Latin America Mexico

Mexico LFPDPPP 2025: Privacy Notices, Consent, ARCO Rights

Mexico's new LFPDPPP (March 2025): the aviso de privacidad, consent tiers, ARCO rights on 20-day clocks, and enforcement after INAI's dissolution.

Regulation

Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (new LFPDPPP, published March 20, 2025, replacing the 2010 law)

Max Penalty

Fines up to 320,000 UMA per violation (roughly USD 1.9M), doubled for sensitive data

Enforcing Authority

Secretaria Anticorrupcion y Buen Gobierno (transparency unit), succeeding the dissolved INAI

Official Source

www.diputados.gob.mx

Executive Summary

  • Mexico replaced its 2010 private-sector privacy law with a new LFPDPPP, published March 20, 2025, keeping the familiar architecture (aviso de privacidad, consent tiers, ARCO rights) while updating definitions and moving enforcement.
  • The biggest 2025 change is institutional: INAI, the autonomous regulator since 2010, was dissolved in the constitutional reform of late 2024, and its data protection functions moved to the federal executive (the Anticorruption and Good Government Secretariat).
  • The consent model is tiered: tacit consent suffices for ordinary data once notice is given, express consent for financial and patrimonial data, and express written consent for sensitive data.
  • ARCO rights (access, rectification, cancellation, opposition) run on a 20-business-day response clock with 15 additional days to implement, and the new law tightens rules on automated decisions and portability-adjacent duties.
  • Fines are denominated in UMA (inflation-indexed daily units) and reach 320,000 UMA per violation, doubling for sensitive-data infractions, on top of processing suspension orders.

Mexico’s privacy law had a stable decade and then two shocks in four months: the regulator that built its entire enforcement practice, INAI, was constitutionally dissolved in December 2024, and a new LFPDPPP replaced the 2010 statute in March 2025. The substance survived, aviso de privacidad, tiered consent, ARCO rights, so compliant companies stay mostly compliant; the risk sits with anyone who treated Mexico as unenforced and is now facing a new authority with a fresh statute, doubled sensitive-data fines, and something to prove.

LawLFPDPPP, published March 20, 2025
RegulatorSecretaria Anticorrupcion y Buen Gobierno (post-INAI)
Consent tiersTacit / express / express written (sensitive)
ARCO clock20 business days + 15 to implement
Max fine320,000 UMA (~USD 1.9M), x2 for sensitive data

Updating a Mexico program for 2025

Re-validate the aviso. Diff your full and simplified notices against the new law’s content list, especially secondary-purpose opt-outs and the ARCO contact point; the aviso is the first thing any investigator reads and the easiest defect to find.

Map data to consent tiers. Financial, patrimonial, and sensitive data need express (and for sensitive, written-equivalent) consent records; tacit consent covers the rest only after the aviso was actually made available.

Wire ARCO into the DSAR pipeline. 20 business days is its own clock, slower than Brazil’s 15 calendar days, faster than a GDPR month with extensions; route Mexican requests to the designated contact the aviso names.

Treat transfers as a separate workstream. Domestic and cross-border transfers carry notice and consent mechanics of their own, covered in the Mexico transfers guide, and regional programs should reconcile Mexico with Brazil, Argentina, and Chile’s 2026 law.

Whether your aviso is linked, your secondary-purpose opt-out exists, and your trackers respect it is all visible from outside: check with a free scan.

Frequently Asked Questions

What changed between the 2010 law and the 2025 LFPDPPP?

Continuity with sharper edges. The 2025 law keeps the principles (licitud, consentimiento, informacion, calidad, finalidad, lealtad, proporcionalidad, responsabilidad), the aviso de privacidad, the consent tiers, and ARCO rights. It updates definitions (broader processing and controller concepts, clearer processor duties), tightens the aviso's content requirements, and re-homes enforcement in the federal executive after INAI's dissolution. Compliance documentation built for the 2010 law needs review, not reconstruction; the aviso and consent records are where the wording changes bite.

Who enforces the law now that INAI is gone?

The December 2024 constitutional reform extinguished INAI along with other autonomous bodies. Data protection oversight for the private sector moved to the Secretaria Anticorrupcion y Buen Gobierno, exercising the powers the law previously gave INAI: investigations, verification procedures, ARCO enforcement, and sanctions. Practitioners are watching how aggressively the new arrangement enforces; the prudent read is that the substantive obligations are unchanged and the procedural muscle is being rebuilt, a poor moment to be the test case.

What must the aviso de privacidad contain?

The privacy notice is the LFPDPPP's central instrument, in full and simplified forms: the controller's identity and domicile, the personal data processed and whether sensitive data is included, the purposes (distinguishing necessary from secondary ones the person can refuse), transfer recipients and purposes, the mechanics for exercising ARCO rights and revoking consent, and how changes will be communicated. Secondary purposes need an opt-out at first contact. A missing or defective aviso is the most commonly sanctioned violation, and it is externally checkable on any website.

How do the consent tiers work in practice?

Three levels. Tacit consent: for ordinary data, processing may proceed once the aviso is made available and the person does not object, this covers most commercial flows. Express consent: for financial or patrimonial data (spoken, written, or by unmistakable electronic means). Express and written consent: for sensitive data (health, biometrics, ideology, religion, sexual life, ethnic origin), via signature, electronic signature, or equivalent authentication. Exceptions exist for legal obligations, emergencies, and contract necessity, but marketing always allows opposition.

What are the ARCO deadlines and what happens if we miss them?

The controller must answer an ARCO request within 20 business days and, if granted, implement within 15 more; the law allows one extension for justified cause. Requests go through the contact point named in the aviso (a designated person or data protection department is mandatory). Unanswered or refused requests escalate to a data protection rights procedure before the authority, and from there to sanctions, fines up to 320,000 UMA, doubled for sensitive data, and, for repeat or serious conduct, suspension of processing. Blown ARCO clocks are the classic trigger for regulatory attention.

Regulatory Crosswalk

LGPDGDPRCCPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.