CiberLATAMbywhalemate

Mexico advances cybersecurity law

Mexico’s cybersecurity bill would protect data, people and critical infrastructure. The proposal has been sent to the Senate.

Whalemate Labs · AI-assisted researchPublished:3 min read

Mexican media report that the proposed National Cybersecurity Law and Agency has been introduced in the Senate for debate. The bill aims to protect data, people and critical infrastructure, while a separate criminal reform seeks tougher penalties for hacking and for spreading information obtained illegally.

Mexican media report that the proposed National Cybersecurity Law and Agency has been introduced in the Senate for debate. The bill seeks to protect data, people and critical infrastructure, while federal deputy Humberto Ambriz Delgadillo is also promoting a reform to the Federal Penal Code to increase penalties when information obtained through unlawful access to computer systems is sold or disclosed.

What does Mexico’s cybersecurity law propose?

The proposed National Cybersecurity Law and Agency seeks to protect data, people and critical infrastructure, and has already been submitted to the Senate for debate, according to Mexican media. In that same discussion, ecosystem groups such as GASA say the law should also create a framework for sharing incident and threat information under clear rules.

GASA Mexico described the bill under discussion in Congress as a key tool for building collective threat intelligence, beyond protecting critical infrastructure alone. That approach aims to organize the flow of information between public and private actors around incidents, with defined criteria for sharing useful data on attacks and vulnerabilities.

What changes does the criminal reform presented in September?

The reform introduced by Humberto Ambriz Delgadillo proposes changing article 211 Bis 7 of the Federal Penal Code to toughen penalties when information obtained through unlawful access to computer systems is commercialized or disclosed. The initiative also seeks to raise sanctions by up to half when data stolen through hacking is used for the benefit of the offender or a third party.

According to Diario 7 Noticias, the proposal is intended to punish both the sale and the spread of information obtained through hacking more severely. The legislative text also includes use for the benefit of the offender or others, an expansion meant to cover different forms of later exploitation of unlawful access.

What is happening elsewhere in the region?

In Chile, Bill 18.623-07 proposes increasing the members of the Board of Directors of the Personal Data Protection Agency from three to five and setting partial renewals every two years, without changing the substantive obligations on processing records, lawful bases, data subject rights, security measures or breach protocols. The change reorganizes the agency’s leadership, but leaves the main regulatory duties intact.

In Brazil, regulatory monitoring summaries record proposals to amend the LGPD and define criteria that would allow personal data to be used in training and improving artificial intelligence systems. The move adds to legislative monitoring of AI bills in the Federal Senate, where initiatives such as PL 93/2023, PL 2581/2023 and PL 2338/2023 are among the measures under review.

Peru, meanwhile, continues with a gradual compliance framework under Law 29733 and its implementing rules. Compliance analyses indicate that mid-sized companies have a reference date of November 30, 2026 to complete the appointment of the Personal Data Officer, while the technical measures required under article 18 include periodic vulnerability testing, response drills and verifiable backup restoration.

What do the Peruvian security and compliance frameworks require?

Sector analyses of Law 29733 and its implementing rules directly link operational cybersecurity with personal data protection. In that framework, companies must carry out periodic vulnerability tests, incident response exercises and checks to restore backup copies as part of their technical controls.

In addition to the deadline for appointing the Personal Data Officer, Peru’s timeline reflects a phased rollout based on an organization’s size and type. That reading of the rules places technology and compliance teams under concrete obligations, not only on paper but also in operations.

Sources

View all