Mandatory scheme
Federal personal data protection compliance
Federal personal data protection compliance — mandatory scheme, Mexico. It binds private-sector personal-data processing nationwide.
- Jurisdiction
- Mexico
- Record class
- Mandatory scheme
- Last verified
Where this applies
This record is scoped to Mexico. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Ley Federal de Protección de Datos Personales en Posesión de los Particulares (new law, DOF 20 March 2025)
Who it binds
Private-sector personal-data processing nationwide
What it requires
Mexico's federal private-sector data protection law was replaced in full on 20 March 2025. Under this new law's own Art. 2 fracc. XV, the "Secretaría" responsible for the law is the Secretaría Anticorrupción y Buen Gobierno — not INAI. Whether and how INAI's own constitutional status changed under the same reform is unconfirmed and not asserted here in either direction.
Route to the authority
Last verified:
Related records and requirements
- Personal Information Protection and Electronic Documents Act (PIPEDA) (Canada) — PIPEDA is Canada's federal general-compliance data-protection law, binding organisations that collect, use or disclose personal information in the course of commercial activity.
- Act Respecting the Protection of Personal Information in the Private Sector (Québec) (Canada) — Québec's own private-sector privacy law is the general-compliance regime for private-sector businesses handling personal information within Québec — it takes the place of PIPEDA for that in-province activity.
- Privacy Act 1988 — Australian Privacy Principles (Australia) — The Privacy Act 1988 binds Australian government agencies and covered organisations to 13 Australian Privacy Principles — the small-business turnover exemption has documented exceptions.
- Act on the Protection of Personal Information (APPI) compliance (Japan) — APPI's general obligations (Art. 21(1) purpose notification, Art. 23 security-management measures) bind business operators handling personal information in Japan.
- Personal Data (Privacy) Ordinance compliance (Hong Kong SAR China) — Hong Kong's Cap. 486 sets six Data Protection Principles binding data users in Hong Kong, overseen by the PCPD.
- Personal data protection compliance (Vietnam) — Vietnam's Decree 13/2023 and, from 1 January 2026, Law 91/2025 bind organisations processing personal data in Vietnam to a general data-protection compliance regime.
- Personal Data Protection Law (PDPL) compliance (Saudi Arabia) — Saudi Arabia's PDPL (Royal Decree M/19) binds entities processing personal data in Saudi Arabia to a general data-protection compliance law.
- Federal personal data protection compliance (United Arab Emirates) — The UAE's federal PDPL (Federal Decree-Law No. 45 of 2021) binds organisations processing personal data inside or outside the UAE where the processing relates to the UAE — separate from DIFC's and ADGM's own free-zone regimes.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.