Mexico’s privacy law had a stable decade and then two shocks in four months: the regulator that built its entire enforcement practice, INAI, was constitutionally dissolved in December 2024, and a new LFPDPPP replaced the 2010 statute in March 2025. The substance survived, aviso de privacidad, tiered consent, ARCO rights, so compliant companies stay mostly compliant; the risk sits with anyone who treated Mexico as unenforced and is now facing a new authority with a fresh statute, doubled sensitive-data fines, and something to prove.
| Law | LFPDPPP, published March 20, 2025 |
|---|---|
| Regulator | Secretaria Anticorrupcion y Buen Gobierno (post-INAI) |
| Consent tiers | Tacit / express / express written (sensitive) |
| ARCO clock | 20 business days + 15 to implement |
| Max fine | 320,000 UMA (~USD 1.9M), x2 for sensitive data |
Updating a Mexico program for 2025
Re-validate the aviso. Diff your full and simplified notices against the new law’s content list, especially secondary-purpose opt-outs and the ARCO contact point; the aviso is the first thing any investigator reads and the easiest defect to find.
Map data to consent tiers. Financial, patrimonial, and sensitive data need express (and for sensitive, written-equivalent) consent records; tacit consent covers the rest only after the aviso was actually made available.
Wire ARCO into the DSAR pipeline. 20 business days is its own clock, slower than Brazil’s 15 calendar days, faster than a GDPR month with extensions; route Mexican requests to the designated contact the aviso names.
Treat transfers as a separate workstream. Domestic and cross-border transfers carry notice and consent mechanics of their own, covered in the Mexico transfers guide, and regional programs should reconcile Mexico with Brazil, Argentina, and Chile’s 2026 law.
Whether your aviso is linked, your secondary-purpose opt-out exists, and your trackers respect it is all visible from outside: check with a free scan.