Skip to the content
Global Data RulesData governance rules, country by country

Mexico

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Mexico — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Waking up

Mexico's general privacy law does not care where you store data. There is no approved-country list, no standard contract to sign and no permission to ask for. You need the right wording in your privacy notice and, usually, the person's consent. The rules that actually pin data to Mexico live in banking, money-laundering and tax law, not in the privacy law.

Data governance in Mexico

The eight things that decide how you handle data about people in Mexico. Same eight on every country page, so you can compare.

Who has to follow these rules

Probably yes, but Mexico is unusually vague about it. The privacy law says only that it applies across Mexican territory. It does not spell out when it reaches a company based abroad. The old rulebook did say the law caught a foreign company that used equipment or systems located in Mexico. It also let that company appoint a local representative instead of opening an office. That old rulebook belonged to a law that was scrapped in March 2025, so its status today is unclear. There is no revenue or headcount threshold to fall below.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Under the general privacy law, yes, and with very little paperwork. Mexico has no list of approved countries and no list of banned ones. Sending data to a company abroad is treated exactly like sending it to a company down the road: say so in your privacy notice, get the person's consent unless one of seven exceptions applies, and pass the privacy notice on to whoever receives the data. Handing data to your own supplier who only follows your instructions is not even counted as a transfer. Five sectors override this, and in three of them the override is severe.

What to do: Plan for a database inside Mexico: this data is not allowed to leave.

Sending data out of the country

Nothing needs approval and no list exists in either direction. The model is simply unrestricted: any destination is allowed. What you need is a privacy notice that names the transfer and carries a clause where the person accepts or refuses it, plus that person's consent unless one of seven legal exceptions covers you. Because there is no list to populate, the government cannot make this stricter by adding a country. It would take a new law or a new regulation.

Ways to send data out:
Nothing required · Explicit consent · Needed for a contract · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

Mexico abolished its independent privacy regulator. The National Institute for Transparency, Access to Information and Data Protection was wound up in March 2025 and its staff, files and cases were moved into a government ministry, the Anti-Corruption and Good Government Ministry. So the referee is now part of the government rather than independent of it. The ministry is staffed, but the law says the detailed procedure for complaints, inspections and fines will be set out in a regulation, and that regulation still has not been published. Financial regulators, by contrast, are visibly active and update their rulebooks almost monthly.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is no single retention period. The privacy law says delete data once it is no longer needed, after a blocking period equal to the time limit for suing over the relationship. One hard ceiling is written into the law: information about someone breaking a contract must be erased six years after the default. The floors are longer and come from other laws. Tax records must be kept five years and their supporting documents must be available at your Mexican tax address. Anti-money-laundering records must be kept ten years at an address you register with the Finance Ministry. Phone companies keep call and location records for two years. Where a floor and a ceiling clash, the floor wins, because the privacy law lets you keep data to meet a legal duty.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least three clocks and they do not agree. Under the general privacy law you must tell the affected people immediately if a breach significantly harms their money or their reputation, and there is no duty to tell the regulator at all. Banks face a much tighter set: tell the banking regulator immediately, tell affected customers within forty-eight hours, file a full report within five working days, and send a remediation plan within fifteen working days of the incident ending. Phone companies must hand requested records to the authorities within twenty-four hours and keep a team available every hour of every day. Mexico has no general cyber-incident reporting law that catches everyone.

What you have to do here:
Tell affected people · Report cyber incidents · Secure the data

What to do: Your breach process has to tell the affected people, not just the regulator.

What catches people out

Five things catch people out. Every private business in Mexico is now legally required to ask customers for their national population ID number. Anti-money-laundering rules force many ordinary businesses to keep ten years of records at a Mexican address, which quietly rules out a pure foreign cloud setup. Mishandling data can put a person in prison, not just cost a company money. Banks must get written permission before any data is handled abroad, and that includes routine cloud hosting. And the rulebook the privacy law keeps pointing at does not exist.

What you have to do here:
Keep data for a minimum period · Register or notify
What it costs if you get it wrong:
Criminal liability

What's changing next

The biggest thing coming is a regulation that is already overdue. The privacy law repeatedly says a rulebook will set the deadlines for complaints, inspections and fines, and the government missed its own June 2025 deadline to publish it. When it lands it could change how enforcement works overnight, with no consultation. Health law was changed in January 2026 to put telehealth on a statutory footing, and the biometric national ID is still being rolled out. The dangerous powers are the ones the government already holds rather than any bill in parliament.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking data must stay in the country

Official name: Disposiciones de carácter general aplicables a las instituciones de crédito, artículos 318, 326 a 328 · Published 2 December 2005, most recently amended by resolutions published 1, 2, 3 and 14 July 2026 · Government rules

In forceYes, with paperwork

This is the real wall in Mexico. A bank must get the banking regulator's written permission before any operational process or database administration is carried out even partly outside Mexico, or by anyone resident abroad, and must apply at least twenty working days ahead. It applies to every such arrangement, whether or not it is important. Audit and performance records must stay in the bank's Mexican head office.

In force since 3 December 2005

Enforced by National Banking and Securities Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision

Securities

Securities data must stay in the country

Official name: Disposiciones de carácter general aplicables a las casas de bolsa, artículo 206 Bis 2 · CNBV general provisions for broker-dealers, article 206 Bis 2 · Government rules

In forceYes, with paperwork

Stockbrokers get a lighter version of the banking rule. Any operational, technology or database process carried out even partly outside Mexico needs twenty working days' advance notice to the regulator, not its permission. The destination country still has to protect personal data, and audit paperwork still has to stay in Mexico.

In force since 19 September 2003

Enforced by National Banking and Securities Commission

How this country controls where data goes: Approval each time · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Payments

Payments data needs a copy kept in the country

Official name: Disposiciones de carácter general aplicables a las instituciones de tecnología financiera, artículos 85 a 87 · Published 10 September 2018, most recently amended by resolution published 6 July 2026 · Government rules

In forceA copy must stay

Crowdfunding platforms must keep their own copy of every transaction record and their daily accounts on their own premises, so that they still work if an outsourced supplier goes dark. Offshore outsourcing needs the regulator's permission and proof that the destination country protects personal data. Cloud applications must name the exact regions where data will sit.

In force since 11 September 2018

Enforced by National Banking and Securities Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Record-keeping rules for tax and accounts

Official name: Ley Federal de Protección de Datos Personales en Posesión de los Particulares · New law published in the Diario Oficial de la Federación, 20 March 2025; last reform 14 November 2025 · Act of parliament

In forceYes — store it anywhere

Mexico's general privacy law, in force since 21 March 2025. It is permissive on sending data abroad - no country list, no approval, no standard contract - but consent-heavy, and it carries criminal offences that attach to individuals. Fines are expressed in a national accounting unit rather than a share of turnover.

In force since 21 March 2025

Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational

How this country controls where data goes: No restriction · Accepted routes: Nothing required, Explicit consent, Needed for a contract, Legal claims, Important public interest

Record-keeping rules for tax and accounts (1982)

Official name: Código Fiscal de la Federación, artículos 28 y 30 · Federal Tax Code, last reform published 9 April 2026 · Act of parliament

In forceA copy must stay

Every taxpayer must keep accounting records for five years, and the documents backing them up must be available at the taxpayer's registered Mexican tax address. Some records - company formation, capital changes, mergers - must be kept for as long as the company exists. This is a quiet mirroring requirement that applies to everyone, not just regulated firms.

In force since 1 January 1982

Enforced by Tax Administration Service

Biometric data rules

Official name: Ley General de Población, artículos 91 Bis a 91 Sexies · Articles added by the decree published in the Diario Oficial de la Federación, 16 July 2025 · Act of parliament

Partly in forceYes — store it anywhere

Mexico has made its population registry number, now carrying fingerprints and a photograph, the compulsory national identity document. Every private business must ask for it before providing a service, with a deadline that passed in October 2025. That is a legal duty to collect a government identifier from every customer, which pulls in the opposite direction from the privacy law's rule to collect as little as possible.

In force since 17 July 2025Enforced from 15 October 2025

Enforced by Ministry of the Interior, National Population Registry

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

General data protection law

Official name: Reglamento de la Ley Federal de Protección de Datos Personales en Posesión de los Particulares · Published in the Diario Oficial de la Federación, 21 December 2011 · Directly binding regulation

UnenforceableYes — store it anywhere

The 2011 rulebook is still printed. It is still the only data protection regulation on the official federal list. But the law it was made under was abolished on 21 March 2025. It supplies the test for when the law reaches a company based abroad, and the security detail the new law leaves blank. So people rely on it, yet its legal force is doubtful. Treat anything that depends on it as unsafe.

In force since 22 December 2011

Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Secretaría Anticorrupción y Buen Gobierno

    General privacy law, private and public sector. Successor to the abolished independent institute.

    Exists and is staffed as a federal ministry, and holds the powers under articles 38 and 39 of the 2025 law. But it is not an independent regulator, the implementing regulation that the law says will set the complaint, inspection and sanction procedures is over fourteen months overdue, and we could not evidence any published private-sector sanction decision under the new law from an official source as at 18 August 2026. Treat privacy enforcement as unproven rather than absent.

  • Comisión Nacional Bancaria y de Valores

    Banks, broker-dealers, fintech institutions; offshore outsourcing authorisation and cyber incident reporting

    Demonstrably active. Its banking rulebook was amended by resolutions published in the official gazette on 26 and 27 March, 18 May, 5 and 12 June and 1, 2, 3 and 14 July 2026, and the fintech rulebook on 6 July 2026.

  • Comisión Reguladora de Telecomunicaciones

    Telecoms and broadcasting; designates which authorised operators are caught by the retention duties

    Now the live regulator. The Federal Telecommunications Institute's own website states it is a historical archive and directs all current business to this commission, which confirms the new board has been constituted and the 2014 telecoms law abrogated.

  • Comisión Nacional de Seguros y Fianzas

    Insurers and surety companies; outsourcing authorisation and suspension powers

    Holds live statutory powers under article 268 of the insurance law.

  • Servicio de Administración Tributaria

    Accounting record retention and the duty to keep supporting documents at the Mexican fiscal domicile

  • Unidad de Inteligencia Financiera, Secretaría de Hacienda y Crédito Público

    Anti-money-laundering record keeping, the ten-year retention duty and the registered-address requirement

  • Secretaría de Gobernación, Registro Nacional de Población

    Biometric national population key and the Single Identity Platform

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the Anti-Corruption and Good Government Ministry has issued any sanction or rights-protection decision against a private company under the 2025 privacy law

    We could not confirm whether the ministry is deciding cases. Its pages on gob.mx returned a bot challenge to every automated request on 18 August 2026, and the official gazette's search form rejected our queries. We can show that it holds the powers and inherited the old institute's files. Enforcement is rated 'waking' on that basis. Check the ministry's site before you rely on it.

  • Whether the 2011 Regulation to the repealed 2010 privacy law remains legally binding

    We could not confirm whether the 2011 regulation still has legal force. The decree of 20 March 2025 abolished the parent law but did not expressly repeal the regulation, and the official federal regulations index still lists it. Mexican legal thinking is that a regulation depends on the law it was made under, and the new law told the Executive to adapt existing regulations. We mark it as no longer applying, as the safer reading. No court has ruled either way, so take advice before relying on it.

  • Whether the applying even if you have no office there scope test survives, and therefore whether a foreign company with no Mexican establishment is caught

    We could not confirm when the law reaches a company based abroad. The test lived only in article 4 of the 2011 regulation, and the 2025 law says nothing. Until a new regulation appears or a court rules, this is unsettled. That is why question one is rated medium confidence.

  • The precise offshore outsourcing conditions in the insurance regulator's circular (Circular Única de Seguros y Fianzas)

    We could not open the National Insurance and Surety Commission's document on 18 August 2026. We cite the law that grants the power instead. So the power is confirmed, but its detailed conditions are not. Ask the Commission if you are an insurer planning to outsource.

  • Whether any rule requires Mexican government or public-sector workloads to be hosted inside Mexico

    We found no such rule in the public-sector data protection law, checked 18 August 2026. Federal technology purchasing policy is issued by the digital transformation agency, and the government portal blocked us from retrieving those documents. We could not confirm this against a government source. If you sell to a Mexican federal body, ask what its purchasing policy requires.

  • The peso to US dollar conversions given for the fine ceilings

    The unit value is confirmed at 117.31 pesos per day, from the national statistics institute's January 2026 release. The dollar figures assume roughly 18.3 pesos to the dollar, which we did not verify on 18 August 2026. Treat the dollar amounts as rough only.

  • Whether any localisation or survey-permit rule applies to detailed mapping and geospatial data held by private companies

    We found no rule requiring private holders of mapping data to store it in a particular place, checked 18 August 2026. The statistics and geography law protects information given to the national institute and binds the institute to confidentiality. Permits for aerial surveys sit in separate aviation and defence rules that we did not reach. If you handle mapping data, check those before you rely on this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.