Mexico LFPDPPP
Security and Breach Notification - Mexico LFPDPPP

Mexico LFPDPPP MX-LFPDPPP-Security-Breach-Notification-Reglamento-63-No-Time-Limit-INAI-Recommendations-CERT-MX: Mexico LFPDPPP Security + Breach Notification + Reglamento 63 + No Specified Time + INAI Recommendations + CERT-MX

Implement technical and organisational security measures + breach notification process under Article 19 + Reglamento Articles 61-67 + INAI Recommendations on Security Measures 2018 amended 2024. Article 19 requires administrative + technical + physical security measures sufficient to ensure confidentiality + integrity + availability of personal data + appropriate to nature of data + state of art + risk. INAI Security Recommendations baseline includes encryption + access controls + identification and authentication + audit trails + secure development lifecycle + supplier security + business continuity + workforce training. Reglamento Article 63 Breach Notification - controller must notify affected data subjects of any vulnerability that significantly affects rights (NOTE: NO SPECIFIED TIME LIMIT - significant gap vs GDPR 72-hour + 2017 LGPDPPSO public-sector law similarly lacks time limit). Controller must investigate cause + take corrective measures + assess affected data subjects impact + update Security Manual + breach register maintenance. INAI does NOT need to be notified at federal level (private sector) under current LFPDPPP (notification to INAI optional unless serious public concern - unlike Public Sector LGPDPPSO which requires INAI notification). CERT-MX coordination for cyber-component breaches + Comision Nacional de Seguridad + Direccion General de Operaciones Cibernetics (DGOC). Sectoral CONDUSEF (financial) + CFE (energy) + COFEPRIS (health) + IFT (telecom) parallel breach notification requirements may apply.

What else in your programme already covers this

This control maps to 115 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • CH-FADP-22 Privacy by design and default
  • CH-FADP-23 Data processing agreements
  • CH-FADP-24 Cross-border transfer safeguards
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

Bahrain PDPL · 4 controls

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

GDPR · 3 controls

ISO 13485 · 3 controls

ISO 27017 · 3 controls

ISO 27018 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 27011:2024 · 3 controls

  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

South Korea PIPA · 3 controls

  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

ISO/IEC 27400:2022 · 2 controls

MTCS (Singapore) · 2 controls

Malaysia PDPA 2010 · 2 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • ASD37-27 Outbound data loss prevention (Very Good)
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

ISO 26000:2010 · 1 control

  • RUSPD-4 Special Categories, Biometric Data

Turkey KVKK · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.