico Global Privacy Control opt-out signal recognition law.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room-specific rule was identified.
Absence provenance: unavailable. Searched: Mexico data clean room regulation privacy.
Cross Context AdvertisingRed
No CPRA-style 'sale'/'share' or cross-context-advertising-specific regime was identified.
Absence provenance: unavailable. Searched: Mexico cross-context advertising sale share personal data law.
Direct MarketingAmber
Direct marketing objections are addressed only through the general ARCO opposition right rather than a dedicated marketing-consent/suppression regime.
Claims (1):
The ARCO opposition right provides the primary (general, non-marketing-specific) mechanism by which data subjects can object to processing, including for direct-marketing purposes.
Category narrative43 words
Mexico's private-sector data protection law does not specifically address internet cookies or trackers, and no dedicated dark-pattern prohibition, opt-out-signal recognition (e.g., Global Privacy Control), clean-room/data-collaboration-room rule, or cross-context-advertising regime was identified. Direct marketing is addressed only indirectly through the general ARCO opposition right.
Sources and claims (2)
ProbableIAPP — The Mexican federal data protection law does not specifically address topics such as internet cookies, employee monitoring, or collection of personal data in connection with credit-card transactions.observed
UncertainIAPP — The ARCO opposition right provides the primary (general, non-marketing-specific) mechanism by which data subjects can object to processing, including for direct-marketing purposes.observed
No binding AI-specific statute exists; biometric governance rests on enforcement precedent rather than codified rules, and profiling/ADM-transparency provisions were not separately documented.
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberNo binding AI-specific statute exists; biometric governance rests on enforcement precedent rather than codified rules, and profiling/ADM-transparency provisions were not separately documented.
Sub-modules (6)
Profiling RestrictionsRed
No profiling-restriction provision analogous to GDPR Art. 22 was specifically documented for Mexico in the sources reviewed.
No ADM-transparency/explanation-right provision was specifically documented for Mexico's private-sector regime in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico automated decision making transparency right explanation law.
Ai Risk AssessmentsRed
Mexico has no dedicated AI law; a Senate National AI Alliance (ANIA) initiative is developing a regulatory proposal covering cybersecurity, privacy and ethical AI use, but remains pre-legislative.
Claims (2):
Mexico does not have a specific AI law; the Senate's National AI Alliance (ANIA) is working on a regulatory proposal covering cybersecurity, privacy, ethical AI use and AI adoption.
As of mid-2026, Mexico's new data protection authority had not yet issued secondary regulation or public sanctions, though there were indications of preliminary investigations concerning sensitive data handling and security-incident management.
Biometric RegimeAmber
Biometric governance has proceeded via enforcement precedent (the 'Fan ID' facial-recognition investigation) and a government digital biometric identity rollout, rather than a codified biometric-specific statute.
Claims (2):
INAI's investigation of the 'Fan ID' facial-recognition system implemented by the Mexican Football Federation became one of the most significant proceedings on biometric data processing in the private sector, raising issues of consent, proportionality and controller/processor responsibility.
The Mexican government is advancing implementation of a biometric digital identity system alongside a National Cybersecurity Plan 2025-2030.
Genetic DataRed
No genetic-data-specific regime was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico genetic data protection law regime.
State Surveillance CarveoutsRed
No detailed national-security/state-surveillance carve-out provision was documented in the sources reviewed for the private-sector regime.
Absence provenance: unavailable. Searched: Mexico national security exemption data protection surveillance carveout.
Category narrative96 words
Mexico has no dedicated AI law; a Senate-based National AI Alliance (ANIA) is developing a regulatory proposal spanning cybersecurity, privacy, and AI ethics, but this remains pre-legislative as of the research date. Biometric data governance has developed through enforcement precedent rather than statute — most notably INAI's investigation into the Mexican Football Federation's 'Fan ID' facial-recognition system, which raised consent, proportionality and controller/processor-responsibility issues. The government is separately advancing a biometric digital-identity system. A thinly sourced reference to a Mexican 'neuro-rights' law protecting neurotechnology/neural data was found but could not be corroborated against a primary text.
Sources and claims (4)
ProbableIAPP — Mexico does not have a specific AI law; the Senate's National AI Alliance (ANIA) is working on a regulatory proposal covering cybersecurity, privacy, ethical AI use and AI adoption.observed
ProbableIAPP — As of mid-2026, Mexico's new data protection authority had not yet issued secondary regulation or public sanctions, though there were indications of preliminary investigations concerning sensitive data handling and security-incident management.observed
ProbableIAPP — INAI's investigation of the 'Fan ID' facial-recognition system implemented by the Mexican Football Federation became one of the most significant proceedings on biometric data processing in the private sector, raising issues of consent, proportionality and controller/processor responsibility.observed
ProbableIAPP — The Mexican government is advancing implementation of a biometric digital identity system alongside a National Cybersecurity Plan 2025-2030.observed
The current statute contains no children's-data-specific regime at all; this is an explicit, confirmed statutory gap rather than a mere silence in secondary sources.
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — RedThe current statute contains no children's-data-specific regime at all; this is an explicit, confirmed statutory gap rather than a mere silence in secondary sources.
Sub-modules (5)
Age VerificationRed
No age-verification requirement was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico NLFPDPPP verificación de edad menores.
Parental ConsentRed
No parental-consent mechanism analogous to GDPR Art. 8 or COPPA was identified for Mexico's private-sector regime.
Claims (1):
The New Federal Law (NLFPDPPP) does not include topics such as the processing of personal data of minors, unlike the GDPR which sets express child-consent age thresholds.
Minor Profiling BansRed
No minor-profiling ban was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico minor profiling ban data protection.
Education SettingsRed
No education-setting-specific children's-data provision was identified.
Absence provenance: unavailable. Searched: Mexico education setting children data protection rule.
Dependent AdultsRed
No dependent-adult (elderly/incapacitated)-specific protection provision was identified in the sources reviewed.
Detailed practitioner review of the enacted NLFPDPPP text confirms that the new law does not include specific provisions addressing the processing of personal data of minors, continuing a longstanding gap relative to GDPR (which contains express child-consent-age rules). No age-verification, parental-consent, minor-profiling-ban, education-setting-specific, or dependent-adult-specific provisions were identified for Mexico's private-sector regime.
Sources and claims (1)
ProbableIAPP — The New Federal Law (NLFPDPPP) does not include topics such as the processing of personal data of minors, unlike the GDPR which sets express child-consent age thresholds.observed
A functioning enforcement and judicial-review pathway exists, but the new regulator's operational capacity, sanctioning track record, and independence remain unproven during this institutional transition.
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberA functioning enforcement and judicial-review pathway exists, but the new regulator's operational capacity, sanctioning track record, and independence remain unproven during this institutional transition.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The Secretaría now exercises verification, complaint-resolution and sanctioning powers formerly held by INAI, but with unresolved questions about its independence given its status as an executive-branch secretariat rather than an autonomous body.
Claims (1):
Unlike INAI (an autonomous constitutional body), the Secretaría Anticorrupción y Buen Gobierno is not required to render an annual activity report to Congress, and the express attribution to develop, promote and disseminate data-protection research and studies was not carried forward in the new law's Article 39.
Enforcement Activity IndexAmber
Historical INAI enforcement produced cumulative fines in the tens of millions of pesos in multiple reporting years under the prior law; specific figures for the new authority's activity were not accessible in the sources reviewed (content behind a paywall/JS-blocked).
Absence provenance: unavailable. Searched: INAI multas 2023 monto total sanciones LFPDPPP, Secretaría Anticorrupción y Buen Gobierno sanciones datos personales 2026.
Regulator Funding And CapacityRed
No detailed budget/headcount data for the new Secretaría's data-protection function was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Secretaría Anticorrupción y Buen Gobierno presupuesto protección de datos personal.
Collective Redress And Class ActionsRed
No dedicated collective-redress or class-action mechanism specific to data protection claims was identified in the sources reviewed.
Absence provenance: unavailable. Searched: Mexico class action data protection collective redress mechanism.
Private Right Of ActionAmber
Data subjects may seek civil damages from data collectors for harm suffered from a breach of the data protection law, and may now challenge regulator resolutions via amparo before specialized courts.
Claims (2):
Data subjects may seek damages from data collectors when they consider they have suffered harm or losses derived from a breach of the data protection law.
Against resolutions of the Secretaría, affected parties may now pursue amparo (constitutional review) proceedings before specialized district and circuit courts, replacing the prior nullity-trial pathway against INAI resolutions.
Recent Developments 180DAmber
Within the last 180 days, secondary reporting (published within the reporting window) indicates Mexico's updated privacy law remains largely structurally continuous with the 2010 regime, the new authority has yet to issue secondary regulation or public sanctions, and the government is simultaneously advancing biometric digital identity and a National Cybersecurity Plan.
Claims (1):
As of early-to-mid 2026, Mexico's updated privacy law entered into force but largely retains the structure of the 2010 regime, and the new data authority had not yet issued secondary regulation or public sanctions, though preliminary investigations into sensitive-data handling and security-incident management were reported, alongside government advancement of a biometric digital identity system and a National Cybersecurity Plan 2025-2030.
Key findings (1)
— source on file
Category narrative109 words
Enforcement authority has migrated from the dissolved, formerly autonomous INAI to the Secretaría Anticorrupción y Buen Gobierno; judicial review of regulator decisions shifted from nullity trials to amparo proceedings before newly created specialized federal courts. As of mid-2026, secondary sources report the new authority had not yet issued public sanctions or completed secondary regulation, notwithstanding reported preliminary investigations. Historically, INAI's cumulative fines under the prior law ran into the tens of millions of Mexican pesos in various reporting years, though specific current-year figures for the new authority were not accessible in the sources reviewed. Civil damages actions by data subjects against controllers are a recognized private right of action.
no periodic updates on record for this sub-brief
Sources and claims (4)
ProbableIAPP — Unlike INAI (an autonomous constitutional body), the Secretaría Anticorrupción y Buen Gobierno is not required to render an annual activity report to Congress, and the express attribution to develop, promote and disseminate data-protection research and studies was not carried forward in the new law's Article 39.observed
ProbableIAPP — Data subjects may seek damages from data collectors when they consider they have suffered harm or losses derived from a breach of the data protection law.observed
ProbableIAPP — Against resolutions of the Secretaría, affected parties may now pursue amparo (constitutional review) proceedings before specialized district and circuit courts, replacing the prior nullity-trial pathway against INAI resolutions.observed
ProbableIAPP — As of early-to-mid 2026, Mexico's updated privacy law entered into force but largely retains the structure of the 2010 regime, and the new data authority had not yet issued secondary regulation or public sanctions, though preliminary investigations into sensitive-data handling and security-incident management were reported, alongside government advancement of a biometric digital identity system and a National Cybersecurity Plan 2025-2030.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
waived
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
11.54
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Mexico
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 50 claim(s) (50 category placement(s)), 27 source(s) in the cumulative register.
All 10 modules populated. No T1 (primary DOF statutory text) was directly accessed; all findings rest on T2 professional secondary sources (IAPP practitioner analyses, DataGuidance jurisdiction summaries/opinion pieces). Coverage is strongest for regulator_and_framework, data_subject_rights, and controller_processor_duties (multiple corroborating T2 sources, including a detailed practitioner line-by-line review of the enacted NLFPDPPP text). Coverage is weakest for adtech_and_commercial_privacy, cross_border_and_adequacy (SCC/BCR/TIA/localisation sub-modules), and children_and_vulnerable_groups sub-modules beyond the core minors-data omission, and sectoral_watch (education, insurance, telecoms) — all carrying explicit absent_field_provenance. A material unresolved conflict exists between a general DataGuidance summary (describing DPIA/risk-assessment introduction) and a detailed IAPP practitioner review of the enacted text (confirming DPIA absence); this was flagged with Uncertain confidence rather than silently resolved.
Unresolved questions (7):
Has the Executive Branch issued the updated implementing Reglamento mandated within 90 days of the NLFPDPPP's 21 March 2025 entry into force (due ~19 June 2025), and what does it say on DPIA, breach notification to the regulator, and DPO requirements?
Are the specialized district/circuit courts for amparo review of Secretaría resolutions (due to be enabled by 19 June 2025) now operational, and what is their case volume?
What are the exact statutory administrative-sanction ranges (UMA-based caps) and criminal penalties under the NLFPDPPP, as distinct from the repealed 2010 FLPPDPP?
Does the primary NLFPDPPP text actually introduce DPIA/risk-assessment obligations (per DataGuidance) or omit them entirely (per IAPP practitioner review)? This conflict is unresolved.
What is the current legal status and scope of the reported Mexican 'neuro-rights' law protecting neurotechnology/neural data — no primary source was located.
Has the new authority (Secretaría Anticorrupción y Buen Gobierno / Personal Data Protection Unit) issued any public sanctions or enforcement resolutions as of the current date, beyond the reported 'preliminary investigations'?
What specific cross-border transfer instruments (SCC-equivalents, BCR-equivalents) exist under the new law, if any, beyond the Art. 36 privacy-notice transfer clause?