Mexico Mexico LFPDPPP data protection platform

Mexico's Data Regulator Fines the Football Federation Over FAN ID Consent, Testing a New Enforcement Body's Teeth

SABG's MXN 42.8M fine against the FMF for mishandling FAN ID facial data is Mexico's first major test of enforcement after INAI's 2025 dissolution.

Mexico's First Big Data-Protection Fine People of Internet Research · Mexico MXN 42.8M Fine imposed on FMF ≈USD 2.14M, calibrated to the FMF'… 7 Autonomous bodies dissolved Dec. 2024 reform folded INAI, IFT,… ~4 years Years R3D warned regulators R3D flagged FAN ID's consent gaps … peopleofinternet.com
Mexico's First Big Data-Protection Fin… People of Internet Research · Mexico MXN 42.8M Fine imposed on FMF 7 Autonomous bodies dissolved ~4 years Years R3D warned regulators peopleofinternet.com

Key Takeaways

On July 12, 2026, Mexico's Secretaría Anticorrupción y Buen Gobierno (SABG) fined the Mexican Football Federation (FMF) MXN 42,849,095 — roughly USD 2.14 million — for mishandling the biometric data collected through its FAN ID stadium-access system. The SABG press release frames it as reaffirming "su compromiso con la protección efectiva de los datos personales." It is also something more specific: the first major enforcement action under Mexico's rebuilt data protection apparatus, and an early signal of how seriously that apparatus intends to be taken.

What the FMF Actually Did Wrong

FAN ID requires fans to submit official identification and a selfie-style photograph, which the system uses to generate a QR code for stadium entry — a response to the March 2022 Querétaro–Atlas violence that killed and injured spectators. The regulator found two specific violations. First, the FMF's privacy notice never disclosed that the facial photographs constituted datos personales sensibles under Mexican law — a categorization that triggers heightened obligations, not an incidental label. Second, the federation obtained authorization through a website checkbox rather than the express written consent Article 8 of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) requires for sensitive data: a signature, electronic signature, or comparable authentication mechanism. A checkbox is not that. The fine amount, per SABG, reflected the severity of the infractions, the sensitivity of biometric data specifically, and the FMF's financial capacity based on its 2024 tax filings.

This is not a novel complaint. R3D (Red en Defensa de los Derechos Digitales) had flagged exactly these two gaps — inadequate consent and insufficient disclosure — as far back as 2022, and separately documented in 2023 that INAI itself redacted 60 pages of its own technical opinion on FAN ID's facial-recognition testing, citing industrial secrecy. The regulator that eventually enforced against opacity had, under its predecessor, once helped shield it.

The Steelman for Enforcement

The case for SABG's action is straightforward and largely correct. Facial recognition data is irreversible in a way a leaked password is not — you cannot rotate your face. A centralized biometric database tied to stadium access, built for a legitimate security purpose, still concentrates risk: a breach exposes fans to identity fraud and tracking that persists for life. Consent-by-checkbox for that category of data is a real compliance failure, not a technicality, and the LFPDPPP's written-consent bar exists precisely because organizations reliably underestimate what sensitive-data handling requires until a regulator makes them pay for it. A publication that argues for proportionate regulation has to concede: this was proportionate. The violation was concrete, the law was clear, and the fine was calibrated to the offender's finances rather than set as a headline-grabbing maximum.

Where the Case for Caution Begins

Where this gets more interesting for anyone tracking Mexican data governance is what the fine does not do. R3D's own analysis makes the point directly: the sanction does not require the FMF to suspend FAN ID, does not mandate deletion or re-consent for biometric data already on file, and comes with no public account of what safeguards now protect that stored data. A fine that corrects the past disclosure failure while leaving the underlying database — and the flawed consent under which it was built — untouched is enforcement theater unless SABG follows up. That follow-through matters more in Mexico's case than most, because SABG is new. It inherited data-protection authority only after the December 2024 constitutional reform that dissolved INAI (along with six other autonomous bodies including the telecom regulator IFT and the antitrust authority Cofece) and folded their functions into the executive branch, formalized when the current LFPDPPP was published in the Diario Oficial de la Federación on March 20, 2025. An oversight function that used to sit at arm's length from government now sits inside it — which is precisely the structure critics of the reform warned would blunt independent enforcement against, say, a national sports federation with obvious political visibility ahead of Mexico's co-hosted 2026 World Cup.

That this fine happened at all is a point in SABG's favor: an executive-branch data authority proved willing to sanction a high-profile domestic institution rather than let the matter quietly lapse. But one enforcement action, without a public remediation order for the millions of biometric records already collected, is a data point, not a track record. The next test — whether SABG requires the FMF to actually fix FAN ID's consent flow before the World Cup, or simply banks the fine and moves on — will say more about the new regime's independence than the July ruling did.

The Broader Signal

For foreign platforms and event organizers operating in Mexico, the practical lesson is narrower than the institutional one: a checkbox is not written consent for biometric data under the LFPDPPP, full stop, and the enforcement gap that let FAN ID operate for three World Cup cycles without a compliant consent flow has closed. Businesses collecting facial or fingerprint data in Mexico should treat Article 8's authentication-mechanism requirement as a hard compliance line, not a best practice. Whether SABG can be trusted to police that line evenhandedly against entities closer to the state than a football federation remains the open question this case leaves unanswered.

Sources & Citations

  1. Infobae — SABG fines the FMF 42.8M pesos over FAN ID data violations
  2. LFPDPPP full text (Diputados)
  3. R3D: Multa a la FMF confirma riesgos advertidos sobre el FAN ID
  4. R3D: INAI y LigaMX ocultan funcionamiento del Fan ID
  5. La República: multa a la FMF por datos biométricos