Client Alerts 03.20.2025

New LFPDPP 2025: a business guide to personal data processing

New LFPDPP 2025: a business guide to personal data processing

Following the publication on March 20, 2025 in the Official Gazette (DOF) of the new Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPP, Federal Personal Data Protection Law), which repeals the statute of the same name published on July 5, 2010, we have prepared this guide to help companies understand the impact of its entry into force.

A. Comparative overview of changes

For a better understanding of the detected changes, the following table provides a comparative view of the main differences between both regimes.

ChapterLFPDPP 2010 / Art.LFPDPP 2025 / Art.Observations
Definitions / glossaryArts. 2–3Arts. 2 (definitions) / 5–7 (principles)Definitions (privacy notice, databases, consent, public access source, transfer) are updated and expanded with more detailed language.
Regulatory authorityCh. VI: Institute (INAI) — Arts. 38–44New assignment of functions and reference to the Anti-Corruption and Good Government SecretariatInstitutional replacement: functions, resources, and powers of the Institute are transferred to the Secretariat. Transitional provisions repeal references to INAI.
Protection principlesArts. 6–14 (lawfulness, consent, information, quality, purpose, proportionality, accountability)Arts. 5–14 (renumbered and refined)Same core principles with greater precision; “reasonable expectation of privacy” is incorporated and free, specific, and informed consent is made explicit.
ConsentArt. 8; Art. 9 (sensitive: express and written)Arts. 7–9: tacit as general rule; express mandatory for financial/property and sensitive dataThe operational emphasis shifts: tacit consent is recognized as the rule, but express consent is required in specific cases and revocation mechanisms must be recorded.
Privacy noticeArts. 15–17 (minimum content: identity, purposes, ARCO rights, transfers, changes)Arts. 14–17 (now Art. 15): additionally requires categories of data, identification of sensitive data, and distinguishing purposes requiring consentSimplified notice is regulated for electronic media, with reinforced content in the full notice.
ARCO rightsArts. 22–26Arts. 22 et seq.: same rights with adjusted terms and electronic channelsThe ARCO catalog is maintained with emphasis on gratuity, simplicity, and timely response.
Transfers and processorsArts. 36–37Arts. 36 et seq.: requirements for domestic and international transfersContractual guarantees (standard clauses) and processor obligations toward the controller are refined.
Security measures and breachesArts. 19–20Arts. 19 et seq.: active duty to implement controls and to notify breachesEmphasis on notifying data subjects and authorities in incidents affecting economic or moral rights.
SanctionsArts. 63–66Arts. 63 et seq.: updated fines and more detailed classificationsAmounts are increased and specific conduct is classified, such as omission of security measures or processing without consent.

B. Key operational impacts for businesses

  • Review and update privacy notices to include categories of data, identification of sensitive data, purposes requiring express consent, and revocation mechanisms.
  • Document consent, especially express consent for financial, property, and sensitive data; maintain auditable records.
  • Update policies and contracts with processors (standard clauses, security obligations, sub-processing).
  • Strengthen security measures and establish internal procedures for detection, containment, notification, and remediation of breaches.
  • Train personnel handling personal data and designate responsibilities (data protection officers where applicable).
  • Map cross-border data flows and ensure transfers are supported by appropriate legal basis and contracts.

C. Our support

At Wolff, Arias & Charua we recommend immediately starting a gap assessment against the new LFPDPP and designing a phased implementation plan. Our personal data team is available to accompany you in redesigning notices, contracts, internal policies, incident protocols, and training programs.