MEXICO Law and Practice Contributed by: Luciano Pérez, Ana Paula Silva and Allan Pastor, Nader Hayaux & Goebel
ly, it remains unclear which government agency will ultimately inherit the powers and duties pre - viously held by the INAI. The proposal suggests that responsibilities related to the private sector could be transferred to the Ministry of Anti-Cor - ruption and Good Governance. Furthermore, local congresses will need to adjust their legislative frameworks to align with the amendment. The impact of these changes on local governmental entities and their respec - tive authorities will depend significantly on the specific regulatory provisions implemented. The effects could range from minor procedural adjustments to substantial reforms in how local authorities manage their operations and engage with constituents. Despite these changes, there is no indication of amendments to the Mexican DPRs as a result of the replacement of the INAI. 1.3 Enforcement Proceedings and Fines Under the DPRs, currently the INAI may initiate the following procedures. • The ARCO Rights protection procedure can be initiated by the data subjects before the INAI, in which the data subjects can claim that the data controller has violated their rights of access, rectification, cancellation or opposition (the “ARCO Rights”). • The verification procedure can be initiated by the INAI ex officio or at the request of a third party, with the purpose of obtaining the appropriate information to verify any violation of the DPRs. If the INAI determines that the DPRs have been breached, it will commence the procedure for imposing sanctions.
The DPRs provide the following penalties: • a warning notice, exclusively applied when the data controller fails to comply with a request to exercise a data subject right; or • a fine, which varies depending on the infrac - tion of the DPR. Fines range from 100 to 320,000 times the daily minimum wage or the Unit of Measurement and Update (UMA). In 2024, each UMA was valued at MXN108.57 (approximately 5.43USD). Depend - ing on the circumstances, higher fines are imposed in cases involving sensitive personal data and data breaches. The DPRs also include the following criminal offences: • security violations committed by authorised personnel for profit are punished with three months to three years in prison; and • data processing offences related to deceit, taking advantage of the data subject’s or authorised personnel’s error to profit inappro - priately, are penalised with six months to five years in prison. If the infraction or conduct involves sensitive personal data, the fines are doubled. For Public DPRs, there is only the verification procedure. This procedure may be initiated by the INAI ex officio or at the request of a third party to verify a violation of the Public DPRs. Furthermore, each state has its own legislation on the subject. Considering the corresponding authorities closely resemble the INAI, proce - dures should be similar to those listed above. Nevertheless, it is essential to review the appli - cable provisions in each case.
324 CHAMBERS.COM
Powered by FlippingBook