Mexico's football federation just learned that a website checkbox is not the same thing as consent — and it cost the Federación Mexicana de Fútbol (FMF) 42,849,095 pesos, roughly $2.3 million.
On July 12, 2026, the Secretaría Anticorrupción y Buen Gobierno (SABG) — the executive-branch body that absorbed Mexico's federal data-protection authority when the autonomous Instituto Nacional de Transparencia (INAI) was formally dissolved on May 9, 2025 — sanctioned FMF over its Fan ID system, the biometric registration fans must complete to enter stadiums for Liga MX and this summer's FIFA World Cup matches co-hosted by Mexico. SABG's own press release lays out two distinct violations of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP): FMF's privacy notice never disclosed that the photographs collected to generate a Fan ID counted as datos personales sensibles — sensitive personal data — and the federation obtained sign-up authorization through nothing more than a checkbox on a webpage, not the express written consent the statute requires for processing sensitive data.
Two Failures, One Consent Bar
Article 9 of the LFPDPPP sets a deliberately high bar: processing sensitive personal data requires consentimiento expreso y por escrito, evidenced by an autograph signature, electronic signature, or another authentication mechanism capable of proving unambiguously that the data subject actually agreed. A checkbox satisfies neither the "express" nor the "written" half of that test as SABG read the statute — it can be pre-ticked, mis-clicked, or clicked by someone other than the person whose face is being scanned. FMF also missed the more basic disclosure duty: telling users, inside the privacy notice itself, that their biometric photo was sensitive data at all. Fans could not meaningfully consent to a category of processing they were never told applied to them.
The Case for Taking This Seriously
The strongest argument for SABG's action doesn't require hypotheticals. Fan ID exists because of a specific, violent incident: crowd violence at Estadio Corregidora in March 2022 pushed FMF toward biometric stadium-entry verification. Mexican digital-rights group R3D flagged consent and disclosure problems with the system almost immediately, publishing its first public warning in June 2022, and has argued since that a centralized database of fans' facial biometrics carries risks — breach, misuse, unreliable matching for marginalized users — that a leaked password doesn't, because a face can't be reset. In a July 15, 2026 response to the ruling, R3D called the fine a vindication of those warnings while noting, fairly, that it addresses only the consent and disclosure failures, not the system's deeper architecture. That distinction matters: the law's elevated consent bar for biometric data exists precisely so that "security" framing doesn't let a private organization normalize mass biometric collection without users understanding what they've agreed to.
A Regulator in a New Building
What makes this more than a routine privacy fine is who imposed it. SABG did not exist as a data-protection authority until it inherited the job from INAI — one of seven autonomous regulatory bodies, including telecom regulator IFT, eliminated in a late-2024 deregulation decree and folded into executive-branch secretariats. Critics warned at the time that shifting data-protection enforcement out of an independent, quasi-judicial commission and into a secretariat answerable to the president would weaken it, whether through political capture or simple deprioritization. The FMF case is the first real data point testing that prediction, and on its face it cuts against the worst-case fear: SABG built a technically sound case, correctly applied Article 9's consent standard, and set a fine large enough — against a federation with substantial World Cup-linked revenue — to function as a genuine deterrent rather than a rounding error.
Proportionate, Not Punitive
Still, this is a case for proportionate enforcement working as intended, not for maximalist regulation. SABG did not order Fan ID suspended, ban biometric stadium entry, or impose a blanket restriction that would make a legitimate security tool unworkable mid-World Cup. It fined FMF for a specific, fixable failure — bad consent design — and left the underlying system in place, giving the federation a clear path to compliance: rewrite the privacy notice, replace the checkbox with authenticated, written consent. That is the outcome a proportionate-regulation framework should want: real accountability for a real harm — uninformed biometric collection at national scale — without treating every biometric verification system as inherently illegitimate.
The open question is durability. An independent regulator's rulings tend to survive changes in political leadership by design; a secretariat's enforcement priorities can shift with an administration. SABG's inaugural marquee case was well-reasoned and proportionate. Whether Mexican data protection keeps making calls this sound — on Fan ID's next iteration, and on the other biometric systems queued up around major infrastructure projects — will say more about the INAI-to-SABG transition than the FMF verdict does on its own.