Skip to content
Compliance review · Mexico

Does your company meet Mexico’s data protection law?

For Mexico only. This checklist covers Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP). It does not cover the GDPR, the CCPA or the data protection law of any other jurisdiction. Who the law applies to.

The article references and quotes are our unofficial translation. The official text of the law is the Spanish one.

The law changed in March 2025. Many privacy notices still cite the 2010 law and the INAI, which is no longer the authority. These are the 17 obligations you can check from the outside, each with the article it comes from.

It does not ask for your email, does not store anything outside your browser and does not say whether you comply. It shows what the law requires and what you answered, so you can check it. It does not replace legal advice.

0of 17 obligations covered17 left to answer.

The privacy notice

Article 15

Article 15 lists six minimum contents. The list is closed, so check each item against the notice you have published today.

  • Does your privacy notice state who the responsible party is and its address?

    Article 15, section IThe identity and address of the responsible party.

  • Does it list the personal data you process and say which of it is sensitive?

    Article 15, section IIThe personal data that will be processed, identifying which of it is sensitive.

  • Does it separate the purposes that need consent from those that do not?

    Article 15, section IIIThe purposes of the processing, identifying those that require the consent of the individual.

  • Does it offer a way to limit the use or disclosure of the data?

    Article 15, section IVThe options and means the responsible party offers individuals to limit the use or disclosure of the data.

  • Does it say how to exercise an ARCO right?

    Article 15, section VThe mechanisms, means and procedures to exercise ARCO rights.

  • Does it explain how you will announce changes to the notice itself?

    Article 15, section VIThe procedure and means by which the responsible party will inform individuals of changes to the privacy notice.

Which law it is written under

Article 2, section XV

The law changed in March 2025. Many privacy notices still cite the 2010 law and the INAI, which is no longer the authority. This is the fastest item to check, and the clearest sign that nobody has reviewed the document.

  • Is your notice written under the 2025 law and not the 2010 law?

    Second transitory article, section IThe law in force was published in Mexico’s Official Gazette (DOF) on March 20, 2025, and repealed the 2010 law.

  • Does it name the correct authority, and not the INAI?

    Article 2, section XVThe INAI no longer exists. The law defines “Secretaría” as the Secretaría Anticorrupción y Buen Gobierno (Ministry of Anti-Corruption and Good Governance).

Handling an ARCO request

Articles 31 and 34

ARCO stands for the rights of access, rectification, cancellation and opposition. The deadline runs from the day a request arrives, whether or not anyone has seen it. These are the pieces you need to answer on time and to prove it later.

  • Do you have a single inbox for ARCO requests, with someone watching it?

    Article 15, section V, and Article 31The notice must state how to exercise ARCO rights, and the Article 31 deadline runs from the day a request is received.

  • Do you log each request with the date received, the right being exercised and the date of the answer?

    Article 31The deadline counts from the date of receipt, so that date is what lets you meet it and prove that you did.

  • Does your team know the deadline is twenty business days, not calendar days?

    Article 31 and Article 2, section VIIITwenty days to communicate the decision and fifteen more to carry it out, and each period can be extended once. The law defines “Días” (days) as business days.

  • Is there a written procedure that says who finds the data, who decides and who answers?

    Article 31The law requires you to answer requests on time. A procedure is what makes that happen when the usual person is on vacation.

  • Do you handle requests without charging for the process?

    Article 34“Exercising ARCO rights is free of charge; fees may only be charged to recover the costs of reproduction, copies or shipping.”

  • Do you have a rule for canceling data without fully deleting it, when you must keep it?

    Article 24Under the law, canceling data leads to a blocking period before the data is deleted. That fits marking the record instead of erasing it.

Consent and sensitive data

Articles 7 and 8

As a general rule, tacit consent is valid. Sensitive data has its own, stricter rule: express consent in writing.

  • If you process sensitive data, do you get express consent in writing?

    Article 8“In the case of sensitive personal data, the responsible party must obtain the express written consent of the individual for its processing.”

If there is a data breach

Article 19

The law says people must be informed “immediately” and does not set a number of hours. What you can prepare in advance is who decides and who writes the notice.

  • Have you decided in advance who determines whether a breach significantly affects people?

    Article 19Breaches that “significantly affect the property or moral rights” of individuals must be reported to them “immediately”.

  • Do you know who would write the notice to the people affected?

    Article 19The notice has to reach people in time for them to defend their rights.

Scope

Who the law applies to

In short: it applies to private companies and private individuals that process personal data, throughout Mexico. There are two exceptions: credit information companies, in the cases their own law covers, and people who keep personal data only for personal use. It covers data held by private parties, not by public bodies.

Article 1
La presente Ley es de orden público y de observancia general en todo el territorio nacional y tiene por objeto la protección de los datos personales en posesión de los particulares, con la finalidad de regular su tratamiento legítimo, controlado e informado, a efecto de garantizar la privacidad y el derecho a la autodeterminación informativa de las personas.

Unofficial translation: This Law is a matter of public order and applies generally throughout the national territory. Its purpose is to protect personal data held by private parties, in order to regulate its legitimate, controlled and informed processing, so as to guarantee people’s privacy and their right to informational self-determination.

Article 1, exceptions
Quedan exceptuados de la aplicación de la presente Ley: I. Las sociedades de información crediticia en los supuestos de la Ley para Regular las Sociedades de Información Crediticia y demás disposiciones aplicables, y II. Las personas que lleven a cabo la recolección y almacenamiento de datos personales, que sea para uso exclusivamente personal, y sin fines de divulgación o utilización comercial.

Unofficial translation: The following are excluded from this Law: I. Credit information companies, in the cases covered by the Law to Regulate Credit Information Companies and other applicable provisions, and II. People who collect and store personal data exclusively for personal use, with no purpose of disclosure or commercial use.

Article 2, sections XIV and XVI
Responsable: Sujetos regulados a que se refiere la fracción XVI de este artículo; […] Sujetos regulados: Personas físicas o morales de carácter privado que llevan a cabo el tratamiento de datos personales;

Unofficial translation: Responsible party (responsable): the regulated parties referred to in section XVI of this article; […] Regulated parties: private individuals or legal entities that process personal data;

Where it comes from

The law, and the article behind each block

A compliance review is only useful if you can go to the text and check it. These are the articles, and the link goes to the official text published by Mexico’s Chamber of Deputies.

The privacy notice

Article 15

Article 15 lists six minimum contents. The list is closed, so check each item against the notice you have published today.

Which law it is written under

Article 2, section XV

The law changed in March 2025. Many privacy notices still cite the 2010 law and the INAI, which is no longer the authority. This is the fastest item to check, and the clearest sign that nobody has reviewed the document.

Handling an ARCO request

Articles 31 and 34

ARCO stands for the rights of access, rectification, cancellation and opposition. The deadline runs from the day a request arrives, whether or not anyone has seen it. These are the pieces you need to answer on time and to prove it later.

Consent and sensitive data

Articles 7 and 8

As a general rule, tacit consent is valid. Sensitive data has its own, stricter rule: express consent in writing.

If there is a data breach

Article 19

The law says people must be informed “immediately” and does not set a number of hours. What you can prepare in advance is who decides and who writes the notice.

Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares), published in Mexico’s Official Gazette (DOF) on March 20, 2025, last amended on November 14, 2025. Official text, in Spanish, consulted on September 8, 2026. The definitions are in Article 2, not Article 3.

Ready to grow?

Get in touch and give your brand the push it needs

Tell us about your challenge in a 30-minute call. You leave it with an assessment and concrete next steps, with no commitment.