Mexico Ended Anonymous Mobile Lines Without Building a Central Registry
Mexico’s Telecommunications Regulatory Commission issued mobile-line identification rules on 8 December 2025. From 9 January 2026, active mobile numbers must be linked by operators to an identified person or organisation, with a final registration deadline of 30 June 2026.
The measure follows the new Telecommunications and Broadcasting Law published on 16 July 2025. Its operational model is important because it is not a revival of the former central biometric mobile-user registry. Operators are responsible for identification and retain the associated records in their own systems.
That design changes where compliance and security risk sits. Instead of one government database, multiple providers must verify identity, maintain reliable records, support correction and protect information connected to millions of active numbers.
Every active line needs an accountable holder
Natural persons use official identification or a passport together with the CURP where applicable. Legal entities must identify the organisation and the person acting on its behalf. Operators must make registration channels available and verify the required information.
Lines that remain unlinked after the deadline are subject to suspension. They cannot make calls, send messages or use mobile data, apart from access needed for emergency communications and the registration process.
Business fleets need ownership records
Corporate accounts can include employee phones, tablets, routers, payment terminals, alarms and other connected devices. An invoice may show the commercial account without showing who is authorised to register, replace or cancel each line.
Organisations need an inventory connecting numbers, devices, users, business owners and account authority. Joiner, mover and leaver processes should update that inventory so an old employee or supplier does not remain associated with a critical line.
Identity verification creates fraud and privacy risk
Registration channels will become attractive targets for phishing, account takeover and false support messages. Users may receive convincing requests to upload identity documents or provide a CURP through an unofficial link.
Operators should make official channels unmistakable, minimise collected data and protect the linkage between identity and number. Strong authentication, change alerts, access logging, retention rules and controls against SIM-swap abuse are central to the same objective.
No central registry does not mean low sensitivity
Keeping records with operators reduces one form of central concentration, but each operator database remains sensitive. A verified link between a person and a mobile number can support impersonation, surveillance or account recovery attacks if misused.
Governance should cover employee access, service providers, customer correction, disclosure requests and deletion after a line is cancelled, subject to applicable legal retention duties.
What operators and organisations should do
- Publish and communicate the official registration route before fraud campaigns fill the gap.
- Protect enrolment, replacement and account-recovery processes against impersonation.
- Inventory business lines, devices, assigned users and authorised representatives.
- Plan for remote workers, foreign representatives and non-phone connected devices.
- Test suspension, correction and reactivation processes before the June deadline.
The difficult part is trusted association
Mexico’s new model aims to remove anonymous active lines without building a central government registry. Its success depends on whether operators can create and maintain accurate associations without turning identification into a new fraud and data-protection weakness.
Official sources
- Official Gazette: Telecommunications and Broadcasting Law
- Chamber of Deputies: official legislative record
- Telecommunications Regulatory Commission: mobile-line identification rules
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


