Frequently asked questions
The LFPDPPP (Ley Federal de Protección de Datos Personales en Posesión de los Particulares) is Mexico’s data protection law. It regulates how private-sector entities collect, use, process, store, and transfer personal data. Its purpose is to protect individuals’ privacy and their right to informational self-determination.
The law applies to all private organizations and individuals that process personal data within Mexico, regardless of size or industry. This includes subsidiaries, service providers, and third parties acting on behalf of other entities.
The LFPDPPP covers:
• Personal Data – Any information relating to an identified or identifiable individual (e.g., name, email, identification numbers, financial details).
• Sensitive Personal Data – Data that, if misused, could significantly affect an individual’s rights and freedoms (e.g., health status, genetic or biometric data, religious beliefs, political opinions, sexual orientation).
Organizations acting as data controllers must:
• Provide clear and accessible privacy notices to data subjects.
• Obtain valid consent where applicable.
• Enable individuals to exercise their ARCO rights (Access, Rectification, Cancellation, and Opposition).
• Implement adequate technical, administrative, and physical security measures to safeguard personal data.
• Ensure third parties processing data on their behalf comply with similar standards.
• Report significant data breaches to the authority and affected individuals.
RCO rights grant individuals control over their personal data:
• Access – To know what personal data is being processed and how.
• Rectification – To correct inaccurate or incomplete data.
• Cancellation – To request deletion of data when it is no longer necessary or processed unlawfully.
• Opposition – To object to the processing of their data for legitimate reasons.
Organizations must establish procedures to handle ARCO requests within the timeframes required by law.
Yes. International transfers of personal data are permitted if the recipient ensures an equivalent level of protection. This is typically documented through contractual clauses or data transfer agreements with appropriate safeguards.
As of March 2025, the former autonomous supervisory authority, the National Institute for Transparency, Access to Information and Protection of Personal Data (INAI), has been dissolved. Its responsibilities have been transferred to the Ministry of Anti-Corruption and Good Governance (Spanish: Secretaría de Anticorrupción y Buen Gobierno).
This Ministry now oversees compliance, investigates breaches, conducts audits, issues binding decisions, and imposes administrative sanctions. Organizations must update all references to INAI in privacy notices, policies, and contracts.
Non-compliance may result in:
• Fines of up to approximately MXN 53 million (around USD 3 million, depending on exchange rates).
• Criminal liability for unlawful processing of sensitive personal data.
• Reputational damage and potential business disruptions.
Although both frameworks share core principles like accountability, transparency, and data subject rights, there are key differences:
• The LFPDPPP does not require appointing a Data Protection Officer (DPO), though it is recommended.
• It is less prescriptive regarding technical and organizational security measures.
• There is no adequacy list for international transfers.
Organizations familiar with the GDPR will find overlapping requirements but must still address Mexico-specific obligations.
To comply with the LFPDPPP, organizations should:
• Review and update privacy notices, especially references to the supervisory authority.
• Assess current consent practices and ARCO request procedures.
• Review contracts with third parties processing personal data.
• Ensure security measures meet legal standards.
• Monitor regulatory updates and guidance from the Ministry of Anti-Corruption and Good Governance.