{"id":26154,"date":"2025-03-21T22:44:48","date_gmt":"2025-03-21T22:44:48","guid":{"rendered":"https:\/\/basham.com.mx\/?p=26154"},"modified":"2025-03-21T22:44:50","modified_gmt":"2025-03-21T22:44:50","slug":"new-federal-law-for-the-protection-of-personal-data-held-by-private-parties-published-in-the-official-gazette-of-the-federation","status":"publish","type":"post","link":"https:\/\/basham.com.mx\/en\/new-federal-law-for-the-protection-of-personal-data-held-by-private-parties-published-in-the-official-gazette-of-the-federation\/","title":{"rendered":"New Federal Law for the Protection of Personal Data Held by Private Parties Published in the Official Gazette of the Federation"},"content":{"rendered":"<p class=\"has-text-align-right wp-block-paragraph\">Mexico City, March 21 2025<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On March 20, 2025, the <strong>New Federal Law for the Protection of Personal Data in Possession of Private Parties (NLFPDPPP)<\/strong> was published in the <strong>Official Gazette of the Federation (DOF)<\/strong>. The law will come into effect on March 21, 2025, superseding the <strong>Federal Law for the Protection of Personal Data Held by Private Parties (LFPDPPP)<\/strong>, which is hereby repealed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key Modifications Introduced by the NLFPDPPP<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Modification and Clarification of Definitions<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The NLFPDPPP revises several definitions from the previous law. Below are some of the key modifications:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Concept<\/strong><\/td><td><strong>LFPDPPP (Old Definition)<\/strong><\/td><td><strong>NLFPDPPP (New Definition)<\/strong><\/td><\/tr><tr><td><strong>Privacy Notice<\/strong><\/td><td>A physical, electronic, or other format document generated by the data controller that is made available to the data subject prior to the processing of their personal data, in accordance with Article 15 of the law.<\/td><td>A document available to the data subject in physical, electronic, or any other format, generated by the data controller at the time their personal data is collected, informing them of the purposes of processing, in accordance with Article 14 of the law.<\/td><\/tr><tr><td><strong>Databases<\/strong><\/td><td>An ordered set of personal data concerning an identified or identifiable person.<\/td><td>An ordered set of personal data referring to an identified or identifiable person, subject to specific criteria, regardless of its form, mode of creation, storage type, processing, or organization.<\/td><\/tr><tr><td><strong>Consent<\/strong><\/td><td>The manifestation of the data subject&#8217;s will, enabling processing.<\/td><td>The free, specific, and informed manifestation of the data subject&#8217;s will, allowing personal data processing.<\/td><\/tr><tr><td><strong>Personal Data<\/strong><\/td><td>Any information concerning an identified or identifiable natural person.<\/td><td>Any information concerning an identified or identifiable person. A person is considered identifiable if their identity can be determined directly or indirectly through any information.<\/td><\/tr><tr><td><strong>Sensitive Personal Data<\/strong><\/td><td>&nbsp; Personal data that affects the most intimate sphere of its holder or whose improper use could lead to discrimination or pose a serious risk to them. In particular, data that may reveal aspects such as racial or ethnic origin, present or future health status, genetic information, religious, philosophical, and moral beliefs, trade union membership, political opinions, and sexual preference are considered sensitive.<\/td><td>Personal data that affects the most intimate sphere of the data subject or whose improper use could lead to discrimination or pose a serious risk to them. By way of example, but not limited to, personal data that may reveal aspects such as racial or ethnic origin, present or future health status, genetic information, religious, philosophical, and moral beliefs, political opinions, and sexual preference are considered sensitive.<\/td><\/tr><tr><td><strong>ARCO Rights<\/strong><\/td><td>No definition in the LFPDPPP.<\/td><td>The rights of <strong>Access, Rectification, Cancellation, and Opposition (ARCO)<\/strong> regarding personal data processing.<\/td><\/tr><tr><td><strong>Public Access Sources<\/strong><\/td><td>Databases that can be consulted by any person, subject to applicable fees, in accordance with the provisions of the Regulations of this Law.<\/td><td>Databases, systems, or files that, by law, may be publicly accessed without any prohibitive regulation, subject to applicable fees. Information obtained unlawfully is not considered a public access source.<\/td><\/tr><tr><td><strong>Data Controller<\/strong><\/td><td>A private individual or legal entity that decides on the processing of personal data.<\/td><td>Now explicitly referred to as <strong>Regulated Entities<\/strong> under section XVI of this article.<\/td><\/tr><tr><td><strong>Regulated Entities<\/strong><\/td><td>No definition in the LFPDPPP.<\/td><td>Individuals or private legal entities engaged in personal data processing.<\/td><\/tr><tr><td><strong>Processing<\/strong><\/td><td>The collection, use, disclosure, or storage of personal data by any means. Includes access, handling, use, exploitation, transfer, or disposal.<\/td><td>Any operation or set of operations applied to personal data, whether manual or automated, including collection, recording, organization, conservation, modification, retrieval, dissemination, and deletion.<\/td><\/tr><tr><td><strong>Transfers<\/strong><\/td><td>Any communication of data to a person other than the data controller or processor.<\/td><td>Any communication of personal data within or outside Mexico to a person other than the data subject, controller, or processor.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Consent Requirements<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The NLFPDPPP mandates that consent must be <strong>free, specific, and informed<\/strong>. Tacit consent remains valid as a general rule, a principle previously outlined in the Regulation of the LFPDPPP but now explicitly incorporated into the law.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Key changes include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The law now allows consent exemptions if authorized by <strong>any legal provision<\/strong>, including regulations and decrees.<\/li>\n\n\n\n<li>The scope of authority-based exemptions has expanded to include <strong>court orders, resolutions, or rulings<\/strong> from competent authorities.<\/li>\n\n\n\n<li>If personal data is processed for purposes other than those specified in the <strong>Privacy Notice<\/strong>, new consent must be obtained\u2014even if the new purpose is compatible with the original intent.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Privacy Notice Changes<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The NLFPDPPP adds the following requirements for Privacy Notices:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>It must <strong>explicitly state the personal data subject to processing<\/strong>.<\/li>\n\n\n\n<li>It must distinguish between <strong>mandatory and voluntary purposes<\/strong>.<\/li>\n\n\n\n<li>The requirement to inform data subjects about <strong>third-party transfers in the Privacy Notice<\/strong> has been eliminated, although disclosure obligations remain under current regulations.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. ARCO Rights Clarifications<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The right to <strong>cancellation<\/strong> now explicitly applies to <strong>files, records, and systems<\/strong> where the personal data is stored.<\/li>\n\n\n\n<li>The right to <strong>object<\/strong> applies when personal data is subjected to <strong>automated processing that significantly affects<\/strong> the data subject\u2019s rights, freedoms, or interests without human intervention.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. New Data Protection Authority<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Ministry of Anticorruption and Good Governance<\/strong> will replace the <strong>National Institute of Transparency, Access to Information, and Protection of Personal Data (INAI)<\/strong> as the primary regulatory authority. Additionally, the Ministry of Economy will no longer oversee privacy regulations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6. Legal Procedures<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The <strong>Indirect Amparo trial<\/strong> is now recognized as a means of challenging administrative actions related to data protection.<\/li>\n\n\n\n<li>The <strong>Federal Judiciary must establish specialized courts<\/strong> for personal data protection cases within 120 days of the law\u2019s enactment.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">It is, however, questionable whether the appropriate means of legal remedy should be the Indirect Amparo rather than the contentious-administrative proceeding before the Federal Court of Administrative Justice (TFJA), given that the latter, in principle, has jurisdiction to review acts issued by federal public administration bodies, including the <strong>Ministry of Anticorruption and Good Governance.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Federal Executive<\/strong> has 90 days to align regulatory frameworks with the new law.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommendations for Compliance<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations handling personal data must <strong>update internal policies and practices<\/strong> to align with the NLFPDPPP. Recommended actions include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Review and adjust internal policies<\/strong> in accordance with the new requirements.<\/li>\n\n\n\n<li><strong>Provide training programs<\/strong> for employees on compliance with the new law and forthcoming regulations.<\/li>\n\n\n\n<li><strong>Monitor regulatory developments<\/strong> from the Ministry of Anticorruption and Good Governance, as its <strong>interpretations and enforcement criteria will differ<\/strong> from the now-dissolved INAI.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Conclusion<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Effective March 21, 2025, the <strong>Ministry of Anticorruption and Good Governance<\/strong> will oversee data protection regulations. Although procedural aspects remain largely unchanged from the LFPDPPP, the structural and jurisdictional differences of the new Ministry warrant close attention. Unlike the INAI, which was an autonomous body, the new Ministry is part of the <strong>Federal Executive<\/strong>, raising concerns about potential shifts in enforcement and regulatory discretion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our firm\u2019s <strong>Information Technology and Data Protection Department<\/strong> remains at your service for further inquiries and compliance assistance.<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><br>Sincerely,<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\">Adolfo Athi\u00e9 Cervantes<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><a href=\"mailto:aathie@basham.com.mx\">aathie@basham.com.mx<\/a><\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\">Renata Denisse Buer\u00f3n Valenzuela<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><a href=\"mailto:rbueron@basham.com.mx\">rbueron@basham.com.mx<\/a><\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\">Erika Itzel Rodriguez Kushelevich<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><a href=\"mailto:erodriguez@basham.com.mx\">erodriguez@basham.com.mx<\/a><\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\">Ivan Garcia Argueta<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><a href=\"mailto:igarcia@basham.com.mx\">igarcia@basham.com.mx<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Mexico City, March 21 2025 On March 20, 2025, the New Federal Law for the Protection of Personal Data in Possession of Private Parties (NLFPDPPP) was published in the Official Gazette of the Federation (DOF). The law will come into effect on March 21, 2025, superseding the Federal Law for the Protection of Personal Data [&hellip;]<\/p>","protected":false},"author":16,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_crdt_document":"","footnotes":""},"categories":[1296],"tags":[206,1473],"class_list":["post-26154","post","type-post","status-publish","format-standard","hentry","category-privacy-data-protection","tag-english","tag-ingles"],"_links":{"self":[{"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/posts\/26154","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/comments?post=26154"}],"version-history":[{"count":1,"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/posts\/26154\/revisions"}],"predecessor-version":[{"id":26155,"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/posts\/26154\/revisions\/26155"}],"wp:attachment":[{"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/media?parent=26154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/categories?post=26154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/basham.com.mx\/en\/wp-json\/wp\/v2\/tags?post=26154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}