← Back to Guides
Compliance
September 30, 2026
Posts on LinkedIn and X by a former employee demanding that her personal data be deleted under the RGPD

A former employee demands that his data be deleted (and posts about it on social media): What should your subsidiary's IT department in Mexico do?

A former employee requests that her data be deleted, citing the " RGPD " and posts about it on social media. What should your subsidiary's IT department in Mexico have in place before this happens?

One Monday, a former employee demands that you delete her data… and posts about it

A hypothetical but very realistic scenario for a Mexican subsidiary of a European group with customers in the United States.

A former employee of your subsidiary sends an email to HR: she asks that all her personal data be deleted and cites RGPD, because her contract was signed by the parent company. Before HR responds, she posts on LinkedIn and X that the company is “ignoring her request,” along with screenshots.

HR passes the issue on to IT: “Where is your data?” And that’s where the problem begins. It’s not a legal issue. It’s an IT issue.

What IT Discovers on the First Day

  • At least three copies: the local RH server, the cloud backup, and the emails from two supervisors who saved his file in their inboxes.
  • No one knows who accessed which copy. Without access logs, nothing can be proven to headquarters or to any authority.
  • No one knows how long each document must be kept. Some must be kept due to legal requirements (pay stubs, Social Security), while others do not.

Two Laws, Two Clocks

The application falls under two categories at the same time, each with its own deadline:

  • LFPDPPP (Mexico): Under the law effective as of March 21, 2025, you have 20 business days to respond to a request ARCO and an additional 15 business days to fulfill it, if applicable. Oversight is no longer the responsibility of the INAI but rather of the Secretariat for Anti-Corruption and Good Governance. The law also requires establishing data retention periods and blocking data before deleting it.
  • RGPD (European Union): The general rule is to respond within one mes (Article 12), which may be extended in complex cases. Fines can reach up to 4% of the group’s total annual revenue or 20 million euros, whichever is greater. Whether the RGPD applies to your subsidiary depends on its specific circumstances (Article 3): it is advisable to confirm this with the parent company and a lawyer.

Note: “Deleting everything” is almost never possible or appropriate. The RGPD itself provides for exceptions when there is a legal obligation to retain data or when it is necessary to defend against a legal claim. Therefore, the correct approach is not to “delete” blindly, but to know what is being deleted, what is being blocked, and why.

What about the United States?

If your subsidiary has customers or employees in the United States, state privacy laws may also apply, depending on where those individuals live and the size of the business. And if your parent company is publicly traded there, auditors will also ask you for evidence of IT controls. We cover this in “SOX and IT Controls for Your Subsidiary.”

What Your IT Department Should Have Ready Before That Request Comes In

  1. An inventory of where each piece of personal data is stored: servers, the cloud, email, laptops, company cell phones, and third-party systems.
  2. Access controls and logs in systems containing personal data, to track who viewed or downloaded what.
  3. A retention policy by document type, with the legal basis for each retention period.
  4. A documented procedure for " ARCO " and deletion requests: who receives them, who reviews them, who decides, who carries them out, and who is responsible, including dates.
  5. Backups that can be purged: if a copy can't be located or deleted, you can't comply.
  6. A rule for crisis communication: No one responds on social media without coordinating with the legal department and headquarters.

Quick Checklist for Your Branch

  • Can you track down all the information about a person in less than 48 hours?
  • Do you know what kinds of copies exist outside of official systems (emails, spreadsheets, cell phones)?
  • Do you know what must be retained by law and for how long?
  • Does your procedure comply with the deadlines set by Mexican authorities and those of the parent company?
  • Does anyone know who would speak out if this ended up on social media?

If you answered "no" to two or more, that's your starting point.

Where to Start

Most subsidiaries don’t need to rebuild their infrastructure—they need to know where their data is and who has access to it. An IT audit documents this, and our 15 typical findings for subsidiaries show you what usually comes up. For the complete framework of both laws, check out LFPDPPP 2025 and GDPR: what your subsidiary’s IT must comply with, and for the differences with Europe, see “IT Regulatory Differences: Europe vs. Mexico.”

Would you like to know how long it would take you today to find someone's information? Write to us, and we'll go over it with you.

This article is for informational purposes only and does not constitute legal advice. Check with your legal department to confirm the deadlines and applicability of each law.

Conceived by us. Created by us. Powered by AI.

Do you need specific help with this topic?

30 minutes with one of our directors. No sales pitch—straight to the point.

Free Diagnosis · 30 minQuote within 24 hours