Data Protection and Privacy 2025

MEXICO Law and Practice Contributed by: Luciano Pérez, Ana Paula Silva and Allan Pastor, Nader Hayaux & Goebel

1. Legal and Regulatory Framework 1.1 Overview of Data and Privacy- Related Laws Mexican Data Protection Regulations (DPRs) In Mexico, personal data protection is regulat - ed by the highest hierarchy in its legal system. The Federal Mexican Constitution ( Constitución Política de los Estados Unidos Mexicanos ) grants and recognises the protection of personal data as a human right. In order to regulate this human right, Mexico’s legal framework divides the regulation into the private and public sector. The Federal Law for the Protection of Personal Data Held by Private Parties ( Ley Federal de Pro - tección de Datos Personales en Posesión de los Particulares ), its Regulation ( Reglamento ) and other secondary provisions (jointly, the Private Data Protection Regulations (Private DPRs)), serve as the tools to protect this right and feature as the core of Mexican personal data protection in the private sector. On the other hand, data privacy for public entities is regulated by the General Law for the Protec - tion of Personal Data Held by Obligated Parties ( Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados ) (the Public DPRs and jointly with the DPRs, the Mexican DPRs), and several other provisions. The Mexican DPRs were prepared based on and include the principles of data protection set forth in the EU Data Protection Directive (the “EU Directive”). Mexico has not adopted the new regulation set forth in the General Data Protection Regulation (GDPR). As of this date, there is no public information on any proposed

bill to amend the Mexican DPRs regarding enforcing the GDPR or any other multi-national systems. The Mexican DPRs do not have strict risk assessment obligations and risk mitigation measures compared to other national systems. Additionally, the Mexican DPRs do not explicitly address the challenges posed by emerging tech - nologies such as AI, blockchain and big data analytics, which are already subject to specific regulations in other countries. 1.2 Regulators Mexico has a total of 33 authorities dedicated in part to data protection. Currently, the National Institute for Transparency, Access to Informa - tion and Data Protection ( Instituto Nacional de Transparencia, Acceso a la Información y Pro - tección de Datos Personales ) (INAI) is the sole authority responsible for enforcing the Mexican DPRs throughout the country. As part of its sur - veillance responsibility, it has the authority to conduct audits and investigations by its own initiative or at the request of an interested third party. However, Mexico’s federal regulatory landscape is expected to undergo significant transformation in the coming months, driven by the transition to a new federal administration. This transforma - tion follows the publication of an amendment to the Federal Mexican Constitution on 20 Decem - ber 2024. The primary objective of this amend - ment is to abolish certain governmental agen - cies, including the INAI. In response to this amendment, the Mexican Congress will comprehensively overhaul all secondary legal provisions currently governing the affected agencies. This process involves not only the dissolution of these agencies but also the establishment of new regulatory bodies to assume their roles and responsibilities. Current -

323 CHAMBERS.COM

Powered by