MEXICO Law and Practice Contributed by: Luis Álvarez Cervantes, Adolfo Athié Cervantes, Alejandro Barrera, Jesús Colunga, Eduardo Kleinberg, Juan José López de Silanes, Carlos Martínez-Betanzos and Amílcar Peredo, Basham, Ringe y Correa S.C.
data by private individuals and entities in Mexico. The law is of public order and general observance throughout Mexican territory. While the LFPDPPP’s principal field of application encompasses private entities established and oper - ating in Mexico, its scope is not strictly limited to domestic processing activities. Article 4 of the 2011 Implementing Regulations – to the extent applicable under the current statutory framework, as further dis - cussed below – sets out four specific circumstances under which the law applies regardless of where the data controller is domiciled: (i) where processing is carried out through an establishment of the controller located in Mexico; (ii) where processing is performed by a processor, irrespective of its location, on behalf of a controller established in Mexico; (iii) where a control - ler not established in Mexico is nonetheless subject to Mexican law by virtue of international law or through the execution of a contract; or (iv) where a controller not established in Mexico uses means located in Mex - ican territory to process personal data, except where such means are used solely for transit purposes. It follows that the mere fact that personal data is stored or processed outside Mexico does not, in and of itself, exempt an entity from compliance with the LFPDPPP, provided that one of the above jurisdictional nexuses is present. Entities operating in cross-border contexts are accordingly advised to conduct a careful analysis of their data processing activities considering these criteria. Entities falling within the scope of the LFPDPPP are subject to a comprehensive set of obligations, including – among others – the duty to provide a privacy notice ( aviso de privacidad ) to data subjects and, where required, to obtain their consent prior to processing. The applicable form of consent varies depending on the nature of the data and the specific processing purpose: tacit consent operates as the general rule for ordinary personal data; express con - sent is required for financial personal data and certain specific processing activities; express written consent is mandated in particular circumstances and when processing involves sensitive personal data. Consent requirements are not, however, absolute: the LFP - DPPP expressly provides for exceptions under which
personal data may be processed without the data subject’s consent, including – among others – where processing is necessary for the performance of a legal obligation incumbent upon the controller, where the data has been made manifestly public by the data subject, or where processing is required for the main - tenance or fulfilment of a legal relationship between the controller and the data subject. In addition, con - trollers must observe the core principles of lawfulness, loyalty, purpose limitation, data quality, proportional - ity, accountability, and transparency throughout the entire lifecycle of processing. 8.3 Role and Authority of the Data Protection Agency Following the institutional reform described in 8.1 Applicable Regulations , the Secretaría Anticorrup- ción y Buen Gobierno (SABG, Ministry of Anti-Corrup - tion and Good Governance) assumed, as of 21 March 2025, the functions previously held by the INAI as the competent authority for the enforcement of personal data protection legislation in the private sector. Unlike its predecessor, the SABG is not an autono - mous constitutional body – it operates within the fed - eral public administration and reports directly to the Executive Branch. This structural change has drawn attention from privacy practitioners and civil society organisations, who have raised concerns regarding the institutional independence of the supervisory authority and its capacity to act impartially in cases involving government-related entities. These concerns are relevant context for any assessment of enforce - ment risk and regulatory predictability under the cur - rent framework. The SABG’s functions in data protection matters include, among others: receiving and resolving com - plaints filed by data subjects in connection with the exercise of their access, rectification, cancellation and objection rights ( derechos ARCO ); investigat - ing potential violations of the LFPDPPP; imposing administrative sanctions on controllers found to be in breach of applicable obligations; issuing guidelines, recommendations, and best practice frameworks; and promoting awareness of data protection rights among both private entities and the general public.
687 CHAMBERS.COM
Powered by FlippingBook