← All guides
Mexico LFPDPPP18 min read27 July 2026

Mexico LFPDPPP Compliance 2026: Aviso de Privacidad, ARCO Rights, Datos Sensibles & INAI Enforcement

Comprehensive guide to Mexico’s Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) — aviso de privacidad requirements, ARCO rights with 20-business-day response, datos sensibles protections, encargado contracts, international transfers, and INAI enforcement with MXN 320M penalties.

LFPDPPP: Mexico’s Personal Data Protection Law

The Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) is Mexico’s federal privacy law for private entities, published in the Diario Oficial de la Federación (DOF) on July 5, 2010 and complemented by its Regulations (Reglamento) of December 21, 2011. The LFPDPPP is enforced by INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales), Mexico’s autonomous constitutional data protection and transparency authority.

Mexico is Latin America’s second-largest economy with 130 million people, a major US-Mexico tech supply chain, and an USMCA digital trade framework that reinforces data protection obligations. INAI has been actively enforcing the LFPDPPP through verification procedures (procedimientos de verificación), investigations, and sanctions, with penalties up to MXN 320 million and criminal sanctions under Articles 67–68 for sensitive data misuse.

Scope of the LFPDPPP

The LFPDPPP applies to:

  • All natural persons and private legal entities (personas físicas y morales de carácter privado) established in Mexico that process personal data
  • Foreign entities that process personal data of Mexican residents or in connection with activities in Mexico

Exemptions: personal or domestic use, journalistic/literary/artistic activities (with proportionality), and data processed by public bodies (which are subject to separate federal and state transparency/data protection laws).

Key Definitions

  • Personal data (dato personal): Any information relating to an identified or identifiable natural person (persona física).
  • Sensitive personal data (datos sensibles): Six categories under Art. 3 VI: racial or ethnic origin, present/future health status, genetic information, religious/philosophical/moral beliefs, union membership, political opinions, and sexual preferences/life. Heightened protection: express written or electronic consent required (Art. 9); no refusal of goods/services for refusing sensitive data consent.
  • Responsible party (responsable): Individual or private legal entity that decides the purposes and means of processing.
  • Processor (encargado): Individual or legal entity that processes personal data on behalf of the responsable.
  • Data subject (titular): Natural person whose personal data is processed.

The Five LFPDPPP Lawful Bases

Unlike GDPR’s six bases, the LFPDPPP provides five lawful grounds for processing:

  1. Consent: Express (written/electronic for sensitive data; verbal or electronic for ordinary data) or implied/tacit (inferred from conduct where purpose is disclosed in privacy notice). Cannot be condition of service for non-essential processing.
  2. Contract performance: Processing necessary for a legal relationship between responsable and titular (Art. 10 I).
  3. Legal obligation: Required by Mexican law or regulation (Art. 10 II).
  4. Emergency/vital interests: To protect health or life of titular or third party where consent is impossible (Art. 10 IV).
  5. Legitimate interests: Narrowly available; three-part test (purpose test, necessity test, balancing test); not available for sensitive data (Art. 10 V).

Aviso de Privacidad: The Privacy Notice Requirement

The aviso de privacidad (privacy notice) is the cornerstone of LFPDPPP compliance. Under Arts. 15–16 and the INAI Lineamientos del Aviso de Privacidad (DOF January 17, 2013), the notice must be provided at or before the moment of data collection and must contain:

  • Identity and domicile of the responsable
  • Purposes of the processing (primary and secondary; secondary use requires either consent or lawful exception)
  • Transfer disclosures: whether transfers will occur, categories of third parties, domestic or international scope
  • Mechanism for the titular to exercise ARCO rights
  • Mechanism to revoke consent
  • Mechanism to limit use or disclosure
  • How changes to the notice will be communicated
  • For sensitive data: explicit statement that sensitive personal data is being collected

Three LFPDPPP notice formats exist:

  • Full notice (aviso de privacidad integral): Required for paper/physical collection; contains all required elements
  • Simplified notice (aviso de privacidad simplificado): For short-form collection; references full notice; contains key elements and link/reference to full notice
  • Short notice (aviso de privacidad corto): For very limited space; minimal elements with reference to full notice — permitted by INAI Lineamientos

ARCO Rights: 20-Business-Day Response Requirement

The LFPDPPP grants titulares four fundamental data subject rights known collectively as ARCO rights:

Acceso (Access — Art. 22)

The titular has the right to know what personal data the responsable holds, from what sources, for what purposes, to which third parties it has been transferred, and the retention period. The responsable must respond within 20 business days and provide access in the format requested (copy, electronic file, certified extract). The 20-day period may be extended by a further 20 days where justified with notice.

Rectificación (Rectification — Art. 24)

The titular may request correction of inaccurate, incomplete, outdated, or misleading personal data. The responsable must respond within 20 business days and, where data has been shared with third parties, must notify them of the correction within 3 business days of implementing it.

Cancelación (Cancellation — Art. 25)

The titular may request deletion of personal data when the purpose of collection has been fulfilled, consent has been revoked, or the data is no longer necessary. The responsable must respond within 20 business days. Data enters a blocking period (período de bloqueo) before deletion — during which it can only be used for legal proceedings — before final deletion. Blocking periods correspond to applicable statutory or regulatory retention obligations.

Oposición (Opposition — Art. 27)

The titular may object to processing for legitimate reasons (harm to interests, rights, or patrimony) or where processing is for purposes not consented to. The responsable must respond within 20 business days. The responsable may continue processing if it can demonstrate compelling legitimate grounds that override the titular’s interests, or for legal proceedings.

ARCO Request Procedures

To exercise ARCO rights: the titular submits a request to the responsable’s designated intake channel (must be accessible, free, and not require excessive authentication). The responsable must: (a) acknowledge receipt, (b) assess identity verification proportionately, (c) respond within 20 business days substantively, (d) implement the action within 15 business days after confirming the response. Denial must be communicated in writing with grounds. Denied or unanswered requests can be escalated to INAI’s procedimiento de protección de derechos.

Datos Sensibles: Heightened Protections

The LFPDPPP’s treatment of sensitive personal data is more restrictive than ordinary personal data:

  • Express consent required: Must be written (paper or electronic with electronic signature); cannot be implied or inferred from conduct (Art. 9)
  • No condition of service: Responsable cannot condition service delivery on providing sensitive personal data consent unless it is strictly necessary for the service (Art. 8)
  • Heightened security: Enhanced technical, administrative, and physical security measures
  • Criminal liability: Arts. 67–68 impose criminal penalties (3–5 years imprisonment) for unlawful processing of sensitive personal data or its transfer without consent for financial gain
  • Privacy notice prominence: Privacy notice must explicitly state that sensitive personal data is being collected (Art. 16 V)

Encargado Contracts: Processor Obligations

When a responsable engages an encargado (processor) to process personal data on its behalf, a written contract is mandatory (Art. 50 Reglamento). The contract must include:

  • Processing only on responsable’s documented instructions
  • Prohibition on transferring data to third parties without responsable’s written authorisation (except by legal obligation)
  • Security measures equivalent to those required of the responsable
  • Confidentiality obligation binding on encargado’s personnel
  • Deletion or return of personal data on termination
  • Sub-contractor controls: encargado must obtain responsable’s prior written authorisation before engaging sub-encargados; same obligations must flow down

Importantly, the responsable remains fully accountable for the encargado’s processing — INAI can hold the responsable liable for an encargado’s failures.

International Data Transfers

Transfers of personal data outside Mexico (cesiones internacionales) require that the recipient provides equivalent LFPDPPP protection through one of these mechanisms:

  • Contractual clauses (cláusulas contractuales): Binding agreement imposing LFPDPPP-equivalent obligations on the foreign recipient
  • Binding corporate rules (BCRs): For intra-group transfers within a multinational
  • Consent: Explicit consent from the titular with disclosure of the recipient country and risks
  • International frameworks: Transfer within a jurisdiction that Mexico recognises as providing equivalent protection

The privacy notice must disclose whether international transfers will occur, the categories of recipients, and whether the transfer is domestic or international. US-Mexico transfers under the USMCA digital trade provisions (Chapter 19) reinforce the adequacy-equivalent standard.

Security and Data Breach Response

Art. 19 LFPDPPP requires technical, administrative, and physical security measures appropriate to the risk and sensitivity of the data processed. INAI’s Recomendaciones de Seguridad provide detailed guidance referencing encryption (AES-256 at rest / TLS 1.2+ in transit), access controls, audit logging, and incident response.

For security incidents (violaciones de seguridad) that significantly affect the rights or patrimony of titulares:

  • INAI notification: No statutory deadline in the original LFPDPPP text, but INAI expects prompt notification “as soon as possible” — 72 hours is the current industry expectation
  • Individual notification: Required when the violation significantly affects the titular’s patrimonial or moral rights — must contain: nature of the violation, personal data involved, recommendations for self-protection, corrective measures, contact details
  • Incident register: Maintained for INAI verification procedures; includes nature, date, affected data, response, and outcome

INAI Enforcement and Penalties

INAI enforces the LFPDPPP through:

  • Procedimiento de protección de derechos: Complaint process for denied ARCO rights — INAI can order the responsable to comply
  • Procedimiento de verificación: INAI-initiated or complaint-triggered investigation; can include document requests, on-site inspections, and witness interviews
  • Procedimiento de imposición de sanciones: Sanctions proceeding that can result in administrative fines

Penalty structure (Art. 63 LFPDPPP; telecommunications entities subject to higher Ley Federal de Telecomunicaciones Art. 71 scale):

  • Failure to provide privacy notice: MXN 100M–200M
  • Failure to comply with ARCO rights: MXN 100M–200M
  • Processing without legal basis: MXN 200M–320M
  • Sensitive data violations: MXN 200M–320M (plus criminal sanctions Arts. 67–68 — 3–5 years imprisonment)
  • International transfer violations: MXN 200M–320M

Mitigating factors include: good-faith compliance programme, prior clean record, voluntary remediation, degree of harm, and cooperation with INAI. INAI’s published enforcement guidelines reward documented privacy programmes.

Use the Free Mexico LFPDPPP Compliance Checklist

ComplyKit’s Mexico LFPDPPP Compliance Checklist covers 42 key obligations across six categories: Aviso de Privacidad & Lawful Bases, ARCO Rights, Responsible Party Obligations, Security & Breach Notification, International Transfers, and Governance & INAI Compliance. Free, no account required.

Related reading: Brazil LGPD Compliance Guide, Brazil LGPD Compliance Checklist, GDPR Compliance Audit.