EnglishEspañol
New Mexico flag

New Mexico

New Mexico Data Privacy Laws: Breach Notification, AG Enforcement & 2026 Legislation

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 7, 2026. · 15 primary sources cited on this page. How we verify our legal content

New Mexico Data Privacy Laws: Breach Notification, AG Enforcement & 2026 Legislation

Frequently Asked Questions

Does New Mexico have a comprehensive consumer data privacy law?

No. As of May 2026, New Mexico does not have a comprehensive consumer data privacy law similar to California's CCPA/CPRA, Virginia's CDPA, or Colorado's CPA. The state relies on its Data Breach Notification Act (NMSA 57-12C), the Unfair Practices Act (NMSA 57-12), and applicable federal laws like HIPAA, FERPA, and COPPA. Multiple comprehensive privacy bills were introduced in the 2025 session (HB 307, HB 410, and SB 420) and the 2026 session (SB 53/CHISPA), but all failed to advance. Similar efforts are expected in future sessions.

How quickly must a business notify New Mexico residents of a data breach?

Under NMSA 57-12C-6, businesses must notify affected New Mexico residents within 45 calendar days of discovering a security breach. This notification must be made in the most expedient time possible within that window. Notification is not required if an investigation determines that the breach does not give rise to a significant risk of identity theft or fraud. Breaches affecting more than 1,000 residents also require notification to the Attorney General and major consumer reporting agencies.

Is biometric data protected under New Mexico law?

Biometric data is included in New Mexico's definition of personal identifying information under the Data Breach Notification Act (NMSA 57-12C-2). A breach involving biometric data such as fingerprints, voice prints, iris patterns, facial characteristics, or hand geometry triggers notification requirements. However, New Mexico does not have a standalone biometric privacy law like Illinois's BIPA that would require consent before collecting biometric data or establish specific retention and destruction schedules.

What penalties can the New Mexico Attorney General impose for data breach notification violations?

Under NMSA 57-12C-11, if a court determines that a person violated the Data Breach Notification Act knowingly or recklessly, it may impose a civil penalty of the greater of $25,000 or $10 per instance of failed notification. For large breaches, the per-instance calculation can produce substantially higher penalties, up to a statutory cap of $150,000. Enforcement authority rests exclusively with the Attorney General. There is no private right of action under the Data Breach Notification Act, though consumers may have separate claims under the Unfair Practices Act for deceptive data handling.

Does New Mexico require businesses to encrypt personal data?

New Mexico does not mandate encryption. However, the Data Breach Notification Act creates a strong incentive to encrypt. Under NMSA 57-12C-2, personal identifying information that is protected through encryption or redaction and otherwise rendered unreadable or unusable falls outside the definition that triggers breach notification requirements. If encrypted data is compromised but the encryption key is not, the breach notification obligations do not apply. Additionally, NMSA 57-12C-4 requires businesses to implement reasonable security measures, and encryption is widely considered a reasonable practice.

What is the TAKE IT DOWN Act and how does it affect New Mexico residents?

The TAKE IT DOWN Act (Pub. L. 119-12) is a federal law signed on May 19, 2025. It criminalizes the publication of nonconsensual intimate images (NCII), including AI-generated deepfakes, and requires covered online platforms to remove such content within 48 hours of receiving a valid notice. FTC enforcement of the platform takedown obligations began May 19, 2026. New Mexico residents who are victims of NCII can submit takedown notices directly to covered platforms. Non-complying platforms are subject to FTC enforcement action.

What happened in New Mexico's lawsuit against Meta?

Attorney General Raúl Torrez filed suit against Meta under the Unfair Practices Act, alleging the company misled the public about the safety of Facebook and Instagram for children and failed to protect minors from predatory contact. On March 24, 2026, a Santa Fe jury found Meta liable for willful violations and ordered the company to pay $375 million in civil penalties, applying the maximum $5,000-per-violation rate under NMSA 57-12-11 across 75,000 counted violations. New Mexico was the first state to prevail at trial against a major tech platform for harms to young people. In a second phase, the court held a bench trial on the state's public nuisance claim and, on August 6, 2026, entered a judgment and decree for the state. It ordered Meta to deposit $567 million into an abatement fund and to meet five years of abatement requirements, including proactive age assurance measures, and it denied the state's request for a Child Safety Monitor.

Updates

Updated the Meta case to report the court's August 6, 2026 abatement decree (a $567 million abatement fund, five years of age assurance requirements, and denial of the state's requested Child Safety Monitor), added a section on New Mexico's Privacy Protection Act (NMSA 57-12B) covering its Social Security number restrictions, and noted that the Data Breach Notification Act does not apply to state or local government.

Replaced dead nmoag.gov links with the Attorney General's current nmdoj.gov site, and expanded the summary of SB 36's disclosure exceptions to include the federal-statute and judicial-proceeding exceptions.

Independently fact-checked against the cited primary sources

Corrected the service-provider notification duty (misattributed to NMSA 57-12C-5, actually 57-12C-6), the civil-penalty example (statute caps per-instance penalties at $150,000, not $500,000), the substitute-notification checklist (added the required website-posting element), the GLBA/HIPAA exemption (full exemption for any entity subject to those laws, not a compliance-conditioned partial exemption), and the misattributed "person" definition (not in NMSA 57-12C-2).

Governing law re-checked for recent changes

May 2026 refresh: Added SB 36 (2025, enacted, eff. July 1, 2025), the Nondisclosure of Sensitive Personal Information Act, NMSA 10-16I-1 through -4. Added Meta $375M jury verdict (March 24, 2026) under Unfair Practices Act. Added SB 53 (CHISPA, 2026 session) which did not advance before the session adjourned February 19, 2026. Added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025, FTC platform enforcement effective May 19, 2026). Added Snap lawsuit (filed September 2024, in discovery). Expanded FAQ from 5 to 7 questions. Updated all as-of-March-2026 date references to May 2026. Title and meta-description updated to reflect Meta verdict and new federal law. 4 new citations added.

Reviewed and approved by an editor

Sources and References

  1. New Mexico Data Breach Notification Act (HB 15, 2017 Session)(nmlegis.gov).gov
  2. NMSA 57-12C-2: Definitions (Personal Identifying Information, Biometric Data)(law.justia.com)
  3. NMSA 57-12C-6: Notification of Security Breach(law.justia.com)
  4. NMSA 57-12C-7: Notification Required Content(law.justia.com)
  5. New Mexico Unfair Practices Act (Chapter 57, Article 12)(law.justia.com)
  6. HB 307: Internet Privacy and Safety Act (2025 Session)(nmlegis.gov).gov
  7. HB 410: Consumer Info and Data Protection Act (2025 Session)(nmlegis.gov).gov
  8. SB 420: Community Privacy and Safety Act (2025 Session)(nmlegis.gov).gov
  9. HIPAA Privacy and Security Information(hhs.gov).gov
  10. FERPA General Guidance(www2.ed.gov).gov
  11. FTC: COPPA Rule(ftc.gov).gov
  12. FTC: Fair Credit Reporting Act(ftc.gov).gov
  13. New Mexico Department of Justice (Office of the Attorney General)(nmdoj.gov).gov
  14. NMSA 57-12C-3: Disposal of Personal Identifying Information(law.justia.com)
  15. NMSA 57-12C-4: Security Measures for Storage of Personal Identifying Information(law.justia.com)
  16. NMSA 57-12C-10: Notification to Attorney General and Credit Reporting Agencies(law.justia.com)
  17. NMSA 57-12C-11: Enforcement, Civil Penalties(law.justia.com)
  18. NMSA 57-12-3: Unfair or Deceptive and Unconscionable Trade Practices Prohibited(law.justia.com)
  19. New Mexico Department of Justice: Landmark Verdict Against Meta (March 2026)(nmdoj.gov).gov
  20. Attorney General Torrez Files Lawsuit Against Snap Inc. (September 2024)(nmdoj.gov).gov
  21. SB 36: Sensitive Personal Information Nondisclosure (2025 Session)(nmlegis.gov).gov
  22. SB 53: Community and Health Info Safety and Privacy Act (2026 Session)(nmlegis.gov).gov
  23. FTC: TAKE IT DOWN Act Enforcement (May 2026)(ftc.gov).gov
  24. FTC: Gramm-Leach-Bliley Act(ftc.gov).gov
  25. State of New Mexico ex rel. Torrez v. Meta Platforms, Inc., No. D-101-CV-2023-02838: Findings of Fact, Conclusions of Law, and Judgment, Order, and Decree (1st Jud. Dist. Ct., filed Aug. 6, 2026)(nmcourts.gov)
  26. NMSA Chapter 57: Privacy Protection Act (Art. 12B) and Data Breach Notification Act (Art. 12C, including 57-12C-12 exemption for the state and its political subdivisions), New Mexico Compilation Commission(nmonesource.com)
Share: