🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-NM · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 17 sources retrieved model claude-sonnet-5 ·

United States – New Mexico

US-NM schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 60 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
60Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive material/territorial scope, no general controller obligations, no registration regime; only breach-notification and general consumer-protection baselines exist.

Primary frameworkNew Mexico Data Breach Notification Act (NMSA 1978, Chapter 57 of the Laws of New Mexico 2017); FTC Act Section 5 (federal baseline)
Traffic-light rationale — RedNo comprehensive material/territorial scope, no general controller obligations, no registration regime; only breach-notification and general consumer-protection baselines exist.

Sub-modules (5)

Regulator And AuthorityAmber

The NM Attorney General (currently Raúl Torrez) and the Consumer & Environmental Protection Division within the NM Department of Justice hold general consumer-protection enforcement authority; the FTC holds concurrent federal Section 5 authority.

Claims (2):

  • FTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to entities operating in New Mexico, as a general federal privacy-enforcement baseline.
  • The New Mexico Attorney General's Consumer & Environmental Protection Division holds general state authority to investigate and enforce consumer-protection and data-related matters, including breach-notification compliance.

Act And InstrumentsAmber

The only dedicated data-protection instrument in force is the Data Breach Notification Act; no omnibus privacy act exists.

Claims (1):

  • New Mexico's Data Breach Notification Act, enacted as Chapter 57 of the Laws of New Mexico 2017 and signed into law in April 2017, requires notification of data breaches.

Material ScopeAmber

Material scope is limited to 'personal identifying information' as defined for breach-notification purposes, which includes biometric data.

Claims (1):

  • The definition of personal identifying information under New Mexico's Data Breach Notification Act includes biometric data.

Territorial ScopeAmber

The breach act applies to persons owning, licensing or maintaining computerized data containing NM residents' personal identifying information regardless of the entity's domicile.

Claims (1):

  • New Mexico's breach-notification obligations extend to any person or entity that owns, licenses, or maintains computerized data containing personal identifying information of New Mexico residents, irrespective of the entity's state of domicile.

Regulator Registration And FilingRed

No controller registration, filing, or notification-to-regulator regime exists absent a data breach.

Claims (1):

  • New Mexico imposes no general controller registration or pre-processing filing regime with the Attorney General absent a qualifying data breach.
Category narrative76 words

New Mexico has no comprehensive omnibus consumer-privacy statute. The operative framework is (a) the federal FTC Act Section 5 unfair/deceptive-practices baseline enforced nationally, (b) New Mexico's Data Breach Notification Act (Chapter 57 of the Laws of New Mexico 2017, codified in NMSA 1978), which addresses breach notification only, and (c) the state's general Unfair Practices Act enforced by the NM Attorney General's Consumer & Environmental Protection Division. There is no state-level DPA-style registration/filing regime for controllers.

Sources and claims (7)
  1. ConfirmedIAPPNew Mexico has not enacted a comprehensive consumer data-privacy statute equivalent to GDPR, CCPA/CPRA, or other US state omnibus privacy laws as of the 2025 legislative session.observed
  2. ConfirmedDataGuidanceNew Mexico's Data Breach Notification Act, enacted as Chapter 57 of the Laws of New Mexico 2017 and signed into law in April 2017, requires notification of data breaches.observed
  3. ConfirmedFederal Trade CommissionFTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to entities operating in New Mexico, as a general federal privacy-enforcement baseline.observed
  4. ProbableNAAGThe New Mexico Attorney General's Consumer & Environmental Protection Division holds general state authority to investigate and enforce consumer-protection and data-related matters, including breach-notification compliance.observed
  5. ConfirmedIAPPThe definition of personal identifying information under New Mexico's Data Breach Notification Act includes biometric data.observed
  6. ProbableDataGuidanceNew Mexico's breach-notification obligations extend to any person or entity that owns, licenses, or maintains computerized data containing personal identifying information of New Mexico residents, irrespective of the entity's state of domicile.observed
  7. ConfirmedIAPPNew Mexico imposes no general controller registration or pre-processing filing regime with the Attorney General absent a qualifying data breach.observed

#

No general lawful-basis or consent framework; only a narrow genetic-data statute exists.

Primary frameworkNew Mexico Genetic Information Privacy Act (NMSA 1978, Chapter 24, Article 21)
Traffic-light rationale — RedNo general lawful-basis or consent framework; only a narrow genetic-data statute exists.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-processing-basis framework exists in New Mexico law.

Claims (1):

  • New Mexico has no statute enumerating lawful bases for processing personal data analogous to GDPR Article 6.

Special CategoriesAmber

The Genetic Information Privacy Act regulates collection, retention, use and disclosure of genetic information, including by direct-to-consumer genetic testing entities.

Claims (1):

  • New Mexico's Genetic Information Privacy Act (NMSA 1978, Chapter 24, Article 21) establishes consent-based rules for the collection, use, and disclosure of genetic information by covered entities, including direct-to-consumer genetic testing companies.

Pseudonymisation And AnonymisationRed

No statutory definition or safe-harbour treatment of pseudonymised or anonymised data exists in New Mexico law.

Claims (1):

  • New Mexico has not enacted a statutory definition or safe-harbour treatment for pseudonymised or anonymised data.
Category narrative43 words

New Mexico has no general statutory scheme of enumerated lawful processing bases or consent standards analogous to GDPR Art 6/7. The one sectoral carve-out is the Genetic Information Privacy Act (Chapter 24, Article 21 NMSA), which imposes consent-based rules on genetic data specifically.

Sources and claims (4)
  1. ConfirmedIAPPNew Mexico has no statute enumerating lawful bases for processing personal data analogous to GDPR Article 6.observed
  2. ConfirmedIAPPNew Mexico has no general statutory consent standard governing commercial personal-data processing outside of sector-specific statutes such as the Genetic Information Privacy Act.observed
  3. ProbableDataGuidanceNew Mexico's Genetic Information Privacy Act (NMSA 1978, Chapter 24, Article 21) establishes consent-based rules for the collection, use, and disclosure of genetic information by covered entities, including direct-to-consumer genetic testing companies.observed
  4. UncertainIAPPNew Mexico has not enacted a statutory definition or safe-harbour treatment for pseudonymised or anonymised data.observed

#

Absence of any comprehensive state-level DSR framework; gap is structural, not a temporary lag.

Traffic-light rationale — RedAbsence of any comprehensive state-level DSR framework; gap is structural, not a temporary lag.

Sub-modules (5)

Access RightRed

No general state-level subject access right exists.

Claims (1):

  • New Mexico law does not grant consumers a general right to access personal data held by private-sector controllers.

Rectification And ErasureRed

No general state-level rectification or erasure ('right to be forgotten') right exists.

Claims (1):

  • New Mexico law does not grant consumers a general right to rectify or delete personal data held by private-sector controllers.

Restriction And ObjectionRed

No general restriction-of-processing or objection/profiling opt-out right exists.

Claims (1):

  • New Mexico law does not grant consumers a general right to restrict processing or object to profiling.

Data PortabilityRed

No statutory data-portability right exists.

Claims (1):

  • New Mexico law does not grant consumers a statutory data-portability right.

Deadlines And Response WindowsRed

No statutory controller-response deadlines exist because there is no underlying DSR framework to attach deadlines to.

Claims (1):

  • New Mexico law prescribes no statutory response-window deadlines for consumer data-subject requests, as no underlying comprehensive DSR framework exists.
Category narrative46 words

New Mexico confers no general consumer data-subject rights (access, rectification, erasure, restriction, objection, portability) at the state level. Residents' only relevant statutory rights are federal FCRA credit-file rights and any rights arising under federal sectoral statutes (HIPAA, GLBA, COPPA), which are outside this state JID's scope.

Sources and claims (5)
  1. ConfirmedIAPPNew Mexico law does not grant consumers a general right to access personal data held by private-sector controllers.observed
  2. ConfirmedIAPPNew Mexico law does not grant consumers a general right to rectify or delete personal data held by private-sector controllers.observed
  3. ConfirmedIAPPNew Mexico law does not grant consumers a general right to restrict processing or object to profiling.observed
  4. ConfirmedIAPPNew Mexico law does not grant consumers a statutory data-portability right.observed
  5. ConfirmedIAPPNew Mexico law prescribes no statutory response-window deadlines for consumer data-subject requests, as no underlying comprehensive DSR framework exists.observed

#

Only breach-notification duties confirmed in force; broader accountability/DPIA/DPO/ROPA apparatus absent.

Primary frameworkNew Mexico Data Breach Notification Act (NMSA 1978, Chapter 57 of the Laws of New Mexico 2017)
Traffic-light rationale — RedOnly breach-notification duties confirmed in force; broader accountability/DPIA/DPO/ROPA apparatus absent.

Sub-modules (7)

Accountability And DpiaRed

No accountability principle or DPIA-trigger regime exists in New Mexico statute.

Claims (1):

  • New Mexico has not enacted an accountability principle or DPIA-trigger requirement applicable to private-sector controllers generally.

Dpo RequirementsRed

No DPO appointment threshold or independence requirement exists.

Claims (1):

  • New Mexico has not enacted a data-protection-officer appointment requirement for private-sector controllers.

Ropa RequirementsRed

No records-of-processing (ROPA) obligation exists.

Claims (1):

  • New Mexico has not enacted a records-of-processing-activities requirement for private-sector controllers.

Joint Controller ArrangementsRed

No statutory joint-controller allocation-of-liability framework exists.

Claims (1):

  • New Mexico has not enacted a statutory joint-controller liability-allocation framework.

Security MeasuresAmber

Whether the Data Breach Notification Act imposes an affirmative reasonable-security-procedures duty independent of the notification trigger is unconfirmed from secondary sources and requires primary statutory text verification.

Claims (1):

  • New Mexico's Data Breach Notification Act may impose an affirmative duty on entities to maintain reasonable security procedures for personal identifying information, consistent with the common structure of comparable state breach statutes, but the specific statutory provision was not independently confirmed in available secondary sources.

Breach NotificationAmber

The Data Breach Notification Act requires notification following unauthorized acquisition of unencrypted (or encrypted with compromised keys) computerized personal identifying information.

Claims (1):

  • New Mexico's Data Breach Notification Act defines a data breach as the unauthorised acquisition of unencrypted computerised data, or of encrypted computerised data together with the confidential process or key needed to decrypt it, that compromises the security, confidentiality, or integrity of personal identifying information, triggering a notification duty.

Retention And DisposalRed

No general statutory data-retention limit or disposal-duty regime exists outside sector-specific federal statutes.

Claims (1):

  • New Mexico has not enacted a general statutory data-retention-limit or secure-disposal duty applicable to private-sector controllers.
Category narrative47 words

New Mexico imposes no general accountability, DPIA, DPO, ROPA, or joint-controller framework. The sole controller-facing duties in force relate to breach notification under the Data Breach Notification Act; whether the Act also imposes an affirmative 'reasonable security procedures' duty independent of the notification trigger requires primary-source verification.

Sources and claims (7)
  1. ConfirmedIAPPNew Mexico has not enacted an accountability principle or DPIA-trigger requirement applicable to private-sector controllers generally.observed
  2. ConfirmedIAPPNew Mexico has not enacted a data-protection-officer appointment requirement for private-sector controllers.observed
  3. ConfirmedIAPPNew Mexico has not enacted a records-of-processing-activities requirement for private-sector controllers.observed
  4. ConfirmedIAPPNew Mexico has not enacted a statutory joint-controller liability-allocation framework.observed
  5. UncertainDataGuidanceNew Mexico's Data Breach Notification Act may impose an affirmative duty on entities to maintain reasonable security procedures for personal identifying information, consistent with the common structure of comparable state breach statutes, but the specific statutory provision was not independently confirmed in available secondary sources.observed
  6. ConfirmedDataGuidanceNew Mexico's Data Breach Notification Act defines a data breach as the unauthorised acquisition of unencrypted computerised data, or of encrypted computerised data together with the confidential process or key needed to decrypt it, that compromises the security, confidentiality, or integrity of personal identifying information, triggering a notification duty.observed
  7. ConfirmedIAPPNew Mexico has not enacted a general statutory data-retention-limit or secure-disposal duty applicable to private-sector controllers.observed

#

No cross-border transfer apparatus exists at the state level; concept is largely inapplicable to a US state absent an omnibus statute.

Traffic-light rationale — RedNo cross-border transfer apparatus exists at the state level; concept is largely inapplicable to a US state absent an omnibus statute.

Sub-modules (6)

Transfer MechanismsRed

No state-level transfer-mechanism regime exists.

Claims (1):

  • New Mexico has not enacted any statutory cross-border data-transfer mechanism (equivalent to adequacy, SCCs, BCRs, or derogations).

Adequacy ReceivedRed

Not applicable to a US state; no adequacy-receipt concept exists at this sub-federal level.

Claims (1):

  • The concept of an adequacy decision received from another regime is not applicable to New Mexico as a sub-federal US jurisdiction lacking an omnibus statute.

Adequacy GrantedRed

Not applicable to a US state; New Mexico has no authority to grant adequacy decisions.

Claims (1):

  • New Mexico has no legal authority or mechanism to grant adequacy decisions to other jurisdictions.

Sccs And BcrsRed

No state-level SCC/BCR framework exists.

Claims (1):

  • New Mexico has not enacted an SCC or BCR authorisation regime.

Transfer Impact AssessmentRed

No TIA requirement exists at the state level.

Claims (1):

  • New Mexico has not enacted a transfer-impact-assessment requirement.

Data LocalisationRed

No data-localisation mandate exists in New Mexico law.

Claims (1):

  • New Mexico has not enacted a data-localisation mandate for personal data.
Category narrative49 words

As a sub-federal US jurisdiction with no comprehensive privacy statute, New Mexico has no transfer-mechanism regime, adequacy-decision apparatus, SCC/BCR framework, TIA requirement, or data-localisation mandate. Cross-border data-flow governance for entities operating in New Mexico is determined entirely by federal law (where applicable) and by contractual practice, not state statute.

Sources and claims (6)
  1. ConfirmedIAPPNew Mexico has not enacted any statutory cross-border data-transfer mechanism (equivalent to adequacy, SCCs, BCRs, or derogations).observed
  2. ConfirmedIAPPThe concept of an adequacy decision received from another regime is not applicable to New Mexico as a sub-federal US jurisdiction lacking an omnibus statute.observed
  3. ConfirmedIAPPNew Mexico has no legal authority or mechanism to grant adequacy decisions to other jurisdictions.observed
  4. ConfirmedIAPPNew Mexico has not enacted an SCC or BCR authorisation regime.observed
  5. ConfirmedIAPPNew Mexico has not enacted a transfer-impact-assessment requirement.observed
  6. ConfirmedIAPPNew Mexico has not enacted a data-localisation mandate for personal data.observed

#

Federal sectoral overlays are well-established and in force; several NM-specific sectoral gaps remain unconfirmed absences rather than verified negatives.

Traffic-light rationale — AmberFederal sectoral overlays are well-established and in force; several NM-specific sectoral gaps remain unconfirmed absences rather than verified negatives.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA privacy/safeguards obligations apply to financial institutions operating in New Mexico as a federal sectoral overlay.

Claims (1):

  • Financial institutions operating in New Mexico are subject to GLBA's privacy and safeguards obligations as a federal sectoral overlay, in the absence of a state-specific equivalent.

Health Sector OverlayAmber

HIPAA applies to covered entities/business associates in New Mexico as a federal sectoral overlay; no NM-specific health-privacy statute supplements it.

Claims (1):

  • Covered entities and business associates operating in New Mexico are subject to HIPAA's privacy and security rules as a federal sectoral overlay, in the absence of a state-specific health-privacy statute.

Telecoms And EprivacyRed

No New Mexico-specific telecoms or eprivacy/cookie-consent statute exists.

Claims (1):

  • New Mexico has not enacted a telecoms or eprivacy/cookie-consent statute governing electronic communications privacy.

Employment DataRed

No New Mexico-specific employment-data-privacy statute exists.

Claims (1):

  • New Mexico has not enacted an employment-specific data-privacy statute.

Credit And ScoringAmber

Federal FCRA rights (file access, dispute, correction) apply to New Mexico residents as a matter of federal sectoral law referenced in NM-specific breach-notice templates.

Claims (1):

  • New Mexico residents hold federal Fair Credit Reporting Act rights, including the right to know what is in their credit file, dispute inaccurate information, and require correction or deletion by consumer reporting agencies.

EducationAmber

No New Mexico-specific comprehensive student-data-privacy statute was confirmed; FERPA applies federally as the baseline for education records.

Claims (1):

  • No New Mexico-specific comprehensive K-12 student-data-privacy statute was confirmed in available sources; federal FERPA supplies the operative baseline for education records held by federally funded institutions.

InsuranceAmber

Adoption status of the NAIC Insurance Data Security Model Law in New Mexico could not be confirmed from available sources and requires primary-source verification.

Claims (1):

  • Whether New Mexico has adopted the NAIC Insurance Data Security Model Law could not be confirmed from available secondary sources.
Category narrative60 words

Sectoral coverage in New Mexico is dominated by federal overlays: GLBA for financial-sector personal data, HIPAA for health data, and FCRA for credit-related consumer-report rights, all displacing the need for (and absence of) state-specific equivalents. No New Mexico-specific telecoms/eprivacy, employment-data, education-sector, or insurance-data-security statute was confirmed; NAIC Insurance Data Security Model Law adoption status in New Mexico requires primary-source verification.

Sources and claims (7)
  1. ConfirmedNAAGFinancial institutions operating in New Mexico are subject to GLBA's privacy and safeguards obligations as a federal sectoral overlay, in the absence of a state-specific equivalent.observed
  2. ConfirmedNAAGCovered entities and business associates operating in New Mexico are subject to HIPAA's privacy and security rules as a federal sectoral overlay, in the absence of a state-specific health-privacy statute.observed
  3. ConfirmedIAPPNew Mexico has not enacted a telecoms or eprivacy/cookie-consent statute governing electronic communications privacy.observed
  4. UncertainIAPPNew Mexico has not enacted an employment-specific data-privacy statute.observed
  5. ConfirmedIAPPNew Mexico residents hold federal Fair Credit Reporting Act rights, including the right to know what is in their credit file, dispute inaccurate information, and require correction or deletion by consumer reporting agencies.observed
  6. UncertainIAPPNo New Mexico-specific comprehensive K-12 student-data-privacy statute was confirmed in available sources; federal FERPA supplies the operative baseline for education records held by federally funded institutions.observed
  7. UncertainIAPPWhether New Mexico has adopted the NAIC Insurance Data Security Model Law could not be confirmed from available secondary sources.observed

#

No adtech/commercial-privacy regime is currently in force; the sole relevant instrument (SB 192) is pending legislation.

Traffic-light rationale — RedNo adtech/commercial-privacy regime is currently in force; the sole relevant instrument (SB 192) is pending legislation.

Sub-modules (6)

Cookies And TrackersRed

No state cookie/tracker consent law exists.

Claims (1):

  • New Mexico has not enacted a cookie or tracking-technology consent statute.

Dark PatternsAmber

No dark-pattern prohibition is currently in force; pending SB 192 would require a dark-pattern-free rights-exercise webpage for data brokers.

Claims (1):

  • New Mexico Senate Bill 192, introduced January 29, 2026 and referred to Senate committee, would require registered data brokers to disclose contact information, collection of minors', geolocation, and reproductive-healthcare data, and provide a webpage allowing consumers to exercise privacy rights without the use of dark patterns; the bill has not been enacted.

Opt Out SignalsRed

No Global Privacy Control or DAA opt-out-signal recognition mandate exists.

Claims (1):

  • New Mexico has not enacted a statutory requirement to recognise universal opt-out signals such as Global Privacy Control.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room regulation exists.

Claims (1):

  • New Mexico has no statutory or regulatory framework addressing data clean rooms or data-collaboration-room practices.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' or cross-context-advertising framework exists.

Claims (1):

  • New Mexico has not enacted a CPRA-style statutory framework defining 'sale' or 'share' of personal information for cross-context behavioural advertising.

Direct MarketingRed

No state-specific direct-marketing consent or suppression statute exists beyond federal TCPA/CAN-SPAM baselines.

Claims (1):

  • New Mexico has no state-specific direct-marketing consent or suppression statute beyond the federal TCPA and CAN-SPAM baselines.
Category narrative56 words

New Mexico has no cookie/tracker consent law, dark-pattern prohibition, opt-out-signal mandate, clean-room regulation, cross-context-advertising 'sale'/'share' framework, or general direct-marketing consent statute. A pending 2026 Senate Bill (SB 192, the proposed Data Broker Privacy Act) would introduce registration, disclosure, and dark-pattern-adjacent transparency duties for data brokers, but remains at the introduced/referred stage and is not in force.

Sources and claims (6)
  1. ConfirmedIAPPNew Mexico has not enacted a cookie or tracking-technology consent statute.observed
  2. ConfirmedDataGuidanceNew Mexico Senate Bill 192, introduced January 29, 2026 and referred to Senate committee, would require registered data brokers to disclose contact information, collection of minors', geolocation, and reproductive-healthcare data, and provide a webpage allowing consumers to exercise privacy rights without the use of dark patterns; the bill has not been enacted.observed
  3. ConfirmedIAPPNew Mexico has not enacted a statutory requirement to recognise universal opt-out signals such as Global Privacy Control.observed
  4. UncertainIAPPNew Mexico has no statutory or regulatory framework addressing data clean rooms or data-collaboration-room practices.observed
  5. ConfirmedIAPPNew Mexico has not enacted a CPRA-style statutory framework defining 'sale' or 'share' of personal information for cross-context behavioural advertising.observed
  6. UncertainIAPPNew Mexico has no state-specific direct-marketing consent or suppression statute beyond the federal TCPA and CAN-SPAM baselines.observed

#

No ADM/profiling/AI-assessment statute in force; biometric and genetic coverage exists only incidentally via other sectoral statutes.

Traffic-light rationale — RedNo ADM/profiling/AI-assessment statute in force; biometric and genetic coverage exists only incidentally via other sectoral statutes.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction statute analogous to GDPR Art 22 exists.

Claims (1):

  • New Mexico has not enacted a profiling-restriction statute analogous to GDPR Article 22.

Automated Decision Making TransparencyRed

No ADM-transparency or explanation-right statute exists.

Claims (1):

  • New Mexico has not enacted an automated-decision-making transparency or explanation-right statute.

Ai Risk AssessmentsAmber

No AI-specific risk-assessment statute exists; the NM AG has engaged in multistate advocacy on AI-enabled data broker and surveillance practices.

Claims (1):

  • The New Mexico Department of Justice joined a multistate attorneys-general comment letter (dated March 23, 2026) raising concerns about AI-assisted data acquisition and analysis by data brokers and the absence of a complementary federal framework governing such practices.

Biometric RegimeAmber

Biometric data is covered only incidentally, as an enumerated category within the Data Breach Notification Act's personal-identifying-information definition; no dedicated biometric-privacy statute (e.g., facial recognition/BIPA-style) exists.

Claims (1):

  • Biometric data is captured within the definition of personal identifying information under New Mexico's Data Breach Notification Act, but no dedicated biometric-privacy statute (e.g., a facial-recognition or fingerprint-specific consent regime) exists.

Genetic DataAmber

The Genetic Information Privacy Act provides the only dedicated algorithmic/biometric-adjacent governance of genetic data, relevant to direct-to-consumer genetic testing and downstream analytics.

Claims (1):

  • New Mexico's Genetic Information Privacy Act (NMSA 1978, Chapter 24, Article 21) is the state's only dedicated statutory governance of genetic data, relevant to direct-to-consumer genetic testing entities and downstream algorithmic use of genetic datasets.

State Surveillance CarveoutsAmber

No New Mexico-specific state-surveillance carve-out or national-security exemption statute was identified; the NM AG has joined multistate advocacy opposing unchecked domestic-surveillance data practices.

Claims (1):

  • No New Mexico-specific statutory carve-out for state surveillance or national-security exemptions from data-protection obligations was identified; the state's Attorney General has instead engaged in multistate advocacy against unchecked domestic-surveillance data practices.
Category narrative73 words

New Mexico has no general profiling-restriction, ADM-transparency, or AI-risk-assessment statute. Biometric data is captured incidentally within the Data Breach Notification Act's PII definition, and genetic data is separately governed by the Genetic Information Privacy Act. The NM Attorney General has joined multistate advocacy (a March 2026 comment letter) raising concerns about AI-assisted data broker practices and domestic surveillance, but this is advocacy, not binding NM law, and no state-surveillance carve-out statute was identified.

Sources and claims (6)
  1. ConfirmedIAPPNew Mexico has not enacted a profiling-restriction statute analogous to GDPR Article 22.observed
  2. ConfirmedIAPPNew Mexico has not enacted an automated-decision-making transparency or explanation-right statute.observed
  3. ConfirmedCalifornia Department of Justice (host)The New Mexico Department of Justice joined a multistate attorneys-general comment letter (dated March 23, 2026) raising concerns about AI-assisted data acquisition and analysis by data brokers and the absence of a complementary federal framework governing such practices.observed
  4. ConfirmedIAPPBiometric data is captured within the definition of personal identifying information under New Mexico's Data Breach Notification Act, but no dedicated biometric-privacy statute (e.g., a facial-recognition or fingerprint-specific consent regime) exists.observed
  5. ProbableDataGuidanceNew Mexico's Genetic Information Privacy Act (NMSA 1978, Chapter 24, Article 21) is the state's only dedicated statutory governance of genetic data, relevant to direct-to-consumer genetic testing entities and downstream algorithmic use of genetic datasets.observed
  6. UncertainCalifornia Department of Justice (host)No New Mexico-specific statutory carve-out for state surveillance or national-security exemptions from data-protection obligations was identified; the state's Attorney General has instead engaged in multistate advocacy against unchecked domestic-surveillance data practices.observed

#

Federal COPPA baseline is in force and NM AG enforcement activity is significant, but no NM-specific statutory age-verification, minor-profiling-ban, or dependent-adults framework exists; several child-safety bills remain unenacted.

Traffic-light rationale — AmberFederal COPPA baseline is in force and NM AG enforcement activity is significant, but no NM-specific statutory age-verification, minor-profiling-ban, or dependent-adults framework exists; several child-safety bills remain unenacted.

Sub-modules (5)

Age VerificationRed

No New Mexico age-verification statute is in force; an Age-Appropriate Design Code Act bill was introduced but not enacted.

Claims (1):

  • A New Mexico bill for an Age Appropriate Design Code Act was introduced but has not been enacted into law.

Minor Profiling BansRed

No statutory ban on profiling minors exists in New Mexico.

Claims (1):

  • New Mexico has not enacted a statutory ban on profiling minors for commercial purposes.

Education SettingsAmber

No NM-specific education-settings data statute was confirmed; FERPA applies federally.

Claims (1):

  • No New Mexico-specific comprehensive education-settings data-privacy statute was confirmed; federal FERPA remains the operative baseline for student education records.

Dependent AdultsRed

No New Mexico-specific dependent-adults data-protection provisions were identified.

Claims (1):

  • No New Mexico-specific statutory data-protection provisions addressing dependent adults (elderly or mentally incapacitated individuals) were identified.
Category narrative81 words

New Mexico has no state-level age-of-consent, parental-consent, minor-profiling-ban, or education-settings-specific data statute; federal COPPA supplies the operative parental-consent baseline for online services directed to children. Multiple NM bills addressing online child safety (e.g., an Age-Appropriate Design Code Act bill and an Internet Privacy and Safety Act bill) have been introduced but not enacted. The NM Attorney General has been active in child-protection enforcement, including litigation against major platforms and a prior COPPA-related settlement with Google. No dependent-adults-specific data-protection provisions were identified.

Sources and claims (5)
  1. ConfirmedIAPPA New Mexico bill for an Age Appropriate Design Code Act was introduced but has not been enacted into law.observed
  2. ConfirmedIAPPFederal COPPA parental-consent requirements apply to operators of online services directed to children accessed by New Mexico residents, in the absence of a state-specific analogue; the New Mexico Attorney General has previously enforced COPPA obligations jointly with the FTC, including a settlement with Google.observed
  3. ConfirmedIAPPNew Mexico has not enacted a statutory ban on profiling minors for commercial purposes.observed
  4. UncertainIAPPNo New Mexico-specific comprehensive education-settings data-privacy statute was confirmed; federal FERPA remains the operative baseline for student education records.observed
  5. UncertainIAPPNo New Mexico-specific statutory data-protection provisions addressing dependent adults (elderly or mentally incapacitated individuals) were identified.observed

#

Active AG enforcement exists but the collective-redress/PRA landscape is unconfirmed, and no comprehensive statutory penalty regime beyond breach-notification and general UPA remedies exists.

Primary frameworkNew Mexico Unfair Practices Act; New Mexico Data Breach Notification Act (NMSA 1978, Chapter 57 of the Laws of New Mexico 2017)
Traffic-light rationale — AmberActive AG enforcement exists but the collective-redress/PRA landscape is unconfirmed, and no comprehensive statutory penalty regime beyond breach-notification and general UPA remedies exists.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The NM AG's Consumer & Environmental Protection Division holds authority to investigate and pursue civil enforcement for unfair or deceptive data practices and breach-notification non-compliance.

Claims (1):

  • The New Mexico Attorney General's Consumer & Environmental Protection Division has authority to investigate and pursue enforcement actions against businesses for unfair or deceptive practices, including those relating to consumer data-handling, under the state's general consumer-protection framework.

Enforcement Activity IndexGreen

Recent enforcement/litigation activity includes lawsuits against Meta and Snap for enabling online child abuse, and a historical joint FTC/NM AG COPPA settlement with Google.

Claims (2):

  • New Mexico Attorney General Raúl Torrez has filed lawsuits against major technology companies including Meta and Snap Inc. for enabling online abuse of children, as part of a child-protection enforcement priority.
  • The New Mexico Attorney General previously joined the FTC in a settlement with Google concerning alleged COPPA violations.

Regulator Funding And CapacityAmber

The Consumer & Environmental Protection Division was reported to comprise roughly ten attorneys handling a broad consumer-protection docket as of a 2022 public account; current headcount is unconfirmed.

Claims (1):

  • As of a 2022 public account, the NM Consumer & Environmental Protection Division comprised roughly ten attorneys overseeing consumer, environmental, and whistleblower matters.

Collective Redress And Class ActionsAmber

General information indicates a subset of US state breach-notification statutes allow private rights of action, but New Mexico's specific position is unconfirmed from available secondary sources.

Claims (1):

  • Whether New Mexico's Data Breach Notification Act affords consumers a private right of action for non-compliance is unconfirmed from available secondary sources, though a subset of US state breach-notification statutes generally are noted to allow such actions.

Private Right Of ActionAmber

Whether New Mexico's Data Breach Notification Act affords consumers a private right of action is unconfirmed and requires primary-source (statutory text) verification.

Claims (1):

  • Whether New Mexico's Data Breach Notification Act affords consumers a private right of action for non-compliance is unconfirmed from available secondary sources, though a subset of US state breach-notification statutes generally are noted to allow such actions.

Recent Developments 180DAmber

Within the last 180 days, New Mexico saw introduction of SB 192 (Data Broker Privacy Act) in January 2026 and NM DOJ participation in a March 2026 multistate letter on domestic surveillance/data broker practices.

Claims (2):

  • New Mexico Senate Bill 192, enacting a proposed Data Broker Privacy Act with registration, disclosure, and deletion-process requirements for data brokers, was introduced to the New Mexico State Senate on January 29, 2026 and referred to Senate committee; it has not been enacted.
  • The New Mexico Department of Justice joined a multistate attorneys-general comment letter dated March 23, 2026 addressing data-broker and AI-enabled domestic-surveillance data practices.
Category narrative108 words

Enforcement in New Mexico proceeds through the Attorney General's general consumer-protection authority (Unfair Practices Act) and the Data Breach Notification Act, supplemented by FTC Section 5 action. The AG's Consumer & Environmental Protection Division (~10 attorneys as of the most recent public account) has pursued active child-safety litigation against major platforms and previously settled a COPPA matter with Google jointly with the FTC. Whether the Data Breach Notification Act includes a private right of action is unconfirmed and requires primary-source verification. Recent 180-day developments include the January 2026 introduction of SB 192 (Data Broker Privacy Act) and the March 2026 multistate AG letter on domestic surveillance/data broker practices.

Sources and claims (7)
  1. ProbableNAAGThe New Mexico Attorney General's Consumer & Environmental Protection Division has authority to investigate and pursue enforcement actions against businesses for unfair or deceptive practices, including those relating to consumer data-handling, under the state's general consumer-protection framework.observed
  2. ConfirmedNAAGNew Mexico Attorney General Raúl Torrez has filed lawsuits against major technology companies including Meta and Snap Inc. for enabling online abuse of children, as part of a child-protection enforcement priority.observed
  3. ConfirmedIAPPThe New Mexico Attorney General previously joined the FTC in a settlement with Google concerning alleged COPPA violations.observed
  4. ProbableNAAGAs of a 2022 public account, the NM Consumer & Environmental Protection Division comprised roughly ten attorneys overseeing consumer, environmental, and whistleblower matters.observed
  5. UncertainIAPPWhether New Mexico's Data Breach Notification Act affords consumers a private right of action for non-compliance is unconfirmed from available secondary sources, though a subset of US state breach-notification statutes generally are noted to allow such actions.observed
  6. ConfirmedDataGuidanceNew Mexico Senate Bill 192, enacting a proposed Data Broker Privacy Act with registration, disclosure, and deletion-process requirements for data brokers, was introduced to the New Mexico State Senate on January 29, 2026 and referred to Senate committee; it has not been enacted.observed
  7. ConfirmedCalifornia Department of Justice (host)The New Mexico Department of Justice joined a multistate attorneys-general comment letter dated March 23, 2026 addressing data-broker and AI-enabled domestic-surveillance data practices.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – New Mexico
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 60 claim(s), 17 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and controller_processor_duties.breach_notification rest on T1/T2/T3 sourcing (FTC.gov, nmag.gov, and DataGuidance secondary summaries of the 2017 Data Breach Notification Act) and carry Confirmed/Probable confidence. lawful_processing_and_special_data.special_categories and algorithmic_biometric_and_surveillance_governance.genetic_data rely on a single T2 DataGuidance statute citation for the Genetic Information Privacy Act and carry Probable confidence pending primary NMSA text review. data_subject_rights, cross_border_and_adequacy, and most of adtech_and_commercial_privacy are populated entirely with negative (absence) findings at Confirmed/high confidence, grounded in the IAPP US State Privacy Legislation Tracker's exclusion of New Mexico from its list of 19 states with comprehensive privacy statutes. sectoral_watch.education, sectoral_watch.insurance, controller_processor_duties.security_measures, and enforcement_and_redress.private_right_of_action rely on T3/T4-equivalent Uncertain findings with explicit absent_field_provenance because no primary statutory text could be retrieved within the allowlisted hostnames. enforcement_and_redress.enforcement_activity_index is grounded in T2/T3 NAAG/IAPP secondary reporting on NM AG litigation and the historical Google COPPA settlement.

Unresolved questions (6):

  • Does the New Mexico Data Breach Notification Act (NMSA 1978, Ch. 57 Art. 12C) contain an affirmative 'reasonable security procedures' duty independent of the breach-notification trigger, and what is its exact statutory citation?
  • Does the New Mexico Data Breach Notification Act afford consumers a private right of action, or is enforcement exclusively vested in the Attorney General?
  • Has New Mexico adopted the NAIC Insurance Data Security Model Law in whole or in part?
  • Does New Mexico have a dedicated K-12 student-data-privacy statute distinct from FERPA, and if so, its citation and effective date?
  • What is the current status (committee action, hearing dates, likelihood of passage) of pending SB 192 (Data Broker Privacy Act) in the 2026 New Mexico legislative session?
  • Is there a New Mexico-specific employment-data-privacy or dependent-adults data-protection statute not captured by general consumer-protection law?

Escalate to primary-source review: yes