CiberLATAMbywhalemate

Argentina, Mexico Advance Cybersecurity Laws

Mendoza and Río Negro push their own bills, while Mexico moves toward a federal cybersecurity law and CDMX has criminalized phishing.

Whalemate Labs · AI-assisted researchAug 3, 20262 min read

While Argentina’s Senate continues debating a national cybersecurity law, Mendoza has introduced its own cybercrime bill focused on personal data. At the same time, Río Negro submitted a proposal to regulate the use of artificial intelligence in the provincial public sector, and Mexico is moving ahead with a federal law alongside new criminal provisions in Mexico City.

Mendoza and Río Negro move forward with their own bills

In Mendoza, lawmakers from Fuerza Patria introduced a cybercrime bill centered on the protection of personal data, applicable to the provincial and municipal public sectors, while the national executive-branch bill on cybersecurity remains under debate in Senate committees.

The Mendoza proposal comes as different subnational jurisdictions across the region seek to set their own rules on digital security, data, and the use of emerging technologies. In Río Negro, a bill was also introduced in the provincial legislature to create a regulatory framework for the responsible use of artificial intelligence in the provincial public sector. The proposal aims to set principles and limits for how state agencies use AI.

Mexico adds a federal law and a local criminal front

In Mexico, alongside the new federal data protection law and changes to identity and population rules, a bill identified as the Cybersecurity Law is moving through the Senate. It was introduced in 2025 and is structured into 64 articles. According to the analysis cited, it is shaping up to be the first comprehensive federal law on cybersecurity governance and could be published in the Diario Oficial de la Federación in the second half of 2026.

The same analysis points to another regulatory move in Mexico City. The capital explicitly added phishing as a crime in its Penal Code through new Article 231 Bis. The measure was promoted by lawmaker Olivia Garza de los Santos, approved unanimously on May 21, 2026, published in the Official Gazette on July 22, and took effect on July 23, 2026. The rule sets penalties of three to six years in prison and fines of 200 to 600 UMA, strengthening the criminal side of the cybersecurity and compliance picture.

A fragmented regulatory map

The cases of Mendoza, Río Negro, and Mexico City show how several subnational jurisdictions are advancing in parallel with national debates on cybersecurity, data protection, and artificial intelligence. In Mexico, attention is now on the possible publication of a comprehensive federal law in the second half of 2026, while in Argentina the provincial bills and the national legislative debate remain open.

Sources

View all