Corporate compliance and legal risk for global entities

Global companies operating in Mexico carry a dual compliance burden. Mexican domestic law imposes its own regulatory requirements. Home-country legislation—US, Canadian, or European—often reaches conduct that occurs in Mexico. Managing both layers simultaneously, without gaps or redundant cost, requires a structured compliance program designed for the Mexican operating environment.

The multi-layer compliance reality

A US-listed company with a Mexican subsidiary faces at least four regulatory frameworks simultaneously: Mexican corporate and commercial law; the US Foreign Corrupt Practices Act (FCPA); Sarbanes-Oxley (SOX) internal control and financial reporting obligations; and Mexican anti-corruption law (Ley General del Sistema Nacional Anticorrupción and Ley General de Responsabilidades Administrativas).

A Canadian company faces the Corruption of Foreign Public Officials Act (CFPOA) alongside Mexican requirements. A UK entity faces the UK Bribery Act, which is broader than the FCPA in that it covers commercial bribery, not just public official bribery.

The practical consequence is that your Mexican compliance program cannot be designed in isolation. It must satisfy both the home regulator looking over your shoulder and the Mexican authorities with direct jurisdiction.

Anti-competition compliance: COFECE

The Comisión Federal de Competencia Económica (COFECE) enforces Mexican competition law. Price-fixing, market allocation, bid-rigging, and other horizontal cartel conduct are absolute prohibitions with criminal exposure. Vertical arrangements (distribution agreements, exclusivity, and resale price maintenance) require case-by-case analysis.

Mexico adopted a leniency program modeled on US and EU precedents. Companies that self-report cartel conduct and cooperate can obtain reduced or eliminated fines. For companies in distribution-intensive industries—manufacturing, consumer goods, pharmaceuticals, and construction—a competition compliance policy and training program are baseline requirements.

Merger control also falls under COFECE. Transactions that meet the thresholds (based on asset and revenue values in Mexico) require pre-closing notification. Missing the filing obligation triggers fines regardless of whether the transaction raises competitive concerns.

LFPIORPI: anti-money laundering for vulnerable activities

The Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita (LFPIORPI) designates certain activities as “vulnerable” and imposes mandatory KYC, transaction reporting, and record-keeping obligations on those who perform them. See our dedicated article on AML compliance for the full list of vulnerable activities and obligations.

For global companies, the key intersection with corporate work arises when the company or its professional advisors perform activities covered by LFPIORPI—particularly real estate transactions, accounting and auditing for specific transaction types, and legal advisory on corporate restructuring and M&A. Ensure that your advisors in Mexico are meeting their LFPIORPI obligations and that your transaction documentation is consistent with what will be reported to the UIF.

Data privacy: LFPDPPP and INAI

The Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) is Mexico’s primary data privacy law for private-sector entities. It is enforced by the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI).

Core obligations for any company that handles personal data of Mexican residents:

  • Privacy notice: Every company that collects personal data must have a written privacy notice available to data subjects at the time of collection. The notice must identify the data controller, the purposes of processing, the data transfers contemplated, and the mechanisms for exercising ARCO rights. A missing or deficient privacy notice is the most common LFPDPPP violation.
  • ARCO Rights: Data subjects have rights of Access, Rectification, Cancellation, and Opposition (ARCO). Companies must have a documented procedure for receiving and responding to ARCO requests within 20 business days.
  • Data Security: Companies must implement technical and administrative safeguards proportional to the sensitivity of the data processed. Health data and financial data carry heightened requirements.
  • Cross-border transfers: Transferring personal data outside Mexico to a recipient in a country without equivalent protection requires a data transfer agreement or other legal mechanism.

INAI enforcement has accelerated. Fines range from approximately MXN 100 to MXN 320 million depending on violation type and company size. More significant for multinationals is reputational risk from public INAI resolutions.

Labor compliance: LFT and the 2021 subcontracting reform

Labor misclassification is one of the highest-risk compliance areas for foreign companies in Mexico. The Ley Federal del Trabajo (LFT) establishes a presumption of employment: if a person performs personal, subordinate, paid work for your benefit on a regular basis, Mexican courts will likely classify that person as an employee regardless of how the relationship is documented.

The 2021 subcontracting reform (amendments to the LFT, IMSS Law, INFONAVIT Law, and tax code) eliminated the prior model of outsourcing all employees through a service company. Under the current rules:

  • Companies may only use specialized outsourced services for activities that are not part of the corporate purpose or predominant economic activity.
  • Specialized service providers must register in the REPSE (Registro de Prestadoras de Servicios Especializados u Obras Especializadas) maintained by the STPS.
  • Contracting companies retain joint liability for labor and social security obligations of unregistered specialized service providers.
  • Profit sharing (PTU) is now calculated based on a fixed cap (three months’ salary or the average of the past three years’ PTU, whichever is higher for the employee) rather than on net taxable income—eliminating the prior practice of zeroing out PTU through service company structures.

Building a compliance calendar

An effective compliance program for a Mexican subsidiary includes a documented calendar of recurring obligations:

  • Monthly: SAT tax returns (IVA, ISR provisional), IMSS contributions, INFONAVIT contributions
  • Quarterly: CNIE reporting if applicable, COFECE reporting for regulated sectors
  • Annual: annual ISR return (April), annual RNIE update (March for prior year), STPS workplace safety inspection coordination, annual shareholders’ assembly, comisario report, financial statements approval
  • Event-driven: RNIE update within 40 days of capital or ownership changes; LFPDPPP incident reporting within 72 hours of a data breach; COFECE merger notification before closing

Internal audit coordination with the home country requires translating Mexican compliance metrics into frameworks the parent’s audit committee recognizes—mapping Mexican regulatory requirements to SOX control frameworks or ISO standards.

Frequently asked questions

Yes, if the parent company is a US issuer or domestic concern, FCPA jurisdiction extends to conduct by subsidiaries, employees, agents, and third parties acting on the company’s behalf anywhere in the world. Payments to Mexican government officials (including employees of state-owned enterprises) made to obtain or retain business are covered. The parent can face liability even for subsidiary conduct the parent did not know about if it failed to implement adequate controls.

REPSE (Registro de Prestadoras de Servicios Especializados u Obras Especializadas) is a registry administered by the STPS for companies that provide specialized services or specialized construction work to third parties. Any company that contracts with third parties to provide services that are not part of the client company’s core corporate purpose must verify that the provider is REPSE-registered. Unregistered providers expose both the provider and the client to labor and tax liability.

Under the LFPDPPP and INAI guidelines, a security incident that materially affects the patrimonial or moral rights of data subjects must be reported to the affected individuals. There is no statutory deadline specified in the current LFPDPPP text for notification to INAI, but best practice (and draft reform legislation) points to a 72-hour notification window similar to GDPR. Notify affected individuals promptly and document the response.

A global privacy notice may satisfy some LFPDPPP requirements if it covers all mandatory content, is available in Spanish, and specifically addresses ARCO rights procedures under Mexican law. In practice, most multinationals use a Mexico-specific addendum that supplements the global notice. The global notice alone is usually insufficient because it omits the Mexican-specific ARCO procedure and INAI contact information.

Administrative fines for absolute monopolistic practices (cartels) can reach up to 10% of the company’s annual income in Mexico. Individual participants (not just the company) can face fines of up to MXN 200 million. Criminal prosecution for individuals who participated in cartel conduct is also available under the Ley Federal de Competencia Económica, though criminal cases remain rare. The leniency program offers the most significant penalty reduction for companies that self-report and cooperate.

Explore the governance models