clic para entrar
← back to blog
Tech tips for business

How to write a privacy notice that complies with the law (2025)

How to write a privacy notice that complies with the law (2025)

A privacy notice that complies with the law in Mexico (2025) is a document where your business tells each person who you are, what data you collect, what you use it for, who you transfer it to, and how they can exercise their rights—with stricter consent following the LFPDPPP reform that took effect on March 21, 2025. It’s not a decorative legal text: it’s the piece that backs up everything you do with your customers’ data.

Many businesses copy a privacy notice off the internet, paste it into a corner of their site, and forget about it. After the 2025 reform, that’s no longer enough. This article explains, in plain language, which sections your notice must include, what the reform changed, and where to place it. It’s focused on the Mexican market and does not constitute definitive legal advice; for sensitive cases it’s best to validate it with a lawyer.

What sections must a privacy notice include?

A complete notice answers, in an orderly way, the questions any person has about their data. These are the sections that can’t be missing:

  • Identity and address of the data controller. Who you are (name or business name) and how to contact you. The person should know who they’re handing their information to.
  • Personal data you collect. What information you ask for: name, email, phone, address, payment details, etc. Be specific.
  • Purposes of processing. What you use that data for. Here it helps to separate necessary purposes (delivering the service, invoicing) from optional ones (marketing, surveys).
  • Transfers to third parties. If you share data with providers or partners, say so, and indicate with whom and for what.
  • ARCO rights. Explain that the person can Access, Rectify, Cancel, or Oppose the use of their data.
  • How to exercise those rights. An email, a form, or a clear procedure so they can request it.
  • Changes to the notice. How you’ll notify them if the notice is updated in the future.

What changed with the 2025 reform?

The core adjustment is that consent became stricter and purposes must be more specific. The reform eliminated the old allowance to use data for purposes “compatible with or analogous to” the original one, so your notice can no longer hide behind vague phrasing.

This has practical consequences for how your notice is written:

  • Concrete purposes, not generic ones. Instead of “we will use your data for purposes related to our business,” list each real use. The more specific, the better.
  • Consent by purpose. If you’re going to use data for something other than what motivated the collection, you need permission for that new use—you can’t assume it’s included.
  • Updated authority. Oversight of data protection moved from the INAI to the Anti-Corruption and Good Governance Secretariat; keep this in mind when referring to the competent authority.
A privacy notice document with its key sections lighting up one by one in cyan light
A good privacy notice answers, section by section, everything a person wants to know about their data.

Where should I place the privacy notice?

At every point where you collect data, not just hidden in the footer. The practical rule is simple: wherever you ask for information, the notice—or a link to it—must be visible.

  • On your website. With a permanent link in the footer, accessible from any section.
  • On every form. Contact, subscription, registration, checkout: each one must link to the notice right at the point of collection.
  • At the physical point of collection. If you capture data at a counter, event, or over the phone, keep a short notice on hand that points to the full one.

A privacy notice doesn’t protect you just by existing, but by reflecting what you actually do with the data. If it says one thing and you do another, it doesn’t comply.

Final checklist for your privacy notice

Before calling your notice done, review it against this quick list:

  • Do you clearly identify who the data controller is and how to contact them?
  • Do you list the specific data you collect?
  • Do you describe each purpose specifically, separating the necessary from the optional?
  • Do you declare transfers to third parties?
  • Do you explain ARCO rights and the means to exercise them?
  • Do you state how you’ll announce future changes?
  • Is it linked on your site and on every form where you ask for data?
  • Did you validate it with a legal specialist if you handle sensitive data?

In summary

A privacy notice that complies with the law in 2025 isn’t copied text: it’s a specific document that declares what data you collect, what for, and how rights are exercised, with concrete purposes and stricter consent per the LFPDPPP reform. Place it on your site and on every form, and validate it with a lawyer if you handle sensitive information.

If you’d rather not build it from scratch, at Normandia Web we can help you draft and place your privacy notice, connect it properly to your forms, and get your site in order so you collect data with confidence and in line with the law.

Ready to put it to work in your company?

Tell us what’s costing you time, money or control. We’ll help you figure out where to start.

Start your consultation →