Mexico Rewrote Its Federal Privacy Law and Moved the Regulator
Mexico’s 2025 federal privacy law preserves many familiar obligations for private organisations while changing the institution that interprets and enforces them.
Mexico published a new Federal Law on the Protection of Personal Data Held by Private Parties on 20 March 2025. It entered into force the following day and replaced the 2010 law of the same name.
For companies, the change is easy to misunderstand. This was not a reset that made existing privacy controls irrelevant. The core framework of lawful and informed processing, privacy notices, security, confidentiality and individual rights remains. The most visible change is institutional: functions formerly exercised by the autonomous INAI moved into the federal executive structure, principally the Secretariat for Anti-Corruption and Good Government.
Continuity still requires a legal map
Organisations should not assume that an old compliance file remains correct merely because the new law looks familiar. Article references, definitions, complaint routes, authority names and procedural rules may have changed.
Every privacy notice, consent text, processor agreement, internal policy and rights-response template should be mapped to the current statute. Documents that direct individuals to the former regulator or quote repealed provisions need correction.
The current official text should be treated as the source of truth because the law was amended again in November 2025 as part of broader procedural harmonisation.
ARCO rights remain operational commitments
People continue to have rights of Access, Rectification, Cancellation and Opposition, the ARCO rights. A response process must do more than accept an email. It needs identity checks, ownership, deadlines, searches across systems and reasoned decisions about deletion or restriction.
Cancellation is especially easy to overpromise. Some information must be retained for tax, employment, fraud, contractual or litigation purposes. A mature workflow blocks inappropriate use while preserving only what a legal obligation requires.
The process also needs to reach service providers. A controller cannot tell an individual that data was cancelled while copies remain active in marketing, support or analytics tools.
The privacy notice is a control interface
Mexico’s layered privacy-notice practice makes transparency part of the data-collection design. The notice should describe the responsible organisation, purposes, options for limiting use or disclosure, methods for exercising rights and the way changes will be communicated.
If a product adds biometric verification, behavioural analytics or a new advertising recipient, the question is not only whether the notice can be edited. The organisation must reassess necessity, consent, security and transfers before the new processing begins.
Security incidents need both containment and legal assessment
The law requires administrative, technical and physical safeguards appropriate to the risks. Material security breaches affecting individuals’ economic or moral rights must be communicated to them without delay.
That threshold is different from a general IT severity score. A small dataset containing identity documents or financial credentials can create serious individual harm even when the business remains online. Incident playbooks should explicitly assess fraud, identity theft, discrimination and reputational damage.
The regulator transition affects evidence and procedure
Moving enforcement authority does not remove the possibility of investigations or sanctions. It changes where complaints, verification activity and administrative proceedings are handled.
Legal and compliance teams should update regulatory contacts, monitor new guidance and preserve evidence in a form that can be produced quickly. Rights logs, notice versions, consent records, processor instructions, security assessments and breach decisions should be maintained as operational records.
A practical migration checklist
- Replace references to the repealed law and former authority in public and internal documents.
- Compare privacy notices and consent mechanisms with current processing activities.
- Retest ARCO workflows across every major system and processor.
- Review contracts for confidentiality, security, return and deletion duties.
- Update the incident playbook to assess harm to individuals.
- Track guidance and procedures issued by the current competent authority.
- Preserve versioned evidence showing what notice and consent applied at a given time.
Mexico’s reform illustrates a broader lesson: privacy compliance depends on institutions as well as statutory language. Even when substantive duties remain recognisable, the route through which people exercise rights and regulators demand evidence can change underneath the programme.
Official sources
- Mexico’s Official Gazette: Decree published 20 March 2025
- Chamber of Deputies: Current Federal Law on Personal Data Held by Private Parties
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


