Mexico · LFPDPPP
Mexico's new data protection law, explained for small businesses
Mexico replaced its federal data protection law on 21 March 2025. The new LFPDPPP dissolved the old regulator, INAI, and moved enforcement to the Secretariat of Anti-Corruption and Good Governance, which has already shown it will open proceedings publicly and quickly after cyber incidents. Data processors and vendors are directly liable for the first time, express consent is required for sensitive and financial data, and penalties scale to roughly USD 3.9 million. A further revision is expected to add a formal DPO duty and mandatory breach notification. MapleNorthIT runs remote readiness audits for businesses with 5 to 100 employees, sharing almost the same business hours from Vancouver.
Last updated: July 2026 · MapleNorthIT
New federal law (LFPDPPP): In force since 21 March 2025
This is not an amendment; it is a new statute. INAI no longer exists, penalties are set in UMA units reaching about USD 3.9 million, and in early 2026 the new authority opened proceedings publicly right after cyber incidents, a sharp break from the old regulator's slower style. A 2026 revision is expected to add DPO and breach-notification duties, so the bar is still rising.
What Mexico businesses need to know
- Penalties under the 2025 LFPDPPP run from 100 to 320,000 UMA, roughly USD 1,200 to USD 3.9 million.
- Data processors are expressly in scope for the first time: vendors and agencies are directly liable for the data they handle.
- Express consent is required to process sensitive and financial data, the categories clinics, hotels, and realtors hold most.
- Specialized federal data protection courts were created, and the new authority has moved publicly and quickly after early 2026 cyber incidents.
Two ways to get compliant
Compliance Readiness Audit
A one-hour remote call plus a review of your setup. Written report within 48 hours, with every gap ranked Critical, Important, or Recommended and a rough cost to fix each one.
Book an auditFixed-scope security projects
One problem, one price, one deliverable: email authentication, account hardening, backup testing, offboarding cleanup, and more, from $399 CAD, fully remote.
View the projectsPay in CAD by card via Stripe. A $400 CAD audit is roughly MXN 5,500.
Common questions
What changed in Mexico's data protection law in 2025?
Everything structural. The 2010 law was repealed and replaced on 21 March 2025. The independent regulator INAI was dissolved and enforcement moved to the Secretariat of Anti-Corruption and Good Governance. Definitions of consent, personal data, and privacy notices were updated, processors were brought directly into scope, and specialized federal courts were created for data protection cases.
Does the LFPDPPP apply to my small business?
If you are a private party processing personal data in Mexico, yes, with no size floor. The bar rises with the data you hold: sensitive data (health, biometrics) and financial data require express consent, which is exactly what dental clinics, hotels, and real estate agencies collect every day.
We are a vendor or agency. Are we liable now?
Yes, and this is the biggest practical change. The new law expressly includes data processors, so anyone involved in handling personal data is subject to it, whether or not they decided what the data is for. Agencies, software houses, and outsourced service providers now carry their own exposure and should expect clients to demand contracts and proof of security.
What does a remote readiness audit include?
A one-hour call covering security controls, consent and privacy-notice handling, access rights, and breach readiness, plus a check of your email authentication and external exposure. You receive a written report within 48 hours with findings ranked Critical, Important, and Recommended. Mexico City is one to two hours ahead of Vancouver, so same-day calls are easy.