Guides

Data protection for nutritionists in Mexico: what changed in 2025

Mexico’s new Federal Law on Protection of Personal Data Held by Private Parties repealed the 2010 law and replaced INAI. What it means for a nutrition practice.

10 min read

In March 2025 Mexico enacted a new Federal Law on Protection of Personal Data Held by Private Parties, repealing the 2010 law and changing the supervisory authority. If your privacy notice still names INAI, it is out of date.

On 20 March 2025 a new Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) was published, repealing the 2010 law. The institutional change is the most visible one: INAI was dissolved and supervisory functions moved to the Secretaría Anticorrupción y Buen Gobierno.

Your data is sensitive by definition

Mexican rules treat as sensitive any personal data touching the most intimate sphere of the data subject, or whose misuse could lead to discrimination or serious risk. Health status is expressly in that category. Processing it requires the subject’s express, written consent — a higher standard than the tacit consent that suffices for ordinary data.

The privacy notice

It is the centrepiece of the Mexican system and it is not optional. It must be made available before collecting data and must state, at minimum:

  • The identity and address of whoever processes the data: you or your practice.
  • The purposes of processing, separating necessary ones from those that are not.
  • That sensitive data will be processed and why, stated expressly.
  • How to exercise ARCO rights — access, rectification, cancellation, objection — and with whom.
  • Any transfers of data and to whom.
  • The procedure for communicating changes to the notice.

Express, written consent

For sensitive data it is not enough that the client does not object. You need express written consent, which in practice means a signature — handwritten or electronic — on a document stating they were told which sensitive data will be processed and for what purpose. Keep that document as carefully as the clinical record: it is your evidence.

How it meets NOM-004

Data protection rules and clinical record rules coexist. NOM-004-SSA3-2012 requires keeping the record for at least five years from the last recorded act; data protection law requires deleting what no longer has a purpose. They do not conflict: the retention duty is itself a purpose justifying keeping the record, even if you never use it actively.

SituationWhat to do with the recordWhat to do with marketing data
Active clientKept and updatedUsed if consent was given
Client stops comingRetained as an obligation, not actively usedStop using
Client withdraws consentRetained as a legal obligationDeleted and documented
Retention period elapsedCan be securely deletedShould already be deleted

Required safeguards

The rules require administrative, technical, and physical safeguards proportionate to risk, and with sensitive data the bar rises. In practice this means the predictable but rarely implemented:

  • A named account for every person with access, with their own password and a second factor.
  • Encryption on devices used to view records.
  • Verified backups, with at least one copy off the main machine.
  • Control over who accesses what, and logging of those accesses where possible.
  • Confidentiality agreements with reception, assistants, and any collaborator.
  • Physical lock-and-key storage for anything still on paper.

Security breaches

Where a breach significantly affects the financial or moral rights of data subjects, they must be informed without delay so they can take action. Always document the incident, which data was affected, what corrective measures you applied, and how you will prevent a repeat.

Frequently asked questions

Can I still use my previous privacy notice?

The structure remains valid, but references to the authority must be updated and you should check that purposes and sensitive data are described with the precision the current law requires.

Can consent be electronic?

Yes, as long as there is evidence attributable to the data subject. What matters is not paper but being able to prove who consented, when, and to what information.

What if I work with clients outside Mexico?

More than one framework can apply at once. If you serve residents of the European Union, for instance, the GDPR may reach you, and it is worth aligning to the stricter standard.

Do I need to register my database with an authority?

The Mexican model is not based on prior registration of databases but on the accountability of whoever processes the data: the privacy notice, consent, and safeguards are what you will be asked to evidence.

This guide is informational and is not legal advice. Check the regulations in force in your country and consult a professional if in doubt.

Next step

Take clinical nutrition to the next level with Almendra

Design plans, manage clients, and automate follow-ups in a single platform.

Get started for free
We use cookies
These cookies help us keep the page secure, give you a better experience, and show you more relevant advertising. We won't turn them on unless you agree.

Read more on our Privacy policy