Latin America Mexico

Mexico Cross-Border Data Transfers for US Companies

LFPDPPP transfer rules for US companies moving data out of Mexico: notice and consent mechanics, exceptions, processor remisiones, and the 2025 enforcement shift.

Regulation

LFPDPPP transfer provisions (new law published March 20, 2025) and its regulations

Max Penalty

Unlawful transfers rank among the serious infractions: fines up to 320,000 UMA (~USD 1.9M), doubled for sensitive data

Enforcing Authority

Secretaria Anticorrupcion y Buen Gobierno (post-INAI)

Official Source

www.diputados.gob.mx

Executive Summary

  • Mexico regulates transfers through notice and consent rather than adequacy lists: transfers to third parties, domestic or foreign, must be described in the aviso de privacidad, and the recipient is bound to the same obligations the transferor communicated.
  • Consent to the transfer is the default requirement, with statutory exceptions for intra-group transfers under common policies, contract necessity, legal requirements, emergencies, and judicial cooperation.
  • A transfer (transferencia) to another controller differs from a remision to a processor acting on your instructions: remisiones need a data processing agreement, not transfer consent.
  • US companies pulling Mexican customer or employee data north need three artifacts: an aviso disclosing the transfer, a consent or exception analysis per flow, and contracts passing the aviso's obligations to the recipient.
  • USMCA Article 19.11 restricts Mexico from blocking cross-border data flows outright, which is why the LFPDPPP polices transfers through accountability and consent rather than localization.

Mexico polices data exports differently from every regime US companies usually benchmark: no adequacy list, no standard clauses, no filings. The control point is the aviso de privacidad, if the transfer and its purpose are disclosed there, consented to or excepted, and the recipient is contractually bound to the same terms, the flow is lawful; if any leg is missing, it is an infraction in the serious tier, and the 2025 law doubled down on that architecture while handing enforcement to a new authority. For US companies the work is notice drafting and contract hygiene, not clause execution.

MechanismNotice + consent/exception + recipient contract
StatuteLFPDPPP (2025), transfer provisions
Key splitTransferencia (controller) vs remision (processor)
Workhorse exceptionIntra-group under common policies
Trade backstopUSMCA Art. 19.11 free-flow commitment

Building the Mexico transfer file

Classify every northbound flow. Controller-purpose uses are transferencias needing aviso disclosure and consent or a documented exception; instruction-only processing is a remision needing a DPA, keep the register per flow.

Fix the aviso first. Most Mexican transfer violations are really notice violations: the aviso requirements demand recipient categories and purposes, and an undisclosed transfer cannot be cured by contract.

Paper the intra-group exception properly. A group privacy policy genuinely adopted by the Mexican entity converts most parent-subsidiary flows to consent-free, the highest-leverage document in the file.

Reconcile the regional stack. The same pipeline may need Brazilian SCCs, Argentine onward-transfer clauses, and EU SCCs on other legs; a per-leg register beats a single-mechanism assumption.

Trackers and pixels sending Mexican visitor data to US ad platforms are cross-border flows your aviso must cover: see what actually fires with a free scan.

Frequently Asked Questions

Does Mexico have an adequacy list or SCC system like the EU or Brazil?

No. The LFPDPPP does not gate transfers on destination-country adequacy and has no standard-clause annex. Instead it makes the transferor accountable: disclose the transfer and its purposes in the aviso de privacidad, obtain consent unless an exception applies, and contractually bind the recipient to process only per the aviso. That design survives in the 2025 law. It is lighter paperwork than Brazilian SCCs but heavier notice discipline, the aviso must actually name the categories of recipients and purposes, and a transfer outside what the aviso describes is unlawful regardless of contracts.

What is the difference between a transferencia and a remision?

A transferencia is a communication of data to a distinct controller (a US parent using Mexican customer data for its own purposes, a business partner, a buyer in M&A). A remision is handing data to an encargado (processor) that processes strictly on the controller's behalf, a US cloud provider, a payroll processor. Remisiones are not transfers: they need no consent and no aviso disclosure as transfers, but they do require a contract fixing the processor's obligations (process only on instructions, security, confidentiality, deletion). Misclassifying a parent-company analytics use as a remision is the classic error; if the recipient decides purposes, it is a transfer.

When can we transfer without consent?

The statutory exceptions: transfers required by law or treaty; intra-group transfers to parents, subsidiaries, or affiliates operating under the same internal data protection policies; transfers necessary for a contract concluded or to be concluded in the data subject's interest; transfers necessary for medical care; transfers to competent authorities; and transfers necessary for the maintenance or fulfillment of the legal relationship with the data subject. The intra-group exception is the workhorse for US multinationals, but it requires genuinely common policies, adopt and document a group privacy policy covering the Mexican entity before relying on it.

What do our contracts with the US recipient need to say?

The recipient must assume the same obligations that apply to the transferor under the aviso: process only for the communicated purposes, honor the LFPDPPP principles, maintain security measures, and support ARCO requests reaching back through the chain. In practice this is a transfer agreement or intercompany data-sharing agreement attaching the aviso (or its relevant terms). For processor remisiones, a DPA with instruction-only processing, security, sub-processor controls, and deletion terms. Neither requires filing with the authority, but both must exist when an investigation asks.

How does this interact with GDPR, LGPD, and USMCA obligations?

Independently. A Monterrey-to-Texas flow needs LFPDPPP mechanics (aviso disclosure plus consent or exception); if the same pipeline carries EU data it also needs EU SCCs, and a Brazil leg needs Brazilian SCCs under Resolution 19/2024, three regimes, three artifacts, one dataset. USMCA Article 19.11 commits the three countries not to restrict cross-border business data flows beyond legitimate public-policy measures, which keeps Mexico from adopting localization but does not exempt anyone from the LFPDPPP's consent and notice rules. Multinationals should run a per-leg transfer register rather than assuming one mechanism covers the continent.

Regulatory Crosswalk

LGPD transfersGDPR SCCsUSMCA Article 19.11

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.