
LFPDPPP In 2025, the regulatory authority changed, and the “ GDPR ” may now apply to your Mexican subsidiary. What steps should your IT department take to comply with both laws simultaneously?
If your company is the Mexican subsidiary of a European group, it’s easy to assume that you’re only required to comply with Mexican law. In practice, however, many subsidiaries are subject to two data protection regimes at the same time: the Mexican General Data Protection Act ( LFPDPPP ), because they operate and process data in Mexico, and the European General Data Protection Regulation (GDPR ), because they process data belonging to EU citizens, receive processing instructions from the parent company, or are part of its chain of data processors.
The Federal Law on the Protection of Personal Data Held by Private Parties underwent a significant update: the new law took effect on March 21, 2025 (published in the Official Gazette of the Federation on March 20, with an amendment on November 14, 2025), replacing the 2010 law. The most important change from a practical standpoint: the Federal Commission for the Protection of Personal Data ( INAI ) was dissolved, and oversight and enforcement regarding data protection were transferred to the Secretariat for Anti-Corruption and Good Governance. If your compliance team continues to document processes “before the Federal Commission for the Protection of Personal Data ( INAI),” that document is now outdated.
The law applies to any individual or legal entity in the private sector that carries out “any operation involving personal data: collection, use, recording, organization, retention, communication, dissemination, storage, access, processing, exploitation, disclosure, transfer, or disposal”—that is, virtually any company with employees, customers, or suppliers in Mexico.
Article 3 of the General Data Protection Regulation ( GDPR ) extends its scope beyond the European Union in two scenarios that frequently apply to Mexican subsidiaries of European groups: when the company offers goods or services to individuals in the EU (regulators look for indicators such as prices in euros or content in European languages), and when it monitors the behavior of individuals in the EU —for example, if systems operated from Mexico process cookies or IP addresses of European visitors to a group website. Fines for noncompliance can reach 4% of annual global revenue or 20 million euros, whichever is higher—and are calculated at the group level, not just for the subsidiary.
Most subsidiaries don’t need to reinvent their architecture: they need an IT audit to document where personal data is located, who has access to it, and what controls are already in place, as well as cybersecurity management to close technical gaps—encryption, access control, logs—before a request under the General Data Protection Regulation ( ARCO ) or an audit by the parent company uncovers them first. Also review the typical findings we encounter at subsidiaries during these audits.
30 minutes with one of our directors. No sales pitch—straight to the point.