Law / Mexico

Mexico

14 of 16 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 19 September 2026.

When they take effect11 of 14 carry a date, 3 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 6 instruments (6 in force) 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (238 words)

Mexico has no general AI-transparency, AI-risk-obligations, AI-training-data, or AI-governance statute; two competing comprehensive AI bills, a Senate-commission framework proposal (Iniciativa de Ley General de Inteligencia Artificial, chaired by Sen. Rolando Zapata Bello) and a separate initiative by Sen. Karina Isabel Ruiz Ruiz (Ley Nacional para Regular el Uso de la Inteligencia Artificial, filed 11 February 2026 in four variants), remained in Senate committees with no floor vote in either chamber as of this review and bind nobody; they are not recorded as instruments here because neither has passed a chamber, per the marquee-proposal threshold, and no official Senate procedural record was read to confirm their current text.

Two enacted instruments do reach AI specifically. The Código Penal Federal's Título Séptimo Bis criminalises non-consensual intimate sexual content since a 2021 reform (the "Ley Olimpia" package) and, separately, extends the same penalty to intimate sexual content that does not actually correspond to the person shown in it, which reaches an AI-synthesised or otherwise manipulated depiction on its face even though the text does not use the words "artificial intelligence" or "deepfake".

A 2026 decree amending the Ley Federal del Trabajo and the Ley Federal del Derecho de Autor requires consent and contractually specified compensation before an AI system may process, clone, or generate a performing artist's voice or image, and separately bars an AI-generated clone or impersonation of a performer's interpretation absent consent, subject to parody, satire, and non-replacement exceptions.

AI prohibited practices

Código Penal Federal, Violación a la Intimidad Sexual (Arts. 199 Octies a 199 Decies), including manipulated or non-corresponding depictions

Código Penal Federal Título Séptimo Bis, Capítulo II, arts. 199 Octies, 199 Nonies, 199 Decies, adicionados por decreto publicado en el Diario Oficial de la Federación el 1 de junio de 2021Código Penal Federal, official consolidated text on the Cámara de Diputados' LeyesBiblio

In force since 2 June 2021. Binds public and private bodies.

What this law does

Article 199 Octies criminalises, for any person, divulging, sharing, distributing, or publishing images, videos, or audio of intimate sexual content of an adult without their consent, approval, or authorisation, and separately criminalises video-recording, audio-recording, photographing, printing, or producing such content of a person without their consent, approval, or authorisation, each carrying 3 to 6 years' imprisonment and a fine of 500 to 1,000 times the Unidad de Medida y Actualización (UMA).

Article 199 Nonies imposes the same penalties where the intimate sexual images, videos, or audio disseminated, shared, distributed, or published do not actually correspond to the person indicated or identified in them: the article's text requires only that the disseminated content not correspond to the identified person, without regard to how the non-corresponding depiction was produced, so it reaches a manipulated, fabricated, or AI-synthesised depiction of a person's face or voice in intimate sexual content on the same terms as any other non-corresponding depiction.

Article 199 Decies increases the minimum and maximum penalty by up to one half where the offence is committed by a spouse, partner, or person in a relationship of trust with the victim; by a public servant in the exercise of their functions; against a person unable to understand or resist the act; for non-lucrative benefit; for profit; or where the victim, as a consequence of the offence, attempts against their own physical integrity or life.

What it requires

AI sector rules

Reform to the Federal Labor Law and the Federal Copyright Law, AI Voice and Image Consent Regime for Performing Artists

Decreto por el que se reforman y adicionan diversas disposiciones de la Ley Federal del Trabajo y de la Ley Federal del Derecho de Autor en materia de derechos de las personas trabajadoras artistas intérpretes o ejecutantes, Diario Oficial de la Federación, 14 de mayo de 2026 (arts. 305 Bis LFT; 87, 102, 118 fracción VII, 121 LFDA)Text of the decree amending the Ley Federal del Trabajo and the Ley Federal del Derecho de Autor, Diario Oficial de la Federación

In force 4 months, effective 15 May 2026. Binds private bodies.

What this law does

New Article 305 Bis of the Ley Federal del Trabajo requires a performing artist's labor contract to specifically stipulate the conditions and remuneration for using their image or voice through artificial intelligence systems or any other technology.

Reformed Article 87 of the Ley Federal del Derecho de Autor requires a performing artist's express consent, or that of their representative or rights-holder, before their image, including their voice, may be used or published, and expressly extends that protection to results generated by AI systems or other technology; a performer who received specific remuneration for a use is presumed to have consented only to the agreed purpose and modality, and any different use requires new authorisation and remuneration.

The article exempts use where the performer's image forms a minor part of a group, is captured in a public place, or is used for informational or journalistic purposes, and does not treat parody, satire, or creative imitation as a violation, nor a use that is not a cloning or impersonation intended to mislead the public or to substitute the performer's own professional work in the market through AI or another technology.

New Article 118, fracción VII, of the same law gives a performer a right against the impersonation of their interpretations by AI systems or other technology that generates clones of their interpretations or simulates their voice identifiably, subject to the same parody, satire, and non-replacement exceptions.

Article 121 requires a prior written agreement between the parties for any cloning or impersonation of a performer's voice or image using AI or other technology within an audiovisual work, beyond what a production contract ordinarily authorises. Article 231, fracción II, makes contravening Articles 87 or 118, fracción VII, an infraction, and Article 232 fixes the administrative fine for that infraction between 5,000 and 40,000 days of the general minimum wage.

What it requires

Privacy law6 instruments, 6 in force

Research summary (251 words)

Mexico's comprehensive private-sector data-protection statute, the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), was entirely re-enacted (a new law, not an amendment) by the same decree published in the Diario Oficial de la Federación on 20 March 2025 that also created the Ley General de Transparencia y Acceso a la Información Pública and the Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados for the public sector; the decree expressly abrogated the prior 2010 LFPDPPP and the 2017 general public-sector data-protection law.

The new LFPDPPP transferred oversight from the dissolved INAI to the Secretaría Anticorrupción y Buen Gobierno.

It conditions processing on the data subject's consent (express or tacit, express and written for sensitive data), gives the data subject ARCO rights (access, rectification, cancellation, objection) including a right to object to a fully automated decision that produces undesired legal effects or significantly affects the person, requires notice of security breaches that significantly affect the data subject's patrimonial or moral rights, and lets a controller transfer data domestically or internationally without consent only within a list of enumerated grounds.

No provision of the LFPDPPP names a biometric identifier, voiceprint, or faceprint as a sensitive category; the sensitive-data definition is illustrative rather than exhaustive but enumerates only racial or ethnic origin, health status, genetic information, religious, philosophical or moral beliefs, political opinion, and sexual preference, so a biometric identifier not otherwise tied to one of those categories is protected only as ordinary personal data.

Breach notification

Ley Federal de Protección de Datos Personales en Posesión de los Particulares, security-breach notice

LFPDPPP, art. 19 (security-breach notice)Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares

In force since 21 March 2025. Binds private bodies.

What this law does

Article 19 requires the responsable to inform the data subject immediately of a security breach occurring at any stage of processing personal data that significantly affects the data subject's patrimonial or moral rights, so the data subject can take the steps needed to defend their rights. The Law states no separate deadline measured in hours or days: immediacy of the breach itself is the period, and the duty runs to the affected data subject alone.

The Law states no duty to report a breach to the Secretaría; article 39 gives the Secretaría general investigative and sanctioning powers over compliance with this Law, but no provision requires a breach report to it specifically.

What it requires

Comprehensive regime

Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)

Ley Federal de Protección de Datos Personales en Posesión de los Particulares Nueva Ley publicada en el Diario Oficial de la Federación el 20 de marzo de 2025, última reforma DOF 14-11-2025, arts. 1-7, 9-18, 20 and 37 (scope, principles, consent, notice, security and confidentiality, self-regulation)Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares

In force since 21 March 2025. Binds private bodies.

What this law does

Article 1 protects personal data in the possession of private parties nationwide, excepting only credit-reporting societies and purely personal, non-commercial data collection. Article 5 requires lawfulness, purpose limitation, loyalty, consent, quality, proportionality, information and accountability in every processing, and article 6 bars collecting or processing personal data through deceptive or fraudulent means.

Article 7 conditions processing on the data subject's consent, express or tacit, except where article 9 dispenses with it (a legal provision, a publicly available source, prior dissociation, a legal relationship's requirements, an emergency, medical care, or a judicial order), and requires express consent specifically for financial or patrimonial data; consent is revocable at any time without retroactive effect.

Article 10 requires the responsable to keep personal data accurate, complete and current, to suppress it once its retention purpose lapses, and specifically to delete data relating to a contractual default once seventy-two months have passed from the date of the default. Article 11 limits processing to the purposes stated in the privacy notice and requires fresh consent for a different purpose.

Articles 14 to 17 require a privacy notice, made available at or before first collection, stating the responsable's identity and address, the categories of data collected (identifying which are sensitive), the purposes requiring consent, the data subject's options to limit use or disclosure, the ARCO mechanisms, and how notice changes will be communicated, in full or simplified form depending on the collection channel.

Article 18 requires administrative, technical and physical security measures against damage, loss, alteration, destruction or unauthorized use, access or processing, at a level no lower than the responsable's own information-security measures. Article 20 requires everyone involved in any stage of processing to keep personal data confidential, an obligation that survives the end of their relationship with the responsable.

Article 37 lets responsables adopt binding self-regulation schemes, notified to the Secretaría, that complement the Law's duties. This statute states no registration, data-protection-impact-assessment, or data-protection-officer duty on the responsable.

What it requires

Cross border transfer

Ley Federal de Protección de Datos Personales en Posesión de los Particulares, transfer of personal data

LFPDPPP, arts. 35-36 (transfer of personal data)Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares

In force since 21 March 2025. Binds private bodies.

What this law does

Article 35 conditions any transfer of personal data to a national or foreign third party, other than the persona encargada, on communicating the privacy notice and the purposes to which the data subject's processing is subject; the notice must state whether the data subject accepts the transfer, and the recipient assumes the same duties as the transferring responsable.

Article 36 lists the grounds on which a domestic or international transfer may proceed without the data subject's consent: a law or treaty to which Mexico is a party, medical prevention, diagnosis, care, or health-service management, a transfer within a corporate group under common control operating under the same internal processes and policies, a contract concluded or to be concluded in the data subject's interest, a public-interest or judicial-administration ground, the recognition, exercise, or defense of a right in a judicial proceeding, or the maintenance or performance of a legal relationship between the responsable and the data subject.

The chapter treats domestic and cross-border transfers under the same regime rather than imposing a separate data-localization or adequacy-list requirement for transfers leaving Mexico.

What it requires

Data subject rights

Ley Federal de Protección de Datos Personales en Posesión de los Particulares, ARCO rights

LFPDPPP, arts. 21-34 (ARCO rights and their exercise)Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares

In force since 21 March 2025. Binds private bodies.

What this law does

Article 21 lets any data subject or their legal representative exercise the ARCO rights (access, rectification, cancellation, and objection), none conditioning or blocking the others, and requires personal data to be safeguarded so these rights can be exercised without delay. Article 22 gives a right of access to the data subject's personal data and to the conditions of its processing through the privacy notice.

Article 23 gives a right to rectify or correct inaccurate, incomplete, or outdated personal data. Article 24 gives a right to cancel personal data from the responsable's files, records, and systems at any time, subject to a blocking period equal to the statute of limitations for the underlying legal relationship before the data is finally suppressed, with notice to the data subject once cancelled and to any third party the data were transferred to before the cancellation.

Article 25 lists the grounds on which the responsable need not cancel data (a contractual necessity, a legal requirement, an obstacle to judicial or administrative proceedings, the data subject's own protected interests, the public interest, a legal obligation of the data subject, or a health professional's care under a duty of secrecy).

Article 26 gives a right to object to processing for a legitimate cause, including an unqualified right at article 26, fracción II to object to a fully automated decision that produces undesired legal effects or significantly affects the data subject's interests, rights, or freedoms, and that is intended to evaluate, without human intervention, their professional performance, economic situation, health status, sexual preferences, reliability, or behaviour; objection does not lie where processing is necessary to comply with a legal obligation imposed on the responsable.

Articles 27 to 30 set the request's required content and require the responsable to designate a person or department to handle it. Article 31 requires the responsable to communicate its determination within a maximum of twenty days of receiving an ARCO request, to give effect to a favourable determination within fifteen days of that communication, and lets both periods be extended once for an equal period on justified grounds.

Article 33 lists the grounds on which an ARCO request may be denied (inadequate identification, the data not being in the responsable's possession, a third party's rights, a legal impediment or an authority's ruling, or a request already carried out), each requiring written reasons.

Article 34 makes exercising ARCO rights free, limited to reproduction, copying, or shipping costs, and caps a repeat request within twelve months at three times the Unidad de Medida y Actualización absent a substantial change to the privacy notice.

What it requires

Enforcement supervision

Ley Federal de Protección de Datos Personales en Posesión de los Particulares, enforcement, sanctions and offences

LFPDPPP, arts. 38-64 (Secretaría, rights-protection procedure, verification, sanctions and offences)Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares

In force since 21 March 2025. Binds private bodies.

What this law does

Article 38 charges the Secretaría with disseminating knowledge of the right to data protection, promoting its exercise, and overseeing compliance with the Law.

Article 39 gives the Secretaría the power to monitor and verify compliance, interpret the Law administratively, support responsables technically, issue criteria and recommendations, publish security standards and best practices, resolve rights-protection and verification proceedings and impose sanctions, cooperate with other supervisory authorities, and prepare privacy-impact studies before new processing modalities, among other functions.

Article 40 lets a data subject or representative file a rights-protection request with the Secretaría within fifteen days of the responsable's response, or after the response deadline lapses without one, when the responsable denies, ignores, or inadequately answers an ARCO request; the Secretaría gives the responsable fifteen days to answer, admits evidence, and allows five days for closing arguments.

Article 42 sets a maximum of fifty days to resolve the rights-protection request, extendable once for an equal period on justified cause. Article 43 gives the responsable ten days to give effect to a favourable resolution once notified. Article 45 lets the Secretaría cure deficiencies in the complaint without altering its original content. Article 46 lets the Secretaría dismiss the request, confirm, revoke, or modify the responsable's response, or order delivery of the data.

Article 49 lets the Secretaría seek conciliation between the parties at any point, with a binding written agreement closing the matter. Article 51 lets a party challenge a Secretaría resolution by amparo before specialized federal courts, and article 52 lets the Secretaría publish its resolutions with the data subject's identifying references removed.

Article 53 lets a data subject who suffered damage or injury from the responsable's or persona encargada's non-compliance pursue the compensation available under other applicable law.

Article 54 lets the Secretaría open a verification procedure on its own initiative or on request, and article 56 opens a sanctions procedure when a rights-protection or verification proceeding surfaces a suspected violation; article 57 gives the accused responsable fifteen days to submit evidence and five days for closing arguments, with a fifty-day resolution deadline extendable once for an equal period.

Article 58 lists nineteen infractions, from failing to satisfy an ARCO request without justified reason to processing personal data contrary to the Law's principles, creating a sensitive-data database without a justified purpose, and obstructing a verification act.

Article 59 fines an infraction from 100 to 160,000 times the Unidad de Medida y Actualización for the lesser infractions and 200 to 320,000 times the UMA for the more serious ones, adds 100 to 320,000 UMA for a repeated infraction, and lets sanctions for infractions involving sensitive personal data double.

Article 60 lists the factors the Secretaría weighs when it grounds a sanction: the nature of the data, how plainly unjustified the responsable's refusal was, intent, the responsable's economic capacity, and recidivism. Article 61 states that these administrative sanctions apply without prejudice to any resulting civil or criminal liability.

Articles 62 to 64 create criminal offences: three months to three years' imprisonment for a person authorized to process personal data who, for profit, causes a security breach of a database in their custody; six months to five years' imprisonment for anyone who processes personal data through deceit for undue profit, taking advantage of the data subject's or an authorized person's error; and double the penalty in either offence where the data processed is sensitive personal data.

What it requires

Sensitive categories

Ley Federal de Protección de Datos Personales en Posesión de los Particulares, sensitive personal data

LFPDPPP, arts. 2(VI), 8 and 12 (sensitive personal data)Text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares

In force since 21 March 2025. Binds private bodies.

What this law does

Article 2, fracción VI defines sensitive personal data as data touching the data subject's most intimate sphere, or whose misuse could cause discrimination or a serious risk to them, and lists, illustratively but not exhaustively, racial or ethnic origin, present or future health status, genetic information, religious, philosophical or moral beliefs, political opinions, and sexual preference; the list does not name a biometric identifier, voiceprint, or faceprint, so a biometric identifier not otherwise tied to one of the enumerated categories is protected only as ordinary personal data under this Law's general regime.

Article 8 requires the data subject's express, written consent, given by autograph signature, electronic signature, or another authentication mechanism, before processing sensitive personal data, and bars creating a database of sensitive personal data unless its creation serves a legitimate, specific purpose consistent with the responsable's explicit activities or aims.

Article 12 requires the responsable to make reasonable efforts to limit the period sensitive personal data is processed to the minimum indispensable, on top of the general proportionality principle article 12 states for personal data generally.

Article 9, fracción VI separately lets a responsable process sensitive personal data without consent for medical prevention, diagnosis, care, or health-service management while the data subject cannot consent, carried out by someone bound by professional secrecy.

What it requires

Scraping law3 instruments, 3 in force

Research summary (236 words)

Mexico has no scraping-specific statute; three general federal regimes bear on it.

The Código Penal Federal's unauthorised-access chapter (Arts. 211 bis 1 to 211 bis 7) criminalises modifying, destroying, causing loss of, knowing, or copying information in a computer system or equipment WITHOUT AUTHORISATION only where that system is protected by a security mechanism, so on its face a scraper reading a public, unauthenticated page that defeats no security mechanism falls outside it; defeating a login or another access control to reach the same data plausibly falls within it.

The Ley Federal del Derecho de Autor (LFDA) gives a compilation-style protection to a database's selection and arrangement (Art. 107) and a separate 5-year exclusive-use protection to a non-original database held by whoever compiled it (Art. 108), and its 2020 technological-protection-measures chapter (Arts. 114 Bis, 232 Bis) fines circumventing a technological protection measure that controls access to a copyrighted work.

No Mexican court decision addressing browsewrap or clickwrap Terms-of-Service enforceability, robots.txt's legal weight, or an unfair-competition or misappropriation doctrine specific to scraping was located in the sources checked; these read as unsettled rather than as an established permission or prohibition.

Personal data collected by scraping falls within the reach of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), researched separately as this jurisdiction's privacy-topic document, which the LFDA's own Article 109 cross-references for a database containing private information about identifiable people.

Computer misuse

Código Penal Federal, Unauthorised Access to Computer Systems and Equipment (Arts. 211 bis 1 to 211 bis 7)

Código Penal Federal, Arts. 211 bis 1 al 211 bis 7Código Penal Federal, official consolidated text on the Cámara de Diputados' LeyesBiblio

In force. Binds public and private bodies.

What this law does

Article 211 bis 1 punishes with 6 months to 2 years' imprisonment and a fine anyone who, without authorisation, modifies, destroys, or causes the loss of information contained in a computer system or equipment protected by a security mechanism, and with 3 months to 1 year's imprisonment anyone who, without authorisation, learns of or copies such protected information.

Articles 211 bis 2 and 211 bis 3 impose heavier penalties, up to 10 years for public-security systems, for the same conduct against a State computer system, distinguishing an outsider acting without authorisation from an insider authorised to access the system who acts improperly within it. Articles 211 bis 4 and 211 bis 5 apply a parallel regime to financial-sector computer systems.

Article 211 bis 7 increases every penalty in the chapter by up to one half where the information obtained is used for the offender's own benefit or a third party's. Each offence turns on defeating a security mechanism protecting the system ("protegidos por algún mecanismo de seguridad") without authorisation; the text does not on its face reach reading a page that carries no such mechanism.

What it requires

Ley Federal del Derecho de Autor, Technological Protection Measures and Circumvention (Arts. 114 Bis, 232 Bis)

Ley Federal del Derecho de Autor (LFDA) arts. 114 Bis y 232 Bis, adicionados por decreto publicado en el Diario Oficial de la Federación el 1 de julio de 2020Ley Federal del Derecho de Autor, official consolidated text on the Cámara de Diputados' LeyesBiblio

In force since 2 July 2020. Binds public and private bodies.

What this law does

Article 114 Bis lets a copyright or related-right holder implement an effective technological protection measure, defined as any technology, device, or component that, in the normal course of its operation, protects the right or controls access to a work, performance, or phonogram, and lets rights-management information be attached to a work.

Article 232 Bis fines, from 1,000 to 20,000 times the Unidad de Medida y Actualización (UMA), anyone who produces, reproduces, manufactures, distributes, imports, markets, leases, stores, transports, offers, makes available, or otherwise supplies a device, mechanism, product, component, or system that is promoted, marketed, or advertised for the purpose of circumventing an effective technological protection measure; is used predominantly for that purpose; or is designed, produced, or executed for that purpose.

Neither article names crawling, scraping, or a bot as such; the prohibition reaches circumventing an access-control or copy-control mechanism on a copyrighted work regardless of the collection method used afterward.

What it requires

Database right

Ley Federal del Derecho de Autor, Database Compilation and Non-Original Database Protection (Arts. 107 to 110)

Ley Federal del Derecho de Autor (LFDA), arts. 107 a 110Ley Federal del Derecho de Autor, official consolidated text on the Cámara de Diputados' LeyesBiblio

In force. Binds public and private bodies.

What this law does

Article 107 protects a database or other machine-readable material as a compilation where its selection or arrangement of content constitutes an intellectual creation, and the protection does not extend to the underlying data and materials themselves. Article 108 separately protects a non-original database in its exclusive use by whoever compiled it, for 5 years, without requiring the originality Article 107 asks of a compilation.

Article 109 conditions access to, and publication, reproduction, disclosure, public communication, or transmission of, private information about identifiable people contained in such a database on the prior authorisation of the persons concerned, exempting law-enforcement investigations and lawful access to public archives.

Article 110 gives the holder of the patrimonial right over a database the exclusive right to authorise or prohibit its reproduction, translation, adaptation, reordering or other modification, distribution, and public communication, including of the results of a permitted modification. Mexico's regime protects the compilation's selection and arrangement and, separately, a 5-year producer-style exclusive-use right over a non-original database.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (633 words)

Mexico's federal legislature has not enacted a standalone cybersecurity or product-security statute.

The Camara de Diputados' LeyesBiblio index of laws currently in force lists no Ley General or Ley Federal de Ciberseguridad, and the 2025 telecommunications law (Ley en Materia de Telecomunicaciones y Radiodifusion, DOF 16-07-2025, which replaced the former LFTR) carries no security-by-design, vulnerability-handling or incident-notification provision for a telecommunications, platform or software provider: that law's text does not use ciberseguridad, seguridad de la informacion or vulnerabilidad at all, and its one use of incidente is an unrelated procedural term in its sanctions chapter.

No manufacturer duty on a connected device or a product with digital elements (a pre-market security requirement, an update or support-period duty, or a vulnerability-disclosure channel) appears in any statute covered here, so product_security_requirements is absent rather than partially covered.

A general, clocked vulnerability or incident-reporting duty running to an authority is likewise absent from primary federal legislation. Two financial-sector statutes delegate an information-security duty to secondary regulation instead of stating the operative standard themselves.

The Ley para Regular las Instituciones de Tecnologia Financiera (Ley Fintech), in the authorization-application article for an Institucion de Tecnologia Financiera (ITF, a CNBV-licensed fintech institution offering crowdfunding or electronic-payment-fund services), requires the applicant's dossier to include evidence of secure technological support and of minimum security standards assuring the confidentiality, availability and integrity of information and the prevention of fraud and cyberattacks, then hands the operative standard, audit cadence and any incident clock to disposiciones de caracter general the CNBV and Banco de Mexico issue jointly; no primary text for those disposiciones is available here.

The Ley de Instituciones de Credito, which binds banks, carries no comparable cybersecurity or information-security-programme article of its own; the only seguridad de la informacion language in that statute concerns safeguarding client-identification records under its anti-money-laundering reporting regime, not a general information-security duty, and the bank-specific cybersecurity requirements this jurisdiction is understood to carry sit in a CNBV circular (Disposiciones de caracter general aplicables a las instituciones de credito), for which neither dof.gob.mx nor a stable CNBV normateca URL is available here.

Both sit in sector_security_regimes territory without a reachable primary text carrying a clock, so neither is a flaggable instrument; neither bound party (a CNBV-licensed ITF, a bank) has a declared activity in the LexLint vocabulary in any case, so both would be deferred as a financial-entity sector regime even against the secondary text.

The one duty flagged here sits outside the financial sector, in the general consumer-protection statute rather than in a dedicated security law.

Ley Federal de Proteccion al Consumidor (LFPC) Arts. 76 Bis and 76 Bis 1, added to that statute in 2000 and unchanged in the relevant fractions through the DOF 14-11-2025 reform, bind any proveedor conducting a transaction with a consumidor through medios electronicos, opticos o de cualquier otra tecnologia: the provider must use an available technical security element to protect the confidentiality of the information the consumer provides, and it must follow the Secretaria de Economia's Norma Mexicana for electronic commerce, whose required content the statute itself specifies must include reliable technical security mechanisms guaranteeing the protection and confidentiality of the consumer's personal information and of the transaction.

Procuraduria Federal del Consumidor (PROFECO) enforces it administratively under the LFPC's general fine bands; no criminal offence or distinct private right of action attaches to this chapter.

Mexico's breach-notification duty for personal data, LFPDPPP Arts. 18 and 19 (a controller must establish and maintain administrative, technical and physical security measures, and inform the data subject immediately of a security breach that significantly affects their patrimonial or moral rights), sits in the privacy topic (data/law-topics/privacy/mx.json) and is not restated here: it is the comprehensive data-protection act's own security-of-processing clause rather than a standalone security statute, which is the line this topic draws against privacy.

Security baseline statutes

Ley Federal de Protección al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1)

Ley Federal de Proteccion al Consumidor (LFPC) Capitulo VIII Bis "De los Derechos de los Consumidores en las Transacciones Efectuadas a traves del Uso de Medios Electronicos, Opticos o de Cualquier Otra Tecnologia", Arts. 76 Bis y 76 Bis 1, capitulo adicionado por decreto publicado en el Diario Oficial de la Federacion el 29 de mayo de 2000, texto vigente con ultima reforma DOF 14-11-2025Ley Federal de Proteccion al Consumidor

In force since 29 May 2000. Binds private bodies.

What this law does

Article 76 Bis opens the chapter: its rules apply to the relationship between a proveedor (provider) and a consumidor (consumer) in a transaction carried out through medios electronicos, opticos o de cualquier otra tecnologia. Fraccion I requires the provider to keep the consumer's information confidential and not disclose it to another provider outside the transaction without the consumer's express authorization or a competent authority's request.

Fraccion II requires the provider to use an available technical security element to give security and confidentiality to that information, and to tell the consumer, before the transaction closes, the general characteristics of that element.

Article 76 Bis 1 separately requires a provider that offers, commercializes or sells goods, products or services using those means to follow the Norma Mexicana the Secretaria de Economia issues for electronic commerce, which the article specifies must contain at least seven categories of information; fraccion V of that list is reliable technical security mechanisms guaranteeing the protection and confidentiality of the consumer's personal information and of the transaction itself.

Neither article names a sector, a company size or a data category; the duty runs to any provider transacting electronically with a consumer in Mexico.

Procuraduria Federal del Consumidor (PROFECO), the decentralized administrative authority the LFPC itself creates to protect consumer rights, enforces the statute; this chapter creates no distinct criminal offence and no separate private right of action beyond PROFECO's ordinary consumer-complaint and sanction procedures under the LFPC's general fine bands (Arts. 126 to 128 Bis, amounts adjusted annually by DOF accord and not restated here to avoid publishing a figure that goes stale before the next adjustment).

What it requires

Age gating law1 instrument, 1 in force

Research summary (183 words)

Mexico binds a private video-game distributor, seller, or renter to an age-verification duty under the Ley General de los Derechos de Niñas, Niños y Adolescentes (LGDNNA): a video game classified as exclusively for adults may not be sold or rented to a person who does not prove they have reached the age of majority.

Two further instruments reach minors and content but not through a gating or access-control duty, so neither is recorded here as an instrument: the LGDNNA and the Ley en Materia de Telecomunicaciones y Radiodifusión (LMTR, in force since 16 July 2025, replacing the 2014 Ley Federal de Telecomunicaciones y Radiodifusión) both bind a radio and television concessionaire to display an on-screen content classification and to abstain from broadcasting content harmful to minors, which is a labelling and scheduling duty rather than a gating one.

The Código Penal Federal's Article 202 criminalises producing, offering, or distributing child-sexual-abuse material generally, which is a general criminal offence rather than a private-service gating duty. No social-media minor-access restriction, app-store or device-level age-verification duty, or age-appropriate design code was located in the sources checked.

Adult content age verification (AV)

Ley General de los Derechos de Niñas, Niños y Adolescentes, Video Game Age Verification (Art. 69 Bis)

Ley General de los Derechos de Niñas Niños y Adolescentes (LGDNNA), art. 69 Bis, adicionado por decreto publicado en el Diario Oficial de la Federación el 9 de marzo de 2018Ley General de los Derechos de Niñas, Niños y Adolescentes, official consolidated text on the Cámara de Diputados' LeyesBiblio

In force since 10 March 2018. Binds private bodies.

What this law does

Article 69 Bis requires the Secretaría de Gobernación to issue the guidelines classifying video games distributed, marketed, or rented by any means, and to oversee compliance. A video-game distributor must print or affix the applicable classification on the game's cover and in its advertising. A video-game marketer must not advertise, exhibit, sell, or rent a video game whose classification is not visible under the guidelines.

A video-game marketer or renter must require a person seeking to buy or rent a video game classified as exclusively for adults to prove they have reached the age of majority, without which the sale or rental may not proceed. Article 148, fracción VII Bis, makes contravening this duty an infraction, sanctioned under Article 149 with a fine of 3,000 to 30,000 days of the general minimum wage in effect when the conduct occurred, doubled on recidivism. The article itself does not specify a required proof-of-age method.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (132 words)

Mexico's Ley Federal del Derecho de Autor (LFDA) lets anyone reproduce, without the rightsholder's authorisation or remuneration, a quotation of a text of non-substantial length, and separately lets anyone reproduce an article, photograph, illustration, or commentary on a current event published by the press or broadcast, unless the rightsholder has expressly prohibited that use; both exceptions require citing the source and leaving the work unaltered.

Mexico has no press-publisher neighbouring right comparable to the EU's Digital Single Market (DSM) Article 15, no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, no text-and-data-mining exception or machine-readable opt-out mechanism distinct from the general reproduction exceptions above, and no hot-news or misappropriation doctrine or linking or framing case law distinct from ordinary copyright law was located in the sources checked.

Snippet reproduction

Ley Federal del Derecho de Autor, Quotation and Current-Events News Reproduction Exceptions (Art. 148, fracciones I y II)

Ley Federal del Derecho de Autor (LFDA), art. 148, fracciones I y IILey Federal del Derecho de Autor, official consolidated text on the Cámara de Diputados' LeyesBiblio

In force. Binds public and private bodies.

What this law does

Article 148's chapeau permits using an already-divulged literary or artistic work, without the rightsholder's authorisation and without remuneration, provided the normal exploitation of the work is not affected, the source is always cited, and the work is not altered, only in the cases the article then lists. Fracción I permits quoting a text, provided the amount taken cannot be considered a simulated and substantial reproduction of the work's content.

Fracción II permits reproducing articles, photographs, illustrations, and commentary on current events, published by the press or broadcast by radio, television, or any other medium, unless the rightsholder has expressly prohibited that use. Fracción II's own permission is opt-out rather than opt-in: a news publisher who has not expressly prohibited the reuse cannot object to a reproduction that otherwise meets Article 148's conditions.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.