Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)
Ley Federal de Protección de Datos Personales en Posesión de los Particulares Nueva Ley publicada en el Diario Oficial de la Federación el 20 de marzo de 2025, última reforma DOF 14-11-2025
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 March 2025.
A comprehensive regime rule binding private bodies.
As of 7 September 2026.
What it requires
- Obtain the data subject's consent, express and in writing for sensitive personal data, before processing their personal data, unless a statutory exception applies (a legal provision, a publicly available source, prior dissociation, or another Article 9 ground).
- State the purposes of processing in a privacy notice made available to the data subject when their personal data is first collected.
- Honor a data subject's request to access, rectify, cancel, or object to the processing of their personal data, including their right to object to a fully automated decision that produces undesired legal effects or significantly affects them.
- Notify the data subject immediately of a security breach, at any stage of processing, that significantly affects their patrimonial or moral rights.
- Before transferring personal data domestically or internationally, communicate the privacy notice and its purposes to the recipient and indicate in the notice whether the data subject accepts the transfer, unless an Article 36 no-consent-required ground applies.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 62 punishes with 3 months to 3 years' imprisonment a person authorized to process personal data who, for profit, causes a security breach of the database in their custody. Article 63 punishes with 6 months to 5 years' imprisonment anyone who processes personal data through deceit, for undue profit, taking advantage of the data subject's or an authorized person's error. Article 64 doubles both penalties where the data processed is sensitive personal data. Separately, Article 59 fines an administrative infraction from 100 to 160,000 times the Unidad de Medida y Actualización (UMA) for lesser infractions and 200 to 320,000 times the UMA for more serious ones (doubled for sensitive data), with an additional 100 to 320,000 UMA fine for a repeated infraction; these are administrative fines denominated in UMA multiples rather than a fixed peso amount, so no penalty_structure object is coded here to avoid inferring a peso conversion the statute itself does not state.
Who enforces it
Enforcement body
Secretaría Anticorrupción y Buen Gobierno
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Breach notice, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 protects personal data in the possession of private parties, excepting only credit-reporting societies and purely personal, non-commercial data collection. Article 5 requires lawfulness, purpose limitation, loyalty, consent, quality, proportionality, information, and accountability in every processing.
Article 7 requires consent, express or tacit, except where Article 9 dispenses with it (a legal provision, publicly available sources, prior dissociation, a legal relationship's requirements, an emergency, medical care, or professional-secret relationships).
Article 8 requires express written consent, by autograph or electronic signature or another authentication mechanism, before creating a database of sensitive personal data (Article 2(VI): race or ethnicity, health status, genetic information, religious, philosophical or moral belief, political opinion, or sexual preference, an illustrative but not exhaustive list that does not name a biometric identifier).
Articles 21 to 26 give the data subject ARCO rights (access, rectification, cancellation, objection), including a right at Article 26(II) to object to a decision based solely on automated processing that produces undesired legal effects on the person or significantly affects their interests, rights, or freedoms, and that is intended to evaluate, without human intervention, their professional performance, economic situation, health, sexual preferences, reliability, or behaviour.
Article 19 requires the controller to inform the data subject immediately of a security breach at any stage of processing that significantly affects their patrimonial or moral rights.
Article 35 conditions a transfer to a third party on communicating the privacy notice and its purposes, and requires the notice to state whether the data subject accepts the transfer; Article 36 lists grounds on which a national or international transfer may proceed without the data subject's consent (a law or treaty, medical necessity, transfer within a corporate group under common control, a contract in the data subject's interest, a public-interest or judicial ground, or defense of a right in a judicial proceeding).
Breach of these duties is enforced administratively by the Secretaría Anticorrupción y Buen Gobierno with fines under Article 59, and Articles 62 to 64 create separate criminal offences for a person authorized to process personal data who, for profit, causes a security breach, and for anyone who processes personal data through deceit for undue profit, with the criminal penalty doubled for sensitive data.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares
official consolidated text on the Cámara de Diputados' LeyesBiblio