Privacy Notice in Mexico: Complete 2026 Guide (with Free Generator)
Privacy Notice in Mexico: Complete 2026 Guide
If you operate a business in Mexico — whether it's a restaurant, dental clinic, law firm, or online store — you are legally required to have a privacy notice (aviso de privacidad). This is not optional. It's the law.
Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) requires every individual or legal entity that collects personal data to inform data subjects about how their data is collected, used, and protected.
Penalties for non-compliance can reach $51 million pesos (approximately $2.8 million USD).
In this guide, we cover everything: what it is, who needs one, what it must include, and how to create yours in minutes with our free AI generator.
What is a Privacy Notice (Aviso de Privacidad)?
A privacy notice is a legal document that informs individuals (data subjects) about:
- Who collects their personal data
- What data is collected
- Why it is used
- Who it is shared with
- How they can exercise their rights over their data
It is Mexico's equivalent of a Privacy Policy, but with specific requirements under Mexican legislation.
Who Needs a Privacy Notice?
Every individual or legal entity that collects personal data in Mexico. This includes:
- Restaurants (when taking reservations)
- Clinics and medical offices (patient records)
- Law firms (client data)
- Online stores (name, address, payment info)
- Real estate agencies (buyer/tenant data)
- Gyms (membership contracts)
- Schools (student and parent data)
- Hotels (guest registration)
- Any business with a contact form on its website
If you ask someone for their name and email, you need a privacy notice.
What Does the Law Require? (LFPDPPP)
The key articles of the LFPDPPP establish:
Article 15
Every data controller that collects personal data must inform data subjects through a privacy notice.
Article 16
The notice must contain at least:
- Identity and address of the data controller
- Personal data to be collected
- Purposes of data processing
- Mechanism for communicating changes
- Means to exercise ARCO rights
Article 17
The notice must be made available:
- Forms: when collecting data directly
- Website: visible and accessible from any page
- Premises: available at physical locations
The 3 Types of Privacy Notice
1. Comprehensive Notice (Integral)
The most complete version. Must include ALL legally required elements. This is what you need on your website and in formal contracts.
2. Simplified Notice
A condensed version for limited spaces (flyers, short forms). Must include at least the controller's identity, purposes, and a link to the comprehensive notice.
3. Short Notice
The briefest version. Used in printed forms or phone communications. Must reference the comprehensive notice.
Our free generator creates the comprehensive notice — the most complete version that most businesses need.
What Must Your Privacy Notice Include?
A comprehensive privacy notice must have these sections:
- Identity and address of the data controller
- Personal data collected (specific list)
- Sensitive data (if applicable — health, biometric, etc.)
- Purposes (primary and secondary)
- Data transfers to third parties
- Consent clause for secondary purposes
- ARCO rights (Access, Rectification, Cancellation, Opposition)
- Mechanism to revoke consent
- Cookies and tracking technologies
- Modifications to the privacy notice
- Consent clause
Penalties for Non-Compliance
| Violation | Fine (days of UMA) | Approximate Amount (2026) |
|---|---|---|
| No privacy notice | 100 to 160,000 | $10,000 to $16M MXN |
| Processing without consent | 200 to 320,000 | $20,000 to $32M MXN |
| Security breach | 200 to 320,000 | $20,000 to $32M MXN |
| Unauthorized transfers | 200 to 320,000 | $20,000 to $32M MXN |
INAI (National Institute for Transparency) can also order suspension of data processing and publish sanctions publicly.
Generate Your Privacy Notice Now
Create a LFPDPPP-compliant privacy notice in minutes:
Generate my free privacy notice
Free, no signup required, customized for your business type. The AI generates a legally structured document you can copy, download, and publish today.
This article is informational and does not constitute legal advice. For complex cases, consult a lawyer specializing in personal data protection.
Want an AI Agent like this for your business?
We build and deploy AI Agents that automate real work — compliance, customer service, document processing, and more.
Talk to us