Mexico LFPDPPP
Sensitive Data and Minors - Mexico LFPDPPP

Mexico LFPDPPP MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent: Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent

Process sensitive personal data and minor data under enhanced conditions in Article 3 Section VI + Article 9. Sensitive Personal Data definition Article 3 Section VI covers data affecting intimate sphere or wrongful use affecting discrimination including: racial or ethnic origin + present and future state of health + genetic information + religious philosophical or moral beliefs + union affiliation + political opinions + sexual preference. Processing of sensitive data requires written and express consent (Article 9) - higher standard than tacit consent for ordinary data. Reglamento Article 56 imposes additional safeguards - identification verification of consent giver + separate ledger of sensitive data processing + segregation of sensitive data from ordinary data + access restricted to need-to-know basis. Minors under 18 (Article 9) require parental or guardian consent + appropriate to maturity level + clear and accessible language. Mexico Child Rights Law (LGDNNA) coordination for minor processing. Health data under Ley General de Salud + COFEPRIS coordination + Norma Oficial Mexicana NOM-024-SSA3-2010 Electronic Clinical Records. Biometric data under Lineamientos INAI sobre Datos Biometricos. Financial sensitive data under CONDUSEF + Banco de Mexico + CNBV jurisdiction.

What else in your programme already covers this

This control maps to 203 controls across 81 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 4 controls

ISO 27043 · 4 controls

ISO/SAE 21434 · 4 controls

Malaysia PDPA 2010 · 4 controls

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

South Korea ISMS-P · 3 controls

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO 13485 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 27799 · 2 controls

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO/IEC 27014:2020 · 2 controls

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • ASD37-17 TLS encryption between email servers (Limited)
  • DS-2 Ensure software supply chain security

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data
  • CA-10 Selects and Develops Control Activities

FIDO2 / WebAuthn · 1 control

  • 62351-9 Cyber security key management

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO/IEC 23894:2023 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 203 it maps to, and the evidence behind each claim, over MCP and REST.