Country:墨西哥 · Data Privacy
Mexico · Data Privacy
Mexico regulates privacy under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP 2017) and the independent agency INAI, with a framework close to GDPR (covering consent, purpose limitation, data-subject rights, privacy notice). Processing personal data requires a privacy notice, consent and a data-processing agreement. Cross-border transfers require data-subject consent or the recipient having adequate protection. This overlaps with PIPL creating dual compliance. From 2025, AML and data-authenticity requirements are tightening.
Key points
- LFPDPPP 2017: consent, purpose limitation, subject access/rectification/deletion rights, privacy notice.
- Regulator: INAI (Federal Institute for Access to Information and Data Protection) receives complaints and imposes penalties.
- Cross-border transfer: requires consent or the recipient having adequate protection, plus standard contractual clauses.
- Obligations: privacy notice (Aviso de Privacidad), data-processing agreement (DPA), security measures.
- Penalties: warning, fine (up to a multiple of revenue or daily wage) up to criminal liability.
- China data-outbound obligations (pkulaw verification 2026-07): transferring or returning data to China requires one of three routes — security assessment (CAC Decree No. 11), standard contract (No. 13) or certification (CAC-SAMR Decree No. 20, 2025-10-14); 2024–2025 regulatory stance has eased — the 'Provisions on Promoting and Regulating Cross-Border Data Flows' (No. 16) and the 'Network Data Security Management Regulations' (State Council Decree No. 790) are in force, with some cases exempt from filing.
Procedure
- Data mapping and publish privacy notice
- Obtain consent and sign DPA
- Assess consent/adequacy/SCC before cross-border transfer
- Establish subject-rights response mechanism
- Periodic compliance audit
Hard requirements
- Privacy notice; consent; DPA; cross-border compliance
Costs
Compliance system build; possible certification⏱ ⏱ Timeline:System build weeks; ongoing compliance⚠ Common risks
- No privacy notice or consent violation draws INAI penalties
- Cross-border transfer without consent/SCC (stacks with PIPL)
- Unaddressed data breach amplifies liability
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese enterprises processing personal data of Mexican residents in Mexico, or transferring it back to China (governed by the Federal Law on Protection of Personal Data Held by Private Parties, LFPDPPP 2017, regulated by INAI).
Prerequisites
- Processing activities identified and privacy notice published
- Consent obtained and data-processing agreement (DPA) signed
- Compliance and audit budget reserved
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data mapping and publish privacy notice Map processing activities and publish a Spanish Privacy Notice (Aviso de Privacidad) covering purpose, rights and transfers. | Legal | 2 weeks | Internal and translation cost | Privacy notice | Must be complete and easily accessible Penalty:Warning, fine up to criminal liability |
| 2 | Obtain consent and sign DPA Obtain consent under LFPDPPP and sign a data-processing agreement (DPA) with the processor, implementing security measures. | Legal | 1–2 weeks | Internal cost | Consent record, DPA | Purpose limitation Penalty:Same as step 1 |
| 3 | Cross-border transfer consent/adequacy/SCC Transferring abroad (incl. China) requires data-subject consent, or the recipient having adequate protection and signing standard contractual clauses, linking to PIPL outbound requirements. | Legal | 3–6 weeks | Internal and legal fees | Cross-border consent, standard contractual clauses (SCC) and PIPL outbound documents | Must inform of the data transfer Penalty:Penalised by INAI for lacking a lawful transfer mechanism |
| 4 | Establish data-subject rights response mechanism Build a response process for access, rectification, deletion, opposition and other rights (ARCO rights). | Data Protection Officer (DPO) / customer service | Ongoing | Internal cost | Data Subject Access Request (DSAR) process | Must be recorded Penalty:Refusing requests faces penalties |
| 5 | Security measures and breach response Implement technical and administrative security measures and build a security-incident response mechanism. | IT / security | Ongoing | Internal cost | Security policy and contingency plan | 2025 AML and data-authenticity requirements tighten Penalty:Insufficient security measures face penalties |
| 6 | Periodic compliance audit Periodically internally audit processing activities and policy effectiveness. | Compliance | Annual | Internal / audit fees | Audit report | Cooperate with INAI inspections Penalty:Cumulative continued non-compliance |
✅ Self-check list
⚠ Common pitfalls
Processing without privacy notice影响:INAI penalty规避:Publish a complete privacy notice first
Cross-border without consent/SCC影响:Violation (stacks with PIPL penalties)规避:Obtain consent or sign SCC
Returning data to China ignoring PIPL outbound影响:Dual-violation risk规避:Handle the China-side compliance mechanism in parallel
ARCO request unaddressed影响:Penalised规避:Build a DSAR process
Insufficient security measures影响:Breach liability aggravated规避:Implement technical and administrative security measures
Ignoring 2025 data-authenticity requirements影响:Compliance gap规避:Update AML-related controls
📅 Ongoing post-incorporation obligations
- Maintenance and update of the privacy notice
- Ongoing response to data-subject access requests
- Periodic compliance audits
- China-bound PIPL outbound mechanism kept valid
- Maintenance of security measures and incident response
🔗 Official portals
📎 Source:Mexico Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP, 2017); INAI; USMCA data chapter; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.