Mexico
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Mexico's general privacy law does not care where you store data. There is no approved-country list, no standard contract to sign and no permission to ask for. You need the right wording in your privacy notice and, usually, the person's consent. The rules that actually pin data to Mexico live in banking, money-laundering and tax law, not in the privacy law.
Eight questions about Mexico
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Mexico's rules apply to my company?
Probably yes, but Mexico is unusually vague about it. The privacy law says only that it applies across Mexican territory. It does not spell out when it reaches a company based abroad. The old rulebook did say the law caught a foreign company that used equipment or systems located in Mexico, and let that company appoint a local representative instead of opening an office. That old rulebook belonged to a law that was scrapped in March 2025, so its status today is genuinely unclear. There is no revenue or headcount threshold to fall below.
The new Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), published 20 March 2025, states in article 1 only that it is 'de orden publico y de observancia general en todo el territorio nacional'. Unlike the European Union's General Data Protection Regulation it contains no targeting or monitoring test. The extraterritorial hook sat in article 4 of the 2011 Reglamento to the repealed 2010 law, which applied the regime where processing was carried out by a controller with an establishment in Mexico, by a processor acting for such a controller, or by a controller with no Mexican establishment that used 'medios situados en dicho territorio'. That article also permitted appointment of a representative rather than an establishment. The 2011 Reglamento has not been replaced and the law it regulated was abrogated by transitory article Segundo of the March 2025 decree. Two exclusions survive in article 1: credit bureaux (regulated separately) and purely personal, non-commercial data collection.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal Law on Protection of Personal Data Held by Private Parties, article 1 (scope and exclusions)
diputados.gob.mx
“La presente Ley es de orden público y de observancia general en todo el territorio nacional”
Link checked 18 August 2026
- Official sourceCámara de DiputadosRegulation to the Federal Law on Protection of Personal Data Held by Private Parties (21 December 2011), article 4 (when the regime applies to a controller outside Mexico)
diputados.gob.mx
“El responsable no esté establecido en territorio mexicano y utilice medios situados en dicho territorio, salvo que tales medios se utilicen únicamente con fines de tránsito”
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations - the only regulation listed for this law is still the one dated 21 December 2011
diputados.gob.mx
Link checked 18 August 2026
Can I store my users' data outside Mexico?
Under the general privacy law, yes, and with very little paperwork. Mexico has no list of approved countries and no list of banned ones. Sending data to a company abroad is treated exactly like sending it to a company down the road: say so in your privacy notice, get the person's consent unless one of seven exceptions applies, and pass the privacy notice on to whoever receives the data. Handing data to your own supplier who only follows your instructions is not even counted as a transfer. Five sectors override this, and in three of them the override is severe.
Articles 35 and 36 LFPDPPP. Article 35 requires the controller to pass the privacy notice and the purposes to the recipient, and requires the privacy notice to carry a clause by which the data subject accepts or refuses the transfer; the recipient assumes the same obligations as the transferor. Article 36 lists seven cases where no consent is needed: transfer required by a law or treaty; medical diagnosis, healthcare or health-service management; transfer to a holding company, subsidiary or affiliate under common control operating under the same internal policies; transfer necessary under a contract in the data subject's interest; safeguarding a public interest or the administration of justice; establishing, exercising or defending a right in judicial proceedings; and maintaining or performing a legal relationship with the data subject. Critically, the law draws the same line for domestic and international transfers - the word 'internacionales' triggers no additional requirement anywhere in the statute. Transmission to an 'encargado' (processor) is a 'remision', not a transfer, and is carved out of article 35. Sector overrides found: (1) BANKING - data can leave with the right paperwork. Article 328 of the CNBV banking rulebook requires the bank to obtain the Commission's authorisation, in every case, before contracting any operational process or database administration performed wholly or partly outside Mexico or by a non-resident, applying at least twenty business days ahead, and to satisfy a destination-country test and keep audit documentation in its Mexican head office. (2) SECURITIES - data can leave with the right paperwork. Article 206 Bis 2 of the brokerage rulebook imposes the same destination test and Mexican-head-office requirement but by twenty-business-day prior notice rather than authorisation. (3) FINTECH / CROWDFUNDING - a copy must stay in the country. Articles 85 and 86 of the fintech rulebook require CNBV authorisation and, separately, that the institution keep detailed records of every operation and its daily closing accounting records on its own premises, usable even when the outsourced service is unavailable. (4) INSURANCE - data can leave with the right paperwork; article 268 of the insurance law empowers the insurance regulator to designate outsourcing that needs prior authorisation, and to order suspension of the service. (5) TELECOMS - a copy must stay in the country in practice; article 183 of the 2025 telecoms law requires twenty-four months of communications records to be held in systems that allow real-time query and delivery to Mexican authorities, with a twenty-four-hour delivery deadline and a unit staffed around the clock. Two cross-cutting rules bite regardless of sector: the anti-money-laundering law requires ten years of records at an address registered with the Finance Ministry, and the Federal Tax Code requires supporting accounting documentation to be available at the taxpayer's Mexican fiscal domicile for five years. Checked on 18 August 2026: we found no localisation rule for health data, education, gaming, e-commerce or mapping and geospatial data. The statistics and geography law protects data given to the national statistics institute but imposes no storage-location duty on private companies.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 35 and 36 (transfers to third parties, domestic or foreign)
diputados.gob.mx
“Las transferencias nacionales o internacionales de datos podrán llevarse a cabo sin el consentimiento de la persona titular cuando se ubiquen en alguno de los supuestos siguientes”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328 (services performed outside Mexican territory)
cnbv.gob.mx
“Las Instituciones requerirán de la autorización de la Comisión, para la contratación con terceros de la prestación de servicios o comisiones, para la realización de un proceso operativo o para la administración de bases de datos, que se proporcionen o ejecuten parcial o totalmente fuera de territorio nacional o por residentes en el extranjero”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to broker-dealers, article 206 Bis 2 (offshore processing requires twenty business days' prior notice)
cnbv.gob.mx
“deberán dar aviso a la Comisión de la intención de contratar dicho proceso con una anticipación de por lo menos veinte días hábiles”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to financial technology institutions, article 86 (authorisation, destination-country test and on-premises records)
cnbv.gob.mx
“Los mecanismos que permitirán a la institución de financiamiento colectivo, mantener en sus instalaciones los registros detallados de todas las Operaciones que se realicen, así como de sus registros contables al cierre diario”
Link checked 18 August 2026
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law 2025, article 183 (communications records, real-time geolocation)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de DiputadosNational Statistical and Geographical Information System Law, articles 37 and 38 (confidentiality of data supplied to the statistics institute)
diputados.gob.mx
Link checked 18 August 2026
What do I need in place before data leaves Mexico?
Nothing needs approval and no list exists in either direction. The model is simply unrestricted: any destination is allowed. What you need is a privacy notice that names the transfer and carries a clause where the person accepts or refuses it, plus that person's consent unless one of seven legal exceptions covers you. Because there is no list to populate, the government cannot make this stricter by adding a country. It would take a new law or a new regulation.
There is no adequacy mechanism, no standard contractual clauses published by any Mexican authority, no binding corporate rules approval route and no registration of transfers. Article 37 LFPDPPP allows voluntary self-regulation schemes (codes of practice, trust seals) notified to the authority, but these complement the law rather than unlock transfers. The practical instrument is therefore the aviso de privacidad plus, in most cases, a data processing agreement driven by article 20 (confidentiality controls binding everyone involved in processing) and article 35 (the recipient assumes the transferor's obligations). Where the recipient is a group company under common control operating under the same internal policies, article 36 fraction III removes the consent requirement entirely, which is why intra-group transfers are the easy case in Mexico. In the financial sector the picture inverts: the CNBV performs a destination-country assessment that functions like an adequacy test, requiring evidence that the provider resides in a country whose domestic law protects personal data, or that has an international agreement with Mexico on data protection or on information exchange between supervisors.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 35, 36 and 37 (transfers and self-regulation schemes)
diputados.gob.mx
“El tratamiento de los datos se hará conforme a lo convenido en el aviso de privacidad, el cual contendrá una cláusula en la que se indique si la persona titular acepta o no la transferencia de sus datos”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328 fraction I (destination-country test applied by the banking regulator)
cnbv.gob.mx
“Que los terceros o comisionistas con los que se contrate residan en países cuyo derecho interno proporcione protección a los datos de las personas, resguardando su debida confidencialidad, o bien, los países de residencia mantengan suscritos con México acuerdos internacionales en dicha materia o de intercambio de información entre los organismos supervisores”
Link checked 18 August 2026
Who enforces the rules in Mexico, and what can they do?
Mexico abolished its independent privacy regulator. The National Institute for Transparency, Access to Information and Data Protection was wound up in March 2025 and its staff, files and cases were moved into a government ministry, the Anti-Corruption and Good Government Ministry. So the referee is now part of the government rather than independent of it. The ministry is staffed, but the law says the detailed procedure for complaints, inspections and fines will be set out in a regulation, and that regulation still has not been published. Financial regulators, by contrast, are visibly active and update their rulebooks almost monthly.
The decree of 20 March 2025 abrogated the 2010 privacy law and extinguished the Instituto Nacional de Transparencia, Acceso a la Informacion y Proteccion de Datos Personales (INAI). Transitory articles Quinto and Decimo Tercero moved INAI's staff and case files to the Secretaría Anticorrupción y Buen Gobierno, which operates the transparency function under the banner 'Transparencia para el Pueblo'. Articles 38 and 39 LFPDPPP give that ministry the objects and powers of the regulator; articles 40 to 57 set out the rights-protection, verification and sanction procedures, but each of those chapters expressly defers the form, terms and time limits to 'el Reglamento'. Transitory article Decimo Segundo required the Executive to issue the corresponding regulatory adjustments within ninety calendar days of entry into force, that is by approximately 18 June 2025. As at 18 August 2026 the official federal regulations index still lists only the 2011 Reglamento made under the repealed law. We could not evidence any published private-sector sanction decision under the new law from an official source. We therefore rate enforcement as waking rather than active: the powers exist and the obligations are live, but the machinery is unproven and the regulator is no longer independent. Sectoral enforcement is a different story. The banking regulator's rulebook has been amended by resolutions published in the official gazette on 26 and 27 March, 18 May, 5 and 12 June and 1, 2, 3 and 14 July 2026, which is direct evidence of an active supervisor. The telecoms regulator changed identity during the period: the Instituto Federal de Telecomunicaciones now serves only as a historical archive and directs all live business to the Comisión Reguladora de Telecomunicaciones, confirming that the new commission's board has been constituted and that the 2014 telecoms law has been abrogated.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 38 to 59 and transitory articles Segundo, Quinto, Decimo Segundo and Decimo Tercero (transfer of the regulator's functions to the ministry)
diputados.gob.mx
“Secretaria: Secretaría Anticorrupción y Buen Gobierno”
Link checked 18 August 2026
- Official sourceDiario Oficial de la FederaciónDecree of 20 March 2025 enacting the three transparency and data protection laws, Official Gazette of the Federation
dof.gob.mx
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations, checked 18 August 2026 - no regulation has been issued under the 2025 privacy law
diputados.gob.mx
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions - amendment history showing resolutions published up to 14 July 2026
cnbv.gob.mx
Link checked 18 August 2026
- Official sourceInstituto Federal de TelecomunicacionesFederal Telecommunications Institute website, now a historical archive redirecting to the Telecommunications Regulatory Commission
ift.org.mx
“Este sitio es un archivo historico del IFT disponible unicamente para consulta. Para tramites y servicios vigentes, visita la Comisión Reguladora de Telecomunicaciones”
Link checked 18 August 2026
How long do I have to keep the data?
There is no single retention period. The privacy law says delete data once it is no longer needed, after a blocking period equal to the time limit for suing over the relationship. One hard ceiling is written into the law: information about someone breaking a contract must be erased six years after the default. The floors are longer and come from other laws. Tax records must be kept five years and their supporting documents must be available at your Mexican tax address. Anti-money-laundering records must be kept ten years at an address you register with the Finance Ministry. Phone companies keep call and location records for two years. Where a floor and a ceiling clash, the floor wins, because the privacy law lets you keep data to meet a legal duty.
CEILINGS. Article 10 LFPDPPP: once data are no longer necessary for the purposes in the privacy notice they must be deleted after blocking, once the retention period ends. Article 10 also contains a rare absolute ceiling - data about breach of contractual obligations must be erased after seventy-two months from the date of the default. Article 24: cancellation triggers a blocking period equal to the limitation period for actions arising from the underlying legal relationship, after which the data are suppressed; the controller may keep them only for liabilities arising from the processing. Article 12 requires a specific effort to minimise the processing period for sensitive data. FLOORS. Federal Tax Code article 30: accounting and related documentation must be kept five years from the date the related return was or should have been filed, extended for the life of the company for incorporation deeds, capital changes, mergers, demergers and dividend records. Article 28 fraction III adds the location duty - the supporting documentation must be available at the taxpayer's fiscal domicile. Anti-money-laundering law articles 15 fraction IV and 18 fraction IV: at least ten years, and article 18 requires it to be kept physically or electronically 'en el domicilio registrado ante la Secretaria para este efecto'; the ten-year figure and the domicile wording were both set by the reform published 16 July 2025. Telecommunications law article 183 fraction II: twenty-four months, split as twelve months in systems allowing real-time query and twelve further months in electronic archive with a forty-eight-hour retrieval deadline. CONFLICT RESOLUTION. Article 36 fraction I and the general architecture of the law treat processing required by another law as lawful, so a statutory floor overrides the deletion duty for as long as the floor runs.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 10, 12 and 24 (deletion, blocking and the six-year ceiling on contractual default data)
diputados.gob.mx
“El responsable estará obligado a eliminar los datos relativos al incumplimiento de obligaciones contractuales, una vez que transcurra un plazo de setenta y dos meses”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFederal Tax Code, articles 28 fraction III and 30 (five-year retention; supporting documents available at the fiscal domicile)
diputados.gob.mx
“La documentación comprobatoria de dichos registros o asientos deberá estar disponible en el domicilio fiscal del contribuyente”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFederal Law for the Prevention and Identification of Operations with Illicit Proceeds, articles 15 and 18 (ten-year retention at a registered address)
diputados.gob.mx
“deberá conservarse de manera física o electrónica, en el domicilio registrado ante la Secretaría para este efecto, excepto para la fracción XIV del artículo 17 de esta Ley, por al menos un plazo de diez años”
Link checked 18 August 2026
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law 2025, article 183 fraction II (twelve months live plus twelve months archived)
diputados.gob.mx
Link checked 18 August 2026
What happens if there is a breach?
There are at least three clocks and they do not agree. Under the general privacy law you must tell the affected people immediately if a breach significantly harms their money or their reputation, and there is no duty to tell the regulator at all. Banks face a much tighter set: tell the banking regulator immediately, tell affected customers within forty-eight hours, file a full report within five working days, and send a remediation plan within fifteen working days of the incident ending. Phone companies must hand requested records to the authorities within twenty-four hours and keep a team available every hour of every day. Mexico has no general cyber-incident reporting law that catches everyone.
GENERAL LAW. Article 19 LFPDPPP: security breaches at any stage of processing that significantly affect the data subject's patrimonial or moral rights must be reported to the data subject 'de forma inmediata' so they can defend themselves. There is no stated hour count, no regulator notification duty, and no risk-threshold test beyond significance. This is materially lighter than the European Union's seventy-two-hour regulator notification. BANKING. Article 168 Bis 17 area of the CNBV banking rulebook: the chief executive must ensure information-security incidents are reported to the Commission immediately by email to a dedicated cybersecurity address with a timestamped acknowledgement, stating start time, whether it is ongoing, a description and an initial impact assessment. Reportable incidents are those causing economic loss, loss of information or service interruption; those whose method could be replicated at other institutions; those that could affect customers, the stability of the financial or payments system, central payment systems, their service providers, clearing houses or securities depositories; or any the institution considers serious. A full report following annexes 64 and 64 Bis is due within five business days of identification, and a remediation plan within fifteen business days of the incident concluding. Where sensitive information in the custody of the bank or its service providers was extracted, lost, deleted or altered, or unauthorised access is suspected, customers must be notified within forty-eight hours of the incident or of becoming aware of it. TELECOMS. Article 183 fractions III and IV of the 2025 telecoms law: conserved data must be handed to designated authorities within a maximum of twenty-four hours of notification, and the operator must maintain an area available twenty-four hours a day, three hundred and sixty-five days a year. The overlap that catches people is the banking one: forty-eight hours to customers is far shorter than the practical reading of 'immediately' most companies apply under the general law, and the five-business-day regulator report is easy to miss while incident response is still running.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 18 and 19 (security measures and breach notification to the data subject)
diputados.gob.mx
“Las vulneraciones de seguridad ocurridas en cualquier fase del tratamiento de datos personales que afecten de forma significativa los derechos patrimoniales o morales de las personas titulares le serán informadas de forma inmediata por el responsable”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions - information security incident reporting duties
cnbv.gob.mx
“dentro de las siguientes 48 horas a que ocurrió el Incidente de Seguridad de la Información o a que se tuvo conocimiento de éste”
Link checked 18 August 2026
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law 2025, article 183 fractions III and IV (twenty-four hour delivery, round-the-clock unit)
diputados.gob.mx
“están obligados a entregar la información dentro de un plazo máximo de veinticuatro horas siguientes, contado a partir de la notificación”
Link checked 18 August 2026
What trips people up in Mexico?
Five things catch people out. Every private business in Mexico is now legally required to ask customers for their national population ID number. Anti-money-laundering rules force many ordinary businesses to keep ten years of records at a Mexican address, which quietly rules out a pure foreign cloud setup. Mishandling data can put a person in prison, not just cost a company money. Banks must get written permission before any processing happens abroad, and that includes routine cloud hosting. And the rulebook the privacy law keeps pointing at does not exist.
1. THE POPULATION ID DUTY. The Ley General de Poblacion was amended on 16 July 2025 to make the Clave Unica de Registro de Poblacion (CURP) containing fingerprints and a photograph the compulsory national identity document. Article 91 Sexies states that 'todo ente publico o particular estara obligado a solicitar la Clave Unica de Registro de Poblacion para la prestacion de sus tramites y servicios', and transitory article Cuarto gave all public and private entities ninety calendar days from entry into force - roughly 15 October 2025 - to build the CURP into their processes. A statutory duty on every private company to collect a government identifier from every customer sits awkwardly against the privacy law's own minimisation principle in article 12, and nothing in either text resolves the tension. 2. TEN YEARS AT A MEXICAN ADDRESS. Article 18 fraction IV of the anti-money-laundering law requires records supporting a 'vulnerable activity' to be kept, physically or electronically, at the address registered with the Finance Ministry, for at least ten years. Vulnerable activities reach far beyond banks - real estate, vehicle dealers, jewellers, professional services, virtual asset providers and others. This is a storage-location duty hiding in a financial crime statute rather than in the privacy law, and most privacy programmes never look at it. 3. PRISON, NOT JUST FINES. Articles 62 to 64 LFPDPPP create criminal offences. Causing a security breach to a database in your custody, for profit, while authorised to process the data, carries three months to three years in prison. Processing data by deception for improper gain carries six months to five years. Where sensitive data are involved, both penalties double. These attach to individuals and sit alongside, not instead of, administrative fines and civil liability. 4. BANKING PERMISSION FOR ORDINARY CLOUD. Article 328 of the banking rulebook is not limited to material outsourcing. It applies 'en todo momento, con independencia de que los procesos de que se trate puedan o no afectar cualitativa o cuantitativamente' the bank's operations. Any operational process or database administration performed even partly outside Mexico needs the Commission's authorisation, applied for at least twenty business days ahead, with board or audit-committee approval on record covering geographic distance and language risk. Article 328 fraction II also requires the bank to keep evaluations, audit results and performance reports in its principal offices in Mexico and to produce them in Spanish on demand. 5. THE MISSING RULEBOOK. The 2025 law defers the procedure for rights complaints, verification and sanctions to a Reglamento that has not been issued, more than fourteen months after the ninety-day deadline in transitory article Decimo Segundo. Meanwhile the only published Reglamento regulates a law that no longer exists. Practitioners cannot safely rely on the 2011 text and have nothing else. 6. HONOURABLE MENTION - children. Unlike India or the United States, the Mexican privacy law sets no specific age threshold and no parental consent mechanism for children. That is a gap rather than a protection, and it means general civil-law capacity rules apply.
Sources
- Official sourceCámara de DiputadosGeneral Population Law, articles 91 Bis and 91 Sexies and transitory article Cuarto (biometric CURP as compulsory national identity document; duty on every public and private entity to request it)
diputados.gob.mx
“Todo ente público o particular estará obligado a solicitar la Clave Única de Registro de Población para la prestación de sus trámites y servicios”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFederal Law for the Prevention and Identification of Operations with Illicit Proceeds, article 18 fraction IV
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 62 to 64 (criminal offences for improper processing)
diputados.gob.mx
“Se impondrán de tres meses a tres años de prisión al que, estando autorizado para tratar datos personales, con ánimo de lucro, provoque una vulneración de seguridad a las bases de datos bajo su custodia”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328 fraction II (audit records must stay in the Mexican head office)
cnbv.gob.mx
“Que las Instituciones manifiesten a la Comisión que mantendrán en sus oficinas principales ubicadas en los Estados Unidos Mexicanos, al menos la documentación e información relativa a las evaluaciones, resultados de auditorías y reportes de desempeño”
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations showing the only data protection regulation is dated 21 December 2011
diputados.gob.mx
Link checked 18 August 2026
What is changing soon in Mexico?
The biggest thing coming is a regulation that is already overdue. The privacy law repeatedly says a rulebook will set the deadlines for complaints, inspections and fines, and the government missed its own June 2025 deadline to publish it. When it lands it could change how enforcement works overnight, with no consultation. Health law was changed in January 2026 to put telehealth on a statutory footing, and the biometric national ID is still being rolled out. The dangerous powers are the ones the government already holds rather than any bill in parliament.
EXPECTED WITHIN TWELVE MONTHS. 1. The Reglamento to the 2025 privacy law. Transitory article Decimo Segundo required it within ninety calendar days of 21 March 2025. It is over fourteen months overdue. It will define the sanction procedure, the verification procedure and the rights-protection procedure, and it is the single change most likely to shift Mexico's enforcement rating. 2. Continued rollout of the biometric CURP and the Plataforma Unica de Identidad. The platform was to be built within ninety days of 17 July 2025 and the biometric enrolment programme for children within one hundred and twenty days. Linkage to the national health register follows when that register starts operating. 3. Telehealth. Articles 71 Quinquies to 71 Septies were added to the General Health Law by the reform published 15 January 2026, requiring secure systems, informed consent and proper record-keeping for remote care. Secondary Mexican Official Standards are the natural next step. DORMANT SWITCHES - powers already held that could change the picture without warning. A. The banking regulator can add or tighten conditions in article 328 of its rulebook by a single resolution in the official gazette, as it did nine times between March and July 2026. A change there would immediately affect every bank's cloud arrangements. B. The insurance law, article 268 fraction IV, already empowers the insurance regulator to designate which outsourcing needs prior authorisation, and the final paragraph lets it order partial or total, temporary or definitive suspension of a service provided through a third party. Neither requires new legislation. C. The telecoms law lets the Telecommunications Regulatory Commission designate which authorised operators, beyond concession holders, are caught by the twenty-four-month retention and real-time geolocation duties in article 183. That designation is an administrative act. D. Because enforcement now sits inside a ministry rather than an independent institute, the intensity of privacy enforcement is a policy choice of the executive rather than of an autonomous body. We found no pending bill that would introduce a general data localisation requirement, checked 18 August 2026.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, transitory article Decimo Segundo (ninety-day deadline for the implementing regulation)
diputados.gob.mx
“La persona titular del Ejecutivo Federal deberá expedir las adecuaciones correspondientes a los reglamentos y demás disposiciones aplicables, incluida la emisión del Reglamento Interior de Transparencia para el Pueblo, dentro de los noventa días naturales siguientes a la entrada en vigor del presente Decreto”
Link checked 18 August 2026
- Official sourceCámara de DiputadosGeneral Health Law, articles 71 Sexies and 71 Septies on telehealth, added by the reform published 15 January 2026
diputados.gob.mx
“Los servicios de telesalud deberán cumplir con las siguientes condiciones”
Link checked 18 August 2026
- Official sourceCámara de DiputadosGeneral Population Law, transitory articles First to Fifth (Plataforma Unica de Identidad and biometric enrolment deadlines)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de DiputadosInsurance and Surety Institutions Law, article 268 (regulator may require prior authorisation and order suspension of outsourced services)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions - amendment history, nine resolutions between March and July 2026
cnbv.gob.mx
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
6 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules5 rules
Ley Federal de Protección de Datos Personales en Posesión de los Particulares
Act of parliament · New law published in the Diario Oficial de la Federación, 20 March 2025; last reform 14 November 2025
Mexico's general privacy law, in force since 21 March 2025. It is permissive on sending data abroad - no country list, no approval, no standard contract - but consent-heavy, and it carries criminal offences that attach to individuals. Fines are expressed in a national accounting unit rather than a share of turnover.
Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational
Transfer model: No restriction · Accepted routes: Nothing required, Explicit consent, Needed for a contract, Legal claims, Important public interest
What it makes you do
- Get consentConsent is the default basis. Sensitive data need express written consent.
- Tell people what you doThe privacy notice must carry a clause where the person accepts or refuses transfers to third parties.
- Let people see their data — within 480 hoursTwenty days to answer, then fifteen days to act. Both can be extended once.
- Let people correct their data — within 480 hours
- Let people delete their data — within 480 hoursCancellation triggers a blocking period equal to the limitation period of the underlying relationship.
- Let people object — within 480 hours
- Secure the data
- Tell affected peopleImmediately, where the breach significantly affects patrimonial or moral rights. No regulator notification duty.
- Publish a complaints contactA named person or department must handle rights requests. No requirement that they be in Mexico.
- Extra vendor secrecy termsConfidentiality controls must bind everyone involved in processing and survive the end of the relationship.
- Delete data after a period — 6 yearsData about breach of contractual obligations must be erased six years after the default.
What it costs if you get it wrong
- Fixed maximum fine: 160,000 UMA (about 18.8 million Mexican pesos) — about $1 millionMid-tier infringements, for example ignoring a rights request or processing in breach of the privacy notice
- Fixed maximum fine: 320,000 UMA (about 37.5 million Mexican pesos) — about $2 millionSerious infringements, including transferring data in breach of the law or a security breach caused by inadequate measures
- Fixed maximum fine: 640,000 UMA (about 75.1 million Mexican pesos) — about $4 millionSerious infringements involving sensitive data, where the penalty may be doubled
- Criminal liability: Five years' imprisonmentProcessing data by deception for improper gain; three years where an authorised person causes a breach for profit. Doubled for sensitive data.
- Claims by individualsCivil liability sits alongside administrative penalties
Sources
- Official sourceCámara de DiputadosFederal Law on Protection of Personal Data Held by Private Parties (consolidated official text)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceDiario Oficial de la FederaciónDecree of 20 March 2025 enacting the law, Official Gazette of the Federation
dof.gob.mx
Link checked 18 August 2026
- Official sourceInstituto Nacional de Estadística y GeografíaValue of the Unit of Measurement and Update (UMA) from 1 February 2026: 117.31 pesos per day
inegi.org.mx
“Los valores de la UMA que entrarán en vigor a partir del 1 de febrero de 2026 son: Diario 117.31 pesos mexicanos”
Link checked 18 August 2026
Reglamento de la Ley Federal de Protección de Datos Personales en Posesión de los Particulares
Directly binding regulation · Published in the Diario Oficial de la Federación, 21 December 2011
The 2011 rulebook is still printed and still the only data protection regulation on the official federal list, but the law it was made under was abolished on 21 March 2025. It supplies the extraterritorial scope test and the security detail the new law leaves blank, so it is widely relied on, yet its legal force is doubtful. Treat anything that depends on it as unsafe.
Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational
What it makes you do
- Appoint a local representativeArticle 4 allowed a controller outside Mexico using means located in Mexico to appoint a representative instead of establishing locally. Whether this still works is now uncertain.
- Assess high-risk projectsRisk analysis duties in the security chapter. Not restated in the 2025 statute.
Sources
- Official sourceCámara de DiputadosRegulation to the Federal Law on Protection of Personal Data Held by Private Parties, 21 December 2011
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de Diputados2025 privacy law, transitory article Segundo abrogating the 2010 law, and transitory article Decimo Segundo requiring new regulations within ninety days
diputados.gob.mx
“A la entrada en vigor del presente Decreto se abrogan las disposiciones siguientes: I. La Ley Federal de Protección de Datos Personales en Posesión de los Particulares, publicada en el Diario Oficial de la Federación el 5 de julio de 2010”
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations, checked 18 August 2026
diputados.gob.mx
Link checked 18 August 2026
Código Fiscal de la Federación, artículos 28 y 30
Act of parliament · Federal Tax Code, last reform published 9 April 2026
Every taxpayer must keep accounting records for five years, and the documents backing them up must be available at the taxpayer's registered Mexican tax address. Some records - company formation, capital changes, mergers - must be kept for as long as the company exists. This is a quiet mirroring requirement that applies to everyone, not just regulated firms.
Enforced by Tax Administration Service
What it makes you do
- Keep data for a minimum period — 5 yearsFive years from when the related return was or should have been filed. Indefinite for incorporation deeds, capital changes, mergers, demergers and dividend records.
- Keep the data in the countryThe documents supporting the accounting entries must be available at the taxpayer's Mexican fiscal domicile.
- Keep records of processingAccounting must be kept electronically and uploaded monthly to the tax authority's website.
Sources
- Official sourceCámara de DiputadosFederal Tax Code, article 28 fraction III and article 30
diputados.gob.mx
“La documentación comprobatoria de dichos registros o asientos deberá estar disponible en el domicilio fiscal del contribuyente”
Link checked 18 August 2026
Ley General de Población, artículos 91 Bis a 91 Sexies
Act of parliament · Articles added by the decree published in the Diario Oficial de la Federación, 16 July 2025
Mexico has made its population registry number, now carrying fingerprints and a photograph, the compulsory national identity document. Every private business must ask for it before providing a service, with a deadline that passed in October 2025. That is a legal duty to collect a government identifier from every customer, which pulls in the opposite direction from the privacy law's rule to collect as little as possible.
Enforced by Ministry of the Interior, National Population Registry
What it makes you do
- Allowed because the law requires it — from 15 October 2025Every public body and every private business must request the national population key (CURP) before providing its services.
- Tell people what you doBiometric enrolment itself requires the person's prior consent, but the duty on businesses to request the identifier does not.
Sources
- Official sourceCámara de DiputadosGeneral Population Law, articles 91 Bis to 91 Sexies and transitory articles First to Fifth
diputados.gob.mx
“La Clave Única de Registro de Población que, además de los datos previstos en el artículo 91 de esta Ley, contenga huellas dactilares y fotografía, será el documento nacional de identificación obligatorio, de aceptación universal y obligatoria en todo el territorio nacional”
Link checked 18 August 2026
Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados
Act of parliament · New law published in the Diario Oficial de la Federación, 20 March 2025; last reform 14 November 2025 · Government
Public bodies and their suppliers run on a separate law. It allows data to go abroad only where the recipient promises to protect it to the same standard, which is an accountability test rather than a country list. Anyone selling to Mexican government agencies inherits this through contract.
Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational
Transfer model: No restriction · Accepted routes: Nothing required, Explicit consent
What it makes you do
- Put a transfer safeguard in placeThe foreign recipient or processor must undertake to protect the data to the standard of this law.
- Tell people what you doThe privacy notice must be passed to every recipient.
- Get consentConsent is needed unless one of nine exceptions applies, including national security.
Sources
- Official sourceCámara de DiputadosGeneral Law on Protection of Personal Data Held by Obliged Subjects, articles 61 to 65
diputados.gob.mx
“El responsable sólo podrá transferir o hacer remisión de datos personales fuera del territorio nacional cuando el tercero receptor o la persona encargada se obligue a proteger los datos personales conforme a los principios y deberes que establece la presente Ley”
Link checked 18 August 2026
Industry rules6 rules
Disposiciones de carácter general aplicables a las instituciones de crédito, artículos 318, 326 a 328
Government rules · Published 2 December 2005, most recently amended by resolutions published 1, 2, 3 and 14 July 2026 · Banking
This is the real wall in Mexico. A bank must get the banking regulator's written permission before any operational process or database administration is carried out even partly outside Mexico, or by anyone resident abroad, and must apply at least twenty working days ahead. It applies to every such arrangement, whether or not it is important. Audit and performance records must stay in the bank's Mexican head office.
Enforced by National Banking and Securities Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in placeThe provider must reside in a country whose domestic law protects personal data, or whose country has an agreement with Mexico on data protection or on information exchange between supervisors.
- Register or notify — within 480 hoursApplication to the supervising vice-presidency of the Commission at least twenty business days before contracting.
- Keep the data in the countryEvaluations, audit results and provider performance reports must be held in the bank's principal offices in Mexico, and supplied in Spanish on request.
- Written vendor contractThe contract must cover subcontracting limits, dispute resolution, data protection duties, and secure return and deletion of data at the end of the service.
- Independent audit — 2 yearsCompliance audit at least every two years; the Commission may order one earlier.
- Report cyber incidentsImmediate email report to the Commission; full report within five business days; remediation plan within fifteen business days of the incident ending.
- Tell affected people — within 48 hoursCustomers must be told within forty-eight hours where sensitive information was extracted, lost, deleted, altered or accessed without authority.
What it costs if you get it wrong
- Order to stopThe Commission may act on the outsourcing arrangement where the rules are breached
- Criminal liabilityBreach of banking secrecy duties, which extend to the third-party provider and its staff
Sources
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328
cnbv.gob.mx
“Las Instituciones deberán solicitar la autorización de que se trata a la vicepresidencia de la Comisión encargada de su supervisión, con cuando menos veinte días hábiles de anticipación a la fecha en que pretendan contratar los servicios o la comisión que corresponda”
Link checked 18 August 2026
- Official sourceCámara de DiputadosCredit Institutions Law, article 46 Bis 1 (the enabling power, including the regulator's power to require prior authorisation)
diputados.gob.mx
Link checked 18 August 2026
Disposiciones de carácter general aplicables a las casas de bolsa, artículo 206 Bis 2
Government rules · CNBV general provisions for broker-dealers, article 206 Bis 2 · Securities
Stockbrokers get a lighter version of the banking rule. Any operational, technology or database process carried out even partly outside Mexico needs twenty working days' advance notice to the regulator, not its permission. The destination country still has to protect personal data, and audit paperwork still has to stay in Mexico.
Enforced by National Banking and Securities Commission
Transfer model: Approval each time · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What it makes you do
- Register or notify — within 480 hoursNotice, not permission: at least twenty business days before contracting. This is the key difference from banks.
- Put a transfer safeguard in placeSame destination-country test as banks.
- Keep the data in the countryEvaluations, audit results and provider performance reports must be kept in the firm's principal offices in Mexico, in Spanish on request.
Sources
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to broker-dealers, article 206 Bis 2
cnbv.gob.mx
“Las casas de bolsa al contratar con terceros la prestación de servicios para la realización de un proceso operativo, tecnológico o para la administración de bases de datos, que se proporcionen o ejecuten parcial o totalmente fuera de territorio nacional o por residentes en el extranjero”
Link checked 18 August 2026
- Official sourceCámara de DiputadosSecurities Market Law (enabling framework for the broker-dealer rulebook)
diputados.gob.mx
Link checked 18 August 2026
Disposiciones de carácter general aplicables a las instituciones de tecnología financiera, artículos 85 a 87
Government rules · Published 10 September 2018, most recently amended by resolution published 6 July 2026 · Payments
Crowdfunding platforms must keep their own copy of every transaction record and their daily accounts on their own premises, so that they still work if an outsourced supplier goes dark. Offshore outsourcing needs the regulator's permission and proof that the destination country protects personal data. Cloud applications must name the exact regions where data will sit.
Enforced by National Banking and Securities Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision
What it makes you do
- Keep the data in the countryDetailed records of every operation and the daily closing accounting records must be held on the institution's own premises, in a usable format, and remain usable if the outsourced service goes down.
- Register or notifyAuthorisation from the regulator, which is deemed granted if it does not answer within twenty-five business days.
- Put a transfer safeguard in placeFor offshore services, documentary evidence that the provider's country protects personal data or has an agreement with Mexico.
- Independent audit — 1 yearAnnual internal or external audit of the outsourced service.
- Secure the dataFor cloud services the application must state the cloud type and the specific regions where data will be stored and processed.
Sources
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to financial technology institutions, articles 85 to 87
cnbv.gob.mx
“Regiones específicas donde se almacenará y procesará la información”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFintech Law, article 54 (a fintech institution may contract services with third parties located in Mexico or abroad) and article 48 (record keeping)
diputados.gob.mx
“localizados en el territorio nacional o el extranjero”
Link checked 18 August 2026
Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, artículos 15 y 18
Act of parliament · Published 17 October 2012; retention and address duties as reformed by the decree published 16 July 2025 · Finance
This is the storage rule most companies miss because it lives in the anti-money-laundering law rather than the privacy law. Businesses carrying on a listed 'vulnerable activity' - which reaches estate agents, car dealers, jewellers, professional advisers and crypto firms, not just banks - must keep ten years of records at an address they have registered with the Finance Ministry. A purely foreign cloud arrangement with no Mexican address of record does not satisfy it.
Enforced by Financial Intelligence Unit, Ministry of Finance
What it makes you do
- Keep data for a minimum period — 10 yearsTen years, restarting where a legal challenge is brought.
- Keep the data in the countryThe records must be kept, physically or electronically, at the address registered with the Finance Ministry for that purpose.
- Register or notifyRegistration in the national register of persons carrying on vulnerable activities, through the government portal.
- Keep records of processingRecords must allow individual transactions to be reconstructed, including commercial correspondence between the parties.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep or produce required records
- Criminal liabilityConcealing or destroying records
Sources
- Official sourceCámara de DiputadosFederal Law for the Prevention and Identification of Operations with Illicit Proceeds, articles 15 fraction IV and 18 fraction IV
diputados.gob.mx
“La información y documentación a que se refiere el párrafo anterior deberá conservarse de manera física o electrónica, en el domicilio registrado ante la Secretaría para este efecto ... por al menos un plazo de diez años”
Link checked 18 August 2026
Ley en Materia de Telecomunicaciones y Radiodifusión, artículo 183
Act of parliament · New law published in the Diario Oficial de la Federación, 16 July 2025 · Telecoms
Phone and internet companies must keep two years of who-called-whom, where and on what device: twelve months instantly searchable, twelve months archived. Requested records must reach the authorities within twenty-four hours, and a team must be reachable at any hour on any day. The law is fully in force, but the 2014 law it replaced only fell away once the new regulator's board was constituted, which has now happened.
Enforced by Telecommunications Regulatory Commission
What it makes you do
- Keep data for a minimum period — 2 yearsTwelve months in systems allowing real-time query and delivery, then twelve months in electronic archive with forty-eight-hour retrieval.
- Keep logsSubscriber name and address, communication type, origin and destination, date, time and duration, first activation, cell identifier, device identifiers and the digital geographic position of the line.
- Keep the data in the countryNot stated as a location rule, but real-time delivery to Mexican authorities plus a twenty-four-hour maximum response make offshore-only storage impractical.
- Appoint a local representativeAn area must be available twenty-four hours a day, three hundred and sixty-five days a year.
- Delete data after a periodUse of the retained data for any purpose other than those in the law is prohibited and punishable.
What it costs if you get it wrong
- Criminal liabilityFailure to cooperate with real-time geolocation requests, and misuse of retained data
Sources
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law, article 183 and transitory articles Third, Fifth, Sixth and Eighth
diputados.gob.mx
“el concesionario y en su caso, el autorizado deberá conservar los datos referidos en el párrafo anterior durante los primeros doce meses en sistemas que permitan su consulta y entrega en tiempo real a las autoridades competentes”
Link checked 18 August 2026
- Official sourceInstituto Federal de TelecomunicacionesFederal Telecommunications Institute site, now an archive pointing to the Telecommunications Regulatory Commission - evidence the new commission's board is constituted
ift.org.mx
Link checked 18 August 2026
Ley de Instituciones de Seguros y de Fianzas, artículo 268
Act of parliament · Insurance and Surety Institutions Law, published 4 April 2013, last reform 14 November 2025 · Insurance
Insurers may outsource, including abroad, but the insurance regulator can decide which arrangements need its permission first, and can order a service switched off entirely. Insurance secrecy follows the data to the supplier and binds the supplier's staff even after they leave. We could not retrieve the regulator's detailed circular, so the precise offshore conditions are not confirmed.
Enforced by National Insurance and Surety Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Extra vendor secrecy termsInsurance secrecy binds the third-party provider and its directors and staff, and survives after they stop working there.
- Written vendor contractThe provider must give the regulator, external auditors and independent actuaries access to records and technical support.
- Register or notifyThe regulator may designate which types of outsourcing need its prior authorisation.
What it costs if you get it wrong
- Order to stopThe regulator may order partial or total, temporary or permanent suspension of a service provided through a third party
Sources
- Official sourceCámara de DiputadosInsurance and Surety Institutions Law, article 268
diputados.gob.mx
“quedando facultada la Comisión para señalar el tipo de operaciones en las que se requerirá de su autorización previa”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the Anti-Corruption and Good Government Ministry has issued any sanction or rights-protection decision against a private company under the 2025 privacy law
The ministry's pages on gob.mx returned a bot challenge to every automated request on 18 August 2026, and the official gazette's search form rejected our queries. We can evidence that it holds the powers and inherited the old institute's files, but not that it is deciding cases. Enforcement is rated 'waking' on that basis and should be re-checked.
Whether the 2011 Regulation to the repealed 2010 privacy law remains legally binding
The decree of 20 March 2025 abrogated the parent law but did not expressly repeal the regulation, and the official federal regulations index still lists it. Mexican doctrine is that a regulation depends on its enabling statute, and the new law's own transitory article Decimo Segundo ordered the Executive to adapt existing regulations. We mark it 'disapplied' as the more prudent reading, but no court ruling confirms this either way.
Whether the extraterritorial scope test survives, and therefore whether a foreign company with no Mexican establishment is caught
The test lived only in article 4 of the 2011 regulation. The 2025 statute is silent. Until a new regulation is published or a court rules, this is genuinely unsettled, which is why question one is rated medium confidence.
The precise offshore outsourcing conditions in the insurance regulator's circular (Circular Única de Seguros y Fianzas)
The National Insurance and Surety Commission's website would not serve the document to us on 18 August 2026. We cite the enabling statute instead, so the existence of the power is confirmed but its detailed conditions are not.
Whether any rule requires Mexican government or public-sector workloads to be hosted inside Mexico
No such rule was found in the public-sector data protection law, checked 18 August 2026. Federal ICT procurement policy is issued administratively by the digital transformation agency and we could not retrieve those documents because the government portal blocked automated access. Absence of a finding here is not proof of absence.
The peso to US dollar conversions given for the fine ceilings
The unit value is confirmed at 117.31 pesos per day from the national statistics institute's January 2026 release, but the dollar figures assume an exchange rate of roughly 18.3 pesos to the dollar, which we did not verify on 18 August 2026. Treat the dollar amounts as indicative only.
Whether any localisation or survey-permit rule applies to detailed mapping and geospatial data held by private companies
The statistics and geography law protects information supplied to the national institute and imposes confidentiality on the institute, but we found no storage-location duty on private holders of mapping data, checked 18 August 2026. Aerial survey permitting sits in separate aviation and defence instruments we did not reach within this run.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Mexico versus Argentina
- Mexico versus Armenia
- Mexico versus Australia
- Mexico versus Austria
- Mexico versus Azerbaijan
- Mexico versus Brazil
- Mexico versus Bulgaria
- Mexico versus Cambodia
- Mexico versus Canada
- Mexico versus China
- Mexico versus Croatia
- Mexico versus Cyprus
- Mexico versus Estonia
- Mexico versus France
- Mexico versus Georgia
- Mexico versus Germany
- Mexico versus Greece
- Mexico versus Hong Kong SAR
- Mexico versus Hungary
- Mexico versus Iceland
- Mexico versus India
- Mexico versus Indonesia
- Mexico versus Ireland
- Mexico versus Israel
- Mexico versus Italy
- Mexico versus Japan
- Mexico versus Latvia
- Mexico versus Lithuania
- Mexico versus Luxembourg
- Mexico versus Malta
- Mexico versus Mongolia
- Mexico versus Nepal
- Mexico versus Netherlands
- Mexico versus Poland
- Mexico versus Russia
- Mexico versus Saudi Arabia
- Mexico versus Serbia
- Mexico versus Singapore
- Mexico versus Slovakia
- Mexico versus Slovenia
- Mexico versus South Korea
- Mexico versus Spain
- Mexico versus Sri Lanka
- Mexico versus Sweden
- Mexico versus Switzerland
- Mexico versus Taiwan
- Mexico versus Thailand
- Mexico versus Turkey
- Mexico versus Ukraine
- Mexico versus United Arab Emirates
- Mexico versus United Kingdom
- Mexico versus United States
- Mexico versus Uzbekistan