Skip to content

Evidence request lists

Mexico LFPDPPP

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

ARCO Data Subject Rights - Mexico LFPDPPP

MX-LFPDPPP-ARCO-Rights-Articles-22-25-Acceso-Rectificacion-Cancelacion-Oposicion-Reglamento-89-103
Mexico LFPDPPP ARCO Rights + Articles 22-25 + Acceso + Rectificacion + Cancelacion + Oposicion + Reglamento 89-103

Provide and operate channels for data subjects to exercise ARCO rights (Acceso + Rectificacion + Cancelacion + Oposicion = Access + Rectification + Cancellation + Objection) under Articles 22-25 + Reglamento Articles 89-103. Acceso (Access) Article 23 within 20 working days extendable by 20 working days + response within 15 working days after acceptance + first request free of charge per 12-month period + identification verification. Rectificacion (Rectification) Article 24 free of charge for inaccurate or incomplete data. Cancelacion (Cancellation) Article 25 right to erasure with blocking period before deletion + grounds for refusal (legal obligation + freedom of expression + research + scientific or historical research + statistical purposes + administrative or judicial procedures + administrative law fines). Oposicion (Objection) Article 26 right to object to specific processing + ab

Artefacts an auditor will ask for
  • ARCO request register with 20+15 working day SLA evidence
  • Identification verification procedure
  • Cancelacion blocking period prior to deletion + grounds for refusal evidence
  • Free first request per 12-month period evidence
  • INAI complaint procedure + Recurso de Revision to TFJA preparedness within 15 days
Where this commonly fails
  • 20+15 working day SLA not tracked
  • Cancelacion deletion without blocking period (Article 25 breach)
  • Recurso de Revision 15-day SLA missed
  • Right of Portability (limited form) not operationalised post 2017 Parameters

Cross-Border and Domestic Transfer - Mexico LFPDPPP

MX-LFPDPPP-Cross-Border-Transfer-Articles-36-37-Reglamento-66-68-Domestic-International-APEC-CBPR-USMCA
Mexico LFPDPPP Cross-Border + Articles 36-37 + Reglamento 66 + 68 + Domestic + International + APEC CBPR + USMCA

Govern cross-border transfers under Articles 36-37 + Reglamento Articles 66 (international) and 68 (domestic). International transfers (Article 36) prohibited without informing data subject in Aviso de Privacidad + same purpose limitation + recipient agreement to same safeguards + recipient acceptance of LFPDPPP obligations. Reglamento Article 66 details for international transfers including written notification to data subject + transfer contract with recipient privacy obligations + recipient declaration of compliance + retention of evidence. Exceptions Article 37 including: legal/treaty obligation + medical emergency + parties processing + foreign companies needed for contract performance + judicial cooperation + recognition of judicial decisions. APEC CBPR pioneering economy (one of 9 APEC CBPR participants + first Latin American 2018) provides recognised cross-border transfer mechani

Artefacts an auditor will ask for
  • Aviso de Privacidad disclosure of international transfers per Article 36
  • Reglamento Article 66 international transfer contract with recipient privacy obligations + recipient declaration of compliance
  • Reglamento Article 68 domestic transfer safeguards
  • APEC CBPR Accountability Agent oversight evidence (if participating)
  • USMCA / T-MEC Article 19 cross-border alignment
  • 2025 reform cross-border regime gap analysis
Where this commonly fails
  • International transfers without Article 36 disclosure in Aviso de Privacidad
  • Reglamento Article 66 contract obligations not in written agreement
  • APEC CBPR claimed but no Accountability Agent oversight
  • Reglamento Article 68 not applied to intra-Mexico transfers

Eight Personal Data Protection Principles - Mexico LFPDPPP

MX-LFPDPPP-Eight-Principles-Article-6-Licitud-Consentimiento-Informacion-Calidad-Finalidad-Lealtad-Proporcionalidad-Responsabilidad
Mexico LFPDPPP Eight Principles + Article 6 + Licitud + Consentimiento + Informacion + Calidad + Finalidad + Lealtad + Proporcionalidad + Responsabilidad

Implement the eight foundational Personal Data Protection Principles under LFPDPPP Article 6. (1) Licitud (lawfulness) - lawful basis for processing. (2) Consentimiento (consent) - tacit consent default + express consent for financial/asset data + written consent for sensitive data. (3) Informacion (notice) - mandatory Aviso de Privacidad. (4) Calidad (data quality) - accuracy + completeness + currency. (5) Finalidad (purpose) - specified explicit and lawful purposes. (6) Lealtad (loyalty/good faith) - no deceptive or fraudulent means of collection. (7) Proporcionalidad (proportionality/minimisation) - adequate + relevant + not excessive. (8) Responsabilidad (accountability) - controller responsibility to demonstrate compliance + appropriate safeguards even when sub-processing + Officer for Personal Data designation. Aviso de Privacidad (Article 16) mandatory in Spanish + Integral (full)

Artefacts an auditor will ask for
  • Article 6 eight principles implementation matrix (Licitud + Consentimiento + Informacion + Calidad + Finalidad + Lealtad + Proporcionalidad + Responsabilidad)
  • Aviso de Privacidad in Spanish Integral + Simplified + Short formats per INAI Lineamientos 2013 amended 2024
  • Tacit / express / written consent records appropriate to data category
  • Sensitive data written and express consent under Article 9
  • Minor under 18 parental consent records
Where this commonly fails
  • English-only Aviso de Privacidad (Spanish required)
  • Tacit consent assumed for sensitive data (written and express required)
  • Short Aviso missing on printed forms
  • Lineamientos 2024 amendments not adopted

Enforcement Sanctions and Remedies - Mexico LFPDPPP

MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN
Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN

Manage INAI enforcement under Articles 63-67. Article 63 INAI investigation powers including information requests + on-site inspections + emergency measures + Procedure for Imposition of Sanctions (PIS). Article 64 administrative sanctions calculated in DAYS OF MEXICAN GENERAL MINIMUM WAGE (Salario Minimo General) up to 320,000 days (approximately MXN 33 million / USD 1.9 million 2025 minimum wage of MXN 248.93/day - ONE OF HIGHEST PENALTIES IN LATIN AMERICA) for serious violations including: non-existent or deficient Aviso de Privacidad + unlawful disclosure + denial or obstruction of ARCO rights + sensitive data processing without consent + minor data without parental consent + obstructing INAI. Penalties doubled for repeat offenders. Article 67 CRIMINAL PENALTIES up to 3 years imprisonment for unauthorised processing of sensitive data for profit + 6 months to 3 years for negligence af

Artefacts an auditor will ask for
  • INAI enforcement notice and Procedure for Imposition of Sanctions (PIS) response evidence
  • Penalty exposure assessment (up to 320,000 days minimum wage approximately MXN 33M / USD 1.9M)
  • Article 67 criminal exposure assessment (up to 3 years imprisonment + 6 months to 5 years)
  • Recurso de Revision 15-day appeal preparedness to TFJA
  • Supreme Court (SCJN) constitutional grounds escalation
  • Civil claim and class action preparedness under Codigo Civil Federal + Codigo Federal de Procedimientos Civiles
  • Bilateral MoU coordination with Spain AEPD + Argentina AAIP + Uruguay URCDP + Peru ANPD + RIPD Network
  • 2025 SABG transition stakeholder mapping
Where this commonly fails
  • 320,000-day-minimum-wage exposure not flagged to board
  • Article 67 criminal exposure not communicated to executive team
  • Recurso de Revision 15-day SLA not in incident response plan
  • RIPD bilateral cooperation not engaged for cross-border investigations
  • 2025 SABG transition stakeholder map not updated

Governance Officer Security Manual Risk Assessment - Mexico LFPDPPP

MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014
Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014

Operate Mexico LFPDPPP governance structure including Officer for Personal Data designation + Security Manual + Risk Assessment + Self-Regulation Parameters adherence. Reglamento Article 47 mandatory Officer for Personal Data (Encargado del Tratamiento o Responsable Especifico) designation for data controllers + responsibilities including coordinating compliance + responding to ARCO requests + INAI liaison + privacy training + breach response. Reglamento Article 50 Security Manual (Manual de Seguridad) documenting administrative + technical + physical security measures with risk-based justification. Reglamento Article 57 Risk Analysis (Analisis de Riesgos) + Threshold Analysis (Analisis de Brecha) identifying vulnerabilities + threats + impacts + mitigation. Reglamento Article 61 Security Measures aligned with INAI Recommendations on Security Measures (2018 amended 2024) including encryp

Artefacts an auditor will ask for
  • Officer for Personal Data designation per Reglamento Article 47
  • Security Manual per Reglamento Article 50 documenting admin/tech/physical measures
  • Risk Analysis + Threshold Analysis per Reglamento Article 57
  • Self-Regulation Parameters 2014 adherence + INAI-registered Code of Conduct membership
  • INAI Recommendations on Security Measures 2018 amended 2024 implementation
Where this commonly fails
  • Officer designated nominally but lacks authority + reporting line
  • Security Manual outdated and not maintained
  • Risk Analysis not refreshed annually
  • Codes of Conduct claimed but not INAI-registered

Scope and Authority - Mexico LFPDPPP

MX-LFPDPPP-Scope-Article-3-DOF-5-July-2010-Effective-6-July-2010-INAI-Reglamento-2011-Constitution-Articles-6-16
Mexico LFPDPPP Scope + Article 3 + DOF 5 July 2010 + INAI + Reglamento 2011 + Constitution Articles 6 and 16

Establish the legal foundation of Mexico LFPDPPP (Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares) enacted 27 April 2010 by Congress of the Union + signed by President Felipe Calderon Hinojosa + published Diario Oficial de la Federacion 5 July 2010 + effective 6 July 2010 + 69 Articles across XI Titulos + Reglamento (Regulation) 21 December 2011 with 144 Articles. Parameters for Self-Regulation 2014 + companion LGPDPPSO 2017 for public sector. Constitutional anchor Constitucion Politica de los Estados Unidos Mexicanos Articles 6 and 16 (right to data protection added by 2007 + 2014 amendments). INAI (Instituto Nacional de Transparencia Acceso a la Informacion y Proteccion de Datos Personales) autonomous constitutional body + 7 Commissioners appointed by Senate for 7-year staggered terms + replaced IFAI 2014. 2025 REFORM: Congress approved 21 November 2024 di

Artefacts an auditor will ask for
  • LFPDPPP applicability assessment
  • Constitutional anchor Articles 6 + 16 documentation
  • INAI / SABG correspondence records
  • Sectoral coordination evidence (CONDUSEF + COFEPRIS + IFT + CNBV)
  • 2025 reform readiness gap analysis
Where this commonly fails
  • No 2025 reform readiness for SABG transition
  • Sectoral coordination not mapped
  • USMCA Article 19 cross-border alignment not assessed

Security and Breach Notification - Mexico LFPDPPP

MX-LFPDPPP-Security-Breach-Notification-Reglamento-63-No-Time-Limit-INAI-Recommendations-CERT-MX
Mexico LFPDPPP Security + Breach Notification + Reglamento 63 + No Specified Time + INAI Recommendations + CERT-MX

Implement technical and organisational security measures + breach notification process under Article 19 + Reglamento Articles 61-67 + INAI Recommendations on Security Measures 2018 amended 2024. Article 19 requires administrative + technical + physical security measures sufficient to ensure confidentiality + integrity + availability of personal data + appropriate to nature of data + state of art + risk. INAI Security Recommendations baseline includes encryption + access controls + identification and authentication + audit trails + secure development lifecycle + supplier security + business continuity + workforce training. Reglamento Article 63 Breach Notification - controller must notify affected data subjects of any vulnerability that significantly affects rights (NOTE: NO SPECIFIED TIME LIMIT - significant gap vs GDPR 72-hour + 2017 LGPDPPSO public-sector law similarly lacks time limit

Artefacts an auditor will ask for
  • Article 19 security measures (admin + technical + physical) with state-of-art justification
  • INAI Recommendations 2018 amended 2024 implementation matrix
  • Reglamento Article 63 breach notification to affected data subjects evidence + breach register + corrective measures + Security Manual update
  • CERT-MX coordination for cyber-component breaches
  • Sectoral parallel notification (CONDUSEF + COFEPRIS + IFT) cross-walk
Where this commonly fails
  • No breach notification process despite Reglamento Article 63 trigger
  • INAI optional notification not exercised even for serious breaches (reputation risk)
  • Time-to-notify not pre-defined (LFPDPPP lacks 72-hour requirement)
  • Sectoral parallel notification missed

Sensitive Data and Minors - Mexico LFPDPPP

MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent
Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent

Process sensitive personal data and minor data under enhanced conditions in Article 3 Section VI + Article 9. Sensitive Personal Data definition Article 3 Section VI covers data affecting intimate sphere or wrongful use affecting discrimination including: racial or ethnic origin + present and future state of health + genetic information + religious philosophical or moral beliefs + union affiliation + political opinions + sexual preference. Processing of sensitive data requires written and express consent (Article 9) - higher standard than tacit consent for ordinary data. Reglamento Article 56 imposes additional safeguards - identification verification of consent giver + separate ledger of sensitive data processing + segregation of sensitive data from ordinary data + access restricted to need-to-know basis. Minors under 18 (Article 9) require parental or guardian consent + appropriate to

Artefacts an auditor will ask for
  • Sensitive data inventory under Article 3 Section VI with written and express consent records (Article 9)
  • Minor under 18 parental consent records
  • Reglamento Article 56 safeguards - identification of consent giver + separate ledger + segregation + need-to-know access
  • INAI Lineamientos sobre Datos Biometricos compliance for biometric processing
  • NOM-024-SSA3-2010 Electronic Clinical Records compliance for health
Where this commonly fails
  • Written and express consent not obtained for sensitive data (Article 9 breach)
  • Minor consent obtained without parental verification
  • Sensitive data ledger not separate from ordinary data ledger (Reglamento Article 56)
  • Biometric processing without INAI Lineamientos compliance
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Mexico LFPDPPP framework page.