MEXICO Law and Practice Contributed by: Alejandro Mendiola Diaz and Gunter A. Schwandt G, Nader Hayaux & Goebel
Despite the absence of a legal requirement for cer - tification, many companies in Mexico recognise the importance of cybersecurity and voluntarily pursue various certifications to enhance their security pos - ture. These certifications, such as ISO/IEC 27001, are often seen as best practices to demonstrate their commitment to safeguarding sensitive information and mitigating cyber threats. Given the growing complexity and frequency of cyber- attacks, Mexico may eventually adopt more stringent regulations that mandate cybersecurity certifications for companies or professionals operating in certain sectors, particularly those responsible for managing critical infrastructure or sensitive data. Until such reg - ulations are enacted, voluntary certification remains an essential tool for organisations aiming to mitigate risks and enhance their cybersecurity measures. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Mexico’s data privacy regulations are closely linked to cybersecurity, primarily due to the increasingly com - plex landscape of personal data processing in con - temporary society. However, the current legal frame - work does not explicitly address cybersecurity in a dedicated manner. Instead, it outlines general prin - ciples and obligations that require organisations to implement security practices, which implicitly include cybersecurity measures as part of broader data pro - tection strategies. Security Measures and Obligations under the Mexican DPRs The Mexican DPRs require data controllers (entities responsible for processing personal data) to adopt technical security measures to safeguard personal data against various threats. These threats include damage, loss, alteration, destruction and unauthor - ised use, access or processing of sensitive informa - tion. The regulations specify that these measures should be designed with an understanding of evolving technological developments, reflecting the dynamic nature of cybersecurity challenges.
However, the regulations do not provide clear or spe - cific guidelines on what constitutes “technical security measures”, nor do they articulate concrete cybersecu - rity obligations. The provisions are somewhat vague, leaving room for interpretation, and do not set out explicit requirements or standards for the types of cybersecurity practices that data controllers should adopt. This lack of specificity creates challenges in ensuring comprehensive compliance and uniformity in practices across different sectors and organisations. Data Breach Notification Requirements In the event of a data breach, public entities that han - dle personal data are obligated to notify affected indi - viduals (data subjects) of the incident. This is a crucial step in ensuring transparency and accountability in cases of data breaches. Private data controllers, on the other hand, have a more limited obligation. They are only required to noti - fy those data subjects directly affected by the breach, rather than making a broader public notification. When notifying affected individuals, the data controller must provide detailed information, including: • a description of the nature of the incident; • the personal data that was compromised; • recommendations for the data subjects to protect their interests following the breach; • an overview of the immediate corrective measures taken upon detecting the breach; and • information on how individuals can seek further details about the incident. Despite these requirements, the Mexican DPRs do not offer a detailed, standardised procedure for data breach notification. The absence of clear guidance on the format, timing, and channels for notification can lead to inconsistencies in how organisations manage and communicate data breaches. Differences Between Public and Private Sector Obligations The Mexican DPRs distinguish between the obliga - tions of public and private-sector entities in the pro - cessing of personal data. Public entities face more extensive obligations. In contrast, private-sector
253 CHAMBERS.COM
Powered by FlippingBook