{
 "jurisdiction_id": "MX",
 "jurisdiction": "Mexico",
 "url": "https://dataprotection.gi/jurisdictions/mexico/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 50,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A comprehensive statute remains in force and a named regulator exists, but the supervising authority itself is mid-transition, independence and procedural rules are unsettled, and mandated secondary regulation is overdue.",
   "claims": [
    {
     "statement": "On 28 November 2024 the Mexican Senate approved the 'Simplificación Orgánica' constitutional reform dissolving seven autonomous constitutional bodies, including INAI.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/se-establece-una-nueva-autoridad-en-materia-de-protecci-n-de-datos-personales-en-m-xico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The constitutional reform transfers access-to-information, transparency and personal-data-protection responsibilities to a body within the federal public administration responsible for personal data held by both private and public entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-authority-established-for-personal-data-protection-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 12 May 2025 the Ministry of Anticorruption and Good Governance announced creation of two new decentralized bodies, Transparencia para el Pueblo and the Personal Data Protection Unit, assuming roughly 80% of INAI's former functions, with a Specialized Court to be established under the judiciary.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mexico-ministry-launches-new-institutions-transparency",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The New Federal Law for the Protection of Personal Data in Possession of Private Parties (NLFPDPPP) was published in the DOF on 20 March 2025 and entered into force 21 March 2025, superseding and repealing the 2010 FLPPDPP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Executive Branch is mandated to issue updated implementing regulations within 90 days of the NLFPDPPP's entry into force to harmonize the regulatory framework, with the prior 2010 Regulations remaining only provisionally applicable in the interim.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Credit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate sectoral regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The private-sector data protection statute applies to processing of personal data by companies and persons on Mexican territory regardless of where the data subjects reside, requiring Mexican-based internet companies to comply even for non-Mexican users' data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and sensitive-data structures exist and are GDPR-adjacent, but definitional gaps (research/journalistic carve-outs, anonymisation safe-harbour detail) remain unresolved pending new regulations.",
   "claims": [
    {
     "statement": "The Federal Law sets out grounds for processing personal data distinct from the GDPR and does not address processing for scientific or historical research purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Federal Law does not address matters such as processing for journalistic or artistic purposes, unlike the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NLFPDPPP Article 15 revises mandatory privacy-notice content, requiring identification of the data subject to the processing and its purposes and distinguishing purposes that require consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the prior law, the NLFPDPPP no longer lists disclosure of intended data transfers as a mandatory element of the privacy notice.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Federal Law provides additional requirements for processing sensitive data and defines conditions for consent, in ways broadly similar to the GDPR's special-category regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "'Disociación' (dissociation) of personal data is defined as a recognized legal element/exception basis under the private-sector data protection framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/de-lo-internacional-a-lo-nacional-reto-de-la-regulacion-y-desregulacion-normativa-de-los-datos-personales",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core ARCO rights are well-established and enforceable, but data portability is confirmed absent from the new statute, and deadline/response-window specifics await the pending implementing regulations.",
   "claims": [
    {
     "statement": "ARCO rights (access, rectification, cancellation and opposition) form the procedural core of data-subject rights under the private-sector data protection law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/de-lo-internacional-a-lo-nacional-reto-de-la-regulacion-y-desregulacion-normativa-de-los-datos-personales",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The New Law redefines the access right so that the data subject may access personal data and also know general conditions of the processing, expanding beyond the prior law's narrower formulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Both the GDPR and the Mexican Federal Law provide that data subjects may request cancellation or erasure of their data in certain circumstances for legitimate reasons.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal data must be deleted where it is no longer required for the purposes indicated in the privacy notice provided to data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Opposition to processing is recognized as one of the four ARCO rights under the private-sector framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/de-lo-internacional-a-lo-nacional-reto-de-la-regulacion-y-desregulacion-normativa-de-los-datos-personales",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Practitioner analysis of the enacted NLFPDPPP text confirms the new law does not include a data portability right, among other omissions relative to GDPR-style frameworks.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the 2010-era framework, data collectors had 10 days to comply with a resolution issued by the data protection authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Against resolutions of the new Secretaría (replacing INAI), affected parties may now pursue amparo proceedings before specialized district and circuit courts, which were to be enabled within 120 calendar days of the reform decree's publication (i.e., by 19 June 2025).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Security and controller-liability principles exist and are enforceable, but DPO, DPIA, privacy-by-design and regulator-facing breach notification — all GDPR Art. 25/33/35/37-39 analogues — are confirmed absent from the current statute and Regulations.",
   "claims": [
    {
     "statement": "Neither the Federal Law nor its Regulations address Data Protection Impact Assessments (DPIAs).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A general secondary summary describes the NLFPDPPP as imposing stricter obligations including the need for risk assessments and data protection impact evaluations, which conflicts with detailed practitioner review of the enacted text confirming DPIAs are not addressed; this discrepancy is unresolved pending primary-text confirmation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Neither the Federal Law nor the Regulations require organizations to designate a formal Data Protection Officer or notify the authority of a DPO appointment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the 2010-era law, all data controllers and processors had to appoint a person or group responsible for personal-data-related requirements (a privacy officer), and employers had to appoint a person or department for employee data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Federal Law specifies that data controllers are liable for violations of its principles, though neither the Law nor Regulations define the liabilities of data processors in detail.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Federal Law does not itself define security measures, but Article 2(VII) of the Regulations defines 'technical security measures' as controls ensuring authorized, identified access to logical databases.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Mexico's data-protection regime imposes risk-based technical, administrative and physical safeguards on data processors under both the private-sector Federal Law and the public-sector General Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mexicos-cybersecurity-framework-in-2025-a-practitioners-guide",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the current legislative framework there is no requirement to inform the data protection authority when a data breach occurs; the Federal Law/Regulations only impose notification obligations toward the affected data subject.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/eu-mexico-gdpr-v-federal-law-and-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Banks must immediately notify the National Banking and Securities Commission (CNBV) of any qualifying information-security incident, and the chief information security officer must submit a monthly information-security management report.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mexicos-cybersecurity-framework-in-2025-a-practitioners-guide",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal data must be deleted if no longer required for the purposes indicated in the privacy notice provided to data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "A transfer mechanism exists in statute but enforcement reach is explicitly limited by the authority's own historical acknowledgment of extraterritorial enforcement gaps, and SCC/BCR/TIA/localisation specifics are largely undocumented in current secondary sources.",
   "claims": [
    {
     "statement": "Under Article 36 of the private-sector law, a controller transferring personal data abroad must communicate the signed privacy notice to the new foreign controller so it remains bound by the same purposes and obligations, conditioned on a transfer clause having been included in the notice and accepted by the data subject.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/de-lo-internacional-a-lo-nacional-reto-de-la-regulacion-y-desregulacion-normativa-de-los-datos-personales",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The data protection authority has historically lacked international enforcement powers to compel foreign companies subject to a different legal order to comply with Mexican data protection obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/de-lo-internacional-a-lo-nacional-reto-de-la-regulacion-y-desregulacion-normativa-de-los-datos-personales",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Federal Law and Regulations cite European Union adequacy decisions as a basis for enabling international data transfers out of Mexico.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/eu_-_mexico-_gdpr_v._federal_law_and_regulations_.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial-sector overlay is well documented; health, telecoms, education and insurance overlays are thinly evidenced or absent in the sources reviewed.",
   "claims": [
    {
     "statement": "Banks in Mexico must immediately notify the Comisión Nacional Bancaria y de Valores (CNBV) of any qualifying information-security incident.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mexicos-cybersecurity-framework-in-2025-a-practitioners-guide",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The chief information security officer at Mexican banks must submit a monthly information-security management report to the CEO and, when required, to the board or relevant committees.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mexicos-cybersecurity-framework-in-2025-a-practitioners-guide",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Sector-specific laws exist in the financial services and health/pharmaceutical sectors distinct from the general private-sector Federal Law and Regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/eu-mexico-gdpr-v-federal-law-and-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Employers must appoint a person or establish a personal data department to handle employees' personal data and promote its protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Credit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No dedicated adtech/commercial-privacy regime exists; only the general opposition right within ARCO offers any traction for direct-marketing objections.",
   "claims": [
    {
     "statement": "The Mexican federal data protection law does not specifically address topics such as internet cookies, employee monitoring, or collection of personal data in connection with credit-card transactions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ARCO opposition right provides the primary (general, non-marketing-specific) mechanism by which data subjects can object to processing, including for direct-marketing purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/de-lo-internacional-a-lo-nacional-reto-de-la-regulacion-y-desregulacion-normativa-de-los-datos-personales",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No binding AI-specific statute exists; biometric governance rests on enforcement precedent rather than codified rules, and profiling/ADM-transparency provisions were not separately documented.",
   "claims": [
    {
     "statement": "Mexico does not have a specific AI law; the Senate's National AI Alliance (ANIA) is working on a regulatory proposal covering cybersecurity, privacy, ethical AI use and AI adoption.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/la-interseccion-entre-la-inteligencia-artificial-y-la-proteccion-de-datos-personales-en-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of mid-2026, Mexico's new data protection authority had not yet issued secondary regulation or public sanctions, though there were indications of preliminary investigations concerning sensitive data handling and security-incident management.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notas-de-la-iapp-america-latina-brasil-marca-el-ritmo-mientras-la-regi-n-acelera-su-regulaci-n-en-ia-y-protecci-n-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "INAI's investigation of the 'Fan ID' facial-recognition system implemented by the Mexican Football Federation became one of the most significant proceedings on biometric data processing in the private sector, raising issues of consent, proportionality and controller/processor responsibility.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/qu-direcci-n-tomar-el-sistema-de-protecci-n-de-datos-personales-en-m-xico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Mexican government is advancing implementation of a biometric digital identity system alongside a National Cybersecurity Plan 2025-2030.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notas-de-la-iapp-america-latina-brasil-marca-el-ritmo-mientras-la-regi-n-acelera-su-regulaci-n-en-ia-y-protecci-n-de-datos",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The current statute contains no children's-data-specific regime at all; this is an explicit, confirmed statutory gap rather than a mere silence in secondary sources.",
   "claims": [
    {
     "statement": "The New Federal Law (NLFPDPPP) does not include topics such as the processing of personal data of minors, unlike the GDPR which sets express child-consent age thresholds.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/mexico/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "A functioning enforcement and judicial-review pathway exists, but the new regulator's operational capacity, sanctioning track record, and independence remain unproven during this institutional transition.",
   "claims": [
    {
     "statement": "Unlike INAI (an autonomous constitutional body), the Secretaría Anticorrupción y Buen Gobierno is not required to render an annual activity report to Congress, and the express attribution to develop, promote and disseminate data-protection research and studies was not carried forward in the new law's Article 39.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects may seek damages from data collectors when they consider they have suffered harm or losses derived from a breach of the data protection law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2010-10-26-new-data-privacy-law-in-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Against resolutions of the Secretaría, affected parties may now pursue amparo (constitutional review) proceedings before specialized district and circuit courts, replacing the prior nullity-trial pathway against INAI resolutions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of early-to-mid 2026, Mexico's updated privacy law entered into force but largely retains the structure of the 2010 regime, and the new data authority had not yet issued secondary regulation or public sanctions, though preliminary investigations into sensitive-data handling and security-incident management were reported, alongside government advancement of a biometric digital identity system and a National Cybersecurity Plan 2025-2030.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notas-de-la-iapp-america-latina-brasil-marca-el-ritmo-mientras-la-regi-n-acelera-su-regulaci-n-en-ia-y-protecci-n-de-datos",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}