Country:墨西哥 · Data Privacy
Medium confidenceUpdated 2026-08-03Handbook

Mexico · Data Privacy

Mexico regulates privacy under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP 2017) and the independent agency INAI, with a framework close to GDPR (covering consent, purpose limitation, data-subject rights, privacy notice). Processing personal data requires a privacy notice, consent and a data-processing agreement. Cross-border transfers require data-subject consent or the recipient having adequate protection. This overlaps with PIPL creating dual compliance. From 2025, AML and data-authenticity requirements are tightening.

Key points

Procedure

  1. Data mapping and publish privacy notice
  2. Obtain consent and sign DPA
  3. Assess consent/adequacy/SCC before cross-border transfer
  4. Establish subject-rights response mechanism
  5. Periodic compliance audit

Hard requirements

Costs

Compliance system build; possible certification⏱ ⏱ Timeline:System build weeks; ongoing compliance

⚠ Common risks

  • No privacy notice or consent violation draws INAI penalties
  • Cross-border transfer without consent/SCC (stacks with PIPL)
  • Unaddressed data breach amplifies liability
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese enterprises processing personal data of Mexican residents in Mexico, or transferring it back to China (governed by the Federal Law on Protection of Personal Data Held by Private Parties, LFPDPPP 2017, regulated by INAI).

Prerequisites

  • Processing activities identified and privacy notice published
  • Consent obtained and data-processing agreement (DPA) signed
  • Compliance and audit budget reserved
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Data mapping and publish privacy notice
Map processing activities and publish a Spanish Privacy Notice (Aviso de Privacidad) covering purpose, rights and transfers.
Legal2 weeksInternal and translation costPrivacy noticeMust be complete and easily accessible
Penalty:Warning, fine up to criminal liability
2Obtain consent and sign DPA
Obtain consent under LFPDPPP and sign a data-processing agreement (DPA) with the processor, implementing security measures.
Legal1–2 weeksInternal costConsent record, DPAPurpose limitation
Penalty:Same as step 1
3Cross-border transfer consent/adequacy/SCC
Transferring abroad (incl. China) requires data-subject consent, or the recipient having adequate protection and signing standard contractual clauses, linking to PIPL outbound requirements.
Legal3–6 weeksInternal and legal feesCross-border consent, standard contractual clauses (SCC) and PIPL outbound documentsMust inform of the data transfer
Penalty:Penalised by INAI for lacking a lawful transfer mechanism
4Establish data-subject rights response mechanism
Build a response process for access, rectification, deletion, opposition and other rights (ARCO rights).
Data Protection Officer (DPO) / customer serviceOngoingInternal costData Subject Access Request (DSAR) processMust be recorded
Penalty:Refusing requests faces penalties
5Security measures and breach response
Implement technical and administrative security measures and build a security-incident response mechanism.
IT / securityOngoingInternal costSecurity policy and contingency plan2025 AML and data-authenticity requirements tighten
Penalty:Insufficient security measures face penalties
6Periodic compliance audit
Periodically internally audit processing activities and policy effectiveness.
ComplianceAnnualInternal / audit feesAudit reportCooperate with INAI inspections
Penalty:Cumulative continued non-compliance

✅ Self-check list

⚠ Common pitfalls

Processing without privacy notice影响:INAI penalty规避:Publish a complete privacy notice first
Cross-border without consent/SCC影响:Violation (stacks with PIPL penalties)规避:Obtain consent or sign SCC
Returning data to China ignoring PIPL outbound影响:Dual-violation risk规避:Handle the China-side compliance mechanism in parallel
ARCO request unaddressed影响:Penalised规避:Build a DSAR process
Insufficient security measures影响:Breach liability aggravated规避:Implement technical and administrative security measures
Ignoring 2025 data-authenticity requirements影响:Compliance gap规避:Update AML-related controls

📅 Ongoing post-incorporation obligations

  • Maintenance and update of the privacy notice
  • Ongoing response to data-subject access requests
  • Periodic compliance audits
  • China-bound PIPL outbound mechanism kept valid
  • Maintenance of security measures and incident response

🔗 Official portals

📎 Source:Mexico Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP, 2017); INAI; USMCA data chapter; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.