Federal Law on Protection of Personal Data Held by Private Parties
Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) establishes the rules for the collection, use, disclosure, storage and protection of personal data by private-sector organisations.
The law is built around principles including lawfulness, consent, information, quality, purpose limitation, loyalty, proportionality and accountability. Organisations must provide individuals with a privacy notice and comply with applicable requirements for consent, security, data subject rights and international data transfers.
Mexico
In force
Americas
The LFPDPPP applies to private individuals and legal entities that process personal data in the course of their activities, subject to the scope and exclusions established by Mexican law.
Organisations that collect or otherwise process personal data in Mexico should assess their obligations under the LFPDPPP and its implementing regulations.
The LFPDPPP establishes administrative sanctions and other penalties for violations of the law. The applicable amount depends on the nature and circumstances of the violation, with increased sanctions applicable to certain violations involving sensitive personal data.
Organisations should therefore maintain appropriate privacy, security and compliance controls to reduce the risk of regulatory enforcement.
Consent is an important component of Mexico's privacy framework, but the law does not require the same form of consent for every category of personal data.
For ordinary personal data, consent may generally be tacit when the privacy notice has been made available and the individual does not express opposition, unless the law requires express consent.
For certain categories, stronger consent requirements apply. In particular, the processing of sensitive personal data requires express written consent, subject to applicable legal provisions.
The implementing regulations further provide that consent should be free, specific and informed, with express consent also being unequivocal.
The Aviso de Privacidad is a central requirement under the LFPDPPP.
Organisations should provide individuals with information about the processing of their personal data, including the purposes for which data is collected and other information required by the applicable privacy notice rules.
Where personal data is collected directly from an individual, the privacy notice should be made available before or at the time of collection as required by the applicable framework.
Individuals have four core rights under Mexico's privacy framework, commonly known as ARCO rights:
Organisations should provide appropriate procedures and channels for receiving and responding to these requests.
Organisations processing personal data must establish and maintain appropriate security measures to protect information against risks such as loss, alteration, destruction, unauthorised access or unauthorised processing.
The LFPDPPP and its regulations also establish confidentiality obligations for individuals involved in the processing of personal data.
Privacy-notice-first consent experience to support Mexico's notice-driven privacy framework
Customisable consent banners for different processing purposes
Express consent capture for processing that requires stronger consent
Consent and preference receipts to maintain evidence of user choices
Prior-script blocking to help control selected non-essential tracking technologies
Region Rule Engine to configure Mexico-specific privacy experiences
ARCO request workflows to help organise privacy requests
Audit-ready records for consent and privacy interactions
Multi-jurisdictional compliance controls for organisations operating across Mexico and other markets
Manage privacy notices, consent preferences, user requests and compliance evidence across Mexico and other jurisdictions from one platform.
This page is a plain-English summary for general information and is not legal advice. Organisations should confirm their specific obligations with qualified Mexican privacy counsel.
Run a free scan to identify cookies, trackers and other technologies operating on your website. Understand what data may be collected and which third parties may receive it.
Configure the ConsentX banner to provide visitors with a privacy experience appropriate for Mexico and the applicable processing activities.
Make relevant privacy information and purposes easily accessible before or at the appropriate point of data collection.
Configure ConsentX to support the applicable consent mechanism for different categories of processing, including stronger consent requirements where applicable.
Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable privacy choice has been made.
Maintain consent and preference receipts containing relevant information about the user's interaction with your privacy controls.
Use ConsentX workflows to organise access, rectification, cancellation and opposition requests and maintain a central record of request handling.