Mexico advances cybersecurity law
Mexico’s cybersecurity bill would protect data, people and critical infrastructure. The proposal has been sent to the Senate.
Mexican media report that the proposed National Cybersecurity Law and Agency has been introduced in the Senate for debate. The bill aims to protect data, people and critical infrastructure, while a separate criminal reform seeks tougher penalties for hacking and for spreading information obtained illegally.
Mexican media report that the proposed National Cybersecurity Law and Agency has been introduced in the Senate for debate. The bill seeks to protect data, people and critical infrastructure, while federal deputy Humberto Ambriz Delgadillo is also promoting a reform to the Federal Penal Code to increase penalties when information obtained through unlawful access to computer systems is sold or disclosed.
What does Mexico’s cybersecurity law propose?
The proposed National Cybersecurity Law and Agency seeks to protect data, people and critical infrastructure, and has already been submitted to the Senate for debate, according to Mexican media. In that same discussion, ecosystem groups such as GASA say the law should also create a framework for sharing incident and threat information under clear rules.
GASA Mexico described the bill under discussion in Congress as a key tool for building collective threat intelligence, beyond protecting critical infrastructure alone. That approach aims to organize the flow of information between public and private actors around incidents, with defined criteria for sharing useful data on attacks and vulnerabilities.
What changes does the criminal reform presented in September?
The reform introduced by Humberto Ambriz Delgadillo proposes changing article 211 Bis 7 of the Federal Penal Code to toughen penalties when information obtained through unlawful access to computer systems is commercialized or disclosed. The initiative also seeks to raise sanctions by up to half when data stolen through hacking is used for the benefit of the offender or a third party.
According to Diario 7 Noticias, the proposal is intended to punish both the sale and the spread of information obtained through hacking more severely. The legislative text also includes use for the benefit of the offender or others, an expansion meant to cover different forms of later exploitation of unlawful access.
What is happening elsewhere in the region?
In Chile, Bill 18.623-07 proposes increasing the members of the Board of Directors of the Personal Data Protection Agency from three to five and setting partial renewals every two years, without changing the substantive obligations on processing records, lawful bases, data subject rights, security measures or breach protocols. The change reorganizes the agency’s leadership, but leaves the main regulatory duties intact.
In Brazil, regulatory monitoring summaries record proposals to amend the LGPD and define criteria that would allow personal data to be used in training and improving artificial intelligence systems. The move adds to legislative monitoring of AI bills in the Federal Senate, where initiatives such as PL 93/2023, PL 2581/2023 and PL 2338/2023 are among the measures under review.
Peru, meanwhile, continues with a gradual compliance framework under Law 29733 and its implementing rules. Compliance analyses indicate that mid-sized companies have a reference date of November 30, 2026 to complete the appointment of the Personal Data Officer, while the technical measures required under article 18 include periodic vulnerability testing, response drills and verifiable backup restoration.
What do the Peruvian security and compliance frameworks require?
Sector analyses of Law 29733 and its implementing rules directly link operational cybersecurity with personal data protection. In that framework, companies must carry out periodic vulnerability tests, incident response exercises and checks to restore backup copies as part of their technical controls.
In addition to the deadline for appointing the Personal Data Officer, Peru’s timeline reflects a phased rollout based on an organization’s size and type. That reading of the rules places technology and compliance teams under concrete obligations, not only on paper but also in operations.
Sources
- De compartir información a construir inteligencia: GASA México en Forbesgasa.org· GASA México
- Prórroga a ley de protección de datos personaleslatercera.com· La Tercera
- Postergación de la Ley 21.719 a 2027softdigital.cl· Softdigital
- Tramitación de proyectos vinculados a la Ley 21.719senado.cl· Senado de Chile
- Nube y proveedores de software: qué exige el reglamentomifirmadigital.pe· Mi Firma Digital
- Ley 21.719: qué cambia en tu oficina antes de diciembre 2026prido.cl· Prido
- Projeto de Lei nº 2338/2023 – Brazil AI Regulation Billaipolicytracker.org· AI Policy Tracker
- Mexico's New Cybersecurity Agency Bill Answers a Real Ransomware Crisis, But Repeats an Old Institutional Design Flawpeopleofinternet.com· People of Internet
- ¿Se posterga la Ley 21.719? Lo que su pyme debe saberperitum.cl· Peritum
- PL 2338/2023 – tramitaçãowww25.senado.leg.br· Senado Federal do Brasil
- Proponen Agencia Nacional de Ciberseguridad en Méxicoacento21.com· Acento 21
- Impulsa iniciativa para sancionar con más rigor comercialización y divulgación de información obtenida por hackeodiario7noticias.com.mx· Diario 7 Noticias
- Oficial de Datos Personales: La Figura que el Reglamento Volvió Claveaypdigital.com· AYP Digital
- Relatório e Estado da Regulação de IA no Brasilmonitor.lcfconsulting.com.br· LCF Consulting
- PL 93/2023 – Tramitaçãowww25.senado.leg.br· Senado Federal do Brasil
- Flujo transfronterizo de datos personales en Perúmifirmadigital.pe· Mi Firma Digital
- PL 2581/2023 – Tramitaçãowww25.senado.leg.br· Senado Federal do Brasil
- Resolución N° 277/026 base de datosgub.uy· Unidad Reguladora y de Control de Datos Personales – Uruguay
- Atualizações da regulação de IA no Brasil — o que mudoumonitor.lcfconsulting.com.br· LCF Consulting
- Disegno di legge C.2417 (difesa dello spazio cibernetico)parlamento19.openpolis.it· Openpolis – Parlamento19
- Marco legal de IA no Brasilgopliance.com.br· Gopliance
- Disegno di legge C.1534 (deepfakes e immagini generate da IA)parlamento19.openpolis.it· Openpolis – Parlamento19
- Marco Legal da IA: por que a votação nunca acontece no Brasilportalsegurancatec.com.br· Portal Segurancatec
- Normas de ciberseguridad para empresas en el Perú (2026)apaxi.info· Apaxi



