LFPDPPP
Federal Law on Protection of Personal Data Held by Private Parties
Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) establishes the rules for the collection, use, disclosure, storage and protection of personal data by private-sector organisations.
The law is built around principles including lawfulness, consent, information, quality, purpose limitation, loyalty, proportionality and accountability. Organisations must provide individuals with a privacy notice and comply with applicable requirements for consent, security, data subject rights and international data transfers.
Mexico
In force
Américas
Quem tem de cumprir
The LFPDPPP applies to private individuals and legal entities that process personal data in the course of their activities, subject to the scope and exclusions established by Mexican law.
Organisations that collect or otherwise process personal data in Mexico should assess their obligations under the LFPDPPP and its implementing regulations.
Sanções
The LFPDPPP establishes administrative sanctions and other penalties for violations of the law. The applicable amount depends on the nature and circumstances of the violation, with increased sanctions applicable to certain violations involving sensitive personal data.
Organisations should therefore maintain appropriate privacy, security and compliance controls to reduce the risk of regulatory enforcement.
Obrigações principais
- Provide a privacy notice (Aviso de Privacidad) when collecting personal data
- Clearly explain the purposes for which personal data will be processed
- Obtain consent when required by the LFPDPPP
- Obtain express and written consent for sensitive personal data
- Obtain express consent for financial or property-related information, subject to applicable legal exceptions
- Process personal data according to the principles of lawfulness, consent, information, quality, purpose, loyalty, proportionality and accountability
- Implement appropriate administrative, technical and physical security measures
- Maintain confidentiality of personal data
- Respect ARCO rights — Access, Rectification, Cancellation and Opposition
- Establish mechanisms through which individuals can exercise their privacy rights
- Provide mechanisms for individuals to revoke consent
- Manage transfers of personal data in accordance with applicable requirements
- Maintain appropriate documentation and evidence of privacy compliance
Consent requirements under LFPDPPP
Consent is an important component of Mexico's privacy framework, but the law does not require the same form of consent for every category of personal data.
For ordinary personal data, consent may generally be tacit when the privacy notice has been made available and the individual does not express opposition, unless the law requires express consent.
For certain categories, stronger consent requirements apply. In particular, the processing of sensitive personal data requires express written consent, subject to applicable legal provisions.
The implementing regulations further provide that consent should be free, specific and informed, with express consent also being unequivocal.
Privacy Notice requirements
The Aviso de Privacidad is a central requirement under the LFPDPPP.
Organisations should provide individuals with information about the processing of their personal data, including the purposes for which data is collected and other information required by the applicable privacy notice rules.
Where personal data is collected directly from an individual, the privacy notice should be made available before or at the time of collection as required by the applicable framework.
ARCO Rights
Individuals have four core rights under Mexico's privacy framework, commonly known as ARCO rights:
- Access — request information about personal data held and processed by the organisation
- Rectification — request correction of inaccurate or incomplete personal data
- Cancellation — request deletion of personal data where the applicable requirements are met
- Opposition — object to the processing of personal data in applicable circumstances
Organisations should provide appropriate procedures and channels for receiving and responding to these requests.
Security and confidentiality
Organisations processing personal data must establish and maintain appropriate security measures to protect information against risks such as loss, alteration, destruction, unauthorised access or unauthorised processing.
The LFPDPPP and its regulations also establish confidentiality obligations for individuals involved in the processing of personal data.
Como a ConsentX ajuda
Privacy-notice-first consent experience to support Mexico's notice-driven privacy framework
Customisable consent banners for different processing purposes
Express consent capture for processing that requires stronger consent
Consent and preference receipts to maintain evidence of user choices
Prior-script blocking to help control selected non-essential tracking technologies
Region Rule Engine to configure Mexico-specific privacy experiences
ARCO request workflows to help organise privacy requests
Audit-ready records for consent and privacy interactions
Multi-jurisdictional compliance controls for organisations operating across Mexico and other markets
Prepare LFPDPPP com a ConsentX
Manage privacy notices, consent preferences, user requests and compliance evidence across Mexico and other jurisdictions from one platform.
This page is a plain-English summary for general information and is not legal advice. Organisations should confirm their specific obligations with qualified Mexican privacy counsel.
Como cumprir o LFPDPPP com a ConsentX
- 1
Scan your website
Run a free scan to identify cookies, trackers and other technologies operating on your website. Understand what data may be collected and which third parties may receive it.
- 2
Show a Mexico-specific privacy experience
Configure the ConsentX banner to provide visitors with a privacy experience appropriate for Mexico and the applicable processing activities.
- 3
Present clear privacy information
Make relevant privacy information and purposes easily accessible before or at the appropriate point of data collection.
- 4
Capture the appropriate consent
Configure ConsentX to support the applicable consent mechanism for different categories of processing, including stronger consent requirements where applicable.
- 5
Block selected trackers
Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable privacy choice has been made.
- 6
Record consent and preferences
Maintain consent and preference receipts containing relevant information about the user's interaction with your privacy controls.
- 7
Manage ARCO requests
Use ConsentX workflows to organise access, rectification, cancellation and opposition requests and maintain a central record of request handling.