🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
MX · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

Mexico

MX schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 50 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
50Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive statute remains in force and a named regulator exists, but the supervising authority itself is mid-transition, independence and procedural rules are unsettled, and mandated secondary regulation is overdue.

Primary frameworkLey Federal de Protección de Datos Personales en Posesión de los Particulares (NLFPDPPP, 2025), successor to the 2010 Federal Law
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno (Dirección General de Datos Personales en el Sector Privado)
Traffic-light rationale — AmberA comprehensive statute remains in force and a named regulator exists, but the supervising authority itself is mid-transition, independence and procedural rules are unsettled, and mandated secondary regulation is overdue.

Sub-modules (5)

Regulator And AuthorityAmber

INAI, the former autonomous DPA, was dissolved by constitutional reform; its private-sector data-protection function was transferred to the Secretaría Anticorrupción y Buen Gobierno, supplemented by two new decentralized bodies created May 2025.

Claims: CLM-MX-a1b2c3d4, CLM-MX-b2c3d4e5, CLM-MX-c3d4e5f6

Act And InstrumentsGreen

The operative private-sector instrument is the NLFPDPPP (DOF 20 Mar 2025, in force 21 Mar 2025), which repealed the 2010 FLPPDPP; a parallel General Law covers public-sector 'obligated parties'.

Claims: CLM-MX-d4e5f6a7, CLM-MX-e5f6a7b8

Material ScopeGreen

The law governs legitimate, controlled and informed processing of personal data by private parties to guarantee privacy and informational self-determination; credit-reporting entities remain carved out under separate sectoral law.

Claims: CLM-MX-f6a7b8c9

Territorial ScopeAmber

The private-sector law has historically applied on a territorial basis to processing by companies/persons established in Mexico regardless of data-subject residence; the new law preserves this structure.

Claims: CLM-MX-a7b8c9d0

Regulator Registration And FilingRed

No dedicated national registry/filing obligation for controllers was identified in the sources reviewed for the private-sector regime.

Absence provenance: not recorded. Searched: Mexico LFPDPPP data controller registration filing requirement, NLFPDPPP registro responsables tratamiento datos.

Category narrative162 words

Mexico's private-sector data protection regime underwent a foundational institutional rupture between Nov 2024 and mid-2025. The Senate approved a constitutional 'organic simplification' reform dissolving seven autonomous bodies including INAI (the former DPA), with functions redistributed to the federal executive branch. A New Federal Law for the Protection of Personal Data Held by Private Parties (NLFPDPPP) was published 20 March 2025 (effective 21 March 2025), repealing the 2010 FLPPDPP, alongside a companion General Law for the public sector. The Secretaría Anticorrupción y Buen Gobierno, acting through its Dirección General de Datos Personales en el Sector Privado, now exercises the former INAI's private-sector functions; two decentralized administrative bodies (Transparencia para el Pueblo and the Personal Data Protection Unit) were stood up in May 2025 to absorb roughly 80% of INAI's functions, with a Specialized Court under the judiciary also contemplated. As of mid-2026 the new authority had not yet issued the harmonizing secondary regulation mandated within 90 days of the NLFPDPPP's entry into force.

Sources and claims (7)
  1. ConfirmedIAPPOn 28 November 2024 the Mexican Senate approved the 'Simplificación Orgánica' constitutional reform dissolving seven autonomous constitutional bodies, including INAI.
  2. ConfirmedIAPPThe constitutional reform transfers access-to-information, transparency and personal-data-protection responsibilities to a body within the federal public administration responsible for personal data held by both private and public entities.
  3. ConfirmedOneTrust DataGuidanceOn 12 May 2025 the Ministry of Anticorruption and Good Governance announced creation of two new decentralized bodies, Transparencia para el Pueblo and the Personal Data Protection Unit, assuming roughly 80% of INAI's former functions, with a Specialized Court to be established under the judiciary.
  4. ConfirmedOneTrust DataGuidanceThe New Federal Law for the Protection of Personal Data in Possession of Private Parties (NLFPDPPP) was published in the DOF on 20 March 2025 and entered into force 21 March 2025, superseding and repealing the 2010 FLPPDPP.
  5. ConfirmedOneTrust DataGuidanceThe Executive Branch is mandated to issue updated implementing regulations within 90 days of the NLFPDPPP's entry into force to harmonize the regulatory framework, with the prior 2010 Regulations remaining only provisionally applicable in the interim.
  6. ConfirmedIAPPCredit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate sectoral regulation.
  7. ProbableIAPPThe private-sector data protection statute applies to processing of personal data by companies and persons on Mexican territory regardless of where the data subjects reside, requiring Mexican-based internet companies to comply even for non-Mexican users' data.

#

Core lawful-basis and sensitive-data structures exist and are GDPR-adjacent, but definitional gaps (research/journalistic carve-outs, anonymisation safe-harbour detail) remain unresolved pending new regulations.

Primary frameworkNLFPDPPP Arts. 6-22 (principles, consent, sensitive data)
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberCore lawful-basis and sensitive-data structures exist and are GDPR-adjacent, but definitional gaps (research/journalistic carve-outs, anonymisation safe-harbour detail) remain unresolved pending new regulations.

Sub-modules (4)

Lawful BasesAmber

The law sets out grounds for processing distinct from GDPR (e.g., legal mandate, public-source data, prior dissociation, contractual necessity) and does not address research or journalistic/artistic processing purposes.

Claims: CLM-MX-b8c9d0e1, CLM-MX-c9d0e1f2

Special CategoriesGreen

The law imposes additional requirements for sensitive/special-category data akin to GDPR Art. 9, though with a narrower definitional scope than the European regime.

Claims: CLM-MX-f2a3b4c5

Pseudonymisation And AnonymisationAmber

The statute defines 'disociación' (dissociation) as a recognized legal mechanism/exception basis, but detailed anonymisation safe-harbour standards were not located in the sources reviewed.

Absence provenance: not recorded. Searched: NLFPDPPP disociación anonimización estándar técnico.

Claims: CLM-MX-a3b4c5d6

Category narrative63 words

Mexico's private-sector regime recognizes a privacy-notice-and-consent-centred model with enumerated exceptions to consent (public sources, legal mandate, prior dissociation, contractual necessity), plus enhanced conditions for 'sensitive' (special-category) data. The NLFPDPPP revises privacy-notice content requirements (Art. 15) but the underlying lawful-basis and consent architecture is substantially continuous with the 2010 law; the statute does not address processing for scientific/historical research or journalistic/artistic purposes, unlike GDPR.

Sources and claims (6)
  1. ProbableOneTrust DataGuidanceThe Federal Law sets out grounds for processing personal data distinct from the GDPR and does not address processing for scientific or historical research purposes.
  2. ProbableOneTrust DataGuidanceThe Federal Law does not address matters such as processing for journalistic or artistic purposes, unlike the GDPR.
  3. ConfirmedIAPPNLFPDPPP Article 15 revises mandatory privacy-notice content, requiring identification of the data subject to the processing and its purposes and distinguishing purposes that require consent.
  4. ConfirmedIAPPUnlike the prior law, the NLFPDPPP no longer lists disclosure of intended data transfers as a mandatory element of the privacy notice.
  5. ProbableOneTrust DataGuidanceThe Federal Law provides additional requirements for processing sensitive data and defines conditions for consent, in ways broadly similar to the GDPR's special-category regime.
  6. ProbableIAPP'Disociación' (dissociation) of personal data is defined as a recognized legal element/exception basis under the private-sector data protection framework.

#

Core ARCO rights are well-established and enforceable, but data portability is confirmed absent from the new statute, and deadline/response-window specifics await the pending implementing regulations.

Primary frameworkNLFPDPPP Arts. 16-25 (ARCO rights procedure)
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberCore ARCO rights are well-established and enforceable, but data portability is confirmed absent from the new statute, and deadline/response-window specifics await the pending implementing regulations.

Sub-modules (5)

Access RightGreen

The new law broadens the access right beyond simply knowing processed data and the privacy notice, to include information on the general conditions of processing.

Claims: CLM-MX-b4c5d6e7, CLM-MX-c5d6e7f8

Rectification And ErasureGreen

Both GDPR and the Mexican Federal Law recognize a right to request cancellation/erasure of data in certain circumstances; deletion is also required once data is no longer necessary for the stated purpose.

Claims: CLM-MX-d6e7f8a9, CLM-MX-e7f8a9b0

Restriction And ObjectionAmber

Opposition (the 'O' in ARCO) is a recognized right; restriction as a distinct GDPR-style concept is not separately elaborated in the sources reviewed.

Absence provenance: not recorded. Searched: NLFPDPPP derecho de limitación del tratamiento.

Claims: CLM-MX-f8a9b0c1

Data PortabilityRed

Practitioner review of the enacted NLFPDPPP text confirms the new law does not include a data portability right, despite general secondary summaries describing 'enhanced' rights.

Claims: CLM-MX-a9b0c1d2

Deadlines And Response WindowsAmber

Historically, data controllers/authorities operated under short compliance windows (e.g., 10 days to comply with an IFAI/INAI resolution); NLFPDPPP-specific response-window detail awaits the pending implementing regulation.

Claims: CLM-MX-b0c1d2e3, CLM-MX-c1d2e3f4

Category narrative90 words

Mexico's rights framework centers on the ARCO rights (access, rectification, cancellation, opposition). The NLFPDPPP broadens the definition of the access right to include information about the conditions of processing, and replaces judicial review of regulator resolutions from nullity trials to amparo proceedings before newly created specialized federal courts. Critically, per detailed practitioner analysis of the enacted text, the new law does NOT include a data portability right, in contrast to a DataGuidance summary describing 'enhanced' data subject rights generally — this is flagged as an unresolved conflict pending primary-text confirmation.

Sources and claims (8)
  1. ConfirmedIAPPARCO rights (access, rectification, cancellation and opposition) form the procedural core of data-subject rights under the private-sector data protection law.
  2. ConfirmedIAPPThe New Law redefines the access right so that the data subject may access personal data and also know general conditions of the processing, expanding beyond the prior law's narrower formulation.
  3. ConfirmedOneTrust DataGuidanceBoth the GDPR and the Mexican Federal Law provide that data subjects may request cancellation or erasure of their data in certain circumstances for legitimate reasons.
  4. ProbableIAPPPersonal data must be deleted where it is no longer required for the purposes indicated in the privacy notice provided to data subjects.
  5. ConfirmedIAPPOpposition to processing is recognized as one of the four ARCO rights under the private-sector framework.
  6. ConfirmedIAPPPractitioner analysis of the enacted NLFPDPPP text confirms the new law does not include a data portability right, among other omissions relative to GDPR-style frameworks.
  7. ProbableIAPPUnder the 2010-era framework, data collectors had 10 days to comply with a resolution issued by the data protection authority.
  8. ConfirmedIAPPAgainst resolutions of the new Secretaría (replacing INAI), affected parties may now pursue amparo proceedings before specialized district and circuit courts, which were to be enabled within 120 calendar days of the reform decree's publication (i.e., by 19 June 2025).

#

Security and controller-liability principles exist and are enforceable, but DPO, DPIA, privacy-by-design and regulator-facing breach notification — all GDPR Art. 25/33/35/37-39 analogues — are confirmed absent from the current statute and Regulations.

Primary frameworkNLFPDPPP + (provisionally) 2010 FLPPDPP Regulations, pending updated Reglamento
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberSecurity and controller-liability principles exist and are enforceable, but DPO, DPIA, privacy-by-design and regulator-facing breach notification — all GDPR Art. 25/33/35/37-39 analogues — are confirmed absent from the current statute and Regulations.

Sub-modules (7)

Accountability And DpiaRed

The Regulations address a concept of accountability but neither the Federal Law nor Regulations define processor liabilities or require DPIAs/privacy-by-design; a general secondary summary claiming DPIA introduction conflicts with detailed practitioner review of the enacted text.

Claims: CLM-MX-d2e3f4a5, CLM-MX-e3f4a5b6

Dpo RequirementsAmber

Neither the Federal Law nor its Regulations require formal DPO appointment or regulator notification of a DPO; historically the 2010 law required only designation of a responsible person/department (privacy officer).

Claims: CLM-MX-f4a5b6c7, CLM-MX-a5b6c7d8

Ropa RequirementsRed

No explicit records-of-processing-activities (ROPA) obligation equivalent to GDPR Art. 30 was located in the sources reviewed.

Absence provenance: not recorded. Searched: NLFPDPPP registro de actividades de tratamiento obligación.

Joint Controller ArrangementsAmber

The Federal Law specifies controllers are liable for violations of its principles but does not define processor liabilities in GDPR Art. 28 style detail.

Claims: CLM-MX-b6c7d8e9

Security MeasuresGreen

The Federal Law itself does not define security measures, but the (provisionally applicable) Regulations define 'technical security measures' and require risk-based administrative, technical and physical safeguards.

Claims: CLM-MX-c7d8e9f0, CLM-MX-d8e9f0a1

Breach NotificationAmber

The Federal Law does not specify a breach-notification requirement to the regulator; the Regulations (Art. 64) require the controller to inform the data subject without delay of breaches affecting their patrimonial or moral rights. Sector overlays impose separate regulator-facing notification (e.g., banks to CNBV).

Claims: CLM-MX-e9f0a1b2, CLM-MX-f0a1b2c3

Retention And DisposalGreen

Personal data must be deleted once no longer required for the purposes stated in the privacy notice.

Claims: CLM-MX-a1b2c3e4

Category narrative79 words

Mexico's regime imposes accountability, security and (limited) breach-related duties on controllers, but critically diverges from GDPR by not requiring a formal Data Protection Officer appointment/notification, and by not requiring DPIAs or privacy-by-design/default under either the Federal Law or its Regulations — a gap the NLFPDPPP's practitioner review confirms was carried forward. Breach notification runs to affected data subjects, not to the regulator, under the current Regulations (Art. 64); sectoral overlays (e.g., banking) impose separate incident-notification duties to financial regulators.

Sources and claims (10)
  1. ConfirmedOneTrust DataGuidanceNeither the Federal Law nor its Regulations address Data Protection Impact Assessments (DPIAs).
  2. UncertainOneTrust DataGuidanceA general secondary summary describes the NLFPDPPP as imposing stricter obligations including the need for risk assessments and data protection impact evaluations, which conflicts with detailed practitioner review of the enacted text confirming DPIAs are not addressed; this discrepancy is unresolved pending primary-text confirmation.
  3. ConfirmedOneTrust DataGuidanceNeither the Federal Law nor the Regulations require organizations to designate a formal Data Protection Officer or notify the authority of a DPO appointment.
  4. ProbableIAPPUnder the 2010-era law, all data controllers and processors had to appoint a person or group responsible for personal-data-related requirements (a privacy officer), and employers had to appoint a person or department for employee data.
  5. ConfirmedOneTrust DataGuidanceThe Federal Law specifies that data controllers are liable for violations of its principles, though neither the Law nor Regulations define the liabilities of data processors in detail.
  6. ConfirmedOneTrust DataGuidanceThe Federal Law does not itself define security measures, but Article 2(VII) of the Regulations defines 'technical security measures' as controls ensuring authorized, identified access to logical databases.
  7. ConfirmedIAPPMexico's data-protection regime imposes risk-based technical, administrative and physical safeguards on data processors under both the private-sector Federal Law and the public-sector General Law.
  8. ConfirmedOneTrust DataGuidanceUnder the current legislative framework there is no requirement to inform the data protection authority when a data breach occurs; the Federal Law/Regulations only impose notification obligations toward the affected data subject.
  9. ConfirmedIAPPBanks must immediately notify the National Banking and Securities Commission (CNBV) of any qualifying information-security incident, and the chief information security officer must submit a monthly information-security management report.
  10. ProbableIAPPPersonal data must be deleted if no longer required for the purposes indicated in the privacy notice provided to data subjects.

#

A transfer mechanism exists in statute but enforcement reach is explicitly limited by the authority's own historical acknowledgment of extraterritorial enforcement gaps, and SCC/BCR/TIA/localisation specifics are largely undocumented in current secondary sources.

Primary frameworkNLFPDPPP Art. 36 (international transfer clause in privacy notice)
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberA transfer mechanism exists in statute but enforcement reach is explicitly limited by the authority's own historical acknowledgment of extraterritorial enforcement gaps, and SCC/BCR/TIA/localisation specifics are largely undocumented in current secondary sources.

Sub-modules (6)

Transfer MechanismsAmber

Transfers rely on a privacy-notice clause binding the receiving controller to the same purposes and obligations, contingent on data-subject acceptance.

Claims: CLM-MX-b2c3e4f5, CLM-MX-c3e4f5a6

Adequacy ReceivedRed

No evidence found of Mexico having received a formal adequacy determination from another regime (e.g., EU) as of the research date.

Absence provenance: not recorded. Searched: Mexico EU adequacy decision received GDPR.

Adequacy GrantedAmber

Mexico's Federal Law/Regulations reference European adequacy decisions as a basis for enabling transfers, implying a form of unilateral recognition rather than a reciprocal adequacy-granting mechanism.

Claims: CLM-MX-d4e5f6b7

Sccs And BcrsRed

No dedicated SCC or BCR certification/registration scheme for the private sector was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico LFPDPPP cláusulas contractuales tipo BCR esquema certificación.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement analogous to post-Schrems II EU practice was identified for Mexico's private-sector regime.

Absence provenance: not recorded. Searched: Mexico transfer impact assessment requirement data protection.

Data LocalisationRed

No general data-localisation mandate was identified for the private-sector regime in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico data localisation requirement personal data private sector.

Category narrative75 words

Mexico's private-sector regime permits international transfers through privacy-notice-embedded transfer clauses binding the foreign recipient to the same purposes, and secondary commentary indicates the Federal Law/Regulations cite European adequacy decisions as a basis for enabling transfers. However, INAI (and now its successor) has historically lacked international enforcement powers to bind foreign controllers under other legal orders, limiting practical enforceability. No explicit SCC/BCR certification scheme, transfer-impact-assessment requirement, or general data-localisation mandate was identified for the private sector.

Sources and claims (3)
  1. ConfirmedIAPPUnder Article 36 of the private-sector law, a controller transferring personal data abroad must communicate the signed privacy notice to the new foreign controller so it remains bound by the same purposes and obligations, conditioned on a transfer clause having been included in the notice and accepted by the data subject.
  2. ProbableIAPPThe data protection authority has historically lacked international enforcement powers to compel foreign companies subject to a different legal order to comply with Mexican data protection obligations.
  3. ProbableOneTrust DataGuidanceThe Federal Law and Regulations cite European Union adequacy decisions as a basis for enabling international data transfers out of Mexico.

#

Financial-sector overlay is well documented; health, telecoms, education and insurance overlays are thinly evidenced or absent in the sources reviewed.

Supervisory authorityComisión Nacional Bancaria y de Valores (CNBV)
Traffic-light rationale — AmberFinancial-sector overlay is well documented; health, telecoms, education and insurance overlays are thinly evidenced or absent in the sources reviewed.

Sub-modules (7)

Financial Sector OverlayGreen

Banks must immediately notify CNBV of qualifying information-security incidents, with monthly CISO reporting to the CEO/board; credit-reporting entities are exempt from the general law and governed by separate legislation.

Claims: CLM-MX-e5f6a7c8, CLM-MX-f6a7c8d9

Health Sector OverlayAmber

Secondary commentary notes the existence of sector-specific laws in the health and pharmaceutical sectors distinct from the general Federal Law, but granular detail was not found in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico health sector data protection law pharmaceutical overlay detail.

Claims: CLM-MX-a7c8d9e0

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-style overlay (e.g., cookie consent, electronic communications confidentiality specific to the sector) was identified.

Absence provenance: not recorded. Searched: Mexico IFT ePrivacy telecoms data protection overlay.

Employment DataAmber

Historically, employers were required to appoint a person or department responsible for employee personal data and to promote its protection.

Claims: CLM-MX-b8d9e0f1

Credit And ScoringAmber

Credit-reporting entities (sociedades de información crediticia) are exempt from the general Federal Law and governed by separate credit-bureau legislation.

Claims: CLM-MX-c9e0f1a2

EducationRed

No education-sector-specific data protection overlay was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico education sector student data protection law.

InsuranceRed

No insurance-sector-specific data protection overlay was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico insurance sector data protection overlay CNSF.

Category narrative41 words

Mexico layers sector-specific rules atop the general private-sector data protection statute, most notably in financial services (credit-reporting carve-out, CNBV incident-notification duties for banks) and health/pharmaceutical sectors. No dedicated telecoms/ePrivacy, education, or insurance-specific data protection overlays were identified in the sources reviewed.

Sources and claims (5)
  1. ConfirmedIAPPBanks in Mexico must immediately notify the Comisión Nacional Bancaria y de Valores (CNBV) of any qualifying information-security incident.
  2. ConfirmedIAPPThe chief information security officer at Mexican banks must submit a monthly information-security management report to the CEO and, when required, to the board or relevant committees.
  3. ProbableOneTrust DataGuidanceSector-specific laws exist in the financial services and health/pharmaceutical sectors distinct from the general private-sector Federal Law and Regulations.
  4. ProbableIAPPEmployers must appoint a person or establish a personal data department to handle employees' personal data and promote its protection.
  5. ConfirmedIAPPCredit-reporting entities are exempt from the general private-sector data protection law because they are subject to separate regulation.

#

No dedicated adtech/commercial-privacy regime exists; only the general opposition right within ARCO offers any traction for direct-marketing objections.

Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — RedNo dedicated adtech/commercial-privacy regime exists; only the general opposition right within ARCO offers any traction for direct-marketing objections.

Sub-modules (6)

Cookies And TrackersRed

The Mexican private-sector law does not specifically address internet cookies.

Claims: CLM-MX-d0e1f2b3

Dark PatternsRed

No dark-pattern prohibition was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico dark patterns prohibition consumer data law.

Opt Out SignalsRed

No recognition of universal opt-out signals (e.g., Global Privacy Control, DAA) was identified.

Absence provenance: not recorded. Searched: Mexico Global Privacy Control opt-out signal recognition law.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rule was identified.

Absence provenance: not recorded. Searched: Mexico data clean room regulation privacy.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' or cross-context-advertising-specific regime was identified.

Absence provenance: not recorded. Searched: Mexico cross-context advertising sale share personal data law.

Direct MarketingAmber

Direct marketing objections are addressed only through the general ARCO opposition right rather than a dedicated marketing-consent/suppression regime.

Claims: CLM-MX-e1f2b3c4

Category narrative43 words

Mexico's private-sector data protection law does not specifically address internet cookies or trackers, and no dedicated dark-pattern prohibition, opt-out-signal recognition (e.g., Global Privacy Control), clean-room/data-collaboration-room rule, or cross-context-advertising regime was identified. Direct marketing is addressed only indirectly through the general ARCO opposition right.

Sources and claims (2)
  1. ConfirmedIAPPThe Mexican federal data protection law does not specifically address topics such as internet cookies, employee monitoring, or collection of personal data in connection with credit-card transactions.
  2. UncertainIAPPThe ARCO opposition right provides the primary (general, non-marketing-specific) mechanism by which data subjects can object to processing, including for direct-marketing purposes.

#

No binding AI-specific statute exists; biometric governance rests on enforcement precedent rather than codified rules, and profiling/ADM-transparency provisions were not separately documented.

Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberNo binding AI-specific statute exists; biometric governance rests on enforcement precedent rather than codified rules, and profiling/ADM-transparency provisions were not separately documented.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provision analogous to GDPR Art. 22 was specifically documented for Mexico in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico LFPDPPP perfilamiento restricción decisiones automatizadas.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation-right provision was specifically documented for Mexico's private-sector regime in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico automated decision making transparency right explanation law.

Ai Risk AssessmentsRed

Mexico has no dedicated AI law; a Senate National AI Alliance (ANIA) initiative is developing a regulatory proposal covering cybersecurity, privacy and ethical AI use, but remains pre-legislative.

Claims: CLM-MX-f3c4d5e6, CLM-MX-a4d5e6f7

Biometric RegimeAmber

Biometric governance has proceeded via enforcement precedent (the 'Fan ID' facial-recognition investigation) and a government digital biometric identity rollout, rather than a codified biometric-specific statute.

Claims: CLM-MX-b5e6f7a8, CLM-MX-c6f7a8b9

Genetic DataRed

No genetic-data-specific regime was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico genetic data protection law regime.

State Surveillance CarveoutsRed

No detailed national-security/state-surveillance carve-out provision was documented in the sources reviewed for the private-sector regime.

Absence provenance: not recorded. Searched: Mexico national security exemption data protection surveillance carveout.

Category narrative96 words

Mexico has no dedicated AI law; a Senate-based National AI Alliance (ANIA) is developing a regulatory proposal spanning cybersecurity, privacy, and AI ethics, but this remains pre-legislative as of the research date. Biometric data governance has developed through enforcement precedent rather than statute — most notably INAI's investigation into the Mexican Football Federation's 'Fan ID' facial-recognition system, which raised consent, proportionality and controller/processor-responsibility issues. The government is separately advancing a biometric digital-identity system. A thinly sourced reference to a Mexican 'neuro-rights' law protecting neurotechnology/neural data was found but could not be corroborated against a primary text.

Sources and claims (4)
  1. ConfirmedIAPPMexico does not have a specific AI law; the Senate's National AI Alliance (ANIA) is working on a regulatory proposal covering cybersecurity, privacy, ethical AI use and AI adoption.
  2. ProbableIAPPAs of mid-2026, Mexico's new data protection authority had not yet issued secondary regulation or public sanctions, though there were indications of preliminary investigations concerning sensitive data handling and security-incident management.
  3. ConfirmedIAPPINAI's investigation of the 'Fan ID' facial-recognition system implemented by the Mexican Football Federation became one of the most significant proceedings on biometric data processing in the private sector, raising issues of consent, proportionality and controller/processor responsibility.
  4. ProbableIAPPThe Mexican government is advancing implementation of a biometric digital identity system alongside a National Cybersecurity Plan 2025-2030.

#

The current statute contains no children's-data-specific regime at all; this is an explicit, confirmed statutory gap rather than a mere silence in secondary sources.

Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — RedThe current statute contains no children's-data-specific regime at all; this is an explicit, confirmed statutory gap rather than a mere silence in secondary sources.

Sub-modules (5)

Age VerificationRed

No age-verification requirement was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico NLFPDPPP verificación de edad menores.

Minor Profiling BansRed

No minor-profiling ban was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico minor profiling ban data protection.

Education SettingsRed

No education-setting-specific children's-data provision was identified.

Absence provenance: not recorded. Searched: Mexico education setting children data protection rule.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated)-specific protection provision was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico dependent adults elderly incapacitated data protection provision.

Category narrative52 words

Detailed practitioner review of the enacted NLFPDPPP text confirms that the new law does not include specific provisions addressing the processing of personal data of minors, continuing a longstanding gap relative to GDPR (which contains express child-consent-age rules). No age-verification, parental-consent, minor-profiling-ban, education-setting-specific, or dependent-adult-specific provisions were identified for Mexico's private-sector regime.

Sources and claims (1)
  1. ConfirmedIAPPThe New Federal Law (NLFPDPPP) does not include topics such as the processing of personal data of minors, unlike the GDPR which sets express child-consent age thresholds.

#

A functioning enforcement and judicial-review pathway exists, but the new regulator's operational capacity, sanctioning track record, and independence remain unproven during this institutional transition.

Primary frameworkNLFPDPPP enforcement + amparo judicial review procedure
Supervisory authoritySecretaría Anticorrupción y Buen Gobierno
Traffic-light rationale — AmberA functioning enforcement and judicial-review pathway exists, but the new regulator's operational capacity, sanctioning track record, and independence remain unproven during this institutional transition.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Secretaría now exercises verification, complaint-resolution and sanctioning powers formerly held by INAI, but with unresolved questions about its independence given its status as an executive-branch secretariat rather than an autonomous body.

Claims: CLM-MX-e8f9a0b1

Enforcement Activity IndexAmber

Historical INAI enforcement produced cumulative fines in the tens of millions of pesos in multiple reporting years under the prior law; specific figures for the new authority's activity were not accessible in the sources reviewed (content behind a paywall/JS-blocked).

Absence provenance: not recorded. Searched: INAI multas 2023 monto total sanciones LFPDPPP, Secretaría Anticorrupción y Buen Gobierno sanciones datos personales 2026.

Regulator Funding And CapacityRed

No detailed budget/headcount data for the new Secretaría's data-protection function was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Secretaría Anticorrupción y Buen Gobierno presupuesto protección de datos personal.

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism specific to data protection claims was identified in the sources reviewed.

Absence provenance: not recorded. Searched: Mexico class action data protection collective redress mechanism.

Private Right Of ActionAmber

Data subjects may seek civil damages from data collectors for harm suffered from a breach of the data protection law, and may now challenge regulator resolutions via amparo before specialized courts.

Claims: CLM-MX-f9a0b1c2, CLM-MX-a0b1c2d3

Recent Developments 180DAmber

Within the last 180 days, secondary reporting (published within the reporting window) indicates Mexico's updated privacy law remains largely structurally continuous with the 2010 regime, the new authority has yet to issue secondary regulation or public sanctions, and the government is simultaneously advancing biometric digital identity and a National Cybersecurity Plan.

Claims: CLM-MX-b1c2d3e4

Category narrative109 words

Enforcement authority has migrated from the dissolved, formerly autonomous INAI to the Secretaría Anticorrupción y Buen Gobierno; judicial review of regulator decisions shifted from nullity trials to amparo proceedings before newly created specialized federal courts. As of mid-2026, secondary sources report the new authority had not yet issued public sanctions or completed secondary regulation, notwithstanding reported preliminary investigations. Historically, INAI's cumulative fines under the prior law ran into the tens of millions of Mexican pesos in various reporting years, though specific current-year figures for the new authority were not accessible in the sources reviewed. Civil damages actions by data subjects against controllers are a recognized private right of action.

Sources and claims (4)
  1. ConfirmedIAPPUnlike INAI (an autonomous constitutional body), the Secretaría Anticorrupción y Buen Gobierno is not required to render an annual activity report to Congress, and the express attribution to develop, promote and disseminate data-protection research and studies was not carried forward in the new law's Article 39.
  2. ConfirmedIAPPData subjects may seek damages from data collectors when they consider they have suffered harm or losses derived from a breach of the data protection law.
  3. ConfirmedIAPPAgainst resolutions of the Secretaría, affected parties may now pursue amparo (constitutional review) proceedings before specialized district and circuit courts, replacing the prior nullity-trial pathway against INAI resolutions.
  4. ProbableIAPPAs of early-to-mid 2026, Mexico's updated privacy law entered into force but largely retains the structure of the 2010 regime, and the new data authority had not yet issued secondary regulation or public sanctions, though preliminary investigations into sensitive-data handling and security-incident management were reported, alongside government advancement of a biometric digital identity system and a National Cybersecurity Plan 2025-2030.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Mexico
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 50 claim(s), 13 source(s) in the cumulative register.