Mexico: New privacy challenges - The Unique Identity Platform and the future of data protection

Mexico’s Unique Identity Platform takes shape, transforming the foundations of data protection, cybersecurity, and state surveillance

In brief

On 27 November 2025, the Official Gazette of the Federation published the Guidelines for the Development and Operation of the Unique Identity Platform (PUI), in compliance with recent amendments to the General Population Law and the General Law on Forced Disappearance of Persons. These guidelines establish the regulatory, technical, and administrative framework for the management, interconnection, and security of the PUI, which will become the primary source for identity verification in Mexico, integrating biometric data and administrative records of both nationals and foreigners.

The Guidelines impose new obligations on all companies processing personal data, including enhanced requirements for data protection, cybersecurity, and cooperation with authorities. This includes mandatory notifications to regulators, stricter information security measures, and up-to-date documentation regarding personal data protection.


Key takeaways

  • Obligated Parties: The guidelines are mandatory for all government entities and private companies, referred to as “Diverse Institutions.” This definition is broad and includes companies in sectors such as financial services, healthcare, telecommunications, and any organization managing employee databases.
  • Interconnection and Access Requirements: Public institutions and companies must interconnect with the PUI. The technical rules for this interconnection will be published in the Technical Manual for Diverse Institutions, which must be issued within 30 days.
  • Personal Data Segmentation: Companies must structure their personal data to collaborate with authorities, differentiating between basic, historical, and continuous searches.
  • Registration with Authorities: Legal entities must register in Mexico City using their Llave MX (digital key).
  • New Data Protection and Cybersecurity Obligations: Companies connected to the PUI must maintain security measures as required by data protection laws, plus any additional requirements set forth in the Guidelines and Manuals of the PUI.
  • Mandatory Notification to RENAPO: Companies must notify the regulator in case of any breach compromising the security of personal data.
  • Evidence of Compliance: Companies are required to document and keep updated evidence of compliance with personal data protection legislation.
  • Obligation to Cooperate with Authorities: The primary obligation is to assist in the search for missing persons, although the law’s wording may allow for broader interpretations.
  • Liability and Sanctions: Companies failing to implement the required measures for PUI interconnection may face fines ranging from USD 60,000 to USD 120,000.
  • Implementation Deadlines: Technical and operational manuals must be issued within 30 business days, and the National Personal Identification Service will begin operating no later than 45 business days after the manuals are published.

Recommendation for companies

  • Does this apply to me? Assess whether your company qualifies as an obligated party under the law. If necessary, consult with authorities to confirm criteria.
  • Do I collect CURP or should I? Review your company’s Personal Data Management Program, identifying existing databases that may be affected by this law. Document any controls or measures not yet formally recorded.
  • Update internal processes to ensure secure and continuous interconnection with the PUI, differentiating the types of searches required by the regulations.
  • Implement technical and administrative measures for the handling and safeguarding of personal data, ensuring compatibility with the standards defined in the PUI manuals.
  • Train staff on new obligations and regulatory risks related to identity data management and cooperation with authorities in cases of missing persons.
  • Review and strengthen privacy notices and response protocols for PUI information requests.
  • Register your company in the Llave MX system and designate a Technical Liaison for coordination with RENAPO and ATDT.

Conclusion

The entry into force of these guidelines represents a structural change in identity management and personal data protection in Mexico. Companies and obligated parties must anticipate the technical, administrative, and legal challenges posed by interconnection with the Unique Identity Platform, ensuring regulatory compliance, protection of fundamental rights, and avoidance of fines.

Our team is available to provide specialized advice and support your organization in adapting to this new regulatory environment.


Copyright © 2025 Baker & McKenzie. All rights reserved. Ownership: This documentation and content (Content) is a proprietary resource owned exclusively by Baker McKenzie (meaning Baker & McKenzie International and its member firms). The Content is protected under international copyright conventions. Use of this Content does not of itself create a contractual relationship, nor any attorney/client relationship, between Baker McKenzie and any person. Non-reliance and exclusion: All Content is for informational purposes only and may not reflect the most current legal and regulatory developments. All summaries of the laws, regulations and practice are subject to change. The Content is not offered as legal or professional advice for any specific matter. It is not intended to be a substitute for reference to (and compliance with) the detailed provisions of applicable laws, rules, regulations or forms. Legal advice should always be sought before taking any action or refraining from taking any action based on any Content. Baker McKenzie and the editors and the contributing authors do not guarantee the accuracy of the Content and expressly disclaim any and all liability to any person in respect of the consequences of anything done or permitted to be done or omitted to be done wholly or partly in reliance upon the whole or any part of the Content. The Content may contain links to external websites and external websites may link to the Content. Baker McKenzie is not responsible for the content or operation of any such external sites and disclaims all liability, howsoever occurring, in respect of the content or operation of any such external websites. Attorney Advertising: This Content may qualify as “Attorney Advertising” requiring notice in some jurisdictions. To the extent that this Content may qualify as Attorney Advertising, PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME. Reproduction: Reproduction of reasonable portions of the Content is permitted provided that (i) such reproductions are made available free of charge and for non-commercial purposes, (ii) such reproductions are properly attributed to Baker McKenzie, (iii) the portion of the Content being reproduced is not altered or made available in a manner that modifies the Content or presents the Content being reproduced in a false light and (iv) notice is made to the disclaimers included on the Content. The permission to re-copy does not allow for incorporation of any substantial portion of the Content in any work or publication, whether in hard copy, electronic or any other form or for commercial purposes.