Mexico
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Mexico — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Mexico's general privacy law does not care where you store data. There is no approved-country list, no standard contract to sign and no permission to ask for. You need the right wording in your privacy notice and, usually, the person's consent. The rules that actually pin data to Mexico live in banking, money-laundering and tax law, not in the privacy law.
Data governance in Mexico
The eight things that decide how you handle data about people in Mexico. Same eight on every country page, so you can compare.
Who has to follow these rules
Probably yes, but Mexico is unusually vague about it. The privacy law says only that it applies across Mexican territory. It does not spell out when it reaches a company based abroad. The old rulebook did say the law caught a foreign company that used equipment or systems located in Mexico. It also let that company appoint a local representative instead of opening an office. That old rulebook belonged to a law that was scrapped in March 2025, so its status today is unclear. There is no revenue or headcount threshold to fall below.
The new Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), published 20 March 2025, says in article 1 only that it is 'de orden publico y de observancia general en todo el territorio nacional'. Unlike the European Union's General Data Protection Regulation, it has no targeting or monitoring test. The rule that reached foreign companies sat in article 4 of the 2011 Reglamento, made under the 2010 law that has since been repealed. That article applied the rules in three cases: work done by a company with a business in Mexico, work done by a supplier acting for such a company, and work done by a company with no Mexican business that used 'medios situados en dicho territorio'. It also let such a company appoint a representative rather than set up an office. The 2011 Reglamento has not been replaced. The law it was made under was abolished by transitory article Segundo of the March 2025 decree. Two exclusions survive in article 1: credit bureaux, which are regulated separately, and purely personal, non-commercial data collection.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal Law on Protection of Personal Data Held by Private Parties, article 1 (scope and exclusions)
diputados.gob.mx
“La presente Ley es de orden público y de observancia general en todo el territorio nacional”
Link checked 18 August 2026
- Official sourceCámara de DiputadosRegulation to the Federal Law on Protection of Personal Data Held by Private Parties (21 December 2011), article 4 (when the regime applies to a controller outside Mexico)
diputados.gob.mx
“El responsable no esté establecido en territorio mexicano y utilice medios situados en dicho territorio, salvo que tales medios se utilicen únicamente con fines de tránsito”
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations - the only regulation listed for this law is still the one dated 21 December 2011
diputados.gob.mx
Link checked 18 August 2026
Where the data is allowed to live
Under the general privacy law, yes, and with very little paperwork. Mexico has no list of approved countries and no list of banned ones. Sending data to a company abroad is treated exactly like sending it to a company down the road: say so in your privacy notice, get the person's consent unless one of seven exceptions applies, and pass the privacy notice on to whoever receives the data. Handing data to your own supplier who only follows your instructions is not even counted as a transfer. Five sectors override this, and in three of them the override is severe.
Articles 35 and 36 LFPDPPP. Article 35 makes you pass your privacy notice and the purposes on to whoever receives the data. Your privacy notice must carry a clause where the person accepts or refuses the transfer. Whoever receives the data takes on the same duties as you. Article 36 lists seven cases where you need no consent. Those are: a law or treaty requires the transfer; medical diagnosis, healthcare or health-service management; a transfer to a parent company, subsidiary or affiliate under common control that follows the same internal policies; a transfer needed under a contract in the person's interest; protecting a public interest or the administration of justice; establishing, exercising or defending a right in court; and maintaining or performing a legal relationship with the person. The important point is that the law treats domestic and international transfers the same. The word 'internacionales' triggers no extra requirement anywhere in the law. Handing data to your own supplier who only follows your instructions is a 'remision', not a transfer, and article 35 does not cover it. Industry overrides we found: (1) BANKING - data can leave only if conditions are met Article 328 of the CNBV banking rulebook makes the bank get the Commission's permission, in every case, before it contracts out any operational work or database administration done wholly or partly outside Mexico, or by a non-resident. The bank must apply at least twenty business days ahead. It must satisfy a test about the destination country and keep audit paperwork in its Mexican head office. (2) SECURITIES - data can leave only if conditions are met Article 206 Bis 2 of the brokerage rulebook sets the same destination test and the same Mexican head office requirement. But it needs twenty business days' notice rather than permission. (3) FINTECH AND CROWDFUNDING - a copy must stay in the country Articles 85 and 86 of the fintech rulebook require CNBV permission. Separately, the firm must keep detailed records of every transaction and its daily closing accounts on its own premises, usable even when the outsourced service is down. (4) INSURANCE - data can leave only if conditions are met Article 268 of the insurance law lets the insurance regulator decide which outsourcing needs permission first, and lets it order a service suspended. (5) TELECOMS - a copy must stay in the country in effect. Article 183 of the 2025 telecoms law makes operators hold twenty-four months of communications records in systems that allow real-time search and delivery to Mexican authorities. There is a twenty-four-hour delivery deadline and a unit staffed around the clock. Two rules apply whatever your industry. Anti-money-laundering law requires ten years of records at an address registered with the Finance Ministry. The Federal Tax Code requires supporting accounting documents to be available at your Mexican tax address for five years. Checked on 18 August 2026: we found no rule about where data must be stored for health data, education, gaming, e-commerce, or mapping and geospatial data. The statistics and geography law protects data given to the national statistics institute. It sets no storage-location duty on private companies.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 35 and 36 (transfers to third parties, domestic or foreign)
diputados.gob.mx
“Las transferencias nacionales o internacionales de datos podrán llevarse a cabo sin el consentimiento de la persona titular cuando se ubiquen en alguno de los supuestos siguientes”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328 (services performed outside Mexican territory)
cnbv.gob.mx
“Las Instituciones requerirán de la autorización de la Comisión, para la contratación con terceros de la prestación de servicios o comisiones, para la realización de un proceso operativo o para la administración de bases de datos, que se proporcionen o ejecuten parcial o totalmente fuera de territorio nacional o por residentes en el extranjero”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to broker-dealers, article 206 Bis 2 (offshore processing requires twenty business days' prior notice)
cnbv.gob.mx
“deberán dar aviso a la Comisión de la intención de contratar dicho proceso con una anticipación de por lo menos veinte días hábiles”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to financial technology institutions, article 86 (authorisation, destination-country test and on-premises records)
cnbv.gob.mx
“Los mecanismos que permitirán a la institución de financiamiento colectivo, mantener en sus instalaciones los registros detallados de todas las Operaciones que se realicen, así como de sus registros contables al cierre diario”
Link checked 18 August 2026
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law 2025, article 183 (communications records, real-time geolocation)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de DiputadosNational Statistical and Geographical Information System Law, articles 37 and 38 (confidentiality of data supplied to the statistics institute)
diputados.gob.mx
Link checked 18 August 2026
What to do: Plan for a database inside Mexico: this data is not allowed to leave.
Sending data out of the country
Nothing needs approval and no list exists in either direction. The model is simply unrestricted: any destination is allowed. What you need is a privacy notice that names the transfer and carries a clause where the person accepts or refuses it, plus that person's consent unless one of seven legal exceptions covers you. Because there is no list to populate, the government cannot make this stricter by adding a country. It would take a new law or a new regulation.
- Ways to send data out:
- Nothing required · Explicit consent · Needed for a contract · Government sign-off needed
Mexico has no official decision that a country is safe enough, no standard contract clauses published by any Mexican authority, no group-wide rules approval route and no register of transfers. Article 37 LFPDPPP allows voluntary self-regulation schemes, such as codes of practice and trust seals, notified to the authority. These sit alongside the law rather than unlocking transfers. So what you actually need is the aviso de privacidad. In most cases you also need a data protection contract. That is driven by article 20, which makes confidentiality controls bind everyone who handles the data, and by article 35, which makes the recipient take on your duties. Where the recipient is a group company under common control following the same internal policies, article 36 fraction III removes the consent requirement entirely. That is why transfers inside a group are the easy case in Mexico. In the financial sector it works the other way round. The CNBV assesses the destination country itself. It asks for evidence that the provider is based in a country whose own law protects personal data, or that has an agreement with Mexico on data protection or on information sharing between supervisors.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 35, 36 and 37 (transfers and self-regulation schemes)
diputados.gob.mx
“El tratamiento de los datos se hará conforme a lo convenido en el aviso de privacidad, el cual contendrá una cláusula en la que se indique si la persona titular acepta o no la transferencia de sus datos”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328 fraction I (destination-country test applied by the banking regulator)
cnbv.gob.mx
“Que los terceros o comisionistas con los que se contrate residan en países cuyo derecho interno proporcione protección a los datos de las personas, resguardando su debida confidencialidad, o bien, los países de residencia mantengan suscritos con México acuerdos internacionales en dicha materia o de intercambio de información entre los organismos supervisores”
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
Mexico abolished its independent privacy regulator. The National Institute for Transparency, Access to Information and Data Protection was wound up in March 2025 and its staff, files and cases were moved into a government ministry, the Anti-Corruption and Good Government Ministry. So the referee is now part of the government rather than independent of it. The ministry is staffed, but the law says the detailed procedure for complaints, inspections and fines will be set out in a regulation, and that regulation still has not been published. Financial regulators, by contrast, are visibly active and update their rulebooks almost monthly.
The decree of 20 March 2025 abolished the 2010 privacy law and wound up the Instituto Nacional de Transparencia, Acceso a la Informacion y Proteccion de Datos Personales (INAI). Transitory articles Quinto and Decimo Tercero moved INAI's staff and case files to the Secretaría Anticorrupción y Buen Gobierno. That ministry runs the transparency function under the banner 'Transparencia para el Pueblo'. Articles 38 and 39 LFPDPPP give the ministry the regulator's role and powers. Articles 40 to 57 set out the procedures for protecting people's rights, for inspections and for fines. But each of those chapters leaves the form, terms and time limits to 'el Reglamento'. Transitory article Decimo Segundo told the Executive to issue the matching regulations within ninety calendar days of the law starting, so by about 18 June 2025. As at 18 August 2026 the official federal regulations index still lists only the 2011 Reglamento, made under the repealed law. We found no published fine against a private company under the new law from an official source. So we rate enforcement as waking rather than active. The powers exist and the duties are live. But the machinery is unproven and the regulator is no longer independent. Industry enforcement is a different story. The banking regulator's rulebook was amended by resolutions published in the official gazette on 26 and 27 March, 18 May, 5 and 12 June, and 1, 2, 3 and 14 July 2026. That is direct evidence of an active supervisor. The telecoms regulator changed identity during the period. The Instituto Federal de Telecomunicaciones is now only a historical archive and sends all live business to the Comisión Reguladora de Telecomunicaciones. That confirms the new commission's board is in place and the 2014 telecoms law has been abolished.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 38 to 59 and transitory articles Segundo, Quinto, Decimo Segundo and Decimo Tercero (transfer of the regulator's functions to the ministry)
diputados.gob.mx
“Secretaria: Secretaría Anticorrupción y Buen Gobierno”
Link checked 18 August 2026
- Official sourceDiario Oficial de la FederaciónDecree of 20 March 2025 enacting the three transparency and data protection laws, Official Gazette of the Federation
dof.gob.mx
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations, checked 18 August 2026 - no regulation has been issued under the 2025 privacy law
diputados.gob.mx
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions - amendment history showing resolutions published up to 14 July 2026
cnbv.gob.mx
Link checked 18 August 2026
- Official sourceInstituto Federal de TelecomunicacionesFederal Telecommunications Institute website, now a historical archive redirecting to the Telecommunications Regulatory Commission
ift.org.mx
“Este sitio es un archivo historico del IFT disponible unicamente para consulta. Para tramites y servicios vigentes, visita la Comisión Reguladora de Telecomunicaciones”
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is no single retention period. The privacy law says delete data once it is no longer needed, after a blocking period equal to the time limit for suing over the relationship. One hard ceiling is written into the law: information about someone breaking a contract must be erased six years after the default. The floors are longer and come from other laws. Tax records must be kept five years and their supporting documents must be available at your Mexican tax address. Anti-money-laundering records must be kept ten years at an address you register with the Finance Ministry. Phone companies keep call and location records for two years. Where a floor and a ceiling clash, the floor wins, because the privacy law lets you keep data to meet a legal duty.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
WHAT YOU MUST DELETE. Article 10 LFPDPPP: once you no longer need the data for the purposes in your privacy notice, you must block it and then delete it, once the retention period ends. Article 10 also sets a rare absolute limit. Data about someone breaking a contract must be erased seventy-two months after the default. Article 24: when someone asks you to cancel their data, you first block it for a period equal to the time limit for suing over the underlying relationship. After that you delete it. You may only keep it for liabilities arising from your own handling of it. Article 12 makes you take specific steps to shorten how long you keep sensitive data. WHAT YOU MUST KEEP. Federal Tax Code article 30: keep accounting and related documents for five years from the date the related return was, or should have been, filed. Keep them for the life of the company for incorporation deeds, capital changes, mergers, demergers and dividend records. Article 28 fraction III adds the location duty. The supporting documents must be available at your Mexican tax address. Anti-money-laundering law articles 15 fraction IV and 18 fraction IV: at least ten years. Article 18 says the records must be kept, on paper or electronically, 'en el domicilio registrado ante la Secretaria para este efecto'. The ten-year figure and the address wording were both set by the reform published 16 July 2025. Telecommunications law article 183 fraction II: twenty-four months. That splits into twelve months in systems allowing real-time search, and twelve further months in an electronic archive with a forty-eight-hour retrieval deadline. WHICH WINS. Article 36 fraction I and the general design of the law treat work required by another law as lawful. So a legal duty to keep records overrides the duty to delete for as long as that duty runs.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 10, 12 and 24 (deletion, blocking and the six-year ceiling on contractual default data)
diputados.gob.mx
“El responsable estará obligado a eliminar los datos relativos al incumplimiento de obligaciones contractuales, una vez que transcurra un plazo de setenta y dos meses”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFederal Tax Code, articles 28 fraction III and 30 (five-year retention; supporting documents available at the fiscal domicile)
diputados.gob.mx
“La documentación comprobatoria de dichos registros o asientos deberá estar disponible en el domicilio fiscal del contribuyente”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFederal Law for the Prevention and Identification of Operations with Illicit Proceeds, articles 15 and 18 (ten-year retention at a registered address)
diputados.gob.mx
“deberá conservarse de manera física o electrónica, en el domicilio registrado ante la Secretaría para este efecto, excepto para la fracción XIV del artículo 17 de esta Ley, por al menos un plazo de diez años”
Link checked 18 August 2026
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law 2025, article 183 fraction II (twelve months live plus twelve months archived)
diputados.gob.mx
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least three clocks and they do not agree. Under the general privacy law you must tell the affected people immediately if a breach significantly harms their money or their reputation, and there is no duty to tell the regulator at all. Banks face a much tighter set: tell the banking regulator immediately, tell affected customers within forty-eight hours, file a full report within five working days, and send a remediation plan within fifteen working days of the incident ending. Phone companies must hand requested records to the authorities within twenty-four hours and keep a team available every hour of every day. Mexico has no general cyber-incident reporting law that catches everyone.
- What you have to do here:
- Tell affected people · Report cyber incidents · Secure the data
GENERAL LAW. Article 19 LFPDPPP: if a security breach at any stage significantly harms a person's money or their reputation, you must tell that person 'de forma inmediata', so they can protect themselves. There is no stated hour count. There is no duty to tell the regulator. There is no risk threshold beyond significance. This is much lighter than the European Union's seventy-two-hour regulator report. BANKING. Article 168 Bis 17 of the CNBV banking rulebook: the chief executive must make sure information-security incidents are reported to the Commission immediately, by email to a dedicated cybersecurity address, with a timestamped acknowledgement. The report must state the start time, whether it is ongoing, a description and a first assessment of the impact. You must report incidents that cause financial loss, loss of information or service interruption. You must also report incidents whose method could be repeated at other institutions. So must you report incidents that could affect customers, the stability of the financial or payments system, central payment systems, their service providers, clearing houses or securities depositories. You must also report anything else the institution considers serious. A full report following annexes 64 and 64 Bis is due within five business days of identifying the incident. A remediation plan is due within fifteen business days of the incident ending. Where sensitive information held by the bank or its suppliers was taken, lost, deleted or altered, or unauthorised access is suspected, you must tell customers within forty-eight hours of the incident, or of finding out about it. TELECOMS. Article 183 fractions III and IV of the 2025 telecoms law: retained data must reach the designated authorities within twenty-four hours of the request at the latest. The operator must keep a team available twenty-four hours a day, three hundred and sixty-five days a year. The overlap that catches people is the banking one. Forty-eight hours to customers is far shorter than most companies' reading of 'immediately' under the general law. And the five-business-day regulator report is easy to miss while you are still dealing with the incident.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 18 and 19 (security measures and breach notification to the data subject)
diputados.gob.mx
“Las vulneraciones de seguridad ocurridas en cualquier fase del tratamiento de datos personales que afecten de forma significativa los derechos patrimoniales o morales de las personas titulares le serán informadas de forma inmediata por el responsable”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions - information security incident reporting duties
cnbv.gob.mx
“dentro de las siguientes 48 horas a que ocurrió el Incidente de Seguridad de la Información o a que se tuvo conocimiento de éste”
Link checked 18 August 2026
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law 2025, article 183 fractions III and IV (twenty-four hour delivery, round-the-clock unit)
diputados.gob.mx
“están obligados a entregar la información dentro de un plazo máximo de veinticuatro horas siguientes, contado a partir de la notificación”
Link checked 18 August 2026
What to do: Your breach process has to tell the affected people, not just the regulator.
What catches people out
Five things catch people out. Every private business in Mexico is now legally required to ask customers for their national population ID number. Anti-money-laundering rules force many ordinary businesses to keep ten years of records at a Mexican address, which quietly rules out a pure foreign cloud setup. Mishandling data can put a person in prison, not just cost a company money. Banks must get written permission before any data is handled abroad, and that includes routine cloud hosting. And the rulebook the privacy law keeps pointing at does not exist.
- What you have to do here:
- Keep data for a minimum period · Register or notify
- What it costs if you get it wrong:
- Criminal liability
1. THE POPULATION ID DUTY. The Ley General de Poblacion was amended on 16 July 2025. It made the Clave Unica de Registro de Poblacion (CURP), which now carries fingerprints and a photograph, the compulsory national identity document. Article 91 Sexies says that 'todo ente publico o particular estara obligado a solicitar la Clave Unica de Registro de Poblacion para la prestacion de sus tramites y servicios'. Transitory article Cuarto gave all public and private bodies ninety calendar days from the start date, so roughly 15 October 2025, to build the CURP into their processes. A legal duty on every private company to collect a government identifier from every customer sits awkwardly next to the privacy law's own rule in article 12 to collect as little as possible. Neither text resolves the tension. 2. TEN YEARS AT A MEXICAN ADDRESS. Article 18 fraction IV of the anti-money-laundering law makes you keep records supporting a 'vulnerable activity' for at least ten years, on paper or electronically, at the address you registered with the Finance Ministry. Vulnerable activities reach far beyond banks. They cover estate agents, vehicle dealers, jewellers, professional services, virtual asset providers and others. This is a storage-location duty hiding in a financial crime law rather than in the privacy law. Most privacy programmes never look at it. 3. PRISON, NOT JUST FINES. Articles 62 to 64 LFPDPPP create criminal offences. Causing a security breach to a database in your care, for profit, while you are authorised to handle the data, carries three months to three years in prison. Handling data by deception for improper gain carries six months to five years. Where sensitive data is involved, both penalties double. These attach to individuals. They sit alongside administrative fines and civil liability, not instead of them. 4. BANKING PERMISSION FOR ORDINARY CLOUD. Article 328 of the banking rulebook is not limited to important outsourcing. It applies 'en todo momento, con independencia de que los procesos de que se trate puedan o no afectar cualitativa o cuantitativamente' the bank's operations. Any operational work or database administration done even partly outside Mexico needs the Commission's permission. You must apply at least twenty business days ahead. The board or audit committee must have approved it on record, covering distance and language risk. Article 328 fraction II also makes the bank keep evaluations, audit results and performance reports in its main offices in Mexico, and produce them in Spanish on demand. 5. THE MISSING RULEBOOK. The 2025 law leaves the procedure for rights complaints, inspections and fines to a Reglamento that has not been issued. That is more than fourteen months after the ninety-day deadline in transitory article Decimo Segundo. Meanwhile the only published Reglamento covers a law that no longer exists. You cannot safely rely on the 2011 text, and there is nothing else. 6. WORTH KNOWING - children. Unlike India or the United States, the Mexican privacy law sets no specific age threshold and no parental consent step for children. That is a gap rather than a protection. General civil-law rules on capacity apply instead.
Sources
- Official sourceCámara de DiputadosGeneral Population Law, articles 91 Bis and 91 Sexies and transitory article Cuarto (biometric CURP as compulsory national identity document; duty on every public and private entity to request it)
diputados.gob.mx
“Todo ente público o particular estará obligado a solicitar la Clave Única de Registro de Población para la prestación de sus trámites y servicios”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFederal Law for the Prevention and Identification of Operations with Illicit Proceeds, article 18 fraction IV
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, articles 62 to 64 (criminal offences for improper processing)
diputados.gob.mx
“Se impondrán de tres meses a tres años de prisión al que, estando autorizado para tratar datos personales, con ánimo de lucro, provoque una vulneración de seguridad a las bases de datos bajo su custodia”
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328 fraction II (audit records must stay in the Mexican head office)
cnbv.gob.mx
“Que las Instituciones manifiesten a la Comisión que mantendrán en sus oficinas principales ubicadas en los Estados Unidos Mexicanos, al menos la documentación e información relativa a las evaluaciones, resultados de auditorías y reportes de desempeño”
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations showing the only data protection regulation is dated 21 December 2011
diputados.gob.mx
Link checked 18 August 2026
What's changing next
The biggest thing coming is a regulation that is already overdue. The privacy law repeatedly says a rulebook will set the deadlines for complaints, inspections and fines, and the government missed its own June 2025 deadline to publish it. When it lands it could change how enforcement works overnight, with no consultation. Health law was changed in January 2026 to put telehealth on a statutory footing, and the biometric national ID is still being rolled out. The dangerous powers are the ones the government already holds rather than any bill in parliament.
EXPECTED WITHIN TWELVE MONTHS. 1. The Reglamento to the 2025 privacy law. Transitory article Decimo Segundo required it within ninety calendar days of 21 March 2025. It is over fourteen months late. It will set the procedures for fines, inspections and protecting people's rights. It is the single change most likely to shift Mexico's enforcement rating. 2. Continued rollout of the biometric CURP and the Plataforma Unica de Identidad. The platform was to be built within ninety days of 17 July 2025, and the biometric enrolment programme for children within one hundred and twenty days. Linking it to the national health register follows when that register starts working. 3. Telehealth. Articles 71 Quinquies to 71 Septies were added to the General Health Law by the reform published 15 January 2026. They require secure systems, informed consent and proper record-keeping for remote care. Detailed Mexican Official Standards are the natural next step. POWERS ALREADY HELD that could change the answer without warning. A. The banking regulator can add or tighten conditions in article 328 of its rulebook with a single resolution in the official gazette. It did that nine times between March and July 2026. A change there would immediately affect every bank's cloud arrangements. B. The insurance law, article 268 fraction IV, already lets the insurance regulator decide which outsourcing needs permission first. The final paragraph lets it suspend a service provided through a third party, in part or in full, temporarily or permanently. Neither needs new legislation. C. The telecoms law lets the Telecommunications Regulatory Commission decide which authorised operators, beyond concession holders, are caught by the twenty-four-month retention and real-time location duties in article 183. That decision is an administrative act. D. Enforcement now sits inside a ministry rather than an independent institute. So how hard privacy rules are enforced is now a policy choice of the executive, not of an independent body. We found no pending bill that would require data to stay in Mexico, checked 18 August 2026.
Sources
- Official sourceCámara de Diputados (official consolidated text)Federal privacy law, transitory article Decimo Segundo (ninety-day deadline for the implementing regulation)
diputados.gob.mx
“La persona titular del Ejecutivo Federal deberá expedir las adecuaciones correspondientes a los reglamentos y demás disposiciones aplicables, incluida la emisión del Reglamento Interior de Transparencia para el Pueblo, dentro de los noventa días naturales siguientes a la entrada en vigor del presente Decreto”
Link checked 18 August 2026
- Official sourceCámara de DiputadosGeneral Health Law, articles 71 Sexies and 71 Septies on telehealth, added by the reform published 15 January 2026
diputados.gob.mx
“Los servicios de telesalud deberán cumplir con las siguientes condiciones”
Link checked 18 August 2026
- Official sourceCámara de DiputadosGeneral Population Law, transitory articles First to Fifth (Plataforma Unica de Identidad and biometric enrolment deadlines)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de DiputadosInsurance and Surety Institutions Law, article 268 (regulator may require prior authorisation and order suspension of outsourced services)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions - amendment history, nine resolutions between March and July 2026
cnbv.gob.mx
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking data must stay in the country
Official name: Disposiciones de carácter general aplicables a las instituciones de crédito, artículos 318, 326 a 328 · Published 2 December 2005, most recently amended by resolutions published 1, 2, 3 and 14 July 2026 · Government rules
This is the real wall in Mexico. A bank must get the banking regulator's written permission before any operational process or database administration is carried out even partly outside Mexico, or by anyone resident abroad, and must apply at least twenty working days ahead. It applies to every such arrangement, whether or not it is important. Audit and performance records must stay in the bank's Mexican head office.
Enforced by National Banking and Securities Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in placeThe provider must reside in a country whose domestic law protects personal data, or whose country has an agreement with Mexico on data protection or on information exchange between supervisors.
- Register or notify — within 480 hoursApply to the Commission's supervising vice-president at least twenty business days before signing.
- Keep the data in the countryEvaluations, audit results and provider performance reports must be held in the bank's principal offices in Mexico, and supplied in Spanish on request.
- Written vendor contractThe contract must cover subcontracting limits, dispute resolution, data protection duties, and secure return and deletion of data at the end of the service.
- Independent audit — 2 yearsCompliance audit at least every two years; the Commission may order one earlier.
- Report cyber incidentsImmediate email report to the Commission; full report within five business days; remediation plan within fifteen business days of the incident ending.
- Tell affected people — within 48 hoursCustomers must be told within forty-eight hours where sensitive information was extracted, lost, deleted, altered or accessed without authority.
What it costs if you get it wrong
- Order to stopThe Commission may act on the outsourcing arrangement where the rules are breached
- Criminal liabilityBreach of banking secrecy duties, which extend to the third-party provider and its staff
Sources
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to credit institutions, article 328
cnbv.gob.mx
“Las Instituciones deberán solicitar la autorización de que se trata a la vicepresidencia de la Comisión encargada de su supervisión, con cuando menos veinte días hábiles de anticipación a la fecha en que pretendan contratar los servicios o la comisión que corresponda”
Link checked 18 August 2026
- Official sourceCámara de DiputadosCredit Institutions Law, article 46 Bis 1 (the enabling power, including the regulator's power to require prior authorisation)
diputados.gob.mx
Link checked 18 August 2026
Securities data must stay in the country
Official name: Disposiciones de carácter general aplicables a las casas de bolsa, artículo 206 Bis 2 · CNBV general provisions for broker-dealers, article 206 Bis 2 · Government rules
Stockbrokers get a lighter version of the banking rule. Any operational, technology or database process carried out even partly outside Mexico needs twenty working days' advance notice to the regulator, not its permission. The destination country still has to protect personal data, and audit paperwork still has to stay in Mexico.
Enforced by National Banking and Securities Commission
How this country controls where data goes: Approval each time · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What you have to do
- Register or notify — within 480 hoursNotice, not permission: at least twenty business days before contracting. This is the key difference from banks.
- Put a transfer safeguard in placeSame destination-country test as banks.
- Keep the data in the countryEvaluations, audit results and provider performance reports must be kept in the firm's principal offices in Mexico, in Spanish on request.
Sources
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to broker-dealers, article 206 Bis 2
cnbv.gob.mx
“Las casas de bolsa al contratar con terceros la prestación de servicios para la realización de un proceso operativo, tecnológico o para la administración de bases de datos, que se proporcionen o ejecuten parcial o totalmente fuera de territorio nacional o por residentes en el extranjero”
Link checked 18 August 2026
- Official sourceCámara de DiputadosSecurities Market Law (enabling framework for the broker-dealer rulebook)
diputados.gob.mx
Link checked 18 August 2026
Payments data needs a copy kept in the country
Official name: Disposiciones de carácter general aplicables a las instituciones de tecnología financiera, artículos 85 a 87 · Published 10 September 2018, most recently amended by resolution published 6 July 2026 · Government rules
Crowdfunding platforms must keep their own copy of every transaction record and their daily accounts on their own premises, so that they still work if an outsourced supplier goes dark. Offshore outsourcing needs the regulator's permission and proof that the destination country protects personal data. Cloud applications must name the exact regions where data will sit.
Enforced by National Banking and Securities Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision
What you have to do
- Keep the data in the countryDetailed records of every operation and the daily closing accounting records must be held on the institution's own premises, in a usable format, and remain usable if the outsourced service goes down.
- Register or notifyAuthorisation from the regulator, which is deemed granted if it does not answer within twenty-five business days.
- Put a transfer safeguard in placeFor offshore services, documentary evidence that the provider's country protects personal data or has an agreement with Mexico.
- Independent audit — 1 yearAnnual internal or external audit of the outsourced service.
- Secure the dataFor cloud services the application must state the cloud type and the specific regions where data will be stored and processed.
Sources
- Official sourceComisión Nacional Bancaria y de ValoresGeneral provisions applicable to financial technology institutions, articles 85 to 87
cnbv.gob.mx
“Regiones específicas donde se almacenará y procesará la información”
Link checked 18 August 2026
- Official sourceCámara de DiputadosFintech Law, article 54 (a fintech institution may contract services with third parties located in Mexico or abroad) and article 48 (record keeping)
diputados.gob.mx
“localizados en el territorio nacional o el extranjero”
Link checked 18 August 2026
Finance data needs a copy kept in the country
Official name: Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, artículos 15 y 18 · Published 17 October 2012; retention and address duties as reformed by the decree published 16 July 2025 · Act of parliament
This is the storage rule most companies miss because it lives in the anti-money-laundering law rather than the privacy law. Businesses carrying on a listed 'vulnerable activity' - which reaches estate agents, car dealers, jewellers, professional advisers and crypto firms, not just banks - must keep ten years of records at an address they have registered with the Finance Ministry. A purely foreign cloud arrangement with no Mexican address of record does not satisfy it.
Enforced by Financial Intelligence Unit, Ministry of Finance
What you have to do
- Keep data for a minimum period — 10 yearsTen years, restarting where a legal challenge is brought.
- Keep the data in the countryThe records must be kept, physically or electronically, at the address registered with the Finance Ministry for that purpose.
- Register or notifyRegistration in the national register of persons carrying on vulnerable activities, through the government portal.
- Keep records of how you use dataRecords must allow individual transactions to be reconstructed, including commercial correspondence between the parties.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep or produce required records
- Criminal liabilityConcealing or destroying records
Sources
- Official sourceCámara de DiputadosFederal Law for the Prevention and Identification of Operations with Illicit Proceeds, articles 15 fraction IV and 18 fraction IV
diputados.gob.mx
“La información y documentación a que se refiere el párrafo anterior deberá conservarse de manera física o electrónica, en el domicilio registrado ante la Secretaría para este efecto ... por al menos un plazo de diez años”
Link checked 18 August 2026
Internet and platform rules
Official name: Ley en Materia de Telecomunicaciones y Radiodifusión, artículo 183 · New law published in the Diario Oficial de la Federación, 16 July 2025 · Act of parliament
Phone and internet companies must keep two years of who-called-whom, where and on what device: twelve months instantly searchable, twelve months archived. Requested records must reach the authorities within twenty-four hours, and a team must be reachable at any hour on any day. The law is fully in force, but the 2014 law it replaced only fell away once the new regulator's board was constituted, which has now happened.
Enforced by Telecommunications Regulatory Commission
What you have to do
- Keep data for a minimum period — 2 yearsTwelve months in systems allowing real-time query and delivery, then twelve months in electronic archive with forty-eight-hour retrieval.
- Keep logsSubscriber name and address, communication type, origin and destination, date, time and duration, first activation, cell identifier, device identifiers and the digital geographic position of the line.
- Keep the data in the countryNot stated as a location rule, but real-time delivery to Mexican authorities plus a twenty-four-hour maximum response make offshore-only storage impractical.
- Appoint a representativeAn area must be available twenty-four hours a day, three hundred and sixty-five days a year.
- Delete data after a periodUse of the retained data for any purpose other than those in the law is prohibited and punishable.
What it costs if you get it wrong
- Criminal liabilityFailure to cooperate with real-time geolocation requests, and misuse of retained data
Sources
- Official sourceCámara de DiputadosTelecommunications and Broadcasting Law, article 183 and transitory articles Third, Fifth, Sixth and Eighth
diputados.gob.mx
“el concesionario y en su caso, el autorizado deberá conservar los datos referidos en el párrafo anterior durante los primeros doce meses en sistemas que permitan su consulta y entrega en tiempo real a las autoridades competentes”
Link checked 18 August 2026
- Official sourceInstituto Federal de TelecomunicacionesFederal Telecommunications Institute site, now an archive pointing to the Telecommunications Regulatory Commission - evidence the new commission's board is constituted
ift.org.mx
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Ley de Instituciones de Seguros y de Fianzas, artículo 268 · Insurance and Surety Institutions Law, published 4 April 2013, last reform 14 November 2025 · Act of parliament
Insurers may outsource, including abroad, but the insurance regulator can decide which arrangements need its permission first, and can order a service switched off entirely. Insurance secrecy follows the data to the supplier and binds the supplier's staff even after they leave. We could not retrieve the regulator's detailed circular, so the precise offshore conditions are not confirmed.
Enforced by National Insurance and Surety Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Extra vendor secrecy termsInsurance secrecy binds the third-party provider and its directors and staff, and survives after they stop working there.
- Written vendor contractThe provider must give the regulator, external auditors and independent actuaries access to records and technical support.
- Register or notifyThe regulator may designate which types of outsourcing need its prior authorisation.
What it costs if you get it wrong
- Order to stopThe regulator may order partial or total, temporary or permanent suspension of a service provided through a third party
Sources
- Official sourceCámara de DiputadosInsurance and Surety Institutions Law, article 268
diputados.gob.mx
“quedando facultada la Comisión para señalar el tipo de operaciones en las que se requerirá de su autorización previa”
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Record-keeping rules for tax and accounts
Official name: Ley Federal de Protección de Datos Personales en Posesión de los Particulares · New law published in the Diario Oficial de la Federación, 20 March 2025; last reform 14 November 2025 · Act of parliament
Mexico's general privacy law, in force since 21 March 2025. It is permissive on sending data abroad - no country list, no approval, no standard contract - but consent-heavy, and it carries criminal offences that attach to individuals. Fines are expressed in a national accounting unit rather than a share of turnover.
Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational
How this country controls where data goes: No restriction · Accepted routes: Nothing required, Explicit consent, Needed for a contract, Legal claims, Important public interest
What you have to do
- Get consentConsent is the default basis. Sensitive data need express written consent.
- Tell people what you doThe privacy notice must carry a clause where the person accepts or refuses transfers to third parties.
- Let people see their data — within 480 hoursTwenty days to answer, then fifteen days to act. Both can be extended once.
- Let people correct their data — within 480 hours
- Let people delete their data — within 480 hoursCancellation triggers a blocking period equal to the limitation period of the underlying relationship.
- Let people object — within 480 hours
- Secure the data
- Tell affected peopleImmediately, where the breach significantly affects patrimonial or moral rights. No regulator notification duty.
- Publish a complaints contactA named person or department must handle rights requests. No requirement that they be in Mexico.
- Extra vendor secrecy termsConfidentiality controls must bind everyone who handles the data, and must continue after the relationship ends.
- Delete data after a period — 6 yearsData about someone breaking a contract must be erased six years after the default.
What it costs if you get it wrong
- Fixed maximum fine: 160,000 UMA (about 18.8 million Mexican pesos) — about $1 millionMid-tier infringements, for example ignoring a rights request or processing in breach of the privacy notice
- Fixed maximum fine: 320,000 UMA (about 37.5 million Mexican pesos) — about $2 millionSerious infringements, including transferring data in breach of the law or a security breach caused by inadequate measures
- Fixed maximum fine: 640,000 UMA (about 75.1 million Mexican pesos) — about $4 millionSerious infringements involving sensitive data, where the penalty may be doubled
- Criminal liability: Five years' imprisonmentProcessing data by deception for improper gain; three years where an authorised person causes a breach for profit. Doubled for sensitive data.
- Claims by individualsCivil liability sits alongside administrative penalties
Sources
- Official sourceCámara de DiputadosFederal Law on Protection of Personal Data Held by Private Parties (consolidated official text)
diputados.gob.mx
Link checked 18 August 2026
- Official sourceDiario Oficial de la FederaciónDecree of 20 March 2025 enacting the law, Official Gazette of the Federation
dof.gob.mx
Link checked 18 August 2026
- Official sourceInstituto Nacional de Estadística y GeografíaValue of the Unit of Measurement and Update (UMA) from 1 February 2026: 117.31 pesos per day
inegi.org.mx
“Los valores de la UMA que entrarán en vigor a partir del 1 de febrero de 2026 son: Diario 117.31 pesos mexicanos”
Link checked 18 August 2026
Record-keeping rules for tax and accounts (1982)
Official name: Código Fiscal de la Federación, artículos 28 y 30 · Federal Tax Code, last reform published 9 April 2026 · Act of parliament
Every taxpayer must keep accounting records for five years, and the documents backing them up must be available at the taxpayer's registered Mexican tax address. Some records - company formation, capital changes, mergers - must be kept for as long as the company exists. This is a quiet mirroring requirement that applies to everyone, not just regulated firms.
Enforced by Tax Administration Service
What you have to do
- Keep data for a minimum period — 5 yearsFive years from when the related return was or should have been filed. Indefinite for incorporation deeds, capital changes, mergers, demergers and dividend records.
- Keep the data in the countryThe documents supporting the accounting entries must be available at the taxpayer's Mexican fiscal domicile.
- Keep records of how you use dataAccounting must be kept electronically and uploaded monthly to the tax authority's website.
Sources
- Official sourceCámara de DiputadosFederal Tax Code, article 28 fraction III and article 30
diputados.gob.mx
“La documentación comprobatoria de dichos registros o asientos deberá estar disponible en el domicilio fiscal del contribuyente”
Link checked 18 August 2026
Biometric data rules
Official name: Ley General de Población, artículos 91 Bis a 91 Sexies · Articles added by the decree published in the Diario Oficial de la Federación, 16 July 2025 · Act of parliament
Mexico has made its population registry number, now carrying fingerprints and a photograph, the compulsory national identity document. Every private business must ask for it before providing a service, with a deadline that passed in October 2025. That is a legal duty to collect a government identifier from every customer, which pulls in the opposite direction from the privacy law's rule to collect as little as possible.
Enforced by Ministry of the Interior, National Population Registry
What you have to do
- Allowed because the law requires it — from 15 October 2025Every public body and every private business must request the national population key (CURP) before providing its services.
- Tell people what you doBiometric enrolment itself requires the person's prior consent, but the duty on businesses to request the identifier does not.
Sources
- Official sourceCámara de DiputadosGeneral Population Law, articles 91 Bis to 91 Sexies and transitory articles First to Fifth
diputados.gob.mx
“La Clave Única de Registro de Población que, además de los datos previstos en el artículo 91 de esta Ley, contenga huellas dactilares y fotografía, será el documento nacional de identificación obligatorio, de aceptación universal y obligatoria en todo el territorio nacional”
Link checked 18 August 2026
Government data rules
Official name: Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados · New law published in the Diario Oficial de la Federación, 20 March 2025; last reform 14 November 2025 · Act of parliament
Public bodies and their suppliers run on a separate law. It allows data to go abroad only where the recipient promises to protect it to the same standard, which is an accountability test rather than a country list. Anyone selling to Mexican government agencies inherits this through contract.
Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational
How this country controls where data goes: No restriction · Accepted routes: Nothing required, Explicit consent
What you have to do
- Put a transfer safeguard in placeThe foreign recipient or processor must undertake to protect the data to the standard of this law.
- Tell people what you doThe privacy notice must be passed to every recipient.
- Get consentConsent is needed unless one of nine exceptions applies, including national security.
Sources
- Official sourceCámara de DiputadosGeneral Law on Protection of Personal Data Held by Obliged Subjects, articles 61 to 65
diputados.gob.mx
“El responsable sólo podrá transferir o hacer remisión de datos personales fuera del territorio nacional cuando el tercero receptor o la persona encargada se obligue a proteger los datos personales conforme a los principios y deberes que establece la presente Ley”
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
General data protection law
Official name: Reglamento de la Ley Federal de Protección de Datos Personales en Posesión de los Particulares · Published in the Diario Oficial de la Federación, 21 December 2011 · Directly binding regulation
The 2011 rulebook is still printed. It is still the only data protection regulation on the official federal list. But the law it was made under was abolished on 21 March 2025. It supplies the test for when the law reaches a company based abroad, and the security detail the new law leaves blank. So people rely on it, yet its legal force is doubtful. Treat anything that depends on it as unsafe.
Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational
What you have to do
- Appoint a representativeArticle 4 let a company outside Mexico that used equipment in Mexico appoint a representative instead of setting up an office there. Whether this still works is now uncertain.
- Assess high-risk projectsRisk analysis duties in the security chapter. Not restated in the 2025 statute.
Sources
- Official sourceCámara de DiputadosRegulation to the Federal Law on Protection of Personal Data Held by Private Parties, 21 December 2011
diputados.gob.mx
Link checked 18 August 2026
- Official sourceCámara de Diputados2025 privacy law, transitory article Segundo abrogating the 2010 law, and transitory article Decimo Segundo requiring new regulations within ninety days
diputados.gob.mx
“A la entrada en vigor del presente Decreto se abrogan las disposiciones siguientes: I. La Ley Federal de Protección de Datos Personales en Posesión de los Particulares, publicada en el Diario Oficial de la Federación el 5 de julio de 2010”
Link checked 18 August 2026
- Official sourceCámara de DiputadosOfficial index of federal regulations, checked 18 August 2026
diputados.gob.mx
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the Anti-Corruption and Good Government Ministry has issued any sanction or rights-protection decision against a private company under the 2025 privacy law
We could not confirm whether the ministry is deciding cases. Its pages on gob.mx returned a bot challenge to every automated request on 18 August 2026, and the official gazette's search form rejected our queries. We can show that it holds the powers and inherited the old institute's files. Enforcement is rated 'waking' on that basis. Check the ministry's site before you rely on it.
Whether the 2011 Regulation to the repealed 2010 privacy law remains legally binding
We could not confirm whether the 2011 regulation still has legal force. The decree of 20 March 2025 abolished the parent law but did not expressly repeal the regulation, and the official federal regulations index still lists it. Mexican legal thinking is that a regulation depends on the law it was made under, and the new law told the Executive to adapt existing regulations. We mark it as no longer applying, as the safer reading. No court has ruled either way, so take advice before relying on it.
Whether the applying even if you have no office there scope test survives, and therefore whether a foreign company with no Mexican establishment is caught
We could not confirm when the law reaches a company based abroad. The test lived only in article 4 of the 2011 regulation, and the 2025 law says nothing. Until a new regulation appears or a court rules, this is unsettled. That is why question one is rated medium confidence.
The precise offshore outsourcing conditions in the insurance regulator's circular (Circular Única de Seguros y Fianzas)
We could not open the National Insurance and Surety Commission's document on 18 August 2026. We cite the law that grants the power instead. So the power is confirmed, but its detailed conditions are not. Ask the Commission if you are an insurer planning to outsource.
Whether any rule requires Mexican government or public-sector workloads to be hosted inside Mexico
We found no such rule in the public-sector data protection law, checked 18 August 2026. Federal technology purchasing policy is issued by the digital transformation agency, and the government portal blocked us from retrieving those documents. We could not confirm this against a government source. If you sell to a Mexican federal body, ask what its purchasing policy requires.
The peso to US dollar conversions given for the fine ceilings
The unit value is confirmed at 117.31 pesos per day, from the national statistics institute's January 2026 release. The dollar figures assume roughly 18.3 pesos to the dollar, which we did not verify on 18 August 2026. Treat the dollar amounts as rough only.
Whether any localisation or survey-permit rule applies to detailed mapping and geospatial data held by private companies
We found no rule requiring private holders of mapping data to store it in a particular place, checked 18 August 2026. The statistics and geography law protects information given to the national institute and binds the institute to confidentiality. Permits for aerial surveys sit in separate aviation and defence rules that we did not reach. If you handle mapping data, check those before you rely on this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.