WolfSellers — Adobe Experience Cloud Partner en México

Article

Data Protection for Ecommerce in Mexico: LFPDPPP Requirements and Adobe Commerce Compliance

What Mexico's new LFPDPPP requires of an online store after INAI's dissolution, ARCO rights, and how to implement compliance in Adobe Commerce and Real-Time CDP.

By WolfSellers··15 min read
Data Protection for Ecommerce in Mexico: LFPDPPP Requirements and Adobe Commerce Compliance
On this page

Every purchase on a Mexican online store creates a personal data record: full name, delivery address, phone number, email, often a tax ID (RFC) for invoicing, and whatever payment data the gateway processes. That has always been regulated — Mexico has had a private-sector data protection law since 2010 — but there are two new reasons this belongs on every ecommerce team's agenda. The first is that checkout in Mexico now collects more data than ever: automated invoicing, loyalty programs, AI-driven personalization and paid-media activation all depend on increasingly complete customer profiles. The second is that the institutional framework changed fundamentally in March 2025: the agency that oversaw personal data protection in Mexico for 15 years was dissolved, a new law was published, and its functions moved to a different federal government body.

That change is not an administrative footnote. It changes who receives a request to access or delete personal data, who resolves a customer complaint, and who reviews your store's privacy notice. And it happened just over a year ago, so it is not unusual to find privacy notices, checkout policies and internal processes that still reference the old agency.

At WolfSellers we implement Adobe Commerce (formerly Magento) and Adobe Experience Platform for brands operating in Mexico, and the privacy notice, marketing consent and customer data request handling are part of the scope of every ecommerce project, not a legal appendix bolted on afterward. This article covers what the current law requires, what changed with INAI's dissolution, and how each obligation translates into concrete platform configuration.

One necessary caveat before we start: this is not legal advice. Mexico's personal data protection framework was fundamentally reformed in March 2025 and is still being fleshed out by regulation — as of this writing, the implementing regulation for the new law has not yet been published, and some of the authority's interpretive criteria are still being defined. We summarize the framework so technology and business teams know what the platform needs to support; the privacy notice, data processing agreements and any compliance decision must be validated with a firm specialized in Mexican data protection law.


What changed: INAI's dissolution and the new LFPDPPP

Until March 2025, Mexico's data protection authority was INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales), an autonomous constitutional body that had existed since 2002. Beyond overseeing public-sector transparency, INAI was the regulator for the LFPDPPP (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, Mexico's federal law on personal data held by private parties), the statute governing how private companies handle customer data.

As part of the Sheinbaum administration's federal government simplification reform, Congress approved INAI's extinction. Based on public sources and analyses from Mexican law firms, the sequence was:

  1. On February 20, 2025, the Executive submitted a bill to the Senate dissolving INAI and reforming the transparency and data protection framework.
  2. Congress approved it, and on March 20, 2025, the new Ley Federal de Protección de Datos Personales en Posesión de los Particulares was published in the Diario Oficial de la Federación (DOF), repealing the 2010 LFPDPPP and taking effect the following day, March 21, 2025.
  3. INAI's material, financial and human resources were transferred to the Secretaría Anticorrupción y Buen Gobierno (Ministry of Anticorruption and Good Governance), a federal Executive-branch agency that absorbed oversight and regulatory functions for personal data protection covering both the private sector (companies, including telecom and financial institutions) and public-sector data controllers.

Two important distinctions worth keeping separate:

  • The LFPDPPP did not disappear — it was rewritten. A law with that same name still exists and still governs private companies, including any ecommerce operation. What changed is the text — updated references to the regulator, sanction amounts now expressed in UMA (Mexico's inflation-indexed measurement unit) instead of minimum wage, and some procedural details — and, above all, who enforces it.
  • There is a separate law for the public sector. The Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados governs government agencies, not private companies. If your ecommerce operation is not a government entity, the LFPDPPP is the law that applies to you.

Unlike INAI, the Secretaría Anticorrupción y Buen Gobierno is not an autonomous body: it reports to the federal Executive and lacks its own budgetary independence. Analysts, academics and bar associations in Mexico have publicly flagged this as a loss of regulatory independence compared to the previous model. For a practical ecommerce standpoint, what matters operationally is that ARCO rights requests, data-subject complaints and compliance oversight are now handled through this Secretariat rather than INAI. As of this writing, the implementing regulation for the new LFPDPPP is still pending publication, and several operational details — such as the exact channels and forms for filing a complaint — were still in transition. This is exactly the kind of detail to confirm with current legal counsel at implementation time, not to assume from this article.


What the LFPDPPP requires from an ecommerce business

The law organizes the obligations of a company handling personal data — the data controller, in the statute's language — around three pieces: the principles that must govern any data processing, the privacy notice that informs the data subject, and the rights that subject can exercise over their own data.

The eight data processing principles

Principle What it requires in practice
Lawfulness Data is obtained and processed in accordance with the law, never through deceptive or unfair means
Consent The data subject must consent to the processing, subject to the exceptions the law allows (e.g., contractual necessity); the new law specifies consent must be free, specific and informed
Notice The data subject knows what data is collected, for what purpose, and who the controller is, through the privacy notice
Data quality Data must be accurate, complete and up to date for the purpose it was processed for
Purpose limitation Data is only used for what the privacy notice disclosed, not repurposed later without notice
Loyalty Processing may not be carried out through fraudulent or deceptive means
Proportionality Only the data necessary for the stated purpose is collected, not everything that could technically be requested
Accountability The controller must be able to demonstrate compliance with the above, through documented security measures and processes

Proportionality is the principle most often broken by a poorly designed checkout: requiring a full date of birth, a national ID or a mandatory tax ID when the transaction does not legally require it, or making a marketing opt-in mandatory when it is not needed to complete the purchase. Purpose limitation tends to break after checkout, when data captured for invoicing ends up feeding advertising segmentation that the privacy notice never disclosed.

The privacy notice

This is the document through which the controller informs the data subject what data it collects, for what purpose, whether there are third-party transfers, and how to exercise their rights. The law distinguishes between a full (integral) privacy notice — the complete document, typically a dedicated page on the site — and a simplified notice, shorter, shown at the point where the data is collected, such as the checkout form itself or the footer of the order confirmation email. The new law specifies that the simplified notice must clearly distinguish which purposes require the data subject's consent and which do not, and must flag whether sensitive data is involved.

For an ecommerce business, this means the privacy notice is not one static page: you need to think in terms of distinct collection points — account registration, guest checkout, the newsletter form, support chat, the loyalty program — and each one needs its own simplified notice, consistent with the full notice and with the actual purposes of that specific collection.

ARCO rights

The data subject — your customer — has four rights they can exercise against the controller at any time:

Right What the customer can request
Access To know what personal data of theirs the company holds and for what purpose it is processed
Rectification To correct inaccurate or outdated data
Cancellation (erasure) To have their data deleted from the controller's systems once it is no longer needed for the purpose that justified it
Opposition To stop a specific processing of their data, such as marketing communications, without cancelling the entire relationship

The law gives the controller a deadline to respond to an ARCO request — the historical standard under the 2010 LFPDPPP was 20 business days to respond and, if the request is granted, an additional 15 business days to make it effective; it is worth confirming with legal counsel whether the new law keeps these same deadlines, since the implementing regulation is still pending. If the customer is not satisfied with the response, or the controller does not respond, they can file with the Secretaría Anticorrupción y Buen Gobierno.

For an ecommerce operation with thousands of customers, handling ARCO requests manually — searching for the customer in the database, the ERP, the email platform and the CDP separately — does not scale. This is exactly the kind of process that gets automated in customer data architecture, which the next section details.


From law to platform: obligation by obligation

This is the table we use when starting an ecommerce project in Mexico: what the law requires by layer and how it is resolved in Adobe Commerce, Adobe Experience Platform and Real-Time CDP.

Legal obligation What it involves How it's resolved on the platform
Full privacy notice Complete document, accessible from any page CMS page in Adobe Commerce, linked from the footer and checkout; versioned per store view if you operate in multiple languages
Simplified notice at each collection point Short text at the form where the data is captured, with consent-requiring purposes flagged separately Page Builder content or a CMS block embedded in the registration form, guest checkout, newsletter and loyalty program; independent consent checkboxes per purpose, not one generic box
Free, specific, informed consent The customer explicitly chooses which processing they accept — purchase, yes; marketing, optional — with no pre-checked boxes Newsletter opt-in explicit and separate from the transactional purpose; consent record with date, text shown and channel, the same pattern we recommend for consent logging in our Canada privacy and CASL guide
Proportionality principle Not collecting more data than the stated purpose requires Audit of mandatory checkout fields: tax ID and invoicing data only when the customer requests an invoice, not as a mandatory purchase step
Right of access and rectification (ARCO) The customer can request a copy of their data and correct it My Account self-service in Adobe Commerce for basic data; in Adobe Experience Platform, the unified customer profile lets you generate a consolidated access report — ecommerce, CRM, CDP — in a single flow instead of searching system by system
Right of cancellation (erasure) The customer can request their data be deleted Account deletion and historical order anonymization flow in Adobe Commerce that respects tax record-keeping obligations; in Real-Time CDP, profile deletion propagates to connected activation destinations (email, ads, on-site personalization)
Right of opposition The customer can stop receiving marketing without cancelling their account Per-channel communication preferences on the customer profile; the opt-out signal must reach the CDP and any ecommerce marketing tools before the next send, not through a manual process
Third-party transfers (payment gateways, couriers, marketing agencies) The privacy notice must disclose which third parties receive data and why, and the controller remains jointly responsible for that third party's compliant handling Inventory of integrations that receive customer data — payment gateway, courier, ERP, email platform — documented and reflected in the privacy notice; data processing agreements with each vendor
Security measures (accountability principle) The controller must demonstrate technical and organizational controls over the data it processes Adobe Commerce on managed cloud infrastructure, encryption in transit and at rest, role-based access control in the admin; covered in our cloud hosting and cloud infrastructure services
Consent propagated to personalization and AI If customer data feeds personalization, recommendations or activation with Adobe Sensei, the purpose must be covered in the notice Consent status on the Real-Time CDP profile must gate which signals feed personalization models, so segments aren't activated on data without a disclosed purpose

Two points deserve extra detail, because they are the ones that most often break a project that "on paper" complies but is not architected for it.

The right of erasure collides with tax obligations. Mexico's Federal Tax Code (Código Fiscal de la Federación) requires keeping invoices and accounting records for several years, so "deleting a customer's data" is almost never a full physical delete: it is an anonymization of the fields that identify the person — name, address, contact details — while keeping the order's accounting and tax record without a direct link to the data subject. Designing that anonymization flow, rather than a simple DELETE, is the difference between complying with data protection without breaking tax compliance.

Consent has to travel with the profile, not stay on the site. If the project includes Adobe Experience Platform and Real-Time CDP — see unifying data and personalization with Real-Time CDP — the opt-in or opt-out signal captured at checkout must reach the unified customer profile so that segmentation and paid-media activation respect that preference across every channel, not just the site where it was captured.


Penalties: what the law says and what remains unresolved

The new LFPDPPP keeps the administrative sanctions model of the previous law but changed the reference unit: fines are no longer calculated in minimum wages but in UMA (Unidad de Medida y Actualización), whose value INEGI, Mexico's statistics agency, publishes every year. Using the daily UMA value in effect since February 2026 — $117.31 Mexican pesos, per INEGI's press release — the ranges reported by Mexican law firm analyses of the new law are, approximately:

Type of infraction Range in UMA Approximate peso equivalent (2026 UMA)
General infractions 100 to 160,000 UMA ≈$11,700 to ≈$18.8 million pesos
Aggravated infractions Up to 320,000 UMA Up to ≈$37.5 million pesos
Infractions involving sensitive data Up to double the aggravated maximum Up to ≈$75 million pesos

These figures are our own calculation based on the current UMA value and the ranges reported by specialized sources on the new law; they are not a direct quote from the statute and should be confirmed against the current text and its implementing regulation before use in any formal risk analysis. The same caution applies to what counts as sensitive data — health, ethnic origin, religious beliefs, sexual orientation, among others — and what aggravates an infraction.

What is consistent across sources is the real-world risk pattern for an ecommerce business: the process almost never starts with a proactive audit. It starts with a customer complaint about an unanswered ARCO request, or a security incident exposing data that a customer or a competitor reports. A complete privacy notice, an ARCO request workflow that responds within the deadline, and a clear map of where every piece of customer data lives reduce that risk far more than memorizing a fine range.


How we approach this at WolfSellers

At WolfSellers we implement Adobe Commerce and Adobe Experience Cloud for brands operating in Mexico, and we treat data protection as part of the project's architecture, not a legal document drafted at the end. Our job is not to give legal advice — that belongs to the specialized firm each client already has or that we help identify — but to make sure the platform can support whatever that firm determines: a privacy notice per collection point, granular and auditable consent, a real workflow for handling ARCO requests that does not depend on searching for the customer system by system, and a clear map of which third parties receive customer data and why.

The order we follow on a new project or an audit of an existing store: first, an inventory of what data is collected and at which points on the site, checked against what the current privacy notice actually says; then, the design of the ARCO rights and anonymization flow that respects both data protection law and tax record-keeping obligations; and finally, if the project includes personalization or media activation, propagating consent status to Adobe Experience Platform and Real-Time CDP so segmentation respects the customer's preference across every channel.

If your store is already live and you want to know how exposed your current checkout is under the current framework, or you are about to launch an ecommerce operation in Mexico and want to build it right from the start, we invite you to start with a free discovery call with our team. Our Adobe Commerce, consulting and implementation services cover everything from diagnosis to ongoing operation.


FAQ: data protection for ecommerce in Mexico

Is the LFPDPPP still in force, or did it change names?

It is still in force and keeps the same name, but the text is new. The 2010 law was repealed and replaced by a new Ley Federal de Protección de Datos Personales en Posesión de los Particulares, published in the Diario Oficial de la Federación on March 20, 2025, and effective the following day. It remains the statute that applies to private companies, including any ecommerce business; what fundamentally changed is who enforces it — no longer INAI, but the Secretaría Anticorrupción y Buen Gobierno — plus some procedural adjustments and sanction amounts now expressed in UMA. Confirm the exact status of the implementing regulation with your legal advisor, since it was still pending publication as of this writing.

Who do I file an ARCO rights request or complaint with now that INAI is gone?

Oversight and regulatory functions for private-sector data protection moved to the Secretaría Anticorrupción y Buen Gobierno, a federal Executive-branch agency. If your company receives an ARCO rights request from a customer, you handle it directly as the data controller, within the deadlines set by the current law; if the customer is not satisfied with your response or receives no response, they can file with that Secretariat. The exact channels and forms for that process were still in transition at the time of writing, so verify the current procedure with your legal advisor before publishing a privacy notice that references a specific channel.

What data can I request at checkout without violating the proportionality principle?

Only what is necessary to complete the purchase, delivery and, where applicable, invoicing: name, address, contact details and, only when the customer requests an invoice, their tax data. Mandatorily requiring data that is not necessary for that purpose — a tax ID from every buyer, a full date of birth with no business reason, or a mandatory marketing subscription — is exactly the kind of practice the LFPDPPP's proportionality principle aims to prevent, and it is also unnecessary conversion friction. The rule we apply in Adobe Commerce: every mandatory checkout field must be justifiable against a purpose disclosed in the privacy notice.

Does Real-Time CDP help me comply with the LFPDPPP, or is it just for personalization?

Both, and they are more connected than they appear. Real-Time CDP centralizes the customer profile and, with it, their consent status; that means when a customer exercises their right of opposition to marketing, that signal can propagate automatically to activation destinations — email, ads, on-site personalization — instead of relying on someone updating it manually in every tool. It does not replace the legal work of defining the privacy notice or the ARCO request handling process, but it does solve the technical problem of consent being respected consistently across every channel where customer data is used.

If this topic is relevant to your business, these WolfSellers services can help you implement it:

Want to dive deeper?

Let's talk.

We're an Adobe Gold Partner in Mexico with experience in Adobe implementations and integrations. If anything in this article applies to your operation, the first consultation is on us.

Or email us at contacto@wolfsellers.com

Keep reading

Chat with us on WhatsApp