Mexico LFPDPPP
Enforcement Sanctions and Remedies - Mexico LFPDPPP

Mexico LFPDPPP MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN: Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN

Manage INAI enforcement under Articles 63-67. Article 63 INAI investigation powers including information requests + on-site inspections + emergency measures + Procedure for Imposition of Sanctions (PIS). Article 64 administrative sanctions calculated in DAYS OF MEXICAN GENERAL MINIMUM WAGE (Salario Minimo General) up to 320,000 days (approximately MXN 33 million / USD 1.9 million 2025 minimum wage of MXN 248.93/day - ONE OF HIGHEST PENALTIES IN LATIN AMERICA) for serious violations including: non-existent or deficient Aviso de Privacidad + unlawful disclosure + denial or obstruction of ARCO rights + sensitive data processing without consent + minor data without parental consent + obstructing INAI. Penalties doubled for repeat offenders. Article 67 CRIMINAL PENALTIES up to 3 years imprisonment for unauthorised processing of sensitive data for profit + 6 months to 3 years for negligence affecting sensitive data + 6 months to 5 years for unauthorised obtaining of profit from personal data processing. Recurso de Revision (Review Appeal) under Articles 56-58 to TFJA Federal Administrative Justice Tribunal within 15 days of INAI resolution. Final appeal to Supreme Court of Justice of the Nation (SCJN) on constitutional grounds. Civil claim for damages under Article 58 + Codigo Civil Federal damages framework. Class action available under Codigo Federal de Procedimientos Civiles. INAI public censure + resolution publication + biannual report to Senate. 2025 REFORM: enforcement transferred from autonomous INAI to Secretaria Anticorrupcion y Buen Gobierno (SABG) within executive (independence concerns + bilateral MoU disruption with Spain AEPD + Argentina AAIP + Uruguay URCDP + Peru ANPD + RIPD Network).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 80 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 4 controls

  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

Malaysia PDPA 2010 · 3 controls

  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

South Korea PIPA · 3 controls

  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

ISO/IEC 23894:2023 · 2 controls

MTCS (Singapore) · 2 controls

  • APP-8 APP 8 - Cross-border disclosure of personal information
  • BB-DPA-17 Section 24 - Appropriate Safeguards

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management

GDPR · 1 control

  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • ICP-25 Supervisory Cooperation and Coordination

ISO 14001 · 1 control

  • ISO14001-03 Legal and regulatory compliance obligations

ISO 22000 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 45001 · 1 control

  • AC-2 Account Management
  • AC-2 Account Management
  • AC-2 Account Management
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • RUSPD-4 Special Categories, Biometric Data

South Korea ISMS-P · 1 control

Turkey KVKK · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 80 it maps to, and the evidence behind each claim, over MCP and REST.