{"id":146572,"date":"2026-08-11T09:53:12","date_gmt":"2026-08-11T09:53:12","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=146572"},"modified":"2026-08-11T10:10:30","modified_gmt":"2026-08-11T10:10:30","slug":"mexico-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/mexico-tmt\/","title":{"rendered":"Mexico: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-146572","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-mexico"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Nader, Hayaux y Goebel, SC<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2019\/03\/NHG_Logo-principal_claro-1.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Nader, Hayaux y Goebel, SC<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2019\/03\/NHG_Logo-principal_claro-1.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in Mexico<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Federal Copyright Law (Ley Federal de Derecho de Autor, the \u201cCopyright Law\u201d) safeguards the intellectual property of original authors to be reproduced or divulgated by any form. According to this law, Software programs, including artificial intelligence programs, are protected under the terms applicable to literary works (obras literarias); under Article 5th thereunder, immediately after the software is created (and upon it has been affixed to a material support), the developer is entitled to copyright protection for its lifetime and an additional one hundred years; this protection is automatic, which means there is no obligation from the developer to register the software before the Mexican authorities, although it is highly recommended to conduct such registration with the Copyright Public Registry (Registro P\u00fablico del Derecho de Autor), which is overseen by the National Institute of Copyright (Instituto Nacional del Derecho de Autor, the \u201cINDAUTOR\u201d) for added certainty and protection.<\/p>\n<p>Following the latest reform to the Copyright Law published on May 14, 2026, Article 102 expressly provides that software programs, including artificial intelligence programs, are protected under the same terms applicable to literary works. However, software or artificial intelligence programs intended to cause harmful effects to other programs or equipment, or to infringe third-party rights protected under the Copyright Law, are excluded from such protection.<\/p>\n<p>The economic copyright rights set forth in the Copyright Law entitle the holder thereof to authorize or prohibit, with respect to the applicable Software: (i) its permanent or temporary reproduction, in whole or in part, by any means; (ii) its translation, adaptation, adjustment or any other modification thereto and the reproduction of the Software resulting therefrom; (iii) its distribution by any means, including through lease; (iv) its decompiling or disassembling, as well as the application of any reverse engineering processes thereto; and (v) the issuance of any public communication in connection therewith, including without limitation, any information made available to the public in general.<\/p>\n<p>In Mexico, it is not possible to patent Software. According to the Federal Law for the Protection of Industrial Property (Ley Federal de Protecci\u00f3n a la Propiedad Industrial, the \u201cIP Law\u201d), computer programs are not considered inventions and, therefore, cannot be patented.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In accordance with the Copyright Law, the author or developer of a Software will own the resulting copyrights with respect to the newly created Software.<\/p>\n<p>Additionally, pursuant to Article 103 of the Copyright Law, if the Software is developed by one or several employees during their employment or following instructions of their employer, in the absence of an agreement to the contrary, the copyrights with respect to the Software shall correspond to the employer.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific law or statute that governs the harm or liability caused by Software or computer systems. The general regulatory framework applicable to liability arising out between private individuals or legal entities or private acts is set forth in the Federal Civil Code (C\u00f3digo Civil Federal), the Civil Codes (C\u00f3digos Civiles) for each federal entity of Mexico and the Commercial Code (C\u00f3digo de Comercio). The applicable regulation shall depend on the specific context or situation.<\/p>\n<p>For instance, the Federal Consumer Protection Law (Ley Federal de Protecci\u00f3n al Consumidor, the \u201cConsumer Protection Law\u201d), protects the rights of the consumers and clients of any goods and services, including Software and computer systems. If a particular harm or liability is caused by Software in connection with Personal Data held by private parties, the applicable law will be the Federal Law for the Protection of Personal Data Held by Private Parties (Ley Federal de Protecci\u00f3n de Datos Personales en Posesi\u00f3n de los Particulares, the \u201cFederal Privacy Law\u201d).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>While there is no single statute that comprehensively governs the use or misuse of software or computer systems, various legal provisions may apply depending on the specific context and its consequences. For instance, the Federal Criminal Code (C\u00f3digo Penal Federal) penalizes unauthorized access to computer systems, data theft, and other cybercrimes, which may cover cases where software is used unlawfully to interfere with or damage systems or information.<\/p>\n<p>The Copyright Law also protects software as a literary work, meaning unauthorized reproduction, modification, or distribution can result in both civil and criminal liability for copyright infringement.<\/p>\n<p>Where personal data is involved, the Federal Privacy Law applies, particularly for unauthorized access, use, or disclosure of personal data through software.<\/p>\n<p>Depending on the situation, applicable laws may include the Federal Criminal Code, Copyright Law, and data protection laws, with liability determined by the facts and nature of the misuse.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Mexico does not have a comprehensive technology-specific legal framework governing the provision or licensing of Software or Software-as-a-Service (\u201cSaaS\u201d) between a Software vendor and a customer. Such transactions are generally governed by the terms agreed between the parties and the applicable provisions of Mexican commercial and civil law, the Copyright Law and, depending on the nature of the services, the Code of Commerce (C\u00f3digo de Comercio), the Law on Telecommunications and Broadcasting (Ley en Materia de Telecomunicaciones y Radiodifusi\u00f3n), the Federal Consumer Protection Law (Ley Federal de Protecci\u00f3n al Consumidor), the Financial Technology Institutions Law (Ley para Regular las Instituciones de Tecnolog\u00eda Financiera, \u201cFinTech Law\u201d) and the Federal Privacy Law.<\/p>\n<p>However, Article 52 of the Regulations of the Federal Privacy Law expressly regulates cloud computing services where personal data is processed. Under such provision, cloud service providers must, among other requirements, maintain data protection policies consistent with the Federal Privacy Law, disclose relevant subcontracting arrangements, maintain the confidentiality and security of personal data, allow data controllers to limit the processing of personal data and delete such data upon termination of the services, once the data controller has been able to recover it. Cloud service providers may not claim ownership or assume control over the information processed.<\/p>\n<p>Therefore, even though there is no specific legal regime generally governing Software licensing or SaaS transactions, cloud-based services involving the processing of personal data are subject to specific requirements under Mexican data protection regulations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, it is typical for a software vendor to cap its maximum financial liability to a customer in a software transaction in Mexico. According to the Federal Civil Code (C\u00f3digo Civil Federal), civil liability or damages for breach of contract may be limited by the parties in the applicable agreement, except for liability arising from willful misconduct, which is always enforceable.<\/p>\n<p>The liability cap is typically determined in accordance with the aggregate amount of fees received by the licensor under the applicable software license agreement, and it is usually the amount of fees that would be received per 12 months. The market standard level of cap varies depending on the jurisdiction, but in Mexico, a cap on indemnification liability not to exceed 100% of the purchase price is common.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principle of \u201cparties free will\u201d (\u201c<em>autonom\u00eda de la voluntad de las partes<\/em>\u201d) contemplated in the Federal Civil Code (<em>C\u00f3digo Civil Federal<\/em>) provides that the parties to a software agreement, or to any other agreement, are entitled to cap their liability, or even release themselves from liability, in terms of the applicable agreement. There is no standard answer to this question because every transaction is different in matters of parties\u2019 liability in case of default or damages. However, as a general rule, liability arising from willful misconduct is not waivable pursuant to the Federal Civil Code. Further, liability arising from regulatory fines or felonies may not be limited nor waived pursuant to an agreement by private parties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Although it is a highly recommended practice, it is not a common practice for software developers in Mexico to hold in escrow their software source codes. Some of the typical escrow providers in our country are Praxis Technology Escrow and Escrow Tech.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There isn&#8217;t a specific technology law governing IT outsourcing transactions in Mexico. Instead, these transactions fall under the purview of the Labor Law, which covers outsourcing matters, including those related to IT.<\/p>\n<p>Since the amendment to the Labor Law in 2019, the Mexican Federal Government has been diligently working to regulate outsourcing transactions with the aim of safeguarding the labor and social security rights of employees. Furthermore, with the 2021 amendment to the Labor Law, most outsourcing transactions were prohibited, permitting companies to outsource only specialized services, to the extent the outsourced services provider is registered before the REPSE (as explained below) as an authorized specialized services provider.<\/p>\n<p>On April 24, 2021, the Labor, and Employment Ministry (Secretar\u00eda del Trabajo y Previsi\u00f3n Social, the \u201cST\u201d) established the Registry of Specialized Service Providers or Specialized Works (Registro de Prestadoras de Servicios Especializados u Obras Especializadas, the &#8220;REPSE&#8221;) in which the outsourcing providers shall be registered.<\/p>\n<p>According to the Labor Law and the absence of technology-law regulation, IT services would be considered &#8220;specialized services&#8221; which means that the supplier who provides the IT outsourced services must be registered with the REPSE.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The fundamental essence of the Labor Law is to protect the rights of workers, particularly those who are in a more vulnerable position. This law was conceived in response to the need of shielding employees from potential abuses from their employers, creating a legal framework to balance the rights and obligations of workers and employers in Mexico.<\/p>\n<p>The Labor Law safeguards the individual employment and social security rights of workers in cases where services are outsourced to third-party IT service providers. According to the second paragraph of Article 14 of this Law, when a customer (individual or company) contracts specialized services with an outsourcing provider who fails to meet its obligations as an employer toward its employees, the customer becomes jointly responsible before the employees of the outsourcing provider. This legal provision serves as a protective measure for individual workers.<\/p>\n<p>While outsourcing is considered a necessary practice for companies to handle tasks beyond their core practices, regrettably, many companies and outsourcing providers have abused this framework to mimic labor relationships, leading to the violation of labor and social security rights, and in some instances, tax obligations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Telecommunications networks and services are regulated, primarily, by the Mexican Constitution and the Law on Telecommunications and Broadcasting (Ley en Materia de Telecomunicaciones y Radiodifusi\u00f3n, the \u201cTelecommunications and Broadcasting Law\u201d), complemented by its secondary regulations.<\/p>\n<p>The Telecommunications and Broadcasting Law establishes the regulatory framework applicable to the telecommunications and broadcasting sectors. It regulates the use and exploitation of the radioelectric spectrum, public telecommunications networks, the deployment of and access to active and passive infrastructure, orbital resources, satellite communications, space services and applications, and the provision of telecommunications and broadcasting services. Its general purpose is to ensure the efficient development of the telecommunications and broadcasting sectors, promote effective competition and guarantee access to broadband internet and information and communication technologies.<\/p>\n<p>The Telecommunications and Broadcasting Law was published in the Federal Official Gazette on July 16, 2025, and replaced the former Federal Telecommunications and Broadcasting Law (Ley Federal de Telecomunicaciones y Radiodifusi\u00f3n). The new Telecommunications and Broadcasting Law reflects the institutional changes resulting from the Institutional Simplification Decree published in the Federal Official Gazette on December 20, 2024, pursuant to which, the Federal Telecommunications Institute (Instituto Federal de Telecomunicaciones, the \u201cIFT\u201d) was extinguished.<\/p>\n<p>Under the current regulatory framework, the Telecommunications Regulatory Commission (Comisi\u00f3n Reguladora de Telecomunicaciones) is an administrative body of the Digital Transformation and Telecommunications Agency (Agencia de Transformaci\u00f3n Digital y Telecomunicaciones, the \u201cATDT\u201d), with technical, operational and management independence. The Telecommunications Regulatory Commission is responsible for the regulation, promotion and supervision of the radioelectric spectrum, orbital resources, satellite communications, public telecommunications networks, telecommunications and broadcasting services, and the deployment of and access to telecommunications infrastructure. The ATDT is primarily responsible for developing and implementing the Federal Government&#8217;s telecommunications, satellite and broadcasting policies, as well as universal and social coverage policies.<\/p>\n<p>The Telecommunications and Broadcasting Law further provides that, in the absence of specific provisions thereunder or under applicable international treaties, the following laws apply on a supplementary basis: (i) Federal Law of Administrative Procedure (Ley Federal de Procedimiento Administrativo), (ii) Federal Economic Competition Law (Ley Federal de Competencia Econ\u00f3mica), (iii) General Law of National Assets (Ley General de Bienes Nacionales), (iv) Law of General Communication Channels (Ley de V\u00edas Generales de Comunicaci\u00f3n), (v) Federal Consumer Protection Law (Ley Federal de Protecci\u00f3n al Consumidor), (vi) Code of Commerce (C\u00f3digo de Comercio), (vii) Federal Civil Code (C\u00f3digo Civil Federal), (viii) the National Code of Civil and Family Procedures (C\u00f3digo Nacional de Procedimientos Civiles y Familiares), (ix) applicable laws on security matters, and (x) applicable electoral laws.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Mexico, the provision of telecommunications services remains primarily governed by Article 28 of the Mexican Constitution and the Telecommunications and Broadcasting Law, effective as of July 17,2025, which repealed the 2014 Federal Telecommunications and Broadcasting Law. The reform extinguished the IFT and transferred its functions to two new authorities: the ATDT, responsible for policy design, and the Telecommunications Regulatory Commission, a deconcentrated body under the ATDT that exercises the licensing, oversight and enforcement powers previously held by the IFT.<\/p>\n<p>The core licensing instrument is the concession (concesi\u00f3n \u00fanica), which authorises its holder to provide, on a convergent basis, any type of public telecommunications and\/or broadcasting service (fixed and mobile telephony, internet access, data transmission, pay TV, among others). Concessions are granted by use, with distinct holders for each: (i) commercial-use concessions are granted to private individuals or legal entities for profit-making purposes; (ii) public-use concessions are reserved for governments entities at the federal, state or municipal levels, generally for non-profit institutional or broadcasting purposes; and (iii) social-use concessions serve non-profit cultural, scientific, educational or community purposes, expressly including community, indigenous and Afro-Mexican concessions. If spectrum or orbital resources are also required, these must be obtained separately, generally through an auction process.<\/p>\n<p>Beyond the concession regime, the Telecommunications and Broadcasting Law considers a separate authorization requirement for specific activities that do not entail operating a public network. Activities subject to this authorisation include: (i) incorporating, operating and exploiting entities known as retailers (comercializadoras); (ii) installing satellite earth stations, telecommunications systems and other transmission media in a cross border basis; and (iii) the use of infrastructure for purposes such as testing technological developments, satisfy diplomatic visits, among others. A third licensing category consists in the registration certificate (constancia de registro), which is a special license required to operate aeronautical systems or equipment used in special events in cultural, sport or similar contexts without involving any type of exploitation activities.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Access to communications data by law enforcement and government agencies in Mexico is regulated by several key legal instruments, primarily:<\/p>\n<ul>\n<li>\u00a0Article 16 of the Mexican Constitution, which establishes the general right to privacy and due process, provides that private communications are infrangible and that any interception thereof must be authorised by a federal judicial authority.<\/li>\n<li>The National Code of Criminal Procedure (<em>C\u00f3digo Nacional de Procedimientos Penales<\/em>) specifically Articles 252 and 291, which regulate access to communications in criminal investigations, including the interception of private communications, real-time geographical location and access to retained communications data, and establish the applicable judicial and procedural safeguards.<\/li>\n<li>The Telecommunications and Broadcasting Law, particularly Articles 182 and 183, which require telecommunications concessionaires and certain authorised entities to cooperate with competent authorities in connection with written, duly grounded and reasoned requests for real-time geographical location of communication equipment.<\/li>\n<li>Article 177 of the Federal Criminal Code (<em>C\u00f3digo Penal Federal<\/em>), which criminalises the unauthorised interception of private communications.<\/li>\n<li>The National Security Law (<em>Ley de Seguridad Nacional<\/em>), Article 34, which allows for the interception of communications when national security is at risk, again requiring judicial approval.<\/li>\n<\/ul>\n<p>Authorities may request different types of communications data, including subscriber identification and address, the type of communication or messaging service used, origin and destination data, the date, time and duration of communications, first activation and cell identification data, device identification and technical characteristics, and geographical positioning data. Under Article 183 of the Telecommunications and Broadcasting Law, telecommunications providers must retain such data for 24 months. During the first 12 months, the data must be maintained in systems that permit real-time consultation and electronic delivery to competent authorities; during the following 12 months, it must remain in electronic storage and be delivered within 48 hours following a request. Providers must also implement measures to preserve and protect retained data and prevent unauthorised access, destruction or alteration.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Mexico does not currently have a comprehensive cybersecurity law specifically applicable to the telecommunications sector. However, cybersecurity and\/or operational resiliency obligations applicable to telecommunications infrastructure and services are primarily regulated under the Telecommunications and Broadcasting Law and the Federal Privacy Law.<\/p>\n<p>The Telecommunications and Broadcasting Law imposes operational continuity, service quality and network integrity obligations on telecommunications concessionaires and authorized service providers.<br \/>\nOperators of public telecommunications networks must maintain interconnection, may not interrupt traffic between interconnected networks without the required regulatory authorization and must comply with applicable service quality and emergency communications obligations.<\/p>\n<p>The Telecommunications and Broadcasting Law also imposes specific security obligations regarding to retained communications data. Pursuant to Article 183, telecommunications concessionaires and certain authorized entities must implement technical measures to ensure the preservation, protection and integrity of retained data and prevent unlawful access, manipulation, destruction, alteration or deletion. Providers must also restrict the handling and control of such data to authorized personnel.<\/p>\n<p>Additionally, where telecommunications providers process personal data, the Federal Privacy Law requires them to implement administrative, technical and physical security measures to protect personal data against damage, loss, alteration, destruction and unauthorized use, access or processing. Security breaches that materially affect the economic or moral rights of data subjects must be notified to the affected individuals without undue delay.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>One of the main organizations aiming to represent and collaborate with the technological industry is the Mexican Association of the Information Technologies Industry (Asociaci\u00f3n Mexicana de la Industria de Tecnolog\u00edas de Informaci\u00f3n or AMITI). This organization was established about 40 years ago and seeks to represent the technology enterprises that are present in Mexico, being the organization with the most significant impact and representativity of the technology sector in Mexico. The main goal of AMITI is to become the main representative of the technology sector in any conversations and debates held in the public and private forums, as well as to (i) promote the strategy for the technological democratization in Mexico; (ii) develop relevant information to implement digitalization strategies; and (iii) to reduce the digital gap between the Mexican social sectors. AMITI has approximately 135 affiliated companies and a total of six committees, including a cybersecurity committee and an artificial intelligence and new technologies committee, which seek to develop and implement strategies to facilitate the adoption of emerging technologies, as well as to collaborate with the public sector, including the Mexican Congress, seeking to establish a communication channel to regulate new technological trends. For additional information please refer to https:\/\/amiti.org.mx\/quienes-somos\/<\/p>\n<p>Another organization engaged in the technological industry is the National Chamber of Electronic, Telecommunications and Information Technologies Industry (C\u00e1mara Nacional de la Industria Electr\u00f3nica, de Telecomunicaciones y Tecnolog\u00edas de la Informaci\u00f3n or CANIETI). This organization has more than 85 years of experience and more than 1,000 affiliated companies throughout Mexico. Its main goal is to be the organization with the broadest representation capabilities within the electronic, telecommunications and technologies sector. For additional information please refer to https:\/\/canieti.org\/canieti\/quienessomos.aspx<\/p>\n<p>Other organizations in Mexico include, the Internet MX Association (Asociaci\u00f3n de Internet MX (AIMX), the National Association of Educational Institutions in IT (Asociaci\u00f3n Nacional de Instituciones de Educaci\u00f3n en Tecnolog\u00edas de la Informaci\u00f3n, ANIEI), the Board of Cybersecurity and Information Security (Consejo de Seguridad de la Informaci\u00f3n y Ciberseguridad), the Cybersecurity Mexican Association (Asociaci\u00f3n Mexicana de Ciberseguridad, AMECI), among others.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Interoperability is defined in the Telecommunications and Broadcasting Law as the technical characteristics or features of public networks, systems and telecommunications equipment that allow an effective interconnectivity, ensuring a consistent and predictable provision of telecommunication services.<\/p>\n<p>Technical standards provide a basis to permit such interoperability among mobile devices. In Mexico there are multiple technical standards within the telecommunications sector. The Digital Agency for Public Innovation (Agencia Digital de Innovation P\u00fablica) is a governmental agency seeking to conduct, design and surveil the implementation of data management, digital government and technological infrastructure governing in Mexico City, and it has established several technical standards in matters related to Hardware, Software, Electronic Equipment, IT Networks, among others. For additional information please refer to https:\/\/adip.cdmx.gob.mx\/centros\/Asuntos-juridicos-y-normatividad<\/p>\n<p>The Normas Mexicanas (NMX) are non-binding technical documents that establish quality specifications in connection with processes, products, services, systems and others, including within the IT and Telecommunications sectors.<\/p>\n<p>In general, technical standards (either binding or not) allow the development of technology and the interoperability of networks, systems and equipment favouring efficiency and the development of new technologies, principally for the benefit of consumers and the private sector in general.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal laws of Mexico\u2019s data protection legal framework are: (i) the Mexican Constitution. Article 6 provides the fundamental right to access and rectify personal data within public records. Article 16 establishes the rights to access, rectify, cancel, or oppose the processing of personal data (rights known as Derechos Arco). And, furthermore, article 73 empowers the Mexican Congress to legislate comprehensively on matters of data protection, reinforcing the constitutional commitment to safeguarding personal information; (ii) the Federal Privacy Law, which governs the processing of personal data by private entities. Its objectives encompass the meticulous regulation of data retrieval, use, disclosure, storage, access, and transfer, concurrently supporting the establishment of binding self-regulation mechanisms, and to fortify the protection of personal data held by private entities, outlining a comprehensive legal framework that underpins responsible data management practices; (iii) the General Law for the Protection of Data Held by Obliged Subjects (the \u201cGeneral Privacy Law\u201d), that seeks to safeguard and preserve personal data held by any governmental body; (iv) the Parameters for Self-Regulation (Par\u00e1metros de Autorregulaci\u00f3n en materia de Protecci\u00f3n de Datos Personales), that serve as a strategic guideline for entities engaging in self-regulation concerning the protection of personal data; and (v) the Regulations to the Federal Privacy Law and the Privacy Notice Guidelines, which further develop the obligations imposed by the Federal Privacy Law and provide detailed rules regarding privacy notices, data subject rights, security measures and international data transfers.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In case of failure or in the event of a breach of any applicable data protection laws, the maximum sanction that can be imposed by the Anticorruption and Fair Government Ministry consists of MXN$37,539,200 (approximately USD$2,143,263.08).<\/p>\n<p>It is important to note that this sanction is independent of any civil and\/or criminal liability that could result from the breach. The Federal Privacy Law authorizes criminal penalties for individuals in some circumstances, including those causing data breaches or deceitfully processing personal data for profit.<\/p>\n<p>According to the Federal Privacy Law and the General Privacy Law the Ministry employs a meticulous approach to determine the penalty amount, considering factors such as the nature and sensitivity of the compromised personal data, whether the data controller disregarded the data subject\u2019s objections, the intentionality or omission behind the violation, the economic capacity of the data controller, and whether the breach constitutes a repeat offense. This multifaceted evaluation ensures that penalties are proportionate to the gravity of the infringement and serves as a deterrent against future violations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no special legal framework applicable to technology contracts from a data protection standpoint; therefore, they are regulated under the general data privacy framework: mainly the Federal Privacy Law and its Regulations. Technology agreements involving the processing of personal data commonly include provisions addressing the parties&#8217; respective data protection obligations, security measures, confidentiality, cross-border data transfers, breach notification, and compliance with applicable law.<\/p>\n<p>If a Mexican technology contract has no international element, it shall generally be governed by Mexican data protection law, and references to foreign regimes such as the EU General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA) are not required. Nevertheless, under the principle of freedom of contract (party autonomy) recognized under Mexican law, the parties may agree to comply with contractual standards that go beyond Mexican legal requirements, including the voluntary incorporation of obligations based on the GDPR, CCPA or other foreign data protection regimes, provided such provisions do not contravene mandatory Mexican law or public policy.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Although Mexico does not yet have a comprehensive standalone cybersecurity law, cybersecurity matters are regulated under a combination of existing laws:<\/p>\n<ul>\n<li>Federal Criminal Code (Articles 211 Bis 1 through 211 Bis 7), which criminalize unauthorized access to computer systems, data theft, data interference, and related cybercrimes.<\/li>\n<li>Mexican Constitution (Article 6 and 16), which provide the basis for privacy, data protection, and due process rights.<\/li>\n<li>Telecommunications and Broadcasting Law, which includes provisions on the security and integrity of telecommunications infrastructure.<\/li>\n<li>Federal Privacy Law, addressing the protection and processing of personal data, which overlaps with cybersecurity in terms of breach notification and security measures.<\/li>\n<li>General Privacy Law, which establishes equivalent information security obligations for public authorities.<\/li>\n<li>Federal Law on Transparency and Access to Public Information, which mandates safeguards for public sector data.<\/li>\n<li>National Code of Criminal Procedure, which regulates the preservation, collection and admissibility of electronic evidence and establishes the legal framework for certain investigative measures involving digital information.<\/li>\n<li>Copyright Law, which protects digital works and penalizes digital piracy and hacking related to intellectual property.<\/li>\n<li>Law on Credit Institutions and secondary financial regulations, which include provisions related to the protection of banking systems and digital financial operations.<\/li>\n<li>Securities Market Law, in cases involving digital fraud or manipulation of financial systems.<\/li>\n<\/ul>\n<p>In addition to the legislative framework, Mexico has strengthened its cybersecurity governance through administrative measures. On December 4, 2025, the ATDT published the \u201cNational Cybersecurity Plan 2025\u20132030\u201d <em>(Plan Nacional de Ciberseguridad)<\/em>, establishing the federal government&#8217;s strategic roadmap for improving cyber resilience, protecting critical infrastructure and promoting coordination between the public and private sectors. Furthermore, on December 17, 2025, the General Cybersecurity Policy for the Federal Public Administration entered into force following its publication in the Federal Official Gazette, establishing mandatory cybersecurity governance, risk management and information security requirements applicable to federal public entities.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sanctions for breaches of cybersecurity-related laws in Mexico vary depending on the specific law and type of infraction:<\/p>\n<p>A. Administrative Sanctions:<\/p>\n<p>Under Articles 58\u201361 of the Federal Privacy Law, the competent authority may impose:<\/p>\n<ul>\n<li>Fines ranging from 100 to 320,000 times the daily UMA (Unidad de Medida y Actualizaci\u00f3n), which may exceed MXN 37 million for serious or repeated violations.<\/li>\n<li>Additional penalties for intentional misuse or data breaches, particularly if sensitive personal data is involved.<\/li>\n<\/ul>\n<p>B. Criminal Sanctions (Federal Criminal Code, Articles 211 Bis 1\u20137):<\/p>\n<p>The Federal Criminal Code provides for:<\/p>\n<ul>\n<li>Imprisonment ranging from 3 months to 12 years, depending on the nature of the cyber-crime (e.g., unauthorized access, data theft, interference, or system damage).<\/li>\n<li>Fines may accompany imprisonment and are calculated based on the severity of the crime and the financial damage caused.<\/li>\n<\/ul>\n<p>C. Financial and Banking Sector (Special Laws):<\/p>\n<p>Under sector-specific laws such as:<\/p>\n<ul>\n<li>The Law of Credit Institutions and the Securities Market Law, individuals or entities may face:\n<ul>\n<li>Sanctions for unauthorized access to banking or financial systems.<\/li>\n<li>Criminal charges for fraud, identity theft, or data manipulation, including imprisonment and financial penalties.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no general mandatory registration applicable to entities solely because of the provision of information processing and related services. However, Mexican law does contemplate registration, licensing and authorization requirements in specific regulated sectors.<\/p>\n<p>For example, telecommunications operators must obtain the corresponding concession or authorization under the Telecommunications and Broadcasting Law before providing regulated telecommunications services. Also, financial institutions and fintech companies are subject to authorization and ongoing supervision by the National Banking and Securities Commission (Comisi\u00f3n Nacional Bancaria y de Valores) and, where applicable, the Mexican Central Bank (Banco de M\u00e9xico, \u201cBanxico\u201d) and must comply with cybersecurity, operational resilience and information security requirements established under the applicable financial regulatory framework.<\/p>\n<p>Certain regulated entities operating critical infrastructure or providing essential services may also be subject to sector-specific cybersecurity or information security obligations imposed by their respective regulators. However, these obligations generally do not require a separate cybersecurity registration or certification. Rather, cybersecurity compliance forms part of the broader regulatory obligations applicable to entities operating in those sectors.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As of July 2026, Mexico legislation does not contemplate a general cybersecurity incident reporting regime. However, the Federal Privacy Law provides that, where personal data has been compromised due to a security breach, the data controller shall notify the affected data subjects without delay. The notice shall indicate, among other things, the nature of the incident, the personal data involved, recommendations for mitigating potential harm, the corrective actions implemented by the controller and the means through which data subjects may obtain further information in connection with the corresponding incident. In addition, specific regulated sectors may be subject to their own incident reporting requirements. For instance, financial institutions and fintechs must report certain cybersecurity and operational incidents to the National Banking and Securities Commission or other competent authorities in accordance with the applicable financial regulations.<\/p>\n<p>Furthermore, the General Cybersecurity Policy for the Federal Public Administration, published on December 17, 2025, establishes a governance framework for the prevention, management and response to cybersecurity incidents within the federal public administration. The Policy allocates responsibilities to public bodies involved in cybersecurity, requires federal entities to establish incident response mechanisms and promotes coordination and information sharing among competent authorities. However, it does not establish an incident reporting regime nor provide the form, content or procedures applicable to cybersecurity incident reports. Rather, it provides high-level governance and coordination principles for incident management within the federal public administration.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Mexico does not currently have a dedicated artificial intelligence regulator or a comprehensive legal framework governing artificial intelligence (\u201cAI\u201d). Instead, the regulation of AI remains decentralized, with existing authorities exercising oversight where AI systems are deployed within sectors already subject to regulation, such as data protection, financial services, telecommunications, consumer protection and competition.<\/p>\n<p>At the federal level, the ATDT has assumed a leading role in the development of Mexico&#8217;s AI public policy. The ATDT is responsible for coordinating the implementation of the \u201cNational AI Plan\u201d (Plan Nacional de Inteligencia Artificial), which promotes the strategic, ethical and secure adoption of AI within the public sector and seeks to strengthen Mexico&#8217;s technological capabilities. However, the ATDT is not a dedicated AI regulator and does not currently possess general supervisory or enforcement powers over the development or deployment of AI systems by the private sector.<\/p>\n<p>AI governance is also supported by the Ministry of Science, Humanities, Technology and Innovation (Secretar\u00eda de Ciencia, Humanidades, Tecnolog\u00eda e Innovaci\u00f3n \u2013 \u201cSECIHTI\u201d), which, together with the ATDT, issued the \u201cDeclaration of Ethics and Good Practices for the Use and Development of Artificial Intelligence\u201d (Declaraci\u00f3n de \u00c9tica y Buenas Pr\u00e1cticas para el Uso y Desarrollo de la IA en M\u00e9xico). Although the Declaration establishes guiding principles for the responsible, transparent and human-centric development and use of AI, it does not create binding legal obligations nor designates a regulatory authority.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Mexican law does not currently contemplate a comprehensive statute or legal framework specifically applicable to the deployment and use of artificial intelligence. Instead, AI systems are subject to existing legal frameworks depending on the nature of the technology, the sector in which they are deployed and the risks associated with their use.<\/p>\n<p>The principal laws applicable to AI include (i) the Mexican Constitution which protects fundamental rights that may be affected by AI systems, including privacy, personal data protection, equality, non-discrimination, due process and freedom of expression; (ii) Federal Privacy Law and the General Privacy Law, regulate the processing of personal data by AI systems, require organizations to implement appropriate security measures, and grant data subjects the right to object to the processing of their personal data, including processing carried out through automated systems, through the exercise of their ARCO Rights; (iii) the Federal Consumer Protection Law, which applies to AI-enabled products and services offered to consumers and prohibits misleading or unfair commercial practices; and (iv) the Federal Copyright Law, which governs the use of protected works in connection with AI systems and, following the 2026 reforms, includes additional protections relating to the use of AI in the artistic and creative sectors.<\/p>\n<p>In addition to aforementioned legislation, the Mexican government has adopted non-binding policy instruments intended to promote the responsible development and use of AI. These include the National AI Plan, coordinated by the ATDT, and the Declaration of Ethics and Good Practices for the Use and Development of Artificial Intelligence, issued jointly by the ATDT and SECIHTI. Both instruments establish guiding principles for the ethical, transparent, human-centric and secure deployment of AI, but they do not create binding legal obligations or a dedicated AI regulatory regime.<\/p>\n<p>Several legislative initiatives seeking to establish a comprehensive AI regulatory framework have been introduced before Congress. However, none of these initiatives has been enacted as of the date hereof, and AI continues to be governed primarily through existing legislation of general application and sector-specific regulatory frameworks.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As mentioned in our responses to items 24 and 25 above, as of the date hereof, there is no specific regulation for the deployment and use of large language models (\u201cLLMs\u201d) and\/or generative AI in Mexico.<\/p>\n<p>The most significant recent legislative development concerns the 2026 amendments to the Federal Copyright Law and the Federal Labour Law, which strengthen the protection of performers, artists and other rights holders against the unauthorized use of their voice, image and performances, including through artificial intelligence technologies. However, these amendments do not establish a comprehensive regulatory framework for generative AI or LLMs, nor do they impose model-specific obligations on developers or deployers.<\/p>\n<p>In addition, several legislative initiatives introduced during 2025 and 2026 seek to establish a broader legal framework for AI. Most notably, constitutional reform bills propose amending Article 73 of the Constitution to expressly empower Congress to enact a General Law on AI, which would regulate the development, deployment, supervision and use of AI systems under a risk-based approach. These proposals are intended to cover AI technologies generally, including generative AI and foundation models, rather than creating rules specifically applicable to LLMs or agentic AI. However, none of these initiatives has been enacted as of this date.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No. Mexican law does not currently require technology contracts to include mandatory provisions specifically addressing AI risks. Although several legislative initiatives seeking to establish a comprehensive AI regulatory framework are currently under consideration, none has been enacted to date. Accordingly, there are no statutory clauses that must be incorporated into technology agreements solely because AI is involved.<\/p>\n<p>Nevertheless, AI-related contractual provisions have become increasingly common in commercial practice, particularly in software development, software-as-a-service (SaaS), cloud computing, technology licensing, outsourcing and data processing agreements. In the absence of AI-specific legislation, parties generally rely on contractual mechanisms to allocate legal, operational and commercial risks associated with the deployment and use of AI systems.<\/p>\n<p>Please note that, as mentioned in question 7 above, the Federal Civil Code (C\u00f3digo Civil Federal) recognizes the principle of \u201cparties\u2019 free autonomy\u201d, thus, the parties to any technology agreement may negotiate and include any provisions they deem convenient in order to limit or deal with AI risk.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Although Mexican law does not specifically regulate the ownership of AI-generated outputs, software and technology agreements are starting to include provisions addressing intellectual property rights arising from the use of AI systems.<\/p>\n<p>Under the Federal Copyright Law, copyright protection is generally based on human authorship, and Mexican law does not expressly recognize copyright ownership over works generated autonomously by AI. As a result, parties typically regulate these issues contractually.<\/p>\n<p>AI-related agreements may address the ownership of AI-generated outputs, prompts, inputs, datasets and derivative works, as well as restrictions on the use of customer data for training AI models, representations regarding third-party intellectual property rights and indemnification for infringement claims.<\/p>\n<p>In addition, as previously mentioned, the 2026 amendments to the Federal Copyright Law strengthened the protection of performers, artists and other rights holders against the unauthorized use of their voice, image and performances through AI technologies. Accordingly, in the absence of AI-specific legislation, the ownership and exploitation of AI-generated outputs continue to depend primarily on the contractual arrangements agreed by the parties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The use of Blockchain in Mexico is still a very brand-new feature, with a lot of work to do in terms of regulation. The main challenges for Blockchain in Mexico are the lack of regulation we do have on these matters. Recently, there has been an effort from the Mexican Congress and the authorities mentioned in the answer above to regulate this matter.<\/p>\n<p>The principal laws that govern Blockchain and digital assets are the (Circular 4\/2019) later amended by Rule (Circular 37\/2020), both issued by Banxico. Such Rules regulate the use of digital assets by the Financial Technology Institutions (Instituciones de Tecnolog\u00eda Financiera, \u201cFinTechs\u201d) and Credit Institutions (Instituciones de Cr\u00e9dito), with the previous authorization of Banxico, promoting the use of financial technologies and the provisions of services that use digital assets mitigating risks for users and clients.<\/p>\n<p>Furthermore, the amendment to the Federal Law for the Prevention and Identification of Operations with Resources from Illegal Sources (Ley Federal para la Prevenci\u00f3n e Identificaci\u00f3n de Operaciones con Recursos de Procedencia Il\u00edcita,) (the \u201cAnti-Money Laundering and Financial Compliance\u201d), enacted in July, 2025, seeks to strengthen safeguards against illicit financial activities and protect the integrity of the financial system. It establishes that institutions engaging with digital assets must comply with specific regulatory obligations, including Know Your Customer (KYC) procedures. The use, offering, and exchange of digital assets\u2014such as cryptocurrencies\u2014will now be considered a vulnerable activity, requiring all participants to meet legal requirements in order to operate within the law. The FinTech Law, specially regulates the financial services provided by financial technology institutions such as Electronic Payment Fund Institutions (Instituciones de Fondos de Pagos Electr\u00f3nicos, \u201cIFPEs\u201d) and Crowdfunding Institutions (Instituciones de Fondeo Colectivo or \u201cIFC\u201d). The goal is to provide services with digital assets without risk to users and clients.<\/p>\n<p>Additionally, the Financial Information Standard C-22 Cryptocurrencies (Norma de Informaci\u00f3n Financiera C-22 Criptomonedas) issued by the Financial Information Council, outlines general guidelines for valuation, reporting, and disclosure of balance sheets of operations with digital assets.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The primary laws that govern search engines and marketplaces in Mexico are: the Electronic Commerce Mexican Official Standard NMX-COE-001-SCFI-2018 (Norma Oficial Mexicana de Comercio Electr\u00f3nico NMX-COE-001-SCFI-2018), which general purpose is to protect and guarantee the rights of the consumers that utilize marketplaces to buy their goods and\/or services, protecting at the same time their personal data and their access to information rights; and the Consumer Protection Law, which general purpose is to protect the rights of the consumers of any goods and\/or services, including a special chapter for those consumers of marketplaces).<\/p>\n<p>Also, in general matters: (i) the Telecommunications and Broadcasting Law, which general purpose is to regulate the operation and utilization of telecommunications and broadcasting networks and services, (ii) the Code of Commerce, which general purpose is to regulate the commercial relationships between providers of goods and services with consumers, (iii) the Data Privacy Law, which general purpose is to regulate data processing (retrieval, use, disclosure, storage, access, and transfer of data), and (iv) the Federal Consumer Protection Law, which on article 76 Bis that establishes specific obligations for transactions made through electronic, optical, or any other technological means.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is not a comprehensive legal framework that governs the social media in Mexico, however the primary laws in the social media legal framework are: (i) the Mexican Constitution, which on article 6th establishes the right to access and correct personal data in public records, including social media, and on article 7th regulates the right to issue opinions and information; (ii) the Telecommunications and Broadcasting Law, that has as an objective to regulate, promote, and supervise the use, exploitation, and management of networks, encompassing relevant aspects of social media; and (iii) the Data Privacy Law that imposes obligations on companies offering services through online platforms to ensure the consent of the information holder and preserve the privacy of personal data; (iv) the Federal Copyright Law that regulates the content that is copyright protected work that can be found in social media and other digital platforms; (v) the Federal Consumer Protection Law that imposes sanctions regarding false advertising and misleading information; (iv) the legislative framework commonly known as the \u201cOlimpia Law\u201d (Ley Olimpia) comprising amendments to the General Law on Women&#8217;s Access to a Life Free of Violence and the Federal Criminal Code, which recognize and criminalize digital violence, including the non-consensual dissemination of intimate content through digital platforms and information technologies. These provisions have significantly influenced the legal responsibilities associated with the use of social media and online platforms in cases involving digital violence.<\/p>\n<p>Additionally, specific to Mexico City, the Civil Liability for the Protection of the Right to Privacy, Honor and Self-Image Federal District Law (Ley de Responsabilidad Civil para la Protecci\u00f3n del Derecho a la Vida Privada, el Honor y la Imagen en el Distrito Federal), which general purpose is to protect the right to privacy, honor, self-image of social media users.<\/p>\n<p>In 2022, a bill for Protection of Digital Users Federal Law (Ley Federal de Protecci\u00f3n al Usuario Digital) was proposed. This bill appears to have a general purpose focused on promoting and safeguarding the rights of digital users, digital services, and the intermediation of digital services. The specifics of this law, once enacted, will likely play a crucial role in shaping the legal landscape for social media in Mexico.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Mexico, there is currently no law specifically regulating online safety on social media platforms. However, legislative initiatives have been under discussion in recent years.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific legislation in Mexico for spatial computing technologies, including augmented reality, virtual reality, or the metaverse. However, existing laws may apply, including those on data protection, intellectual property, and consumer rights, depending on the use case. Legislative discussions are ongoing regarding how to regulate these emerging technologies.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Mexico, there are no specific laws currently in force that directly regulate quantum computing or quantum cryptography. At the moment these topics are addressed in academic, research, and scientific development contexts, with some support through government research funds and university-led innovation.<\/p>\n<p>However, considering that there have been some initiatives in the general cybersecurity field, this regulation may eventually evolve to include regulations concerning the risks and implications of quantum computing especially in areas like encryption, data protection, and critical infrastructure resilience.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Mexico, there are no specific regulations that apply exclusively to Data Centers; however, their operation is subject to a combination of legal frameworks. The principal legal framework includes the Federal Privacy Law, which requires organizations processing or storing personal data to implement appropriate administrative, technical and physical security measures. If a data centre supports regulated activities, -such as telecommunications, cloud services provided by regulated entities, financial services or fintech operations, -additional obligations may arise under the applicable sector-specific legislation, including the Telecommunications and Broadcasting Law, the Banking Law and the FinTech Law.<\/p>\n<p>Data Centers must also adhere to applicable construction, civil protection, and environmental regulations, as well as standards like NOM-151-SCFI-2016, which establishes requirements for the preservation of electronic messages and the digitalization of documents to ensure their integrity under commercial law. Thus, while not governed by a standalone law, Data Centers in Mexico must operate within a broad legal and regulatory landscape.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>(1) Artificial Intelligence. Mexico is expected to continue developing its regulatory framework for artificial intelligence. While comprehensive AI legislation has not been enacted yet, additional sector-specific rules, guidelines and standards governing the development and use of AI, particularly in relation to transparency, accountability, human oversight and high-risk applications, should be expected. As AI becomes increasingly integrated into sectors such as finance, healthcare and public services, regulation will likely seek to balance innovation with the protection of fundamental rights.<\/p>\n<p>(2) Cybersecurity. As digitalization and the use of AI continue to expand, cybersecurity is expected to remain a significant regulatory priority. Although Mexico has adopted a National Cybersecurity Plan and a General Cybersecurity Policy applicable to the Federal Public Administration, it still lacks a comprehensive cybersecurity law establishing generally applicable obligations across the public and private sectors. Over the next few years, it can be expected the implementation and further development of these policies, together with more robust legal obligations relating to incident reporting, critical infrastructure protection, cyber resilience, inter-agency coordination and risk management.<\/p>\n<p>(3) Regulation of Social Media and Digital Platforms. Although Mexico does not currently have a comprehensive legal framework specifically governing social media and digital platforms, this area should start gaining increasing legislative and regulatory attention. Global regulatory trends are moving beyond traditional data protection rules toward broader obligations for online platforms, including measures to protect minors, increase transparency in content moderation, combat misleading or harmful content, and strengthen platform accountability. As social media and digital platforms continue to play a central role in commerce, communications and public discourse, should Mexico gradually move towards a wider regulatory framework governing the responsibilities of digital platforms, extending beyond data protection to address issues such as user safety, online content, consumer protection and platform accountability.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Some technology agreements in Mexico incorporate provisions addressing sustainability, net-zero obligations and\/or similar environmental commitments. There is still, however, lack of specific legislation, awareness, and environmental protection culture within the country.<\/p>\n<p>Mexico is actively striving to make substantial improvement toward achieving net-zero emissions and enhance sustainability; there is a solid regulatory framework and is aiming for sustainability and self-sufficiency based on energy sovereignty, with plans to increase the productivity and efficiency of the current hydrocarbon-based energy system while progressively integrating clean and renewable energies.<\/p>\n<p>Some Mexican or Mexican-based companies have pledged to become net-zero by 2050. This commitment involves the implementation of Rational Environmental Technologies (Tecnolog\u00edas Ecol\u00f3gicamente Racionales, \u201cTER\u201d) and adherence to Environmental, Social and Governance (\u201cESG\u201d) and Sustainable Development Goals (\u201dSDG\u201d) criteria in almost every legal aspect &#8211; including technology contracts and use of technology.<\/p>\n<p>Also, Mexico has a Climate Change General Law (Ley General de Cambio Climatico) which establishes a fund to allocate financial resources for initiatives combatting climate change. This includes supporting projects focused on energy efficiency and the development of renewable energy sources.<\/p>\n<p>These concerted efforts suggest a growing awareness and commitment to sustainability and environmental protection in Mexico. As this awareness continues to evolve, there is a potential for a broader integration of such provisions into technology contracts, marking a positive step towards aligning business practices with environmental responsibility in the future.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">9158<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/146572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=146572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}