INSIGHT MEXICO 1 MIN READ

Mexico | ICT Regulations & Cybersecurity

Published

Mexico is tightening ICT regulations with a new data protection law, rising cybersecurity investment, and ambitious telecom reforms—amid a 78% surge in cyberattacks.

  • In 2025, Mexico introduced a new Data Protection Framework (FLPPD), expanding “personal data” to legal entities, redefining controllers, and requiring explicit consent for each processing purpose. || Source: Littler
    + Non-compliance with FLPPD may result in fines from 100 to 320,000 UMA (Unit of Measure & Update)—$565.70 to $1.81 million—doubled when sensitive data, such as that risking discrimination, is involved.
  • Also, in 2025, the government introduced an initiative for a new telecom law proposing to transfer IFT (Federal Telecommunications Institute) powers to a new agency, allow spectrum allocation without bidding, and ease rules for public operators. || Source: CSIS
    + However, the initiative has sparked concerns over potential violations of the Constitution and USMCA, including spectrum giveaways, public operator exemptions, and restrictions on foreign media.
  • In 2024, Mexico faced 31 million cyberattack attempts—55% of Latin America’s total—marking a 78% surge from the previous year. || Source: Mexico Business
    + Launched in 2017, Mexico’s National Cybersecurity Strategy supports a $2.8 billion market growing at 11.6% annually, leveraging AI and cloud tools to enhance defense and attract global players. || Source: OAS