For a foreign company with Mexican operations, a subsidiary, or a customer base in Mexico, the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), published in the Diario Oficial de la Federación on 5 July 2010, is not optional compliance. Fines can reach MXN $320 million (approximately USD $16 million), and trafficking in sensitive data carries criminal sanctions.
The legal framework: LFPDPPP and its Reglamento
The LFPDPPP establishes the core rights of data subjects and the obligations of data controllers and data processors. It is supplemented by the Reglamento de la LFPDPPP, published on 21 December 2011, which provides detailed implementation rules for privacy notices, ARCO rights procedures, and security measures.
INAI is the enforcement authority. It receives complaints from data subjects, conducts investigations, issues binding orders, and imposes fines. INAI also issues recommendations (lineamientos) that, while technically non-binding, describe the compliance standard the agency will apply in enforcement proceedings. The Lineamientos emitidos by INAI on data breach notification are particularly important because they set the 72-hour notification standard that the LFPDPPP itself does not specify in those terms.
Who must comply?
Any private individual or legal entity that processes personal data in Mexico must comply. The law applies regardless of where the entity is incorporated. A US company that collects personal data from Mexican residents through a website, a mobile application, or in-person operations in Mexico is a “data controller” under the LFPDPPP. A Canadian real estate developer selling condominiums in Mexico to Mexican and foreign buyers processes personal data of Mexican residents and must comply fully.
Government entities are governed by a separate statute, the Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados, so the LFPDPPP covers the private sector exclusively.
What counts as personal data?
Article 3 of the LFPDPPP defines personal data as any information relating to an identified or identifiable natural person. This is a broad definition. It includes names, addresses, telephone numbers, email addresses, RFC numbers, biometric data, IP addresses when linked to an individual, and photographs.
Sensitive personal data
The LFPDPPP draws a sharper line around a subset of data it calls “sensitive personal data.” These are categories whose misuse could cause the data subject serious harm or discrimination:
- Health and medical information
- Biometric data
- Racial or ethnic origin
- Political opinion
- Sexual preference or conduct
- Religious or philosophical belief
- Union membership
Processing sensitive data requires express, written consent. Silence, a pre-checked checkbox, or a catch-all consent buried in terms and conditions does not satisfy the standard for sensitive data. The practical implication for businesses is that any app or service collecting health data, facial recognition data, or similar categories must implement a distinct, affirmative consent mechanism.
Privacy notice requirements
Every data controller must issue a privacy notice to data subjects at or before the moment of data collection. Articles 15 and 16 of the LFPDPPP, and Articles 24 and 25 of the Reglamento, specify the mandatory contents:
- Identity and address of the data controller, not just a brand name
- The categories of personal data being collected
- Whether sensitive data is included and the specific categories
- The purposes of processing, divided into primary purposes (those necessary to fulfill the legal relationship with the data subject) and secondary purposes (marketing, analytics, or any purpose the data subject can opt out of)
- Whether data will be transferred to third parties and the identity or categories of those recipients and the purposes of the transfer
- The means by which data subjects can exercise their ARCO rights (access, rectification, cancellation, and opposition)
- Whether an data processor (a data processor acting under the data controller’s instructions) will handle the data
- The data subject’s right to revoke consent
- Whether automated decisions will be made using the data
A simplified or short-form notice is permitted in certain contexts, such as when data is collected verbally or where space constraints make a full notice impractical. A simplified notice must at minimum identify the data controller, state the purposes of processing, and direct the data subject to where the full notice can be found.
ARCO rights: what they are and how to handle them
ARCO stands for Acceso (access), Rectificación (rectification), Cancelación (cancellation), and Oposición (opposition). These are statutory rights that any data subject can exercise against a data controller that holds their personal data.
Response timelines
Upon receiving a written ARCO request, the data controller must confirm receipt within 5 business days. The substantive response, granting or denying the request in whole or in part, must follow within 20 business days. That period can be extended once for an additional 20 business days when the volume or complexity of the request justifies it.
For cancellation requests, data must be blocked (blocked from active use but retained for legal purposes) and then deleted within 20 business days of the data controller confirming that the request is legitimate. Access requests must result in actual delivery of the data in a legible, understandable format, not merely a confirmation that data is held.
Grounds for denial
Articles 34 and 35 of the LFPDPPP permit a data controller to deny an ARCO request on limited grounds: a legal obligation requires retention of the data, active legal proceedings depend on the data, the deletion or modification would harm a third party’s legitimate rights, or national security or public order is involved. Any denial must be reasoned and communicated in writing within the same 20-business-day window.
Security measures
The LFPDPPP requires data controllers to implement administrative, physical, and technical security measures proportionate to the sensitivity of the data processed and the risks present in the processing environment. The Reglamento does not prescribe specific controls, leaving the adequacy determination to the data controller, but INAI’s enforcement guidance references international standards such as ISO 27001 as benchmarks.
Data breach notification
INAI’s lineamientos on security breaches establish a 72-hour notification window from discovery of a breach to notification of INAI and the affected data subjects. The notification must describe the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed to mitigate harm. This 72-hour standard mirrors the GDPR approach and is significantly more demanding than merely “prompt” notification.
International data transfers
Mexico does not require data to be stored within Mexican territory. There is no data localization requirement under the LFPDPPP. However, transferring personal data to a recipient outside Mexico, or to a domestic third party in a different corporate group, requires either:
- Express consent of the data subject
- A transfer to a country recognized as providing adequate protection for personal data
- A contractual arrangement (such as binding corporate rules or a data transfer agreement) that ensures equivalent protection in the recipient jurisdiction
Articles 36 and 37 of the LFPDPPP govern these requirements. For multinational groups transferring data from a Mexican subsidiary to a US or Canadian parent, a formal data transfer agreement is generally the most practical mechanism.
Penalties for non-compliance
Articles 63 to 66 of the LFPDPPP establish an administrative fine structure ranging from MXN $100 to MXN $320 million depending on the severity and nature of the violation. The upper end of that range (approximately USD $16 million) applies to the most serious violations, including processing sensitive data without valid consent or unlawfully transferring personal data.
Criminal sanctions under Article 67 of the LFPDPPP can reach five years in prison for trafficking in sensitive personal data for profit. This applies to individuals who obtain, disclose, or transfer sensitive data without authorization and with intent to profit from it.
INAI investigations typically begin with a data subject complaint. The agency has authority to compel document production, conduct on-site inspections, and issue interim measures while an investigation is pending.
Practical compliance steps for foreign-owned businesses
Four areas consistently generate INAI enforcement findings against businesses, particularly foreign-owned entities:
First, employee data. Many companies implement privacy programs focused on customer data but neglect to issue proper privacy notices to employees. The LFPDPPP applies to employment relationships; a separate privacy notice covering recruitment, payroll, benefits administration, and performance data must be issued to all employees and job applicants.
Second, secondary purposes. Marketing, analytics, and profiling are secondary purposes under Mexican law. They must be disclosed separately in the privacy notice, and data subjects must have a meaningful way to opt out. Bundling secondary purposes into the primary purposes disclosure without offering opt-out is a violation.
Third, international transfer disclosures. Companies that transfer employee or customer data to US or Canadian parent entities often fail to disclose this transfer in the privacy notice and fail to execute the required data transfer agreement. Both failures can be cited independently in an INAI investigation.
Fourth, ARCO request handling. Designating a generic inbox for ARCO requests and then failing to monitor it or respond within the statutory period is a common gap. INAI treats an absence of response as a deemed denial, which data subjects can immediately escalate to a complaint proceeding.
Frequently asked questions
Yes, if your website actively collects personal data from Mexican residents, processes their data, or directs goods or services at the Mexican market, INAI takes the position that the LFPDPPP applies. Physical presence is not the test. The determinative factor is whether you process personal data of individuals located in Mexico.
Partially. GDPR and the LFPDPPP share concepts, but the required contents differ in specific ways. A GDPR notice typically does not address the ARCO request procedure in the format Mexico requires, may not use the primary versus secondary purposes distinction, and may not address the right to revoke consent in the manner Article 8 of the LFPDPPP contemplates. A Mexico-specific privacy notice drafted against Articles 15 and 16 of the LFPDPPP and Articles 24 and 25 of the Reglamento is the safer approach.
INAI proceedings initiated on a data subject’s complaint (review complaint) must be filed by the data subject within 15 business days of the denial or non-response. INAI’s own investigative powers (verification procedure) are not subject to the same limitation and can be initiated based on public reporting, third-party complaints, or proactive enforcement priorities.
Yes. Biometric data is expressly listed as a category of sensitive personal data under the LFPDPPP. Collecting fingerprints or facial recognition data from employees for time tracking requires express, written consent and disclosure in the privacy notice as sensitive data. Using that data for any purpose beyond time tracking would require separate consent for each additional purpose.
The Reglamento de la LFPDPPP does not prescribe a mandatory template, but the agreement must ensure that the recipient (the US parent) will provide the transferred data with at least the same level of protection as required under Mexican law. In practice, this means the agreement should address the purposes for which the data can be used, security obligations, sub-transfer restrictions, breach notification obligations, and the data subject’s right to exercise ARCO rights against the data controller in Mexico.