New Mexico
New Mexico Data Privacy Laws: Breach Notification, AG Enforcement & 2026 Legislation
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. · 15 primary sources cited on this page. How we verify our legal content

New Mexico does not have a comprehensive consumer data privacy law as of May 2026. The state's primary protection is the Data Breach Notification Act (NMSA 57-12C), which requires businesses to notify affected residents within 45 calendar days of discovering a breach. The Unfair Practices Act (NMSA 57-12) provides enforcement authority to the Attorney General.
New Mexico residents and businesses operate under a patchwork of state and federal privacy protections rather than a single comprehensive data privacy statute. While states like California, Colorado, and Virginia have enacted broad consumer privacy laws, New Mexico has taken a more incremental approach focused on breach notification, sectoral protections, and consumer protection enforcement.
The state's primary data protection tool is the Data Breach Notification Act, codified as NMSA 57-12C-1 through 57-12C-12. This law establishes strict requirements for how businesses must handle security breaches involving the personal identifying information of New Mexico residents. The Unfair Practices Act provides additional consumer protections the Attorney General has deployed against tech platforms with significant effect.
This guide covers every data privacy protection available to New Mexico residents, the obligations businesses must follow, and the legislative and enforcement developments that have reshaped New Mexico's privacy landscape in 2025 and 2026.
New Mexico Data Breach Notification Act (NMSA 57-12C)
The Data Breach Notification Act is New Mexico's cornerstone data privacy statute. Governor Susana Martinez signed House Bill 15 into law during the 2017 regular session, and the law became effective on June 16, 2017. New Mexico was the 48th state to adopt a breach notification law.

The law is organized into 12 sections covering definitions, security requirements, disposal obligations, notification procedures, enforcement mechanisms, and exemptions.
Who Must Comply
The Data Breach Notification Act applies to any person that owns or licenses computerized data that includes the personal identifying information of a New Mexico resident. NMSA 57-12C-2 does not itself define "person"; New Mexico's general definitions statute, NMSA 12-2A-3, defines the term broadly to include an individual, corporation, business trust, estate, trust, partnership, limited liability company, association, joint venture, or any other legal or commercial entity.
This broad definition means the law covers businesses of all sizes, nonprofit organizations, government contractors, and any other entity that handles personal data belonging to New Mexico residents. There is no minimum size threshold or revenue requirement for compliance.
One significant carve-out limits that reach. Under NMSA 57-12C-12, nothing in the Data Breach Notification Act "shall be interpreted to apply to the state of New Mexico or any of its political subdivisions." State agencies, counties, and municipalities therefore do not owe the Act's 45-day notification duty. That gap is part of why the Nondisclosure of Sensitive Personal Information Act (NMSA 10-16I), covered below, is the regime that governs disclosures of personal information by state employees.
What Counts as Personal Identifying Information
New Mexico's definition of personal identifying information under NMSA 57-12C-2 requires an individual's first name or first initial and last name combined with one or more of the following unencrypted data elements:
- Social Security number
- Driver's license number or state-issued identification number
- Account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to a financial account
- Biometric data (fingerprints, voice prints, iris or retina patterns, facial characteristics, or hand geometry used to authenticate identity)
The definition excludes information lawfully obtained from publicly available sources or from federal, state, or local government records that are lawfully made available to the general public.
Data protected through encryption, redaction, or otherwise rendered unreadable or unusable does not qualify as personal identifying information under this statute. This encryption safe harbor gives businesses a strong incentive to encrypt stored personal data.
Biometric Data Protections
New Mexico includes biometric data in its breach notification trigger. Under NMSA 57-12C-2, "biometric data" is defined as a record generated by automatic measurements of an identified individual's fingerprints, voice print, iris or retina patterns, facial characteristics, or hand geometry.
The biometric data must be used to "uniquely and durably authenticate an individual's identity when the individual accesses a physical location, device, system or account." Biometric data collected for purposes other than authentication, such as aggregate analytics, may fall outside this specific definition.
New Mexico does not have a standalone biometric privacy law comparable to Illinois's Biometric Information Privacy Act. There are no separate requirements for obtaining consent before collecting biometric data or specific retention and destruction schedules outside of the general disposal requirements in the Data Breach Notification Act.
What Constitutes a Security Breach
Under NMSA 57-12C-2, a "security breach" is the unauthorized acquisition of unencrypted computerized data, or of encrypted computerized data together with the confidential process or key used to decrypt it, that compromises the security, confidentiality, or integrity of personal identifying information.
A good-faith acquisition of personal identifying information by an employee or agent for a legitimate business purpose does not constitute a security breach, as long as the information is not subject to further unauthorized disclosure.
Security and Disposal Requirements
The Data Breach Notification Act goes beyond notification. It imposes ongoing obligations for how businesses store and dispose of personal identifying information.
Reasonable Security Measures
Under NMSA 57-12C-4, any person that owns or licenses personal identifying information of a New Mexico resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information. These measures must protect personal identifying information from unauthorized access, destruction, use, modification, or disclosure.
The statute uses a "reasonableness" standard, which allows flexibility based on the size of the organization, the sensitivity of the data, and the current state of technology. Courts and the Attorney General evaluate compliance based on what would be considered reasonable under the circumstances.
Data Disposal Requirements
When personal identifying information is no longer reasonably needed for business purposes, NMSA 57-12C-3 requires proper disposal. Proper disposal means shredding, erasing, or otherwise modifying the personal identifying information to make it unreadable or undecipherable. This applies to both physical records and electronic records; data must be rendered genuinely unusable, not merely deleted in a recoverable way.
Service Provider Obligations
NMSA 57-12C-5 requires a business that discloses personal identifying information to a service provider under contract to require, by contract, that the service provider implement and maintain reasonable security procedures and practices appropriate to the nature of the information. Separately, NMSA 57-12C-6 requires a service provider that maintains or possesses that data without owning or licensing it to notify the owner or licensee of any security breach in the most expedient time possible, but no later than 45 calendar days following discovery of the breach.
This creates a chain of responsibility. A business that outsources data processing to a third party remains responsible for ensuring that provider maintains adequate security.
Notification Requirements

Timeline for Notification
Under NMSA 57-12C-6, notification must be provided to affected New Mexico residents in the most expedient time possible, but no later than 45 calendar days following discovery of the security breach.
This 45-day deadline is among the more moderate timelines nationally. Some states require notification within 30 days, while others have more flexible "without unreasonable delay" standards. New Mexico's fixed deadline provides certainty for businesses while ensuring reasonably prompt disclosure.
Exception to Notification
Notification is not required if, after an appropriate investigation, the entity determines that the security breach does not give rise to a significant risk of identity theft or fraud. This risk assessment must be documented and performed in good faith. Businesses should not use this exception casually, as the Attorney General may later challenge a decision not to notify.
Required Notification Content
Under NMSA 57-12C-7, breach notifications must include all of the following:
- The name and contact information of the notifying person or entity
- A list of the types of personal identifying information reasonably believed to have been compromised
- The date of the security breach, or an estimated date or range of dates if the exact date is unknown
- A general description of the security breach incident
- The toll-free telephone numbers and addresses of major consumer reporting agencies
- Advice directing the recipient to review personal account statements and credit reports for unauthorized activity
- Advice informing the recipient of their rights under the federal Fair Credit Reporting Act
Substitute Notification
If standard notification methods are impractical, NMSA 57-12C-6 allows substitute notification when the cost of notification would exceed $100,000, the affected class exceeds 50,000 New Mexico residents, or the entity does not have sufficient contact information for those who need to be notified.
Substitute notification requires sending electronic notice to those for whom the entity has a valid email address, posting notice of the breach in a conspicuous location on the entity's website if it maintains one, and sending written notification to the New Mexico Attorney General's office and major media outlets serving the state.
Attorney General and Credit Agency Notification
Under NMSA 57-12C-10, any breach affecting more than 1,000 New Mexico residents triggers additional notification requirements. The entity must notify the Office of the Attorney General and the major consumer reporting agencies in the most expedient time possible, and no later than 45 calendar days following discovery of the breach.
Delayed Notification for Law Enforcement
NMSA 57-12C-9 permits delayed notification if a law enforcement agency determines that notification would impede a criminal investigation. Once law enforcement indicates that notification will no longer compromise the investigation, the entity must proceed with notification as quickly as possible.
Attorney General Enforcement and Penalties
Under NMSA 57-12C-11, enforcement of the Data Breach Notification Act rests exclusively with the New Mexico Attorney General. There is no private right of action, meaning individual consumers cannot sue entities directly for violations of this statute.
The Attorney General may bring an action on behalf of individuals and in the name of the state when there is a reasonable belief that a violation has occurred.
Civil Penalties
If a court determines that a person violated the Data Breach Notification Act knowingly or recklessly, the court may impose a civil penalty of the greater of:
- $25,000, or
- $10 per instance of failed notification, up to a maximum of $150,000
For large-scale breaches affecting tens of thousands of residents, the per-instance penalty can quickly exceed the $25,000 floor, but the statute caps the total penalty at $150,000 regardless of how many residents went unnotified. A breach affecting 50,000 residents where notification was not provided would be capped at $150,000, not calculated out to $500,000.
Exemptions
NMSA 57-12C-8 exempts any person subject to the federal Gramm-Leach-Bliley Act (GLBA) or the federal Health Insurance Portability and Accountability Act (HIPAA) of 1996 from the entire Data Breach Notification Act. The exemption applies simply because the entity is subject to GLBA or HIPAA; the statute does not require a separate showing of compliance and does not limit the exemption to only certain provisions.
Separately, NMSA 57-12C-12 exempts the state of New Mexico and its political subdivisions from the Act in full.
The Unfair Practices Act and Data Privacy
While the Data Breach Notification Act targets security breaches specifically, the Unfair Practices Act (NMSA 57-12-1 through 57-12-26) provides a broader framework the Attorney General and consumers can use to challenge deceptive data practices.
How the UPA Applies to Privacy
Under NMSA 57-12-3, unfair or deceptive trade practices and unconscionable trade practices in the conduct of any trade or commerce are unlawful. This includes false or misleading statements made in connection with the sale of goods or services.
In the data privacy context, a business that promises to protect customer data in its privacy policy but fails to implement adequate safeguards could face UPA liability. A company that collects data in ways that contradict its stated privacy practices may be engaged in a deceptive trade practice.
Under NMSA 57-12-2, an "unconscionable trade practice" includes any act that takes advantage of a person's lack of knowledge to a grossly unfair degree. Data harvesting practices that exploit consumers' lack of technical understanding could potentially fall under this definition.
Meta Verdict: $375 Million (March 2026)
New Mexico's UPA enforcement reached a landmark in March 2026. On March 24, 2026, a Santa Fe jury found Meta liable for willful violations of the Unfair Practices Act and ordered the company to pay $375 million in civil penalties. The jury found that Meta misled the public about the safety of Facebook and Instagram for children and failed to prevent predatory contact with minors on its platforms.
The jury applied the maximum penalty of $5,000 per willful violation under NMSA 57-12-11, resulting in 75,000 counted violations. New Mexico became the first state to prevail at trial against a major technology platform for harms to young people.
The case then moved to a second phase on the state's public nuisance claim. After a bench trial held between May 4 and May 22, 2026, the First Judicial District Court entered its Findings of Fact, Conclusions of Law, and Judgment, Order, and Decree on August 6, 2026, ruling in the state's favor and ordering Meta to abate the nuisance.
The decree orders Meta to deposit $567 million into an abatement fund, in addition to the $375 million in Phase 1 civil penalties. The court allocated the fund across treatment ($420 million), screening and assessment ($90 million), awareness and prevention ($33 million), referral, linkage and coordination ($15 million), and implementation, quality improvement and evaluation ($9 million). Meta's compliance obligations run for a five-year abatement period, and it must report in writing to the court and the state each June 30 and December 31.
On age assurance, the court ordered Meta to keep improving its age-estimation models in New Mexico, to attempt to develop a dedicated under-13 prediction model within two years, to proactively request proof of age from New Mexico accounts its systems predict belong to users under 13 and mark for deletion those that do not verify within 30 days, and to treat a user it believes is under 13 or under 18 as such until the user verifies. The court declined to order changes to industry-wide engagement features such as infinite scroll and autoplay, reasoning that regulating them requires legislative or executive action. It also denied the state's request for a Child Safety Monitor, opting instead to set objective requirements the state can enforce by returning to court.
UPA Penalties and Enforcement
Unlike the Data Breach Notification Act, the Unfair Practices Act provides both public enforcement by the Attorney General and a private right of action for consumers. Under NMSA 57-12-10, a person who suffers loss due to an unfair or deceptive trade practice may bring a civil action to recover actual damages or $100, whichever is greater, plus reasonable attorneys' fees.
The Attorney General may also seek civil penalties under NMSA 57-12-11 and injunctive relief to stop ongoing deceptive practices.
New Mexico Privacy Protection Act (NMSA 57-12B)
Chapter 57, Article 12B of the New Mexico Statutes is titled the Privacy Protection Act. It is narrow but directly on point for data privacy: it restricts what a business may do with a consumer's Social Security number. It is easy to overlook because it sits beside the better-known Unfair Practices Act in the same chapter.
Under NMSA 57-12B-2, a "business" is a commercial enterprise that sells or leases products, goods, or services to consumers, an agent of such a business, or an agent of a nonprofit organization selling marketing services to that organization. A "consumer" is a New Mexico resident who purchases, leases, or otherwise contracts for goods or services in New Mexico primarily for personal, family, or household purposes.
Social Security Numbers as a Condition of Sale
NMSA 57-12B-3 bars a business from requiring a consumer's Social Security number as a condition of purchasing or leasing products, goods, or services. The section does not apply where the number will be used in a manner consistent with state or federal law, as part of a credit application, or in connection with annuity or insurance transactions, and a business may still acquire or use the number if the consumer consents.
The same section imposes an affirmative internal-controls duty that businesses frequently miss. A company acquiring or using consumers' Social Security numbers must adopt internal policies that limit access to employees authorized to have that information to perform their duties, and that hold employees responsible if numbers are released to unauthorized persons.
Restrictions on Displaying and Transmitting Social Security Numbers
NMSA 57-12B-4 prohibits a business from doing any of the following, subject to the exceptions in Subsection B:
- Making an entire Social Security number available to the general public, including printing it on a receipt issued for a purchase
- Requiring use of the number over the internet without a secure connection or encryption security
- Requiring the number to access an internet account unless a password, personal identification number, or other authentication device is also required
- Printing the number on materials mailed to a consumer unless authorized or required by federal or state law, subject to detailed exceptions for application and enrollment materials the consumer fills in and mails back
- Transmitting material that associates a Social Security number with a bank, savings and loan, or credit union account number, outside defined application, enrollment, and account-maintenance situations
- Refusing to transact business because a consumer declined to provide the number for a use the section prohibits
Subsection B carves out numbers on documents generated before January 1, 2006; collection or use that is part of an application or enrollment process, is required or authorized by law, or is for internal verification or administrative purposes (provided the business complies with the access-limitation policy required by 57-12B-3); and documents filed in court or public records.
Sections 57-12B-1 through 57-12B-3 took effect January 1, 2004 (Laws 2003, ch. 169) and 57-12B-4 took effect January 1, 2006 (Laws 2005, ch. 127). Article 12B itself sets out no separate penalty provision.
Nondisclosure of Sensitive Personal Information Act (SB 36, 2025)

In April 2025, Governor Michelle Lujan Grisham signed Senate Bill 36, the Nondisclosure of Sensitive Personal Information Act, codified at NMSA 10-16I-1 through 10-16I-4, effective July 1, 2025.
The law targets state agency employees rather than private businesses. It prohibits any state employee from intentionally disclosing an individual's sensitive personal information except in defined circumstances. Under the Act, "sensitive personal information" includes:
- Status as a recipient of public assistance or as a crime victim
- Sexual orientation or gender identity
- Physical or mental disability or medical condition
- Immigration status, national origin, or religion
- Social Security number or tax identification number
The Act permits disclosure in several defined circumstances, including when necessary for the agency's official functions, required by a court order or subpoena, needed to satisfy public records obligations under the Inspection of Public Records Act, required by federal statute, made to or by a court in the course of a judicial proceeding or in a court record, required under a contract with a state contractor bound to the same restrictions, or made with the individual's written consent.
The Attorney General, district attorneys, and the State Ethics Commission may enforce the Act through civil action. The penalty is $250 per violation, not to exceed $5,000. The Act also amends Section 66-2-7.1 of the New Mexico Motor Vehicle Code to reinforce confidentiality for driver license and vehicle registration records.
This law does not create the kind of comprehensive consumer privacy rights available in states with full-scale privacy statutes. It applies only to state-employee conduct and does not give private individuals a direct right of action against state agencies.
Federal Privacy Laws Protecting New Mexico Residents
Because New Mexico lacks a comprehensive state data privacy law, federal statutes play a significant role in protecting residents' personal information across specific sectors.
HIPAA (Health Insurance Portability and Accountability Act)
HIPAA protects the privacy and security of individually identifiable health information held by covered entities (healthcare providers, health plans, and healthcare clearinghouses) and their business associates. New Mexico residents' medical records, health insurance claims, and other protected health information are governed by HIPAA's Privacy Rule and Security Rule.
New Mexico's Data Breach Notification Act exempts entities that are subject to HIPAA's breach notification requirements, avoiding duplicative obligations.
FERPA (Family Educational Rights and Privacy Act)
The Family Educational Rights and Privacy Act protects the privacy of student education records at institutions that receive federal funding. In New Mexico, this covers all public schools, most colleges and universities, and any other educational institution that participates in federal financial aid programs. Parents and eligible students have the right to access education records and request corrections.
COPPA (Children's Online Privacy Protection Act)
The Children's Online Privacy Protection Act restricts the online collection of personal information from children under 13. Websites and online services directed at children or that knowingly collect information from children must obtain verifiable parental consent. This federal law applies to all websites and services accessible to New Mexico children.
Gramm-Leach-Bliley Act (GLBA)
The GLBA requires financial institutions to explain their information-sharing practices and to safeguard sensitive data. Banks, credit unions, securities firms, and insurance companies serving New Mexico residents must provide annual privacy notices and implement data security programs.
Fair Credit Reporting Act (FCRA)
The FCRA regulates the collection, dissemination, and use of consumer credit information. New Mexico residents have the right to know what is in their credit file, to dispute inaccurate information, and to limit who can access their credit reports. The FCRA is referenced directly in New Mexico's breach notification requirements.
TAKE IT DOWN Act (2025)

The TAKE IT DOWN Act (Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act, Pub. L. 119-12) was signed into law on May 19, 2025. It creates federal criminal liability for publishing nonconsensual intimate images (NCII), including AI-generated deepfakes.
The Act requires covered online platforms to establish a notice-and-removal process for NCII. When a platform receives a valid removal request, it must take down the content and any known identical copies within 48 hours. FTC enforcement of platform takedown obligations became effective on May 19, 2026. New Mexico residents who are victims of NCII may submit takedown notices to covered platforms and report non-complying platforms to the FTC.
Privacy Legislation: 2025 and 2026 Sessions
Multiple legislative efforts have attempted to establish comprehensive consumer data privacy protections in New Mexico. None have been enacted as of May 2026.
2025 Session: Three Bills, None Enacted
Three comprehensive privacy bills were introduced in the 2025 regular session and none advanced.
House Bill 307 (Internet Privacy and Safety Act, introduced February 5, 2025) would have established consumer data rights, prohibited retaliation for exercising privacy rights, and required data protection assessments before transferring personal data to third parties outside New Mexico. Civil penalties would have reached $2,500 per affected consumer per negligent violation and $7,500 per intentional violation, with a private right of action. HB 307 was referred to the House Commerce and Economic Development Committee and died there.
House Bill 410 (Consumer Info and Data Protection Act) was the Attorney General-backed approach. Key provisions included definitions for consumer health data and sensitive data, special protections for children's data, a 30-day cure period, civil penalties up to $10,000 per violation, and exclusive AG enforcement with no private right of action. A substitute version passed committee unanimously in March 2025 but was subsequently postponed indefinitely and did not advance.
Senate Bill 420 (Community Privacy and Safety Act) took the most consumer-protective approach: default privacy settings at the maximum protection level, an opt-in requirement for targeted advertising, and additional safeguards for minors including restrictions on nighttime notifications. SB 420 was postponed indefinitely on February 28, 2025.
2026 Session: SB 53 (CHISPA) Did Not Advance
Senate Bill 53 (Community and Health Info Safety and Privacy Act, or CHISPA) was the primary comprehensive privacy bill of the 2026 regular session. SB 53 would have applied to entities processing data from as few as 15,000 consumers, well below the 100,000-consumer threshold common in other state laws, and would have required an affirmative "necessity" standard for most data processing. It also included a private right of action with penalties of $2,500 per negligent violation and $7,500 per intentional violation per affected consumer.
SB 53 received a Do Pass recommendation from the Senate Health and Public Affairs Committee in February 2026, but it did not receive a floor vote before the 30-day session adjourned on February 19, 2026. Industry groups including CCIA and BSA opposed the bill as departing from frameworks adopted in more than 20 other states.
New Mexico is expected to revisit comprehensive privacy legislation. Businesses operating in New Mexico should monitor future sessions closely. When a comprehensive law is eventually enacted, it will likely include consumer rights to access, delete, and opt out of the sale of personal data, along with new obligations for data controllers and processors.
Practical Steps for Businesses Operating in New Mexico
Even without a comprehensive privacy law, businesses handling New Mexico residents' data must comply with several requirements.
Compliance Checklist
- Implement reasonable security measures appropriate to the sensitivity of the personal identifying information you maintain (NMSA 57-12C-4)
- Establish a data disposal policy to shred, erase, or render unreadable personal identifying information no longer needed for business purposes (NMSA 57-12C-3)
- Create an incident response plan that ensures breach notification within the 45-day statutory window (NMSA 57-12C-6)
- Include all required content in breach notification letters as specified in NMSA 57-12C-7
- Know your reporting thresholds: breaches affecting 1,000+ residents require AG and credit agency notification (NMSA 57-12C-10)
- Vet service providers to ensure they maintain reasonable security measures under contract (NMSA 57-12C-5) and will report breaches promptly (NMSA 57-12C-6)
- Review privacy policies for accuracy to avoid Unfair Practices Act liability for deceptive statements about data handling
- Encrypt personal identifying information to take advantage of the encryption safe harbor in the breach notification definitions
- If your platform hosts user content, implement a TAKE IT DOWN Act-compliant notice-and-removal process for nonconsensual intimate images (FTC-enforced as of May 19, 2026)
- Comply with applicable federal laws including HIPAA, GLBA, FERPA, and COPPA as relevant to your industry
Reporting a Data Breach
To report a data breach to the New Mexico Attorney General, businesses should contact the Office of the Attorney General directly. For breaches affecting more than 1,000 New Mexico residents, notification to the AG and major credit bureaus is required under NMSA 57-12C-10.
Consumers who believe their data has been compromised can file complaints with the New Mexico Attorney General's Consumer Protection Division.
This article provides general legal information about New Mexico data privacy laws. It is not legal advice and does not create an attorney-client relationship. Data privacy laws change frequently. Consult with a qualified attorney licensed in New Mexico for advice about your specific situation.
More New Mexico Laws
Frequently Asked Questions
Does New Mexico have a comprehensive consumer data privacy law?
No. As of May 2026, New Mexico does not have a comprehensive consumer data privacy law similar to California's CCPA/CPRA, Virginia's CDPA, or Colorado's CPA. The state relies on its Data Breach Notification Act (NMSA 57-12C), the Unfair Practices Act (NMSA 57-12), and applicable federal laws like HIPAA, FERPA, and COPPA. Multiple comprehensive privacy bills were introduced in the 2025 session (HB 307, HB 410, and SB 420) and the 2026 session (SB 53/CHISPA), but all failed to advance. Similar efforts are expected in future sessions.
How quickly must a business notify New Mexico residents of a data breach?
Under NMSA 57-12C-6, businesses must notify affected New Mexico residents within 45 calendar days of discovering a security breach. This notification must be made in the most expedient time possible within that window. Notification is not required if an investigation determines that the breach does not give rise to a significant risk of identity theft or fraud. Breaches affecting more than 1,000 residents also require notification to the Attorney General and major consumer reporting agencies.
Is biometric data protected under New Mexico law?
Biometric data is included in New Mexico's definition of personal identifying information under the Data Breach Notification Act (NMSA 57-12C-2). A breach involving biometric data such as fingerprints, voice prints, iris patterns, facial characteristics, or hand geometry triggers notification requirements. However, New Mexico does not have a standalone biometric privacy law like Illinois's BIPA that would require consent before collecting biometric data or establish specific retention and destruction schedules.
What penalties can the New Mexico Attorney General impose for data breach notification violations?
Under NMSA 57-12C-11, if a court determines that a person violated the Data Breach Notification Act knowingly or recklessly, it may impose a civil penalty of the greater of $25,000 or $10 per instance of failed notification. For large breaches, the per-instance calculation can produce substantially higher penalties, up to a statutory cap of $150,000. Enforcement authority rests exclusively with the Attorney General. There is no private right of action under the Data Breach Notification Act, though consumers may have separate claims under the Unfair Practices Act for deceptive data handling.
Does New Mexico require businesses to encrypt personal data?
New Mexico does not mandate encryption. However, the Data Breach Notification Act creates a strong incentive to encrypt. Under NMSA 57-12C-2, personal identifying information that is protected through encryption or redaction and otherwise rendered unreadable or unusable falls outside the definition that triggers breach notification requirements. If encrypted data is compromised but the encryption key is not, the breach notification obligations do not apply. Additionally, NMSA 57-12C-4 requires businesses to implement reasonable security measures, and encryption is widely considered a reasonable practice.
What is the TAKE IT DOWN Act and how does it affect New Mexico residents?
The TAKE IT DOWN Act (Pub. L. 119-12) is a federal law signed on May 19, 2025. It criminalizes the publication of nonconsensual intimate images (NCII), including AI-generated deepfakes, and requires covered online platforms to remove such content within 48 hours of receiving a valid notice. FTC enforcement of the platform takedown obligations began May 19, 2026. New Mexico residents who are victims of NCII can submit takedown notices directly to covered platforms. Non-complying platforms are subject to FTC enforcement action.
What happened in New Mexico's lawsuit against Meta?
Attorney General Raúl Torrez filed suit against Meta under the Unfair Practices Act, alleging the company misled the public about the safety of Facebook and Instagram for children and failed to protect minors from predatory contact. On March 24, 2026, a Santa Fe jury found Meta liable for willful violations and ordered the company to pay $375 million in civil penalties, applying the maximum $5,000-per-violation rate under NMSA 57-12-11 across 75,000 counted violations. New Mexico was the first state to prevail at trial against a major tech platform for harms to young people. In a second phase, the court held a bench trial on the state's public nuisance claim and, on August 6, 2026, entered a judgment and decree for the state. It ordered Meta to deposit $567 million into an abatement fund and to meet five years of abatement requirements, including proactive age assurance measures, and it denied the state's request for a Child Safety Monitor.
Updates
Updated the Meta case to report the court's August 6, 2026 abatement decree (a $567 million abatement fund, five years of age assurance requirements, and denial of the state's requested Child Safety Monitor), added a section on New Mexico's Privacy Protection Act (NMSA 57-12B) covering its Social Security number restrictions, and noted that the Data Breach Notification Act does not apply to state or local government.
Replaced dead nmoag.gov links with the Attorney General's current nmdoj.gov site, and expanded the summary of SB 36's disclosure exceptions to include the federal-statute and judicial-proceeding exceptions.
Independently fact-checked against the cited primary sources
Corrected the service-provider notification duty (misattributed to NMSA 57-12C-5, actually 57-12C-6), the civil-penalty example (statute caps per-instance penalties at $150,000, not $500,000), the substitute-notification checklist (added the required website-posting element), the GLBA/HIPAA exemption (full exemption for any entity subject to those laws, not a compliance-conditioned partial exemption), and the misattributed "person" definition (not in NMSA 57-12C-2).
Governing law re-checked for recent changes
May 2026 refresh: Added SB 36 (2025, enacted, eff. July 1, 2025), the Nondisclosure of Sensitive Personal Information Act, NMSA 10-16I-1 through -4. Added Meta $375M jury verdict (March 24, 2026) under Unfair Practices Act. Added SB 53 (CHISPA, 2026 session) which did not advance before the session adjourned February 19, 2026. Added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025, FTC platform enforcement effective May 19, 2026). Added Snap lawsuit (filed September 2024, in discovery). Expanded FAQ from 5 to 7 questions. Updated all as-of-March-2026 date references to May 2026. Title and meta-description updated to reflect Meta verdict and new federal law. 4 new citations added.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Mexico Statutes Annotated 1978, Chapter 57
§ 57-12C-6Notification of security breachIn forcecited in 5 of our articles
A. Except as provided in Subsection C of this section, a person that owns or licenses elements that include personal identifying information of a New Mexico resident shall provide notification to each New Mexico resident whose personal identifying information is reasonably believed to have been subject to a security breach. Notification shall be made in the most expedient time possible, but not later than forty- five calendar days following discovery of the security breach, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act. B. Notwithstanding Subsection A of this section, notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. C.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at nmonesource.com
Cross-referenced in the statute itself: § 57-12C-9
Also relied on in: New Mexico Biometric Privacy Laws: Collection, Consent & Penalties (2026), New Mexico Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 57-12C-2DefinitionsIn forcecited in 4 of our articles
As used in the Data Breach Notification Act: A. "biometric data" means a record generated by automatic measurements of an identified individual's fingerprints, voice print, iris or retina patterns, facial characteristics or hand geometry that is used to uniquely and durably authenticate an individual's identity when the individual accesses a physical location, device, system or account; B. "encrypted" means rendered unusable, unreadable or indecipherable to an unauthorized person through a security technology or methodology generally accepted in the field of information security; C.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-4Security measures for storage of personal identifying information.In forcecited in 2 of our articles
A person that owns or licenses personal identifying information of a New Mexico resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal identifying information from unauthorized access, destruction, use, modification or disclosure.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-3Disposal of personal identifying informationIn forcecited in 2 of our articles
A person that owns or licenses records containing personal identifying information of a New Mexico resident shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes. As used in this section, "proper disposal" means shredding, erasing or otherwise modifying the personal identifying information contained in the records to make the personal identifying information unreadable or undecipherable.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-5Service provider use of personal identifying information; implementation of security measures.In forcecited in 2 of our articles
A person that discloses personal identifying information of a New Mexico resident pursuant to a contract with a service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices appropriate to the nature of the personal identifying information and to protect it from unauthorized access, destruction, use, modification or disclosure.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-7Notification; required contentIn forcecited in 2 of our articles
Notification required pursuant to Subsection A of Section 6 [57-12C-6 NMSA 1978] of the Data Breach Notification Act shall contain: A. the name and contact information of the notifying person; B. a list of the types of personal identifying information that are reasonably believed to have been the subject of a security breach, if known; C. the date of the security breach, the estimated date of the breach or the range of dates within which the security breach occurred, if known; D. a general description of the security breach incident; E. the toll-free telephone numbers and addresses of the major consumer reporting agencies; F. advice that directs the recipient to review personal account statements and credit reports, as applicable, to detect errors resulting from the security breach; and G. advice that informs the recipient of the notification of the recipient's rights pursuant to the federal Fair Credit Reporting.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cross-referenced in the statute itself: § 57-12C-6
§ 57-12C-9Delayed notificationIn forcecited in 2 of our articles
The notification required by the Data Breach Notification Act may be delayed: A. if a law enforcement agency determines that the notification will impede a criminal investigation; or B. as necessary to determine the scope of the security breach and restore the integrity, security and confidentiality of the data system.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-10Notification to attorney general and credit reporting agencies.In forcecited in 4 of our articles
A person that is required to issue notification of a security breach pursuant to the Data Breach Notification Act to more than one thousand New Mexico residents as a result of a single security breach shall notify the office of the attorney general and major consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. Section 1681a(p), of the security breach in the most expedient time possible, and no later than forty-five calendar days, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act. A person required to notify the attorney general and consumer reporting agencies pursuant to this section shall notify the attorney general of the number of New Mexico residents that received notification pursuant to Section 6 of that act [57-12C-6 NMSA 1978] and shall provide a copy of the notification that was sent to affected residents within forty-five calendar days following discovery of the security breach, except as provided in Section 9 of the Data Breach Notification Act.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cross-referenced in the statute itself: § 57-12C-6, § 57-12C-9
§ 57-12C-11Attorney general enforcement; civil penaltyIn forcecited in 4 of our articles
A. When the attorney general has a reasonable belief that a violation of the Data Breach Notification Act has occurred, the attorney general may bring an action on the behalf of individuals and in the name of the state alleging a violation of that act. B. In any action filed by the attorney general pursuant to the Data Breach Notification Act, the court may: (1) issue an injunction; and (2) award damages for actual costs or losses, including consequential financial losses. C. If the court determines that a person violated the Data Breach Notification Act knowingly or recklessly, the court may impose a civil penalty of the greater of twenty- five thousand dollars ($25,000) or, in the case of failed notification, ten dollars ($10.00) per instance of failed notification up to a maximum of one hundred fifty thousand dollars ($150,000).
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
§ 57-12C-8ExemptionsIn forcecited in 2 of our articles
The provisions of the Data Breach Notification Act shall not apply to a person subject to the federal Gramm-Leach-Bliley Act or the federal Health Insurance Portability and Accountability Act of 1996.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- Charlie v. Rehoboth McKinley Christian Health Care Services (District Court, D. New Mexico 2022)“…lth Insurance Portability and Accountability Act of 1996.” NMSA § 57-12C-8. The complaint alleges that Defendant i…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12C-1Short titleIn forcecited in 6 of our articles
This act [57-12C-1 to 57-12C-12 NMSA 1978] may be cited as the "Data Breach Notification Act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- Charlie v. Rehoboth McKinley Christian Health Care Services (District Court, D. New Mexico 2022)“…s’ data under the New Mexico Data Breach Notification Act, N.M. Stat. Ann. § 57-12C-1, et seq. (2017).”); id. at 13 (“Defenda…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12-3Unfair or deceptive and unconscionable trade practices prohibited.In forcecited in 2 of our articles
Unfair or deceptive trade practices and unconscionable trade practices in the conduct of any trade or commerce are unlawful.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 53 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Brooks v. Norwest Corp. (New Mexico Court of Appeals 2004, 136 N.M. 599)“…NM) alleging violations of the Unfair Practices Act (UPA), NMSA 1978, § 57-12-3 (1971), breach of the covenant of good…”
- Hicks v. Eller (New Mexico Court of Appeals 2012, 2 N.M. 1)“…ices in the conduct of any trade or commerce are unlawful.” NMSA 1978, § 57-12-3 (1971). An “unfair or deceptive trade p…”
- Richardson Ford Sales, Inc. v. Johnson (New Mexico Court of Appeals 1984, 100 N.M. 779)“…the intent of the legislature that in construing Section 3 [57-12-3 NMSA 1978] of the Unfair Practices Act the courts…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12-2DefinitionsIn forcecited in 2 of our articles
As used in the Unfair Practices Act: A. “person" means, where applicable, natural persons, corporations, trusts, partnerships, associations, cooperative associations, clubs, companies, firms, joint ventures or syndicates; B. “seller-initiated telephone sale" means a sale, lease or rental of goods or services in which the seller or the seller's representative solicits the sale by telephoning the prospective purchaser and in which the sale is consummated entirely by telephone or mail, but does not include a transaction: (1) in which a person solicits a sale from a prospective purchaser who has previously made an authorized purchase from the seller's business; or (2) in which the purchaser is accorded the right of rescission by the provisions of the federal Consumer Credit Protection Act, 15 U.S.C. 1635, or regulations issued pursuant thereto; C. “trade" or "commerce" includes the advertising, offering for sale or distribution of any services and any property and any other article, commodity or thing of value, including any trade or commerce directly or indirectly affecting the people of this state; D.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 108 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Stevenson v. Louis Dreyfus Corp. (New Mexico Supreme Court 1991, 112 N.M. 97)“…he elements of an Unfair Practices Act (Act) violation. See NMSA 1978, § 57-12-2(D) (Cum.Supp.1990). 1 We a…”
- Ashlock v. Sunwest Bank of Roswell, N.A. (New Mexico Supreme Court 1988, 107 N.M. 100)“…ding representation to a consumer must be “knowingly made.” NMSA 1978, § 57-12-2(C) (Repl.Pamp. 1987); Richardson Ford S…”
- Teague-Strebeck Motors, Inc. v. Chrysler Insurance (New Mexico Court of Appeals 1999, 127 N.M. 603)“…hich may, tends to or does deceive or mislead any person. NMSA 1978, § 57-12-2(D) (1995) (second alteration in origina…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12-10Private remediesIn forcecited in 2 of our articles
A. A person likely to be damaged by an unfair or deceptive trade practice or by an unconscionable trade practice of another may be granted an injunction against it under the principles of equity and on terms that the court considers reasonable. Proof of monetary damage, loss of profits or intent to deceive or take unfair advantage of any person is not required. Relief granted for the copying of an article shall be limited as to the prevention of confusion or misunderstanding as to source. B. Any person who suffers any loss of money or property, real or personal, as a result of any employment by another person of a method, act or practice declared unlawful by the Unfair Practices Act may bring an action to recover actual damages or the sum of one hundred dollars ($100), whichever is greater. Where the trier of fact finds that the party charged with an unfair or deceptive trade practice or an unconscionable trade practice has willfully engaged in the trade practice, the court may award up to three times actual damages or three hundred dollars ($300), whichever is greater, to the party complaining of the practice. C.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 90 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Hale v. Basin Motor Co. (New Mexico Supreme Court 1990, 110 N.M. 314)“…sum of one hundred dollars ($100), whichever is greater. NMSA 1978, § 57-12-10(B) (Repl.Pamp. 1987). The trial court h…”
- Ashlock v. Sunwest Bank of Roswell, N.A. (New Mexico Supreme Court 1988, 107 N.M. 100)“…e, the court may award up to three times actual damages * * NMSA 1978, § 57-12-10(B). (Emphasis ours.) That permissive la…”
- Lohman v. Daimler-Chrysler Corp. (New Mexico Court of Appeals 2007, 142 N.M. 437)“…s a result of any” unfair or deceptive practice by another. NMSA 1978, § 57-12-10(B) (2005). These provisions appear to b…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12-11Civil penaltyIn forcecited in 2 of our articles
In any action brought under Section 57-12-8 NMSA 1978, if the court finds that a person is willfully using or has willfully used a method, act or practice declared unlawful by the Unfair Practices Act, the attorney general, upon petition to the court, may recover, on behalf of the state of New Mexico, a civil penalty of not exceeding five thousand dollars ($5,000) per violation.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Connecticut v. Aurobindo Pharma USA, Inc. (District Court, D. Connecticut 2025)“…l to petition for civil penalties for willful violations. N.M. Stat. Ann. § 57-12-11.…”
- Connecticut v. Sandoz, Inc. (District Court, D. Connecticut 2024)“…ies under certain circumstances. ECF No. 367-1 at 42; see N.M. Stat. Ann. § 57-12-11 (“[I]f the court finds that a person i…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12-1Short titleIn forcecited in 7 of our articles
Chapter 57, Article 12 NMSA 1978 may be cited as the "Unfair Practices Act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 239 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Romero v. Philip Morris Inc. (New Mexico Supreme Court 2010, 148 N.M. 713)“…MSA 1978, §§ 57-1-1 to -15 (1979, as amended through 1987); NMSA 1978, §§ 57-12-1 to -22 (1967, as amended through 1999).…”
- Cordova v. World Finance Corp. of NM (New Mexico Supreme Court 2009, 146 N.M. 256)“…hin the meaning of the New Mexico Unfair Practices Act. See NMSA 1978, §§ 57-12-1 to -24 (1967, as amended through 2003).…”
- Quynh Truong v. Allstate Insurance (New Mexico Supreme Court 2010, 147 N.M. 583)“…cability of an exemption to the Unfair Practices Act (UPA), NMSA 1978, Sections 57-12-1 to -22 (1967, as amended through 1999),…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: New Mexico Lemon Law (2026): How to Qualify & Get a Refund
New Mexico Statutes Annotated 1978, Chapter 10
§ 10-16I-1Short titleIn forcecited in 2 of our articles
Sections 1 through 4 [10-16I-1 to 10-16I-4 NMSA 1978] of this act may be cited as the "Nondisclosure of Sensitive Personal Information Act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cross-referenced in the statute itself: § 10-16I-4
§ 10-16I-4Enforcement; penaltiesIn forcecited in 2 of our articles
The attorney general, a district attorney and the state ethics commission may institute a civil action in district court if a violation has occurred or to prevent a violation of the Nondisclosure of Sensitive Personal Information Act. Penalties for a violation of that act shall be a civil penalty of two hundred fifty dollars ($250) for each violation, but not to exceed five thousand dollars ($5,000).
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
New Mexico Statutes Annotated 1978, Chapter 66
§ 66-2-7.1Motor vehicle-related records; confidentialIn forcecited in 2 of our articles
A. It is unlawful for any department or bureau employee or contractor or for any former department or bureau employee or contractor to disclose to any person other than another employee of the department or bureau any personal information about an individual obtained by the department or bureau in connection with a driver's license or permit, the titling or registration of a vehicle, the administration of the Ignition Interlock Licensing Act [66-5-501 to 66-5-504 NMSA 1978] and the interlock device fund or an identification card issued by the department pursuant to the Motor Vehicle Code [Articles 1 through 8 of Chapter 66 NMSA 1978, except 66-7-102.1 NMSA 1978] except: (1) to the individual or the individual's authorized representative; (2) for use by any governmental agency, including any court, in carrying out its functions or by any private person acting on behalf of the government; (3) for use in connection with matters of motor vehicle and driver safety or theft; motor vehicle emissions; performance monitoring of motor vehicles, motor vehicle parts and dealers; motor vehicle market research activities, including survey research; motor vehicle production…
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2012
Opinions citing this section in our collection:
- Republican Party v. New Mexico Taxation & Revenue Department (New Mexico Supreme Court 2012, 2 N.M. 324)“…94, as amended through 2000) (DPPA) and its state analogue, NMSA 1978, § 66-2-7.1 (2007) (NMDPPA) (collectively, Privacy…”
- Republican Party of N.M. v. New Mexico Taxation & Revenue Dep't (New Mexico Court of Appeals 2010, 148 N.M. 877)“…(2) the New Mexico Driver Privacy Protection Act (NMDPPA), NMSA 1978, Section 66-2-7.1 (2007); (3) Rule 11-503 NMRA, attorney-…”
- Republican Party of NM v. NM TAXATION (New Mexico Court of Appeals 2010, 242 P.3d 444)“…(2) the New Mexico Driver Privacy Protection Act (NMDPPA), NMSA 1978, Section 66-2-7.1 (2007); (3) Rule 11-503 NMRA, attorney-…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Explore the law
The laws cited above reference these related sections in their own text:
- New Mexico Statutes Annotated 1978, Chapter 47 § 47-8-1 — Short title view in our statute record · read at the official source
- New Mexico Statutes Annotated 1978, Chapter 57 § 57-12C-12 — State of New Mexico and political subdivisions exempted. view in our statute record · read at the official source
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- New Mexico Data Breach Notification Act (HB 15, 2017 Session)(nmlegis.gov).gov
- NMSA 57-12C-2: Definitions (Personal Identifying Information, Biometric Data)(law.justia.com)
- NMSA 57-12C-6: Notification of Security Breach(law.justia.com)
- NMSA 57-12C-7: Notification Required Content(law.justia.com)
- New Mexico Unfair Practices Act (Chapter 57, Article 12)(law.justia.com)
- HB 307: Internet Privacy and Safety Act (2025 Session)(nmlegis.gov).gov
- HB 410: Consumer Info and Data Protection Act (2025 Session)(nmlegis.gov).gov
- SB 420: Community Privacy and Safety Act (2025 Session)(nmlegis.gov).gov
- HIPAA Privacy and Security Information(hhs.gov).gov
- FERPA General Guidance(www2.ed.gov).gov
- FTC: COPPA Rule(ftc.gov).gov
- FTC: Fair Credit Reporting Act(ftc.gov).gov
- New Mexico Department of Justice (Office of the Attorney General)(nmdoj.gov).gov
- NMSA 57-12C-3: Disposal of Personal Identifying Information(law.justia.com)
- NMSA 57-12C-4: Security Measures for Storage of Personal Identifying Information(law.justia.com)
- NMSA 57-12C-10: Notification to Attorney General and Credit Reporting Agencies(law.justia.com)
- NMSA 57-12C-11: Enforcement, Civil Penalties(law.justia.com)
- NMSA 57-12-3: Unfair or Deceptive and Unconscionable Trade Practices Prohibited(law.justia.com)
- New Mexico Department of Justice: Landmark Verdict Against Meta (March 2026)(nmdoj.gov).gov
- Attorney General Torrez Files Lawsuit Against Snap Inc. (September 2024)(nmdoj.gov).gov
- SB 36: Sensitive Personal Information Nondisclosure (2025 Session)(nmlegis.gov).gov
- SB 53: Community and Health Info Safety and Privacy Act (2026 Session)(nmlegis.gov).gov
- FTC: TAKE IT DOWN Act Enforcement (May 2026)(ftc.gov).gov
- FTC: Gramm-Leach-Bliley Act(ftc.gov).gov
- State of New Mexico ex rel. Torrez v. Meta Platforms, Inc., No. D-101-CV-2023-02838: Findings of Fact, Conclusions of Law, and Judgment, Order, and Decree (1st Jud. Dist. Ct., filed Aug. 6, 2026)(nmcourts.gov)
- NMSA Chapter 57: Privacy Protection Act (Art. 12B) and Data Breach Notification Act (Art. 12C, including 57-12C-12 exemption for the state and its political subdivisions), New Mexico Compilation Commission(nmonesource.com)