EnglishEspañol
New Mexico flag

New Mexico

New Mexico Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 3 primary sources cited on this page. How we verify our legal content

New Mexico Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How long does a business have to notify New Mexico residents of a data breach?

New Mexico law requires notification no later than 45 calendar days after discovery of the breach. The clock starts on the date of discovery, not the date the breach occurred. N.M. Stat. 57-12C-9 allows the notification to be delayed on either of two independent grounds: a law enforcement agency determines that notification will impede a criminal investigation, or delay is necessary to determine the scope of the breach and restore the integrity, security, and confidentiality of the data system. The 45-day deadline is written as an exception to Section 9, so either ground can carry notification past it.

Does New Mexico require businesses to notify the Attorney General after a data breach?

Yes, but only once a single breach requires notifying more than 1,000 New Mexico residents. At that point, N.M. Stat. 57-12C-10 requires notifying both the Attorney General and the major nationwide consumer reporting agencies, The statute requires notice of the breach, the number of New Mexico residents that received notification under Section 6, and a copy of the notification that was sent to affected residents. A business that uses substitute notice must also send a copy to the Attorney General regardless of how many residents are affected.

Does New Mexico's breach notification law cover biometric data?

Yes. New Mexico includes biometric data in its definition of personal identifying information. This covers fingerprints, voice prints, iris or retina patterns, facial characteristics, and hand geometry used to authenticate identity when accessing a physical location, device, system, or account. A breach of biometric data combined with a name triggers the full 45-day notification requirement.

Are HIPAA-covered entities exempt from New Mexico's breach notification law?

Yes. Section 8 of the Data Breach Notification Act states that the Act does not apply to a person subject to HIPAA or to the federal Gramm-Leach-Bliley Act, so healthcare entities, their business associates, and GLBA-regulated financial institutions are all outside it. The exemption depends on being subject to those federal laws, not on maintaining a particular security program or on how well the entity complies with them. These entities follow their federal frameworks instead.

Can individuals sue for a breach notification violation in New Mexico?

No. New Mexico's breach notification law does not create a private right of action. Only the Attorney General can enforce the statute, under the Data Breach Notification Act's own civil penalty provision, which allows penalties up to $150,000 for knowing or reckless violations. Individuals may pursue common law claims such as negligence, but cannot sue directly under the Data Breach Notification Act.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the New Mexico breach notification rules against the enacted text of the Data Breach Notification Act: notification may be delayed either for a law enforcement investigation or to scope and contain the breach, telephone notice is not a permitted method, the GLBA and HIPAA exemptions turn on being subject to those federal laws rather than on maintaining a comparable program, the Act does not apply to the state or its political subdivisions, and the required contents of both the individual notice and the attorney general notice now match Sections 7 and 10.

Corrected New Mexico's breach-notification page: fixed six dead citation links, corrected the Attorney General and consumer-reporting-agency notification threshold to more than 1,000 residents (not any breach), replaced a fabricated 24-hour service-provider deadline with the statute's actual 45-day standard, swapped the substitute-notice dollar and resident thresholds to their correct values, rewrote the enforcement section to reflect the Data Breach Notification Act's own civil penalty (up to $150,000) rather than the Unfair Practices Act, and added the risk-of-harm exception that can eliminate the notice duty entirely.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. N.M. Stat. 57-12C-1 et seq. (Data Breach Notification Act, enacted text)(nmlegis.gov).gov
  2. New Mexico Attorney General(nmag.gov).gov
  3. N.M. Stat. 57-12C-11 (Attorney General Enforcement; Civil Penalty)(nmlegis.gov).gov
Share: