# Mexico data protection law (LFPDPPP): compliance checklist

> A checklist of the obligations under Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) that can be checked from the outside, each with the article it comes from.

**Mexico only.** This checklist covers Mexico’s federal law on personal data held by private parties. It does not cover the GDPR, the CCPA or the law of any other jurisdiction.

**Unofficial translation.** The article references and quotes below are our own translation. The official text is the Spanish one, linked below.

The interactive tool is at https://c2suite.com/en/mexico-data-protection-law. You answer yes, no or “I don’t know” for each obligation, and it returns how many are covered, what is missing and what to find out. It does not ask for your email, does not record anything, and everything happens in your browser.

**It does not return a score, on purpose.** Legal obligations cannot be averaged. If there is no inbox for ARCO requests, a perfect privacy notice does not make up for half of that gap. A number out of 100 would suggest that one item offsets another. So the tool counts instead.

**And it does not say whether anyone complies.** It shows what the law requires and what the user answered, with the article next to each item. Whether a company complies depends on facts this list does not ask about, and it is decided by an authority, not a form. This does not replace legal advice.

## Who the law applies to

In short: it applies to private companies and private individuals that process personal data, throughout Mexico. There are two exceptions: credit information companies, in the cases their own law covers, and people who keep personal data only for personal use. It covers data held by private parties, not by public bodies.

### Article 1

> La presente Ley es de orden público y de observancia general en todo el territorio nacional y tiene por objeto la protección de los datos personales en posesión de los particulares, con la finalidad de regular su tratamiento legítimo, controlado e informado, a efecto de garantizar la privacidad y el derecho a la autodeterminación informativa de las personas.

Unofficial translation: This Law is a matter of public order and applies generally throughout the national territory. Its purpose is to protect personal data held by private parties, in order to regulate its legitimate, controlled and informed processing, so as to guarantee people’s privacy and their right to informational self-determination.

### Article 1, exceptions

> Quedan exceptuados de la aplicación de la presente Ley: I. Las sociedades de información crediticia en los supuestos de la Ley para Regular las Sociedades de Información Crediticia y demás disposiciones aplicables, y II. Las personas que lleven a cabo la recolección y almacenamiento de datos personales, que sea para uso exclusivamente personal, y sin fines de divulgación o utilización comercial.

Unofficial translation: The following are excluded from this Law: I. Credit information companies, in the cases covered by the Law to Regulate Credit Information Companies and other applicable provisions, and II. People who collect and store personal data exclusively for personal use, with no purpose of disclosure or commercial use.

### Article 2, sections XIV and XVI

> Responsable: Sujetos regulados a que se refiere la fracción XVI de este artículo; […] Sujetos regulados: Personas físicas o morales de carácter privado que llevan a cabo el tratamiento de datos personales;

Unofficial translation: Responsible party (responsable): the regulated parties referred to in section XVI of this article; […] Regulated parties: private individuals or legal entities that process personal data;

## The law

Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares), published in Mexico’s Official Gazette (Diario Oficial de la Federación, DOF) on March 20, 2025 and in force from the next day, last amended on November 14, 2025. It replaced the 2010 law, and the INAI is no longer the authority.

Text consulted on September 8, 2026 at https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf.

The definitions are in **Article 2**, not Article 3: ARCO rights (access, rectification, cancellation and opposition) in section VII, “Días: Días hábiles” (days means business days) in section VIII, and “Secretaría: Secretaría Anticorrupción y Buen Gobierno” in section XV. Article 3 covers the limits on the principles for national security, public order and the rights of third parties.

## The obligations it checks (17)

The list is the same for everyone. It is not narrowed by company size or industry, so no block can end up with no questions.

### The privacy notice (Article 15)

Article 15 lists six minimum contents. The list is closed, so check each item against the notice you have published today.

- **Does your privacy notice state who the responsible party is and its address?** — Article 15, section I: The identity and address of the responsible party.
- **Does it list the personal data you process and say which of it is sensitive?** — Article 15, section II: The personal data that will be processed, identifying which of it is sensitive.
- **Does it separate the purposes that need consent from those that do not?** — Article 15, section III: The purposes of the processing, identifying those that require the consent of the individual.
- **Does it offer a way to limit the use or disclosure of the data?** — Article 15, section IV: The options and means the responsible party offers individuals to limit the use or disclosure of the data.
- **Does it say how to exercise an ARCO right?** — Article 15, section V: The mechanisms, means and procedures to exercise ARCO rights.
- **Does it explain how you will announce changes to the notice itself?** — Article 15, section VI: The procedure and means by which the responsible party will inform individuals of changes to the privacy notice.

### Which law it is written under (Article 2, section XV)

The law changed in March 2025. Many privacy notices still cite the 2010 law and the INAI, which is no longer the authority. This is the fastest item to check, and the clearest sign that nobody has reviewed the document.

- **Is your notice written under the 2025 law and not the 2010 law?** — Second transitory article, section I: The law in force was published in Mexico’s Official Gazette (DOF) on March 20, 2025, and repealed the 2010 law.
- **Does it name the correct authority, and not the INAI?** — Article 2, section XV: The INAI no longer exists. The law defines “Secretaría” as the Secretaría Anticorrupción y Buen Gobierno (Ministry of Anti-Corruption and Good Governance).

### Handling an ARCO request (Articles 31 and 34)

ARCO stands for the rights of access, rectification, cancellation and opposition. The deadline runs from the day a request arrives, whether or not anyone has seen it. These are the pieces you need to answer on time and to prove it later.

- **Do you have a single inbox for ARCO requests, with someone watching it?** — Article 15, section V, and Article 31: The notice must state how to exercise ARCO rights, and the Article 31 deadline runs from the day a request is received.
- **Do you log each request with the date received, the right being exercised and the date of the answer?** — Article 31: The deadline counts from the date of receipt, so that date is what lets you meet it and prove that you did.
- **Does your team know the deadline is twenty business days, not calendar days?** — Article 31 and Article 2, section VIII: Twenty days to communicate the decision and fifteen more to carry it out, and each period can be extended once. The law defines “Días” (days) as business days.
- **Is there a written procedure that says who finds the data, who decides and who answers?** — Article 31: The law requires you to answer requests on time. A procedure is what makes that happen when the usual person is on vacation.
- **Do you handle requests without charging for the process?** — Article 34: “Exercising ARCO rights is free of charge; fees may only be charged to recover the costs of reproduction, copies or shipping.”
- **Do you have a rule for canceling data without fully deleting it, when you must keep it?** — Article 24: Under the law, canceling data leads to a blocking period before the data is deleted. That fits marking the record instead of erasing it.

### Consent and sensitive data (Articles 7 and 8)

As a general rule, tacit consent is valid. Sensitive data has its own, stricter rule: express consent in writing.

- **If you process sensitive data, do you get express consent in writing?** — Article 8: “In the case of sensitive personal data, the responsible party must obtain the express written consent of the individual for its processing.”

### If there is a data breach (Article 19)

The law says people must be informed “immediately” and does not set a number of hours. What you can prepare in advance is who decides and who writes the notice.

- **Have you decided in advance who determines whether a breach significantly affects people?** — Article 19: Breaches that “significantly affect the property or moral rights” of individuals must be reported to them “immediately”.
- **Do you know who would write the notice to the people affected?** — Article 19: The notice has to reach people in time for them to defend their rights.

## The three possible answers

- **Yes**: the obligation is covered.

- **No**: it is missing, and you know what to do. It goes on the list of missing items, with a concrete action.

- **I don’t know**: it is not yet clear whether anything is missing. It goes on a separate list, with where to look to find out. The two lists are kept apart because merging them would create tasks for things that may already be done.

---

Source: https://c2suite.com/en/mexico-data-protection-law

You can cite and summarize this content if you credit C2Suite and link to the source URL.
