{"id":2060,"date":"2025-04-08T16:26:49","date_gmt":"2025-04-08T16:26:49","guid":{"rendered":"https:\/\/www.ibarrapg.com\/?p=2060"},"modified":"2026-04-12T01:28:33","modified_gmt":"2026-04-12T01:28:33","slug":"new-general-law-on-the-protection-of-personal-data-held-by-private-parties","status":"publish","type":"post","link":"https:\/\/www.ibarrapg.com\/en\/new-general-law-on-the-protection-of-personal-data-held-by-private-parties\/","title":{"rendered":"New General Law on the Protection of Personal Data Held by Private Parties"},"content":{"rendered":"<p style=\"text-align: justify;\">On March 20th, 2025, a Decree was published in the Official Gazette establishing a new regulatory framework for the <strong>protection of personal data in Mexico<\/strong>. Pursuant to this Decree, the following laws entered into force: the new General Law on the Protection of Personal Data Held by Private Parties, applicable to the private sector; the new General Law on Transparency and Access to Public Information; and the new General Law on the Protection of Personal Data Held by Obligated Subjects, applicable to public authorities and entities. In addition, a new Federal Law on the Protection of Personal Data Held by Private Parties was issued, reinforcing and updating previous legal provisions in this area.<\/p>\n<h4 style=\"text-align: justify;\">Background<\/h4>\n<p style=\"text-align: justify;\">These new provisions expressly repeal the Federal Law on the Protection of Personal Data Held by Private Parties published in 2010, as well as the previous versions of the General Law on Transparency and Access to Public Information and the General Law on the Protection of Personal Data Held by Obligated Subjects.<\/p>\n<p style=\"text-align: justify;\">Additionally, the Decree <strong>includes the dissolution of the National Institute for Transparency, Access to Information and Protection of Personal Data<\/strong> (INAI). The supervisory, oversight and regulatory functions previously exercised by the INAI will now be carried out by the Secretariat for Anti-Corruption and Good Governance, an entity under the authority of the Federal Executive Branch.<\/p>\n<h4 style=\"text-align: justify;\">New Key Concepts<\/h4>\n<ul style=\"text-align: justify;\">\n<li>\u201c<strong>Personal Data<\/strong>\u201d is redefined as any information that can identify an individual or legal entity, directly or indirectly. Consent must be given freely, specifically and in an informed manner.<\/li>\n<li>Consent must be given freely, specifically and in an informed manner. Its acquisition is now more flexible, including digital channels.<\/li>\n<li>The concept of \u201c<strong>data retention period<\/strong>\u201d is formalized, requiring justified durations according to purpose and clear deletion policies.<\/li>\n<\/ul>\n<h4 style=\"text-align: justify;\"><\/h4>\n<h4 style=\"text-align: justify;\">Privacy Notices<\/h4>\n<ul style=\"text-align: justify;\">\n<li>Both <strong>Comprehensive and Simplified Privacy Notices<\/strong> must now specify what data is collected, sensitive data, purposes requiring consent, data usage limitations and other previously nonmandatory elements.<\/li>\n<li>Although not mandatory, it is recommended to continue disclosing data transfers to <strong>maintain trust with data subjects<\/strong>.<\/li>\n<\/ul>\n<h4 style=\"text-align: justify;\"><\/h4>\n<h4 style=\"text-align: justify;\">New Roles and Obligations<\/h4>\n<ul style=\"text-align: justify;\">\n<li>The concept of<strong> Data Controller<\/strong> is redefined: it now includes anyone making decisions on data processing, regardless of being an individual or legal entity.<\/li>\n<li>Companies must establish internal procedures for managing the data lifecycle, including blocking and deletion measures.<\/li>\n<\/ul>\n<h4 style=\"text-align: justify;\">Strengthened ARCO Rights<\/h4>\n<ul style=\"text-align: justify;\">\n<li>ARCO rights (Access, Rectification, Cancellation, Opposition) are reinforced, allowing data subjects to <strong>oppose certain automated or discriminatory processing without legitimate cause<\/strong>.<\/li>\n<\/ul>\n<h4 style=\"text-align: justify;\">Practical Implications<\/h4>\n<ul style=\"text-align: justify;\">\n<li>Companies should <strong>review and update their privacy notices<\/strong>, internal procedures, security measures and staff training related to data processing.<\/li>\n<\/ul>\n<h4 style=\"text-align: justify;\">Need Legal Counsel?<\/h4>\n<p style=\"text-align: justify;\">Our team is ready to support your implementation of the new provisions, minimizing regulatory risks through <strong>audits, policy drafting and tailored guidance<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On March 20th, 2025, a Decree was published in the Official Gazette establishing a new regulatory framework for the protection of personal data in Mexico. Pursuant to this Decree, the following laws entered into force: the new General Law on the Protection of Personal Data Held by Private Parties, applicable to the private sector; the [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":2123,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2060","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-otros"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/posts\/2060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/comments?post=2060"}],"version-history":[{"count":5,"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/posts\/2060\/revisions"}],"predecessor-version":[{"id":3678,"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/posts\/2060\/revisions\/3678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/media\/2123"}],"wp:attachment":[{"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/media?parent=2060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/categories?post=2060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ibarrapg.com\/en\/wp-json\/wp\/v2\/tags?post=2060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}