Mexico Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) + AI Governance: AI Compliance Requirements
The LFPDPPP was entirely republished on 2025-03-20 (in force 2025-03-21), replacing the 2010 law. Enforcement transferred from the dissolved INAI (constitutional reform effective 2024-12-20) to the Secretariat of Anti-Corruption and Good Governance (SABG), a cabinet-level ministry. It requires explicit consent, a privacy notice (aviso de privacidad), and gives data subjects a right to object to fully-automated processing without human intervention that evaluates behavior, reliability, or professional performance and causes an undesired effect — a real, AI-specific provision the new law added. Penalties are now UMA-indexed (not tied to a fixed peso figure or to revenue). Mexico is also developing a National AI Strategy aligned with the OECD AI Principles. Organizations using AI to make decisions about Mexican individuals must comply with the LFPDPPP's automated-decision provisions.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
July 5, 2010
March 21, 2025
Administrative fines are UMA-indexed (Unidad de Medida y Actualización, an inflation-adjusted unit) per LFPDPPP Arts. 63-64: up to 320,000 UMA (~MXN 34.7-37.5 million, ~$1.8-2M USD at 2024-2025 UMA values) for grave infractions, doubled to up to 640,000 UMA (~MXN 70-75M) for violations involving sensitive personal data. No revenue-percentage penalty exists under Mexican law. Criminal penalties sit separately in Federal Penal Code Art. 211 bis: 3 months-3 years imprisonment for a basic profit-motive violation, 6 months-5 years for an aggravated/deceptive violation for economic benefit, doubled (up to 6 years) for sensitive data.
What Your Business Must Do
4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Privacy Notice (Aviso de Privacidad)
CriticalLFPDPPP Article 15-17 requires a Privacy Notice in Spanish informing individuals about the data controller, purpose of processing, data categories, and rights (ARCO: Access, Rectification, Cancellation, Opposition). AI systems processing Mexican personal data must have an updated aviso de privacidad — the 2025 republished law added a stricter requirement that processing for "similar or analogous" purposes not disclosed in the original notice requires fresh consent, not implied coverage under the existing notice.
Explicit Consent for Sensitive Data Processing
CriticalLFPDPPP Article 8-10 requires explicit (written or electronic) consent for processing sensitive personal data (health, biometric, financial, racial/ethnic origin). AI models trained on or using sensitive Mexican personal data require explicit consent from each individual.
Automated Decision-Making Disclosure
High PriorityThe 2025 republished LFPDPPP gives data subjects a right to object to processing carried out exclusively through automated means, without human intervention, that evaluates certain personal aspects (behavior, reliability, professional performance) and produces an undesired effect on them — a real, AI-specific provision. Organizations must inform individuals when significant decisions affecting them (credit, employment, insurance) are made exclusively by automated means and provide a mechanism to request human review.
ARCO Rights Response Procedure
High PriorityLFPDPPP Articles 23-36 require organizations to respond to Access, Rectification, Cancellation, and Opposition requests within 20 business days. AI systems must have a process to fulfill data subject requests including deletion from training data where feasible. Note: exercising ARCO rights may carry a cost to the data subject unless they provide the means/mechanism to reproduce the requested data.
Recent Regulatory Guidance
INAI (dissolved 2024) — Guidelines on AI and LFPDPPP Automated Decision-Making (2023, historical)
INAI (dissolved via constitutional reform effective 2024-12-20; enforcement now sits with the Secretariat of Anti-Corruption and Good Governance, SABG) published guidance applying the LFPDPPP to AI automated decisions: the aviso de privacidad must disclose AI-driven automated processing; significant decisions (credit, employment, insurance) made exclusively by AI require disclosure and a human review option; ARCO rights apply to AI-processed data and must be fulfilled within 20 business days; explicit consent required for AI processing of sensitive data. The 2025 republished LFPDPPP substantially preserves this framework and adds an explicit right to object to fully-automated, no-human-intervention evaluative processing.
Frequently Asked Questions
Does Mexico Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) + AI Governance apply to my business?
The LFPDPPP was entirely republished on 2025-03-20 (in force 2025-03-21), replacing the 2010 law. Enforcement transferred from the dissolved INAI (constitutional reform effective 2024-12-20) to the Secretariat of Anti-Corruption and Good Governance… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Mexico Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) + AI Governance is: Administrative fines are UMA-indexed (Unidad de Medida y Actualización, an inflation-adjusted unit) per LFPDPPP Arts. 63-64: up to 320,000 UMA (~MXN 34.7-37.5 million, ~$1.8-2M USD at 2024-2025 UMA values) for grave infractions, doubled to up to 640,000 UMA (~MXN 70-75M) for violations involving sensitive personal data. No revenue-percentage penalty exists under Mexican law. Criminal penalties sit separately in Federal Penal Code Art. 211 bis: 3 months-3 years imprisonment for a basic profit-motive violation, 6 months-5 years for an aggravated/deceptive violation for economic benefit, doubled (up to 6 years) for sensitive data.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Mexico Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) + AI Governance?
The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdfLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan