#
No comprehensive material/territorial scope, no general controller obligations, no registration regime; only breach-notification and general consumer-protection baselines exist.
Sub-modules (5)
Regulator And AuthorityAmber
The NM Attorney General (currently Raúl Torrez) and the Consumer & Environmental Protection Division within the NM Department of Justice hold general consumer-protection enforcement authority; the FTC holds concurrent federal Section 5 authority.
Claims (2):
- FTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to entities operating in New Mexico, as a general federal privacy-enforcement baseline.
- The New Mexico Attorney General's Consumer & Environmental Protection Division holds general state authority to investigate and enforce consumer-protection and data-related matters, including breach-notification compliance.
Act And InstrumentsAmber
The only dedicated data-protection instrument in force is the Data Breach Notification Act; no omnibus privacy act exists.
Claims (1):
- New Mexico's Data Breach Notification Act, enacted as Chapter 57 of the Laws of New Mexico 2017 and signed into law in April 2017, requires notification of data breaches.
Material ScopeAmber
Material scope is limited to 'personal identifying information' as defined for breach-notification purposes, which includes biometric data.
Claims (1):
- The definition of personal identifying information under New Mexico's Data Breach Notification Act includes biometric data.
Territorial ScopeAmber
The breach act applies to persons owning, licensing or maintaining computerized data containing NM residents' personal identifying information regardless of the entity's domicile.
Claims (1):
- New Mexico's breach-notification obligations extend to any person or entity that owns, licenses, or maintains computerized data containing personal identifying information of New Mexico residents, irrespective of the entity's state of domicile.
Regulator Registration And FilingRed
No controller registration, filing, or notification-to-regulator regime exists absent a data breach.
Claims (1):
- New Mexico imposes no general controller registration or pre-processing filing regime with the Attorney General absent a qualifying data breach.
Sources and claims (7)
- ConfirmedIAPP — New Mexico has not enacted a comprehensive consumer data-privacy statute equivalent to GDPR, CCPA/CPRA, or other US state omnibus privacy laws as of the 2025 legislative session.observed
- ConfirmedDataGuidance — New Mexico's Data Breach Notification Act, enacted as Chapter 57 of the Laws of New Mexico 2017 and signed into law in April 2017, requires notification of data breaches.observed
- ConfirmedFederal Trade Commission — FTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to entities operating in New Mexico, as a general federal privacy-enforcement baseline.observed
- ProbableNAAG — The New Mexico Attorney General's Consumer & Environmental Protection Division holds general state authority to investigate and enforce consumer-protection and data-related matters, including breach-notification compliance.observed
- ConfirmedIAPP — The definition of personal identifying information under New Mexico's Data Breach Notification Act includes biometric data.observed
- ProbableDataGuidance — New Mexico's breach-notification obligations extend to any person or entity that owns, licenses, or maintains computerized data containing personal identifying information of New Mexico residents, irrespective of the entity's state of domicile.observed
- ConfirmedIAPP — New Mexico imposes no general controller registration or pre-processing filing regime with the Attorney General absent a qualifying data breach.observed