Law / Mexico

Ley Federal de Protección de Datos Personales en Posesión de los Particulares, enforcement, sanctions and offences

LFPDPPP, arts. 38-64 (Secretaría, rights-protection procedure, verification, sanctions and offences)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 March 2025.

An enforcement supervision rule binding private bodies.

As of 19 September 2026.

What it requires

  • Answer a rights-protection request the Secretaría serves on you within fifteen days, offering the evidence and arguments you rely on.
  • Give effect to a resolution favourable to the data subject within ten days of its notification, or the longer period the resolution itself sets.
  • Expect an infraction of the Law to draw a fine of 100 to 320,000 times the Unidad de Medida y Actualización, doubled where the personal data at issue is sensitive, on top of a repeat-infraction surcharge.
  • Expect a security breach you cause for profit, or personal data you process through deceit for undue profit, to carry criminal liability of up to five years' imprisonment, doubled in either case for sensitive personal data.
  • Expect a data subject harmed by your non-compliance with this Law to be able to pursue compensation under the applicable civil-liability law, independent of any administrative or criminal sanction.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 62 punishes with three months to three years' imprisonment a person authorized to process personal data who, for profit, causes a security breach of the database in their custody. Article 63 punishes with six months to five years' imprisonment anyone who processes personal data through deceit, for undue profit, taking advantage of the data subject's or an authorized person's error. Article 64 doubles both penalties where the data processed is sensitive personal data. Separately, article 59 fines an infraction from 100 to 160,000 times the Unidad de Medida y Actualización (UMA) for the lesser infractions and 200 to 320,000 times the UMA for the more serious ones, doubled for sensitive data, with an additional 100 to 320,000 UMA fine for a repeated infraction; these are administrative fines denominated in UMA multiples rather than a fixed peso amount, so no penalty_structure object is coded here to avoid inferring a peso conversion the statute itself does not state. Article 61 states that these administrative sanctions apply without prejudice to any resulting civil or criminal liability, and article 53 lets a data subject harmed by the responsable's or persona encargada's non-compliance pursue the compensation available under other applicable law.

Who enforces it

Enforcement body

Secretaría Anticorrupción y Buen Gobierno

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 38 charges the Secretaría with disseminating knowledge of the right to data protection, promoting its exercise, and overseeing compliance with the Law.

Article 39 gives the Secretaría the power to monitor and verify compliance, interpret the Law administratively, support responsables technically, issue criteria and recommendations, publish security standards and best practices, resolve rights-protection and verification proceedings and impose sanctions, cooperate with other supervisory authorities, and prepare privacy-impact studies before new processing modalities, among other functions.

Article 40 lets a data subject or representative file a rights-protection request with the Secretaría within fifteen days of the responsable's response, or after the response deadline lapses without one, when the responsable denies, ignores, or inadequately answers an ARCO request; the Secretaría gives the responsable fifteen days to answer, admits evidence, and allows five days for closing arguments.

Article 42 sets a maximum of fifty days to resolve the rights-protection request, extendable once for an equal period on justified cause. Article 43 gives the responsable ten days to give effect to a favourable resolution once notified. Article 45 lets the Secretaría cure deficiencies in the complaint without altering its original content. Article 46 lets the Secretaría dismiss the request, confirm, revoke, or modify the responsable's response, or order delivery of the data.

Article 49 lets the Secretaría seek conciliation between the parties at any point, with a binding written agreement closing the matter. Article 51 lets a party challenge a Secretaría resolution by amparo before specialized federal courts, and article 52 lets the Secretaría publish its resolutions with the data subject's identifying references removed.

Article 53 lets a data subject who suffered damage or injury from the responsable's or persona encargada's non-compliance pursue the compensation available under other applicable law.

Article 54 lets the Secretaría open a verification procedure on its own initiative or on request, and article 56 opens a sanctions procedure when a rights-protection or verification proceeding surfaces a suspected violation; article 57 gives the accused responsable fifteen days to submit evidence and five days for closing arguments, with a fifty-day resolution deadline extendable once for an equal period.

Article 58 lists nineteen infractions, from failing to satisfy an ARCO request without justified reason to processing personal data contrary to the Law's principles, creating a sensitive-data database without a justified purpose, and obstructing a verification act.

Article 59 fines an infraction from 100 to 160,000 times the Unidad de Medida y Actualización for the lesser infractions and 200 to 320,000 times the UMA for the more serious ones, adds 100 to 320,000 UMA for a repeated infraction, and lets sanctions for infractions involving sensitive personal data double.

Article 60 lists the factors the Secretaría weighs when it grounds a sanction: the nature of the data, how plainly unjustified the responsable's refusal was, intent, the responsable's economic capacity, and recidivism. Article 61 states that these administrative sanctions apply without prejudice to any resulting civil or criminal liability.

Articles 62 to 64 create criminal offences: three months to three years' imprisonment for a person authorized to process personal data who, for profit, causes a security breach of a database in their custody; six months to five years' imprisonment for anyone who processes personal data through deceit for undue profit, taking advantage of the data subject's or an authorized person's error; and double the penalty in either offence where the data processed is sensitive personal data.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics

Read the law

Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares
official consolidated text on the Cámara de Diputados' LeyesBiblio

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app