New Mexico
New Mexico Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 3 primary sources cited on this page. How we verify our legal content

Under the New Mexico Data Breach Notification Act, N.M. Stat. Ann. 57-12C-1 et seq., businesses must notify affected residents within 45 calendar days of discovering a breach. The clock starts on the date of discovery, not the date the breach occurred. The New Mexico Attorney General and major nationwide consumer reporting agencies must also be notified whenever a single breach requires notifying more than 1,000 New Mexico residents.
If your business handles personal information belonging to New Mexico residents, a data breach triggers specific legal obligations under the New Mexico Data Breach Notification Act. N.M. Stat. 57-12C-1 et seq. (Data Breach Notification Act, enacted text) sets out who must notify, what triggers the duty, and how quickly action is required. New Mexico was one of the later states to adopt a breach notification law, enacting the statute in 2017. However, the law includes modern provisions such as biometric data coverage and a firm 45-day notification deadline.
This guide covers the full scope of New Mexico's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, penalties, exemptions, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With New Mexico's Breach Notification Law
New Mexico's law applies to any person or business that owns or licenses personal identifying information of New Mexico residents. The statute uses the term "person" broadly to include corporations, partnerships, LLCs, associations, and other entities.
Government bodies are the one large category left out. N.M. Stat. 57-12C-12 (Data Breach Notification Act, Section 12) provides that nothing in the Act "shall be interpreted to apply to the state of New Mexico or any of its political subdivisions," and the enacting bill's own caption confirms the point. State agencies, counties, municipalities, and other political subdivisions therefore fall outside the Act's notification duties.
The law also applies to third-party data processors. When a person or business that maintains data on behalf of another entity discovers a breach, it must notify the data owner or licensee in the most expedient time possible, but no later than 45 calendar days following discovery. This is the same 45-day standard that applies to notifying affected residents directly, not a separate shorter deadline.
Out-of-state businesses that handle personal information of New Mexico residents are subject to the law.
What Qualifies as a Breach
Under N.M. Stat. 57-12C-2 (Data Breach Notification Act, Section 2), a "security breach" means the unauthorized acquisition of unencrypted computerized data, or encrypted computerized data together with the confidential process or key, that compromises the security, confidentiality, or integrity of personal identifying information maintained by a person.
Good Faith Exception
A good faith acquisition of personal identifying information by an employee or agent of the person for a legitimate business purpose does not constitute a security breach, provided the personal identifying information is not subject to further unauthorized disclosure. That proviso is the only condition the statute attaches.
Encryption Safe Harbor
New Mexico provides a safe harbor for encrypted data. If the compromised personal identifying information was encrypted and the encryption key or confidential process was not also acquired, notification is not required. If both the encrypted data and the key were compromised, the safe harbor does not apply.
Personal Information That Triggers Notification
New Mexico's definition of personal identifying information is notably broad for a state that enacted its law in 2017. Under N.M. Stat. 57-12C-2 (Data Breach Notification Act, Section 2), personal identifying information means an individual's first name or first initial and last name combined with one or more of the following:
- Social Security number
- Driver's license number
- Government-issued identification number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the financial account
- Biometric data (fingerprint, voice print, iris or retina patterns, facial characteristics, or hand geometry used to authenticate identity when accessing a physical location, device, system, or account)
The inclusion of biometric data places New Mexico among the states with more comprehensive protection, recognizing that biometric identifiers cannot be changed once compromised.
Personal identifying information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
The 45-Day Notification Timeline
New Mexico imposes a firm 45-day deadline for breach notification under N.M. Stat. 57-12C-6 (Data Breach Notification Act, Section 6). Notification must be made no later than 45 calendar days following discovery of the security breach.

The clock starts from the date of discovery, not the date the breach occurred. This distinction matters because breaches are often discovered weeks or months after the initial unauthorized access.
Risk of Harm Exception
Notification to affected residents is not required at all if, after an appropriate investigation, the business determines the breach does not give rise to a significant risk of identity theft or fraud. This exception can eliminate the notice duty entirely, not merely delay it.
When Delay Is Permitted
N.M. Stat. 57-12C-9 (Data Breach Notification Act, Section 9) allows notification to be delayed on either of two independent grounds:
- A law enforcement agency determines that the notification will impede a criminal investigation.
- Delay is necessary to determine the scope of the security breach and to restore the integrity, security, and confidentiality of the data system.
Both grounds carry the same weight. The 45-day deadlines in Section 6 and Section 10 are each written "except as provided in Section 9," so the work of scoping and containing a breach can push notification past 45 days just as a law enforcement request can. The statute sets no outer limit on either delay and does not fix a deadline for notice once the reason for the delay ends, so notifying as soon as the ground for delay no longer applies is the defensible course.
Who Must Be Notified
Affected Individuals
Every New Mexico resident whose unencrypted personal identifying information was or is reasonably believed to have been acquired by an unauthorized person must be notified. The notification must include:
- The name and contact information of the notifying person
- A list of the types of personal identifying information reasonably believed to have been the subject of the breach, if known
- The date, estimated date, or estimated date range of the security breach, if known
- A general description of the security breach incident
- The toll-free telephone numbers and addresses of the major consumer reporting agencies
- Advice directing the recipient to review personal account statements and credit reports, as applicable, to detect errors resulting from the breach
- Advice informing the recipient of the recipient's rights under the federal Fair Credit Reporting Act
New Mexico Attorney General and Consumer Reporting Agencies
Under N.M. Stat. 57-12C-10, a business is required to notify the New Mexico Attorney General and the major nationwide consumer reporting agencies only when a single security breach requires notifying more than 1,000 New Mexico residents. The Attorney General and the consumer reporting agencies share this same threshold; it is not triggered by every breach.
Section 10 spells out what has to accompany that notice, and the list is short:
- Notice of the security breach itself
- The number of New Mexico residents that received notification under Section 6
- A copy of the notification that was sent to affected residents
Nothing else is required by statute. There is no obligation to report the timing or distribution of the individual notices, or the remedial steps taken in response to the breach.
Separately, a business that uses substitute notice under N.M. Stat. 57-12C-6(E) must always send a copy to the office of the Attorney General, regardless of how many residents are affected.
How to Provide Notification
N.M. Stat. 57-12C-6(D) permits three notification methods and no others:
- United States mail
- Electronic notification, if the person required to give notice primarily communicates with the New Mexico resident by electronic means, or if the notice is consistent with the E-SIGN Act (15 U.S.C. 7001)
- Substitute notification, available only in the limited circumstances below
Telephone notice is not among the permitted methods.
Substitute Notice
Substitute notice is available when:
- The cost of providing notification would exceed $100,000
- The affected class exceeds 50,000 New Mexico residents
- The entity does not have sufficient contact information
Substitute notice must include all of the following:
- Email notification to individuals for whom the entity has a valid email address
- Conspicuous posting of the notice on the entity's website, if it maintains one
- Written notification to the office of the Attorney General and major media outlets in New Mexico
New Mexico's substitute notice thresholds ($100,000 cost and 50,000 affected individuals) are moderate, falling between the low thresholds of states like New Hampshire and the high thresholds of states like California.
Enforcement and Penalties
New Mexico's breach notification law is enforced directly by the New Mexico Attorney General under the Data Breach Notification Act's own enforcement provision, N.M. Stat. 57-12C-11, not the separate Unfair Practices Act.
The Attorney General may seek:
- Injunctive relief to stop ongoing violations
- Damages for actual costs or losses, including consequential financial losses
- Civil penalties, for knowing or reckless violations, of the greater of $25,000 or $10 per instance of failed notification, up to a maximum of $150,000
There is no private right of action for breach notification violations. Only the Attorney General can bring enforcement actions under the statute. Individuals may pursue common law claims such as negligence, but not under the breach notification law itself.
Exemptions
N.M. Stat. 57-12C-8 (Data Breach Notification Act, Section 8) is a single sentence: the Act "shall not apply to a person subject to the federal Gramm-Leach-Bliley Act or the federal Health Insurance Portability and Accountability Act of 1996." The exemption turns on status, not on performance.
GLBA-Regulated Financial Institutions
A financial institution that is subject to the Gramm-Leach-Bliley Act is outside New Mexico's breach notification requirements. The statute does not condition that on maintaining any particular information security program, and it does not ask whether the institution's federal procedures are as thorough as the state's.
HIPAA-Covered Entities
A person subject to HIPAA is likewise outside the Act. Healthcare entities and their business associates follow the federal HIPAA breach notification rules; whether they comply with those rules is a question for federal enforcers, not a condition of the state exemption.
These exemptions fully exclude qualifying entities from the state statute rather than requiring parallel compliance.
Data Security Obligations
Beyond breach notification, New Mexico requires that any person who owns or licenses personal identifying information of New Mexico residents must implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect it from unauthorized access, destruction, use, modification, or disclosure. This general data security mandate applies regardless of whether a breach occurs.
Businesses that collect personal identifying information must also take reasonable steps to destroy or arrange for the destruction of records containing personal identifying information that are no longer needed, by shredding, erasing, or otherwise modifying the information to make it unreadable or indecipherable.
This article provides general legal information about New Mexico data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in New Mexico for guidance specific to your situation.
More New Mexico Laws
Frequently Asked Questions
How long does a business have to notify New Mexico residents of a data breach?
New Mexico law requires notification no later than 45 calendar days after discovery of the breach. The clock starts on the date of discovery, not the date the breach occurred. N.M. Stat. 57-12C-9 allows the notification to be delayed on either of two independent grounds: a law enforcement agency determines that notification will impede a criminal investigation, or delay is necessary to determine the scope of the breach and restore the integrity, security, and confidentiality of the data system. The 45-day deadline is written as an exception to Section 9, so either ground can carry notification past it.
Does New Mexico require businesses to notify the Attorney General after a data breach?
Yes, but only once a single breach requires notifying more than 1,000 New Mexico residents. At that point, N.M. Stat. 57-12C-10 requires notifying both the Attorney General and the major nationwide consumer reporting agencies, The statute requires notice of the breach, the number of New Mexico residents that received notification under Section 6, and a copy of the notification that was sent to affected residents. A business that uses substitute notice must also send a copy to the Attorney General regardless of how many residents are affected.
Does New Mexico's breach notification law cover biometric data?
Yes. New Mexico includes biometric data in its definition of personal identifying information. This covers fingerprints, voice prints, iris or retina patterns, facial characteristics, and hand geometry used to authenticate identity when accessing a physical location, device, system, or account. A breach of biometric data combined with a name triggers the full 45-day notification requirement.
Are HIPAA-covered entities exempt from New Mexico's breach notification law?
Yes. Section 8 of the Data Breach Notification Act states that the Act does not apply to a person subject to HIPAA or to the federal Gramm-Leach-Bliley Act, so healthcare entities, their business associates, and GLBA-regulated financial institutions are all outside it. The exemption depends on being subject to those federal laws, not on maintaining a particular security program or on how well the entity complies with them. These entities follow their federal frameworks instead.
Can individuals sue for a breach notification violation in New Mexico?
No. New Mexico's breach notification law does not create a private right of action. Only the Attorney General can enforce the statute, under the Data Breach Notification Act's own civil penalty provision, which allows penalties up to $150,000 for knowing or reckless violations. Individuals may pursue common law claims such as negligence, but cannot sue directly under the Data Breach Notification Act.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the New Mexico breach notification rules against the enacted text of the Data Breach Notification Act: notification may be delayed either for a law enforcement investigation or to scope and contain the breach, telephone notice is not a permitted method, the GLBA and HIPAA exemptions turn on being subject to those federal laws rather than on maintaining a comparable program, the Act does not apply to the state or its political subdivisions, and the required contents of both the individual notice and the attorney general notice now match Sections 7 and 10.
Corrected New Mexico's breach-notification page: fixed six dead citation links, corrected the Attorney General and consumer-reporting-agency notification threshold to more than 1,000 residents (not any breach), replaced a fabricated 24-hour service-provider deadline with the statute's actual 45-day standard, swapped the substitute-notice dollar and resident thresholds to their correct values, rewrote the enforcement section to reflect the Data Breach Notification Act's own civil penalty (up to $150,000) rather than the Unfair Practices Act, and added the risk-of-harm exception that can eliminate the notice duty entirely.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New Mexico Statutes Annotated 1978, Chapter 57
§ 57-12C-6Notification of security breachIn forcecited in 5 of our articles
A. Except as provided in Subsection C of this section, a person that owns or licenses elements that include personal identifying information of a New Mexico resident shall provide notification to each New Mexico resident whose personal identifying information is reasonably believed to have been subject to a security breach. Notification shall be made in the most expedient time possible, but not later than forty- five calendar days following discovery of the security breach, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act. B. Notwithstanding Subsection A of this section, notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud. C.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at nmonesource.com
Also relied on in: New Mexico Data Privacy Laws: Breach Notification, AG Enforcement & 2026 Legislation, New Mexico Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 57-12C-1Short titleIn forcecited in 6 of our articles
This act [57-12C-1 to 57-12C-12 NMSA 1978] may be cited as the "Data Breach Notification Act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2022
Opinions citing this section in our collection:
- Charlie v. Rehoboth McKinley Christian Health Care Services (District Court, D. New Mexico 2022)“…s’ data under the New Mexico Data Breach Notification Act, N.M. Stat. Ann. § 57-12C-1, et seq. (2017).”); id. at 13 (“Defenda…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 57-12-1Short titleIn forcecited in 7 of our articles
Chapter 57, Article 12 NMSA 1978 may be cited as the "Unfair Practices Act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at nmonesource.com
Cited in 239 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Romero v. Philip Morris Inc. (New Mexico Supreme Court 2010, 148 N.M. 713)“…MSA 1978, §§ 57-1-1 to -15 (1979, as amended through 1987); NMSA 1978, §§ 57-12-1 to -22 (1967, as amended through 1999).…”
- Cordova v. World Finance Corp. of NM (New Mexico Supreme Court 2009, 146 N.M. 256)“…hin the meaning of the New Mexico Unfair Practices Act. See NMSA 1978, §§ 57-12-1 to -24 (1967, as amended through 2003).…”
- Quynh Truong v. Allstate Insurance (New Mexico Supreme Court 2010, 147 N.M. 583)“…cability of an exemption to the Unfair Practices Act (UPA), NMSA 1978, Sections 57-12-1 to -22 (1967, as amended through 1999),…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: New Mexico Lemon Law (2026): How to Qualify & Get a Refund
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Explore the law
The laws cited above reference these related sections in their own text:
- New Mexico Statutes Annotated 1978, Chapter 57 § 57-12C-12 — State of New Mexico and political subdivisions exempted. view in our statute record · read at the official source
- New Mexico Statutes Annotated 1978, Chapter 57 § 57-12C-9 — Delayed notification view in our statute record · read at the official source
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- N.M. Stat. 57-12C-1 et seq. (Data Breach Notification Act, enacted text)(nmlegis.gov).gov
- New Mexico Attorney General(nmag.gov).gov
- N.M. Stat. 57-12C-11 (Attorney General Enforcement; Civil Penalty)(nmlegis.gov).gov