Mexico LFPDPPP 2026: 8 Obligations Every Business Owner Must Meet
Mexico's LFPDPPP data protection law applies to your business and non-compliance fines are steep. A clear guide for business owners on what the law requires and how to comply.
LFPDPPP: It's Not Optional, and Ignorance Isn't a Legal Defense
Imagine you receive a letter. It's from the IFAI (National Institute of Transparency, Access to Information and Data Protection). It says something like: "We've detected that your company handled customer data without consent. Fine: $2 million pesos."
Your first thought: "How did I not know that was illegal?"
Welcome to the reality of many Mexican SMB owners. The LFPDPPP (Federal Law for the Protection of Personal Data Held by Private Parties) has existed since 2010; the current text was republished in the DOF on March 20, 2025 and most recently amended on November 14, 2025 (Cámara de Diputados, LeyesBiblio). For many businesses it remains an unpleasant surprise when they thought they were operating legally.
What Exactly Is LFPDPPP?
It's a Mexican law that essentially says: If your company collects, stores, or uses personal data from anyone, you have the legal responsibility to protect that data.
"Personal data" means almost anything that identifies someone:
- Full name
- Phone number
- Address
- RFC or CURP
- Bank information
- Medical history
- Age
- Biometric information (even photos)
- Cookies that track online behavior
If your company has a customer list in Excel on a shared computer, you're under LFPDPPP.
The Three Key Obligations (What You Can Control)
1. Informed Consent
What the law says: You can't collect data from someone without their explicit consent.
What most SMBs do: Nothing. They buy contact lists from vendors, use social media to scrape potential customer information, or inherit databases from previous owners without updating consents.
What you need to do:
- Before collecting any data, tell the person what data you're collecting and why
- Get their explicit consent (a checkbox, a signature, an email confirming)
- Keep a record of that consent
Practical example: When someone subscribes to your newsletter, your form must say something like: "We'll collect your name and email to send you cybersecurity content weekly. You can unsubscribe anytime." Then they have to click "I Accept" before they can submit the form.
2. Duty of Confidentiality and Security
What the law says: Once you have personal data, you have the legal obligation to protect it against unauthorized access, loss, or theft.
What most SMBs do: Store data on unpatched computers (no antivirus), shared among multiple employees, without strong passwords, in Google Drive folders without access controls.
What you need to do:
- Store personal data in secure systems (encryption, strong passwords)
- Limit access: only employees who need that data should have it
- Keep antivirus and software updated
- Use VPN if accessing data from public networks
- If you use a service provider (an accountant, a marketing agency), make sure they also comply with LFPDPPP
Approximate cost: A password manager ($20-50 USD/month), good antivirus ($10-20 USD/month), employee training (one time). Total: less than $100 USD monthly.
3. Subject's Right to Know, Access, and Rectify
What the law says: If someone asks you "What data do you have about me?", you have the legal obligation to tell them within 20 business days.
What most SMBs do: They have no idea where all their data is, or they don't respond on time.
What you need to do:
- Create a process for when someone asks for their data: "I want to know what information you have about me"
- Respond within 20 business days or less
- Be thorough: tell them every data point you have, how you obtained it, how you use it
- If someone asks you to correct wrong data (ex: you have their email wrong), fix it
Cost: The time of one employee to compile the information. Once a month, probably less.
The Exceptions (Where You CAN Ignore LFPDPPP)
There are cases where the law does NOT apply:
- Public data: If someone publishes their address on a public social network, technically it's "public." But it's still wise to ask permission anyway.
- Academic purposes: Scientific research is exempt
- Public security: If police need data for a criminal investigation
But these are NOT exceptions:
- "I need it for my business" (you still need consent)
- "Nobody will find out" (not a legal excuse)
- "My competitors do it too" (doesn't make it legal)
The Sanctions (What Scares You If You Don't Comply)
The IFAI can fine from $2,600 to $2.5 million pesos.
But that's not the worst part. If a data breach from you affects many people, you could face:
- Civil lawsuits from affected customers
- Loss of reputation ("Company X stole data from 50,000 customers" destroys you)
- Regulatory raids
The good news: Basic compliance costs little and takes little time. It's mostly common sense.
How to Get Started Today
Week 1:
1. List all personal data your company collects and where you store it
2. Verify that you have documented consent from the majority
Week 2:
1. Implement strong passwords and a password manager
2. Review access permissions on Google Drive / OneDrive folders (does everyone really need access to everything?)
3. Make sure your antivirus is updated
Week 3:
1. Create a response process for when someone asks for their data
2. Briefly train your team on what LFPDPPP is and isn't
Week 4:
1. Review your privacy policy on the website (does it exist?)
2. Make sure web forms have clear consent clauses
Total cost: $0-500 USD
The Myth of "We're Too Small"
An SMB with 50 employees handling data from 2,000 customers may be subject to the LFPDPPP. Business size alone does not create an exemption; the specific processing and the law’s exclusions must be assessed. Since 2025, federal oversight and rights-protection functions belong to the Secretariat of Anti-Corruption and Good Government.
The Next Step
LFPDPPP might seem scary, but it's mostly common sense: if you get personal data, ask permission and protect it.
At Simiriki, we offer LFPDPPP compliance audits where we review your current practices, identify compliance gaps, and create an action plan. It's cheaper than a fine and much better for your reputation.
Compliance starts with knowing how protected that data is today. Take the free security assessment — 3 minutes on your Microsoft 365 operation, with a score by area.
For companies that require advanced regulatory compliance and ongoing management, see our Enterprise plan.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.