Ley Federal de Protección de Datos Personales en Posesión de los Particulares, security-breach notice
LFPDPPP, art. 19 (security-breach notice)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 March 2025.
A breach notification rule binding private bodies.
As of 19 September 2026.
What it requires
- Notify the affected data subject immediately of the breach, occurring at any stage of processing personal data, that significantly affects their patrimonial or moral rights.
What it reaches
Obligation class
Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 19 requires the responsable to inform the data subject immediately of a security breach occurring at any stage of processing personal data that significantly affects the data subject's patrimonial or moral rights, so the data subject can take the steps needed to defend their rights. The Law states no separate deadline measured in hours or days: immediacy of the breach itself is the period, and the duty runs to the affected data subject alone.
The Law states no duty to report a breach to the Secretaría; article 39 gives the Secretaría general investigative and sanctioning powers over compliance with this Law, but no provision requires a breach report to it specifically.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares
official consolidated text on the Cámara de Diputados' LeyesBiblio
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.