Mexico's new data protection law 2025: what to change on your website

Mexico’s new data protection law—the reform to the LFPDPPP published in the Federal Official Gazette on March 20, 2025, and in force since March 21, 2025—tightens the rules on consent and requires you to review the privacy notice, forms, and CRM on your website. This isn’t a cosmetic change: it directly affects how you request, store, and use your customers’ data online.
If your business has a site with contact forms, an online store, a mailing list, or a CRM where you keep prospects, this reform applies to you. The good news is that catching up doesn’t require lawyers at every step: it requires understanding what changed and reviewing, point by point, where you collect personal data. This article is written for the Mexican market and does not replace a formal legal review, but it gives you the map to get started.
What exactly changed with the 2025 reform?
The core change is that consent became stricter. Previously, the law allowed you to use data for purposes “compatible with or analogous to” the original one without asking permission again; that allowance is gone. Now, if you want to use a person’s data for something different from what you collected it for, you have to request their consent again.
In practical terms, these are the points that matter most to a small business:
- Stricter consent. Collecting data for one purpose does not authorize you to use it for another. If you captured an email to send a quote, you can’t assume the person also authorized advertising or sharing their data with a third party.
- Goodbye to “compatible or analogous” purposes. That concept, which gave room to reuse data, has been eliminated. Today each new purpose needs its own consent.
- The regulator changed. Oversight of data protection moved from the INAI to the Anti-Corruption and Good Governance Secretariat. What matters to you is that there is still an authority that can demand compliance.
Why does this matter to your website?
Because your site is usually the main place where you collect personal data, often without realizing it. Every contact form, every newsletter signup, every “I agree” checkbox, and every shopping cart gathers people’s information. If those pieces don’t reflect the new rules, your business is exposed.
The risk isn’t just a fine: it’s your customers’ trust. When someone leaves you their name, phone number, or card, they expect you to handle it with care. A website that asks for consent clearly conveys professionalism; one that collects data “blindly” breeds distrust and, now, breaks the law.
What should I review on my website to comply?
Start by taking an inventory of every place your site asks for data, and review them against this list. There’s no need to rebuild your site; in most cases these are targeted adjustments.
- Your privacy notice. It should be up to date, easy to find, and describe precisely what you use data for. If it mentions vague or “analogous” purposes, it’s time to fix it.
- Contact and subscription forms. Each one should explain what the data will be used for and link to the privacy notice right at the point of collection.
- Consent checkboxes. Separate the necessary (contacting you about your request) from the optional (receiving promotions). Don’t merge them into a single checkbox or leave them pre-checked.
- Your CRM and mailing lists. Review the purpose under which those contacts came in. If you want to use them for something new—say, a different campaign—you may need to ask permission again.
- Transfers to third parties. If you share data with providers (an email marketing platform, a payment gateway, an agency), your notice must declare it and the user must be informed.
What if I handle sensitive data or have legal doubts?
Here it’s worth being honest: if your business handles sensitive data—health, detailed financial status, minors’ data, biometric information—or if you operate in a heavily regulated sector, this article isn’t enough. The reform sets the broad lines, but every case has nuances, and penalties for mishandling sensitive data are higher.
Complying with data law isn’t a one-time task: it’s a way of operating that protects your customers and your business at the same time.
In those cases, the prudent move is to lean on a legal specialist in data protection to validate your privacy notice and your processes. The investment is small compared with the cost of a penalty or a data breach. For the rest of small businesses with standard forms and CRMs, a solid privacy notice and well-designed forms cover most of the ground.
In summary
The LFPDPPP reform that took effect on March 21, 2025, changed the rules of consent in Mexico: you can no longer reuse data for “analogous” purposes, and you need specific permission for each use. For your website, that translates into reviewing your privacy notice, your forms, your consent checkboxes, and your CRM. These are concrete, achievable adjustments, not a full re-engineering.
If you want to make sure your site collects data correctly and conveys trust, at Normandia Web we can review your forms, your privacy notice, and your data flow with you, and leave you with a website aligned to the new rules and to the good impression your business deserves.
Ready to put it to work in your company?
Tell us what’s costing you time, money or control. We’ll help you figure out where to start.
Start your consultation →