MEXICO Law and Practice Contributed by: Alejandro Mendiola Diaz and Gunter A. Schwandt G, Nader Hayaux & Goebel
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Mexico lacks a specific cybersecurity law, but various legal provisions indirectly regulate the area, involving multiple regulatory bodies. For instance, there are regulations concerning banking, personal data pro - tection, criminal conduct, and telecommunications. These laws shape the cybersecurity landscape by providing frameworks that institutions and business - es must follow to protect digital assets and personal information. Additionally, several government agencies have issued their own cybersecurity guidelines. For exam - ple, the Central Bank of Mexico (Banxico), the coun - try’s central bank, released its cybersecurity strategy for 2024–2027 ( Estrategia de Ciberseguridad del Ban- co de México 2024 – 2027), outlining its guiding prin - ciples and defining the responsibilities of an internal cybersecurity directorate. This initiative highlights the importance of financial cybersecurity and the role of regulatory bodies in ensuring a secure banking envi - ronment. Moreover, financial institutions are required to adhere to strict cybersecurity protocols to prevent fraud, data breaches and cyber-attacks that could compromise national financial stability. Several cybersecurity law proposals have been sub - mitted to Congress for discussion. However, none have been enacted into law, remaining as proposals that could serve as a foundation for future legisla - tive discussions. These proposals generally aim to address cyber crimes related to financial assets, per - sonal freedoms, intellectual property, the financial sys - tem and information systems, among others. Given the increasing frequency and sophistication of cyber threats, there is a growing need for a comprehensive cybersecurity law that establishes clear regulations and penalties for cyber-related offences. Legislative progress in this area will be crucial for strengthen - ing Mexico’s cybersecurity posture and ensuring that individuals and businesses are adequately protected from cyber threats. Finally, considering Mexico’s current legal framework, personal data protection regulations are the most
directly relevant laws to cybersecurity. The protec - tion of personal data remains a central concern, as unauthorised access, data breaches and identity theft continue to pose significant risks. Strengthening data protection regulations and enforcing compliance will be essential in fostering a more secure digital envi - ronment and building public trust in cybersecurity measures. 1.2 Cybersecurity Laws The following legal instruments, though not an exhaus - tive list (see 3.1 Scope of Financial Sector Opera- tional Resilience Regulation for additional regulations in the financial sector), contain provisions relevant to cybersecurity in Mexico as of early 2026. • Federal Criminal Code ( Código Penal Federal ) and state criminal codes. These establish legal conse - quences for cyber-related crimes, including unau - thorised access to systems, fraud, identity theft, illicit interception of communications, hacking, data breaches and cyber-enabled financial crimes. • Federal Law on the Protection of Personal Data Held by Private Parties ( Ley Federal de Protección de Datos Personales en Posesión de los Particu- lares , DPR). This law, reformed in 2025, governs the collection, processing, storage and protection of personal data by private entities. It mandates adequate security measures to safeguard sensitive information, including risk-based approaches and breach notification obligations. Enforcement has shifted from the now-abolished National Institute for Transparency, Access to Information and Per - sonal Data Protection (dissolved in late as part of broader administrative reforms) to sector-specific bodies. • General Law on Transparency and Access to Public Information ( Ley General de Transparencia y Acceso a la Información Pública ) and related reforms (also amended in 2025). These include provisions on information security in public institu - tions, requiring government entities to handle and protect sensitive data responsibly and to ensure accountability for cybersecurity-related incidents. • Fintech Law ( Ley para Regular las Instituciones de Tecnología Financiera ). It establishes compliance requirements for fintech companies, mandating measures to secure financial transactions and
247 CHAMBERS.COM
Powered by FlippingBook