Mexico polices data exports differently from every regime US companies usually benchmark: no adequacy list, no standard clauses, no filings. The control point is the aviso de privacidad, if the transfer and its purpose are disclosed there, consented to or excepted, and the recipient is contractually bound to the same terms, the flow is lawful; if any leg is missing, it is an infraction in the serious tier, and the 2025 law doubled down on that architecture while handing enforcement to a new authority. For US companies the work is notice drafting and contract hygiene, not clause execution.
| Mechanism | Notice + consent/exception + recipient contract |
|---|---|
| Statute | LFPDPPP (2025), transfer provisions |
| Key split | Transferencia (controller) vs remision (processor) |
| Workhorse exception | Intra-group under common policies |
| Trade backstop | USMCA Art. 19.11 free-flow commitment |
Building the Mexico transfer file
Classify every northbound flow. Controller-purpose uses are transferencias needing aviso disclosure and consent or a documented exception; instruction-only processing is a remision needing a DPA, keep the register per flow.
Fix the aviso first. Most Mexican transfer violations are really notice violations: the aviso requirements demand recipient categories and purposes, and an undisclosed transfer cannot be cured by contract.
Paper the intra-group exception properly. A group privacy policy genuinely adopted by the Mexican entity converts most parent-subsidiary flows to consent-free, the highest-leverage document in the file.
Reconcile the regional stack. The same pipeline may need Brazilian SCCs, Argentine onward-transfer clauses, and EU SCCs on other legs; a per-leg register beats a single-mechanism assumption.
Trackers and pixels sending Mexican visitor data to US ad platforms are cross-border flows your aviso must cover: see what actually fires with a free scan.