Guides
Data protection for nutritionists in Mexico: what changed in 2025
Mexico’s new Federal Law on Protection of Personal Data Held by Private Parties repealed the 2010 law and replaced INAI. What it means for a nutrition practice.
In March 2025 Mexico enacted a new Federal Law on Protection of Personal Data Held by Private Parties, repealing the 2010 law and changing the supervisory authority. If your privacy notice still names INAI, it is out of date.
On 20 March 2025 a new Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) was published, repealing the 2010 law. The institutional change is the most visible one: INAI was dissolved and supervisory functions moved to the Secretaría Anticorrupción y Buen Gobierno.
Your data is sensitive by definition
Mexican rules treat as sensitive any personal data touching the most intimate sphere of the data subject, or whose misuse could lead to discrimination or serious risk. Health status is expressly in that category. Processing it requires the subject’s express, written consent — a higher standard than the tacit consent that suffices for ordinary data.
The privacy notice
It is the centrepiece of the Mexican system and it is not optional. It must be made available before collecting data and must state, at minimum:
- The identity and address of whoever processes the data: you or your practice.
- The purposes of processing, separating necessary ones from those that are not.
- That sensitive data will be processed and why, stated expressly.
- How to exercise ARCO rights — access, rectification, cancellation, objection — and with whom.
- Any transfers of data and to whom.
- The procedure for communicating changes to the notice.
Express, written consent
For sensitive data it is not enough that the client does not object. You need express written consent, which in practice means a signature — handwritten or electronic — on a document stating they were told which sensitive data will be processed and for what purpose. Keep that document as carefully as the clinical record: it is your evidence.
How it meets NOM-004
Data protection rules and clinical record rules coexist. NOM-004-SSA3-2012 requires keeping the record for at least five years from the last recorded act; data protection law requires deleting what no longer has a purpose. They do not conflict: the retention duty is itself a purpose justifying keeping the record, even if you never use it actively.
| Situation | What to do with the record | What to do with marketing data |
|---|---|---|
| Active client | Kept and updated | Used if consent was given |
| Client stops coming | Retained as an obligation, not actively used | Stop using |
| Client withdraws consent | Retained as a legal obligation | Deleted and documented |
| Retention period elapsed | Can be securely deleted | Should already be deleted |
Required safeguards
The rules require administrative, technical, and physical safeguards proportionate to risk, and with sensitive data the bar rises. In practice this means the predictable but rarely implemented:
- A named account for every person with access, with their own password and a second factor.
- Encryption on devices used to view records.
- Verified backups, with at least one copy off the main machine.
- Control over who accesses what, and logging of those accesses where possible.
- Confidentiality agreements with reception, assistants, and any collaborator.
- Physical lock-and-key storage for anything still on paper.
Security breaches
Where a breach significantly affects the financial or moral rights of data subjects, they must be informed without delay so they can take action. Always document the incident, which data was affected, what corrective measures you applied, and how you will prevent a repeat.
Frequently asked questions
Can I still use my previous privacy notice?
The structure remains valid, but references to the authority must be updated and you should check that purposes and sensitive data are described with the precision the current law requires.
Can consent be electronic?
Yes, as long as there is evidence attributable to the data subject. What matters is not paper but being able to prove who consented, when, and to what information.
What if I work with clients outside Mexico?
More than one framework can apply at once. If you serve residents of the European Union, for instance, the GDPR may reach you, and it is worth aligning to the stricter standard.
Do I need to register my database with an authority?
The Mexican model is not based on prior registration of databases but on the accountability of whoever processes the data: the privacy notice, consent, and safeguards are what you will be asked to evidence.
This guide is informational and is not legal advice. Check the regulations in force in your country and consult a professional if in doubt.
Next step
Take clinical nutrition to the next level with Almendra
Design plans, manage clients, and automate follow-ups in a single platform.