EnglishEspañol
Mexico flag

Mexico

Mexico Data Privacy Laws: 2025 LFPDPPP Complete Guide

By Recording Law Editorial TeamReviewed July 23, 202623 min read
Mexico Data Privacy Laws: 2025 LFPDPPP Complete Guide

Frequently Asked Questions

What is the LFPDPPP and does it apply to my company?

The LFPDPPP (Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares) is Mexico's federal data protection law for the private sector. A completely new version took effect on March 21, 2025, replacing the original 2010 statute. It applies to any private individual or legal entity that collects, uses, stores, or otherwise processes personal data. The 2025 version expressly extends coverage to data processors, not just controllers. If your organization handles data belonging to individuals in Mexico, regardless of where your servers are located, you should assess whether the law applies.

What happened to INAI and who enforces Mexico's data privacy laws now?

INAI, Mexico's formerly independent data protection authority, was dissolved following a constitutional reform published December 20, 2024, as part of an organic simplification measure eliminating seven autonomous bodies. Its enforcement functions transferred to the Secretariat of Anti-Corruption and Good Governance (SABG), a cabinet-level executive branch ministry, effective March 21, 2025. The SABG now handles ARCO rights complaints, conducts audits, issues binding resolutions, and imposes sanctions. Critics have raised concerns about the loss of institutional independence, since the SABG reports to the President rather than operating as an autonomous body.

What are ARCO rights under Mexican law?

ARCO stands for Access, Rectification, Cancellation, and Opposition. These rights allow individuals to: confirm whether their personal data is being processed and access it; correct inaccurate or incomplete information; request deletion of their data once it is no longer needed; and object to processing for specific purposes. The 2025 law extended the opposition right to cover automated decision-making systems that produce significant effects without human review. Requests go directly to the data controller, which has 20 business days to respond. If the controller denies or ignores the request, individuals can file a complaint with the SABG or seek judicial review through the 30th Judicial Circuit via amparo.

What are the maximum fines under Mexico's 2025 data protection law?

Administrative fines are denominated in UMA (Unidad de Medida y Actualizacion), Mexico's annual inflation-adjusted reference unit. At the 2026 daily UMA rate of MXN 117.31, the maximum standard fine for aggravated violations reaches approximately MXN 37.5 million (roughly USD 1.9 million). For violations involving sensitive personal data, fines can be doubled, reaching approximately MXN 75 million (roughly USD 3.75 million). Repeat offenders face additional penalties of up to the same maximum amount. Criminal sanctions include imprisonment of 3 months to 3 years for intentional security breaches, or 6 months to 5 years for fraudulent processing with intent to gain financially. The SABG can also order suspension of data processing activities. In July 2026, the SABG issued its first published fine under the new law, MXN 42,849,095 against the Federacion Mexicana de Futbol for failing to treat biometric Fan ID data as sensitive personal data and processing it without express written consent.

Does Mexico's data protection law address AI and automated decision-making?

Yes. The 2025 LFPDPPP introduces provisions specifically addressing automated decision-making and AI systems. Organizations using algorithms or AI to make decisions affecting individuals must notify data subjects, disclose information about the algorithmic logic, and allow individuals to object to automated decisions that significantly affect their rights without human review. High-risk automated systems require impact assessments. These provisions make Mexico one of the first Latin American countries to address AI governance directly in data protection legislation, though implementing regulations with operational detail had not been published as of May 2026.

How do cross-border data transfers work under Mexico's LFPDPPP?

Cross-border transfers generally require the prior informed consent of the data subject, with the privacy notice disclosing the destination countries and recipient organizations. Exceptions exist for legally permitted transfers, treaty obligations, medical emergencies, and publicly accessible data. The recipient must commit to equivalent data protection obligations. Unlike the GDPR, the LFPDPPP does not establish formal adequacy decisions or standard contractual clauses as legal instruments. Implementing regulations expected to clarify transfer mechanisms had not been published as of May 2026, leaving consent and contractual undertakings as the primary practical tools.

Is mandatory breach notification to the SABG required?

Not currently. The 2025 LFPDPPP requires controllers to notify affected data subjects when a security breach significantly affects their patrimonial or moral rights, but there is no mandatory reporting obligation to the SABG itself. The notification to data subjects must cover the nature of the breach, what data was affected, protective recommendations, and corrective measures taken. The SABG's January 2026 stakeholder consultations identified mandatory authority breach reporting as a priority for the next regulatory cycle, so this requirement may appear in forthcoming implementing regulations or further legislation.

What is Mexico's constitutional basis for data protection?

The right to personal data protection is guaranteed by two articles of Mexico's Political Constitution. Article 6 states that information about private life and personal data shall be protected in accordance with law. Article 16 expressly recognizes every person's right to protection of their personal data and their rights to access, correct, and cancel that data, and to oppose its disclosure. These constitutional rights set the floor for protection that legislation must meet.

Updates

Added the SABG's first published sanction under the new LFPDPPP: a MXN 42,849,095 fine against the Federacion Mexicana de Futbol (FMF), issued July 12, 2026, for failing to treat Fan ID biometric data as sensitive personal data and processing it without express written consent. Updated the enforcement-activity section, the outlook section, and the fines FAQ accordingly.

Full refresh: updated to reflect the March 20-21, 2025 legislative overhaul (new LFPDPPP and LGPDPPSO), INAI dissolution and SABG succession, 30th Judicial Circuit operational from July 1, 2025, SABG January 2026 stakeholder dialogue announcing DPO, DPIA, and privacy-by-design priorities, implementing regulations still pending as of May 2026, and revised penalty table using 2026 UMA rate of MXN 117.31.

Sources and References

  1. Federal Law for the Protection of Personal Data Held by Private Parties (LFPDPPP 2025) - Diputados.gob.mx(diputados.gob.mx).gov
  2. Official Gazette of the Federation (DOF) - dof.gob.mx(dof.gob.mx).gov
  3. Mexico: New Transparency and Data Protection Laws Enacted - Library of Congress Global Legal Monitor(loc.gov).gov
  4. Data Protection and Privacy 2026: Mexico - Chambers and Partners(practiceguides.chambers.com)
  5. Data Protection Laws and Regulations 2025-2026: Mexico - ICLG(iclg.com)
  6. New Authority for Personal Data Protection in Mexico - IAPP(iapp.org)
  7. Mexico From 2010 to 2025: Evolution of the New LFPDPPP - Baker McKenzie(connectontech.bakermckenzie.com)
  8. Mexico Overhauls Federal Data Protection Law - Hunton Andrews Kurth(hunton.com)
  9. Nueva Ley Federal de Proteccion de Datos Personales - BASHAM(basham.com.mx)
  10. The Extinction of INAI: Legal and Administrative Implications - Global Law Experts(globallawexperts.com)
  11. Mexico Implements New Data Protection Framework - Pandectes(pandectes.io)
  12. LFPDPPP 2025: Mexico New Rules for Privacy and AI Governance - Truyo(truyo.com)
  13. SABG press release: sanction against the Federacion Mexicana de Futbol for Fan ID biometric data violations (July 12, 2026)(gob.mx).gov
Share: