Mexico Tightens Anti-Money Laundering Rules for Retail
Retailers and financial entities in Mexico now face LFPIORPI, PCI DSS and LFPDPPP requirements for payments and personal data.
An analysis of Mexico’s retail regulations says banks, financial firms and merchants that extend credit face combined duties tied to money laundering prevention, transaction security and personal data protection.
A regulatory review of Mexico’s retail sector says financial institutions and retailers that extend credit are subject to LFPIORPI anti-money laundering requirements and to PCI DSS standards for transaction security tied to card data. Based on the material reviewed, that framework creates technical information security obligations for payment operations.
What regulatory framework does the analysis cite for retailers in Mexico?
The regulatory reading comes from an analysis published by Pirani Risk on retailers in Mexico. Other materials consulted for this note include sources from CIAL Dun & Bradstreet México, PLD.mx and KYC Systems, all focused on LFPIORPI, vulnerable activities and AML trends in the country, although the verified material for this write-up is limited to the two points confirmed by Pirani Risk.
What obligations apply to financial institutions and retailers that extend credit?
Financial institutions and retailers that extend credit in Mexico are subject to LFPIORPI for anti-money laundering purposes and to PCI DSS standards for transaction security applied to card data. Based on the material reviewed, that framework creates technical information security obligations for payment operations.
Taken together, those rules leave banks, fintechs and credit-granting retailers facing requirements that range from money laundering prevention to the protection of information linked to payments and personal data. In the reference material, the obligation is not framed as a single regulatory front, but as a set of controls for card processing, information retention and customer data handling under specific rules.
What rule applies to personal data processing?
The same regulatory analysis for retailers in Mexico identifies the Federal Law on Protection of Personal Data Held by Private Parties, or LFPDPPP, as the applicable framework. That law imposes security, incident management and privacy notice obligations for the processing of personal data, including data belonging to financial customers.
Under that framework, the sector’s focus is on simultaneous compliance with anti-money laundering controls, transaction security standards for cards and personal data protection obligations in the handling of financial customer information.
Sources
- Auditoría PLD para Actividades Vulnerables (LFPIORPI 2026)kyc-systems.com· KYC Systems
- Obligaciones Actividades Vulnerables: 13 Claves LFPIORPIkyc-systems.com· KYC Systems
- Todo sobre la regulación para retailers en Méxicopiranirisk.com· Pirani Risk



