Data protection - Mexico - Federal

Personal data in Mexico: a 2026 compliance map for companies

In 2026, companies that process personal data in Mexico must work under the Federal Law on the Protection of Personal Data Held by Private Parties published in 2025 and its current reform. Compliance is not exhausted by publishing a notice: it requires knowing the information flows, limiting purposes, handling rights and maintaining demonstrable security measures. This guide offers a practical map to organize that work. It is informational material and does not constitute legal advice.

Updated Tirzo & Bautista Abogados

In 2026, companies that process personal data in Mexico must work under the Federal Law on the Protection of Personal Data Held by Private Parties published in 2025 and its current reform. Compliance is not exhausted by publishing a notice: it requires knowing the information flows, limiting purposes, handling rights and maintaining demonstrable security measures. This guide offers a practical map to organize that work. It is informational material and does not constitute legal advice.

The regulatory starting point

The federal law applies, generally, to private individuals or entities that decide on the processing of personal data. Their operation must respect the principles of lawfulness, purpose, fairness, consent, quality, proportionality, information and accountability. Sensitive data require reinforced precautions and, except for legal exceptions, express written consent. The Ministry of Anti-Corruption and Good Governance is the authority provided for by the current law. The public dialogues begun in 2026 to update secondary provisions do not replace the applicable text: any change must be confirmed in the Official Gazette of the Federation before modifying policies, forms or internal controls.

From the inventory to the exercise of rights

A useful program begins with an inventory that identifies what data comes in, what it is used for, where it is stored, who has access and with whom it is shared. Each purpose must be linked to a valid basis and reflected in the privacy notice, including the identity and address of the controller, the data processed, the purposes, the means to limit use, the ARCO mechanisms and the procedure to communicate changes. It is also advisable to review contracts with processors and transfers. The company must designate a person or department to handle requests. As a general rule, the ARCO response is communicated within a maximum of twenty business days and, if applicable, made effective within the following fifteen, with the justified extensions the law allows.

Security, incidents and evidence

The administrative, technical and physical measures must correspond to the risk, the sensitivity of the information, technological development and the possible consequences. A generic policy is not enough: role-based access, vendor management, backups, training, limited retention and an incident protocol are needed. When a breach significantly affects people's property or moral rights, the law requires informing them immediately. The incident file must keep the chronology, scope, decisions, communications and corrections, without unnecessarily expanding the data stored. Periodic audits, response drills and request metrics make it possible to evidence accountability and detect deviations before a verification.

Key points

  • The privacy notice is one piece of the system, not the complete compliance system.
  • Purposes, data and retention periods must be necessary and proportionate.
  • Sensitive data and transfers require a specific legal review.
  • The company must be able to demonstrate its decisions, controls and handling of rights.

What to review

  1. Draw up an inventory of processing activities, providers, transfers and retention periods.
  2. Compare notices, consents and ARCO procedures against the current law.
  3. Test the breach protocol and document owners, criteria and communication channels.