Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)
Ley Federal de Protección de Datos Personales en Posesión de los Particulares Nueva Ley publicada en el Diario Oficial de la Federación el 20 de marzo de 2025, última reforma DOF 14-11-2025, arts. 1-7, 9-18, 20 and 37 (scope, principles, consent, notice, security and confidentiality, self-regulation)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 March 2025.
A comprehensive regime rule binding private bodies.
As of 19 September 2026.
What it requires
- Obtain the data subject's consent, express or tacit, before processing their personal data, unless a listed statutory exception applies, and treat consent for financial or patrimonial data as requiring express consent.
- Give the data subject a privacy notice, at or before the first collection of their personal data, stating your identity and address, the categories of data collected and which are sensitive, the purposes that require consent, the options to limit use or disclosure, the ARCO mechanisms, and how you will communicate any change to the notice.
- Limit processing of personal data to the purposes stated in the privacy notice, and obtain the data subject's consent again before processing it for a different purpose.
- Establish and maintain administrative, technical, and physical security measures to protect personal data against damage, loss, alteration, destruction, or unauthorized use, access, or processing, at a level no lower than the measures you keep for your own information.
- Require everyone who takes part in any stage of processing personal data to keep it confidential, an obligation that survives the end of their relationship with you.
- Delete personal data relating to a contractual default once seventy-two months have passed from the date the default occurred, and otherwise suppress personal data, after any blocking period, once it is no longer necessary for the purposes stated in the privacy notice.
What it reaches
Obligation class
Consent, Disclosure, Security, Retention, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 protects personal data in the possession of private parties nationwide, excepting only credit-reporting societies and purely personal, non-commercial data collection. Article 5 requires lawfulness, purpose limitation, loyalty, consent, quality, proportionality, information and accountability in every processing, and article 6 bars collecting or processing personal data through deceptive or fraudulent means.
Article 7 conditions processing on the data subject's consent, express or tacit, except where article 9 dispenses with it (a legal provision, a publicly available source, prior dissociation, a legal relationship's requirements, an emergency, medical care, or a judicial order), and requires express consent specifically for financial or patrimonial data; consent is revocable at any time without retroactive effect.
Article 10 requires the responsable to keep personal data accurate, complete and current, to suppress it once its retention purpose lapses, and specifically to delete data relating to a contractual default once seventy-two months have passed from the date of the default. Article 11 limits processing to the purposes stated in the privacy notice and requires fresh consent for a different purpose.
Articles 14 to 17 require a privacy notice, made available at or before first collection, stating the responsable's identity and address, the categories of data collected (identifying which are sensitive), the purposes requiring consent, the data subject's options to limit use or disclosure, the ARCO mechanisms, and how notice changes will be communicated, in full or simplified form depending on the collection channel.
Article 18 requires administrative, technical and physical security measures against damage, loss, alteration, destruction or unauthorized use, access or processing, at a level no lower than the responsable's own information-security measures. Article 20 requires everyone involved in any stage of processing to keep personal data confidential, an obligation that survives the end of their relationship with the responsable.
Article 37 lets responsables adopt binding self-regulation schemes, notified to the Secretaría, that complement the Law's duties. This statute states no registration, data-protection-impact-assessment, or data-protection-officer duty on the responsable.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachprocesses_voiceprocesses_biometrics
Read the law
Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares
official consolidated text on the Cámara de Diputados' LeyesBiblio
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.