← Back to Guides
Compliance
August 14, 2026
Cover image — replace before publishing

LFPDPPP 2025 and “ GDPR ”: What Your Subsidiary’s IT Department in Mexico Must Comply With

LFPDPPP In 2025, the regulatory authority changed, and the “ GDPR ” may now apply to your Mexican subsidiary. What steps should your IT department take to comply with both laws simultaneously?

Two laws, a single IT infrastructure

If your company is the Mexican subsidiary of a European group, it’s easy to assume that you’re only required to comply with Mexican law. In practice, however, many subsidiaries are subject to two data protection regimes at the same time: the Mexican General Data Protection Act ( LFPDPPP ), because they operate and process data in Mexico, and the European General Data Protection Regulation (GDPR ), because they process data belonging to EU citizens, receive processing instructions from the parent company, or are part of its chain of data processors.

What Changed in the " LFPDPPP " in 2025

The Federal Law on the Protection of Personal Data Held by Private Parties underwent a significant update: the new law took effect on March 21, 2025 (published in the Official Gazette of the Federation on March 20, with an amendment on November 14, 2025), replacing the 2010 law. The most important change from a practical standpoint: the Federal Commission for the Protection of Personal Data ( INAI ) was dissolved, and oversight and enforcement regarding data protection were transferred to the Secretariat for Anti-Corruption and Good Governance. If your compliance team continues to document processes “before the Federal Commission for the Protection of Personal Data ( INAI),” that document is now outdated.

The law applies to any individual or legal entity in the private sector that carries out “any operation involving personal data: collection, use, recording, organization, retention, communication, dissemination, storage, access, processing, exploitation, disclosure, transfer, or disposal”—that is, virtually any company with employees, customers, or suppliers in Mexico.

Specific Obligations for the Subsidiary

  • A privacy notice is available as soon as the data is received, including the identity and address of the data controller, the purposes of the processing, mechanisms ARCO , and the procedure for reporting changes.
  • ARCO 's Rights: 20 business days to respond to a request and an additional 15 business days to fulfill it, if applicable (extendable once for an equal period), at no cost to the data subject.
  • Data Controller-Processor Agreement: If your subsidiary processes data on behalf of the parent company (or vice versa), the law requires that this relationship be formalized in a contract, specifying the scope, instructions, security measures, and the final disposition of the data upon termination of the service.
  • Administrative, technical, and physical security measures appropriate to the type of data and the identified risk — the 2025 regulation, which will specify deadlines for reporting data breaches, has not yet been published.

When does the " GDPR " come into play?

Article 3 of the General Data Protection Regulation ( GDPR ) extends its scope beyond the European Union in two scenarios that frequently apply to Mexican subsidiaries of European groups: when the company offers goods or services to individuals in the EU (regulators look for indicators such as prices in euros or content in European languages), and when it monitors the behavior of individuals in the EU —for example, if systems operated from Mexico process cookies or IP addresses of European visitors to a group website. Fines for noncompliance can reach 4% of annual global revenue or 20 million euros, whichever is higher—and are calculated at the group level, not just for the subsidiary.

What does this mean for local IT?

  • Clearly define whether the subsidiary is responsible for or acts as a data processor for each database it handles, and formalize this in a contract.
  • Encryption of personal data in transit and at rest, as a technical safeguard required under both regimes.
  • Access and audit logs for systems containing personal data—the same type of control required for compliance with GxP; see our article on 21 CFR Part 11.
  • Mapping International Data Transfers: What Data Leaves Mexico for the European Parent Company, on What Legal Basis, and Under What Safeguards.
  • A documented procedure for responding to requests ARCO within the statutory deadlines in Mexico, coordinated with the parent company’s privacy team.

Where to Start

Most subsidiaries don’t need to reinvent their architecture: they need an IT audit to document where personal data is located, who has access to it, and what controls are already in place, as well as cybersecurity management to close technical gaps—encryption, access control, logs—before a request under the General Data Protection Regulation ( ARCO ) or an audit by the parent company uncovers them first. Also review the typical findings we encounter at subsidiaries during these audits.

Do you need specific help with this topic?

30 minutes with one of our directors. No sales pitch—straight to the point.

Free Diagnosis · 30 minQuote within 24 hours