MEXICO Law and Practice Contributed by: Alejandro Mendiola Diaz and Gunter A. Schwandt G, Nader Hayaux & Goebel
entities have less stringent requirements and are only required to notify individuals directly affected by a breach. This differentiation creates a potential imbal - ance in the level of protection afforded to individuals depending on whether their data is handled by public or private entities. The Need for a More Comprehensive Legal Framework The absence of an explicit, comprehensive legal framework for cybersecurity within the Mexican DPRs suggests a need for future reforms. Given the increas - ing frequency and sophistication of cyber threats, it is crucial for the legal framework to evolve in tandem with emerging risks. A more detailed and clear articu - lation of specific cybersecurity obligations would help organisations implement more robust and consistent cybersecurity practices, improving overall data pro - tection and reducing vulnerabilities to cyber-attacks. In conclusion, while Mexico’s data privacy regulations provide essential safeguards for personal data protec - tion, they lack clear, specific provisions on cybersecu - rity obligations. The regulations generally require data controllers to implement security measures, but fail to offer detailed guidance on what constitutes adequate cybersecurity. This gap leaves organisations with sig - nificant room for interpretation, potentially leading to inconsistent practices. As Mexico continues to address the challenges posed by an increasingly digital society, integrating more specific cybersecurity requirements into data privacy regulations will be crucial. Strengthening these provi - sions will help mitigate the growing risks associated with cyber threats and improve the country’s overall ability to safeguard personal data in an interconnected world. 6.2 Cybersecurity and AI As of now, Mexico does not have dedicated cyber - security regulations specifically targeting artificial intelligence (AI). Despite AI technologies significantly transforming a wide range of sectors, from healthcare to finance, the country’s legal framework has not yet fully addressed the unique cybersecurity challenges posed by AI systems. However, AI systems that pro - cess personal data must still comply with existing data
protection regulations, particularly the Mexican DPRs, which primarily focus on safeguarding personal infor - mation. This intersection between data protection and AI represents a crucial yet limited area of AI govern - ance and cybersecurity in Mexico. To address these emerging challenges, Mexico could look to international frameworks and guidelines for AI governance and cybersecurity. For instance, organi - sations such as the European Union have regulated AI through the Artificial Intelligence Regulations, which include provisions on high-risk AI systems and spe - cifically address cybersecurity measures. Additionally, global cybersecurity bodies like the Global Forum on Cyber Expertise (GFCE) are working to develop inter - national norms and best practices for securing AI sys - tems, a critical component of their governance. By aligning with such international efforts, Mexico could adopt best practices and standards in AI cyber - security, fostering a stronger regulatory environment for emerging technologies. Participation in interna - tional forums would also allow Mexico to collabo - rate with other nations, sharing knowledge, risks and solutions for securing AI systems, ensuring it remains competitive while effectively addressing the cyberse - curity challenges inherent to AI. 6.3 Cybersecurity in the Healthcare Sector Data protection legislation comes into play since sensitive personal data related to individuals’ health is processed. Also, there are additional mandatory regulations contained in official standards. In this case, there is a Mexican Official Standard, NOM-004- SSA3-2012, that establishes criteria for the creation, management and conservation of medical records in Mexico. Its primary objective is to ensure proper documentation, confidentiality and accessibility of medical information while protecting patients’ rights and improving healthcare quality. • Scope and application – This standard applies to all healthcare facilities and professionals in public and private sectors. It covers medical records in hospitals, clinics, laboratories, and private prac - tices. • Medical record content – Medical records must include personal patient data, medical history,
254 CHAMBERS.COM
Powered by FlippingBook