Mexico Mexico LFPDPPP data protection platform

Mexico's First Post-INAI Privacy Fine Targets Consent Mechanics, Not Fan ID's Existence

SABG fined the Mexican Football Federation $42.8M pesos for treating biometric photos as ordinary data — a narrow, defensible ruling that leaves Fan ID's mandatory scope untouched.

Mexico's First Post-INAI Privacy Fine People of Internet Research · Mexico $42.8M pesos Fan ID fine amount SABG's sanction against the Mexica… ~$75M pesos Max sensitive-data fine Ceiling for sensitive personal dat… Mar 21, 2025 New LFPDPPP took effect Date the rewritten data protection… peopleofinternet.com
Mexico's First Post-INAI Privacy Fine People of Internet Research · Mexico $42.8M pesos Fan ID fine amount ~$75M pesos Max sensitive-data f… Mar 21, 2025 New LFPDPPP took effect peopleofinternet.com

Key Takeaways

A checkbox, not a signature

On July 12, 2026, Mexico's Secretaría Anticorrupción y Buen Gobierno (SABG) — the executive-branch body that absorbed data protection enforcement when the autonomous INAI was dissolved in March 2025 — imposed a fine of MXN $42,849,095 on the Mexican Football Federation (FMF) over its handling of Fan ID, the biometric credential system Liga MX has required for stadium entry since 2022. The SABG's press release lays out two infractions: the FMF's privacy notice never disclosed that the photographs it collected to generate Fan ID credentials qualified as sensitive personal data under Mexican law, and the federation obtained consent to process that biometric data through a checkbox on a website — not the express, written, unequivocal consent the statute requires for sensitive categories.

Those are narrow, procedural findings. The SABG did not rule that biometric stadium access is unlawful, disproportionate, or unnecessary. It ruled that the FMF got the paperwork wrong.

Why the paperwork matters

Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), rewritten and republished on March 20, 2025, actually loosened consent requirements for most personal data — the new law generally treats tacit consent as sufficient. But it preserved a firm carve-out for sensitive categories, including biometric identifiers, which still require the higher bar of express, documented, written consent. A website checkbox — indistinguishable from an ordinary cookie banner — cannot satisfy that bar, and the SABG's ruling simply enforces a distinction the legislature already drew. That is proportionate regulation working as designed: it did not treat routine data collection and biometric enrollment as the same risk category, which is precisely the discipline critics of blanket privacy crackdowns usually ask regulators to show.

The steelman: this doesn't touch the underlying system

Privacy advocates have a fair complaint here, and it's worth stating plainly. R3D, the Mexican digital rights group that has challenged Fan ID's opacity since 2022, calls the fine a vindication of warnings it raised years ago — but notes it changes nothing structural. Fan ID remains mandatory for match attendance. The centralized biometric database it feeds still carries, in R3D's words, irreversible breach risk once compromised. Facial recognition systems built on that data still carry documented accuracy gaps that fall hardest on women, transgender people, and people of color. And fan data can still be shared with state and municipal security authorities under the security rationale that justified the system in the first place. A regulator serious about proportionality, this argument goes, would have paired the fine with structural remedies — an independent audit of the database, limits on downstream sharing, or a sunset on retention — rather than treating a nine-figure penalty as the end of the matter.

That critique lands, and this piece shouldn't pretend otherwise. But it's also an argument for a different intervention than the one available to a data protection regulator. The SABG's mandate under the LFPDPPP is to police how personal data is processed, not to second-guess Liga MX's stadium security policy or mandate a particular biometric architecture. Conflating those two would turn a privacy enforcer into a general technology regulator — exactly the kind of scope creep that tends to produce vague, unpredictable compliance obligations rather than fixable violations.

What the number signals

The fine itself is calibrated, not punitive. Ritch Mueller's analysis of the ruling — one of the first public windows into how the post-INAI SABG actually applies the 2025 law — notes that sensitive-data violations can draw fines up to roughly MXN $75 million, meaning the FMF was assessed well under the ceiling despite the sensitivity of biometric data and the scale of Fan ID's user base. That is a deterrent, not an extinction event: enough to force the FMF to rebuild its consent flow, not enough to threaten whether the system operates at all.

The credibility test that actually matters

The more interesting question is what this case says about the SABG itself. Folding data protection enforcement into an executive-branch anticorruption ministry — as the March 2025 LFPDPPP rewrite did, per Greenberg Traurig's summary of the reform — traded INAI's constitutional independence for administrative efficiency, and skeptics questioned whether an executive body would enforce privacy law against powerful private actors with the same rigor an autonomous regulator would. A national football federation, tightly bound to broadcast and sponsorship interests, is as good a test case as any. On the substance, the SABG identified a real, well-documented violation and applied a proportionate remedy rather than an existential one. That's the right instinct for a young enforcement regime to establish early: punish sloppy compliance precisely, and leave the harder proportionality fights — mandatory biometric collection, data-sharing with security agencies — to the legislative and judicial processes built to weigh them.

For companies operating in Mexico, the lesson is narrower and more urgent: any consent flow gating sensitive data behind a checkbox is now a documented liability, and the SABG has shown it will act on exactly that gap.

Sources & Citations

  1. SABG press release — FMF sanction
  2. R3D — Multa a la FMF confirma riesgos advertidos
  3. Ritch Mueller — SABG's approach to data privacy enforcement
  4. Greenberg Traurig — Mexico's new 2025 data protection law