Skip to the content
Global Data RulesData governance rules, country by country

Mexico

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Waking up

Mexico's general privacy law does not care where you store data. There is no approved-country list, no standard contract to sign and no permission to ask for. You need the right wording in your privacy notice and, usually, the person's consent. The rules that actually pin data to Mexico live in banking, money-laundering and tax law, not in the privacy law.

Eight questions about Mexico

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Mexico's rules apply to my company?

Probably yes, but Mexico is unusually vague about it. The privacy law says only that it applies across Mexican territory. It does not spell out when it reaches a company based abroad. The old rulebook did say the law caught a foreign company that used equipment or systems located in Mexico, and let that company appoint a local representative instead of opening an office. That old rulebook belonged to a law that was scrapped in March 2025, so its status today is genuinely unclear. There is no revenue or headcount threshold to fall below.

Medium confidenceNational rulesLocal representative

Can I store my users' data outside Mexico?

Under the general privacy law, yes, and with very little paperwork. Mexico has no list of approved countries and no list of banned ones. Sending data to a company abroad is treated exactly like sending it to a company down the road: say so in your privacy notice, get the person's consent unless one of seven exceptions applies, and pass the privacy notice on to whoever receives the data. Handing data to your own supplier who only follows your instructions is not even counted as a transfer. Five sectors override this, and in three of them the override is severe.

High confidenceDepends on your industryNo restrictionYes, with paperworkA copy must stay

What do I need in place before data leaves Mexico?

Nothing needs approval and no list exists in either direction. The model is simply unrestricted: any destination is allowed. What you need is a privacy notice that names the transfer and carries a clause where the person accepts or refuses it, plus that person's consent unless one of seven legal exceptions covers you. Because there is no list to populate, the government cannot make this stricter by adding a country. It would take a new law or a new regulation.

High confidenceNo restrictionNothing requiredExplicit consentNeeded for a contractGovernment sign-off needed

Who enforces the rules in Mexico, and what can they do?

Mexico abolished its independent privacy regulator. The National Institute for Transparency, Access to Information and Data Protection was wound up in March 2025 and its staff, files and cases were moved into a government ministry, the Anti-Corruption and Good Government Ministry. So the referee is now part of the government rather than independent of it. The ministry is staffed, but the law says the detailed procedure for complaints, inspections and fines will be set out in a regulation, and that regulation still has not been published. Financial regulators, by contrast, are visibly active and update their rulebooks almost monthly.

Medium confidenceWaking upRegulator

How long do I have to keep the data?

There is no single retention period. The privacy law says delete data once it is no longer needed, after a blocking period equal to the time limit for suing over the relationship. One hard ceiling is written into the law: information about someone breaking a contract must be erased six years after the default. The floors are longer and come from other laws. Tax records must be kept five years and their supporting documents must be available at your Mexican tax address. Anti-money-laundering records must be kept ten years at an address you register with the Finance Ministry. Phone companies keep call and location records for two years. Where a floor and a ceiling clash, the floor wins, because the privacy law lets you keep data to meet a legal duty.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

There are at least three clocks and they do not agree. Under the general privacy law you must tell the affected people immediately if a breach significantly harms their money or their reputation, and there is no duty to tell the regulator at all. Banks face a much tighter set: tell the banking regulator immediately, tell affected customers within forty-eight hours, file a full report within five working days, and send a remediation plan within fifteen working days of the incident ending. Phone companies must hand requested records to the authorities within twenty-four hours and keep a team available every hour of every day. Mexico has no general cyber-incident reporting law that catches everyone.

High confidenceTell affected peopleReport cyber incidentsSecure the data

What trips people up in Mexico?

Five things catch people out. Every private business in Mexico is now legally required to ask customers for their national population ID number. Anti-money-laundering rules force many ordinary businesses to keep ten years of records at a Mexican address, which quietly rules out a pure foreign cloud setup. Mishandling data can put a person in prison, not just cost a company money. Banks must get written permission before any processing happens abroad, and that includes routine cloud hosting. And the rulebook the privacy law keeps pointing at does not exist.

High confidenceCriminal liabilityKeep the data in the countryKeep data for a minimum periodRegister or notify

What is changing soon in Mexico?

The biggest thing coming is a regulation that is already overdue. The privacy law repeatedly says a rulebook will set the deadlines for complaints, inspections and fines, and the government missed its own June 2025 deadline to publish it. When it lands it could change how enforcement works overnight, with no consultation. Health law was changed in January 2026 to put telehealth on a statutory footing, and the biometric national ID is still being rolled out. The dangerous powers are the ones the government already holds rather than any bill in parliament.

Medium confidenceProposedGovernment rules

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

Ley Federal de Protección de Datos Personales en Posesión de los Particulares

Act of parliament · New law published in the Diario Oficial de la Federación, 20 March 2025; last reform 14 November 2025

In forceYes — store it anywhere

Mexico's general privacy law, in force since 21 March 2025. It is permissive on sending data abroad - no country list, no approval, no standard contract - but consent-heavy, and it carries criminal offences that attach to individuals. Fines are expressed in a national accounting unit rather than a share of turnover.

In force since 21 March 2025

Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational

Transfer model: No restriction · Accepted routes: Nothing required, Explicit consent, Needed for a contract, Legal claims, Important public interest

High confidence

Reglamento de la Ley Federal de Protección de Datos Personales en Posesión de los Particulares

Directly binding regulation · Published in the Diario Oficial de la Federación, 21 December 2011

UnenforceableYes — store it anywhere

The 2011 rulebook is still printed and still the only data protection regulation on the official federal list, but the law it was made under was abolished on 21 March 2025. It supplies the extraterritorial scope test and the security detail the new law leaves blank, so it is widely relied on, yet its legal force is doubtful. Treat anything that depends on it as unsafe.

In force since 22 December 2011

Enforced by Anti-Corruption and Good Government Ministry (data protection function, branded 'Transparencia para el Pueblo') — not yet operational

Medium confidence

Código Fiscal de la Federación, artículos 28 y 30

Act of parliament · Federal Tax Code, last reform published 9 April 2026

In forceA copy must stay

Every taxpayer must keep accounting records for five years, and the documents backing them up must be available at the taxpayer's registered Mexican tax address. Some records - company formation, capital changes, mergers - must be kept for as long as the company exists. This is a quiet mirroring requirement that applies to everyone, not just regulated firms.

In force since 1 January 1982

Enforced by Tax Administration Service

High confidence

Industry rules6 rules

Disposiciones de carácter general aplicables a las instituciones de crédito, artículos 318, 326 a 328

Government rules · Published 2 December 2005, most recently amended by resolutions published 1, 2, 3 and 14 July 2026 · Banking

In forceYes, with paperwork

This is the real wall in Mexico. A bank must get the banking regulator's written permission before any operational process or database administration is carried out even partly outside Mexico, or by anyone resident abroad, and must apply at least twenty working days ahead. It applies to every such arrangement, whether or not it is important. Audit and performance records must stay in the bank's Mexican head office.

In force since 3 December 2005

Enforced by National Banking and Securities Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision

High confidence

Disposiciones de carácter general aplicables a las casas de bolsa, artículo 206 Bis 2

Government rules · CNBV general provisions for broker-dealers, article 206 Bis 2 · Securities

In forceYes, with paperwork

Stockbrokers get a lighter version of the banking rule. Any operational, technology or database process carried out even partly outside Mexico needs twenty working days' advance notice to the regulator, not its permission. The destination country still has to protect personal data, and audit paperwork still has to stay in Mexico.

In force since 19 September 2003

Enforced by National Banking and Securities Commission

Transfer model: Approval each time · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

High confidence

Disposiciones de carácter general aplicables a las instituciones de tecnología financiera, artículos 85 a 87

Government rules · Published 10 September 2018, most recently amended by resolution published 6 July 2026 · Payments

In forceA copy must stay

Crowdfunding platforms must keep their own copy of every transaction record and their daily accounts on their own premises, so that they still work if an outsourced supplier goes dark. Offshore outsourcing needs the regulator's permission and proof that the destination country protects personal data. Cloud applications must name the exact regions where data will sit.

In force since 11 September 2018

Enforced by National Banking and Securities Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision

High confidence

Who you would hear from

  • Secretaría Anticorrupción y Buen Gobierno

    General privacy law, private and public sector. Successor to the abolished independent institute.

    Exists and is staffed as a federal ministry, and holds the powers under articles 38 and 39 of the 2025 law. But it is not an independent regulator, the implementing regulation that the law says will set the complaint, inspection and sanction procedures is over fourteen months overdue, and we could not evidence any published private-sector sanction decision under the new law from an official source as at 18 August 2026. Treat privacy enforcement as unproven rather than absent.

  • Comisión Nacional Bancaria y de Valores

    Banks, broker-dealers, fintech institutions; offshore outsourcing authorisation and cyber incident reporting

    Demonstrably active. Its banking rulebook was amended by resolutions published in the official gazette on 26 and 27 March, 18 May, 5 and 12 June and 1, 2, 3 and 14 July 2026, and the fintech rulebook on 6 July 2026.

  • Comisión Reguladora de Telecomunicaciones

    Telecoms and broadcasting; designates which authorised operators are caught by the retention duties

    Now the live regulator. The Federal Telecommunications Institute's own website states it is a historical archive and directs all current business to this commission, which confirms the new board has been constituted and the 2014 telecoms law abrogated.

  • Comisión Nacional de Seguros y Fianzas

    Insurers and surety companies; outsourcing authorisation and suspension powers

    Holds live statutory powers under article 268 of the insurance law. Its website would not serve its rulebook to us on 18 August 2026, so the detail of its circular is unverified.

  • Servicio de Administración Tributaria

    Accounting record retention and the duty to keep supporting documents at the Mexican fiscal domicile

  • Unidad de Inteligencia Financiera, Secretaría de Hacienda y Crédito Público

    Anti-money-laundering record keeping, the ten-year retention duty and the registered-address requirement

  • Secretaría de Gobernación, Registro Nacional de Población

    Biometric national population key and the Single Identity Platform

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the Anti-Corruption and Good Government Ministry has issued any sanction or rights-protection decision against a private company under the 2025 privacy law

    The ministry's pages on gob.mx returned a bot challenge to every automated request on 18 August 2026, and the official gazette's search form rejected our queries. We can evidence that it holds the powers and inherited the old institute's files, but not that it is deciding cases. Enforcement is rated 'waking' on that basis and should be re-checked.

  • Whether the 2011 Regulation to the repealed 2010 privacy law remains legally binding

    The decree of 20 March 2025 abrogated the parent law but did not expressly repeal the regulation, and the official federal regulations index still lists it. Mexican doctrine is that a regulation depends on its enabling statute, and the new law's own transitory article Decimo Segundo ordered the Executive to adapt existing regulations. We mark it 'disapplied' as the more prudent reading, but no court ruling confirms this either way.

  • Whether the extraterritorial scope test survives, and therefore whether a foreign company with no Mexican establishment is caught

    The test lived only in article 4 of the 2011 regulation. The 2025 statute is silent. Until a new regulation is published or a court rules, this is genuinely unsettled, which is why question one is rated medium confidence.

  • The precise offshore outsourcing conditions in the insurance regulator's circular (Circular Única de Seguros y Fianzas)

    The National Insurance and Surety Commission's website would not serve the document to us on 18 August 2026. We cite the enabling statute instead, so the existence of the power is confirmed but its detailed conditions are not.

  • Whether any rule requires Mexican government or public-sector workloads to be hosted inside Mexico

    No such rule was found in the public-sector data protection law, checked 18 August 2026. Federal ICT procurement policy is issued administratively by the digital transformation agency and we could not retrieve those documents because the government portal blocked automated access. Absence of a finding here is not proof of absence.

  • The peso to US dollar conversions given for the fine ceilings

    The unit value is confirmed at 117.31 pesos per day from the national statistics institute's January 2026 release, but the dollar figures assume an exchange rate of roughly 18.3 pesos to the dollar, which we did not verify on 18 August 2026. Treat the dollar amounts as indicative only.

  • Whether any localisation or survey-permit rule applies to detailed mapping and geospatial data held by private companies

    The statistics and geography law protects information supplied to the national institute and imposes confidentiality on the institute, but we found no storage-location duty on private holders of mapping data, checked 18 August 2026. Aerial survey permitting sits in separate aviation and defence instruments we did not reach within this run.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.