A Record Fine, and a First
On July 12, 2026, Mexico's Secretaría Anticorrupción y Buen Gobierno (SABG) fined the Federación Mexicana de Fútbol (FMF) 42,849,095 pesos — about $2.14 million — over its FAN ID facial-recognition ticketing system. Per SABG's own press release, the federation committed two infractions: it failed to tell fans that the photographs FAN ID collected constituted sensitive personal data, and it never obtained the express written consent Mexican law requires for processing that category of data — relying instead on a website checkbox with no way to confirm the person clicking it was the actual data subject. SABG also found FMF in breach of the accountability and lawfulness principles, for lacking the governance and documentation a biometric program of this kind demands. The penalty was calculated from the severity of the violations, the sensitivity of biometric data specifically, and FMF's own 2024 tax filing. It is the largest fine SABG has issued since it stood up, and by multiple accounts exceeds anything INAI, its predecessor, ever levied.
A System Regulators Had Already Flagged
FAN ID was not a surprise problem. R3D, Mexico's digital-rights organization, was warning about it as early as 2022, when INAI opened an inquiry into the federation's use of facial recognition in stadiums. R3D's objections tracked the standard case against consumer-facing facial recognition: the technology is error-prone, it performs worse identifying women and people with darker skin, and conditioning stadium entry on handing over biometric data treats an entire fan base as suspects. INAI's commissioner at the time noted that FMF never approached the institute for guidance before rolling the system out. Four years and one dissolved regulator later, the substance of SABG's finding is almost identical to what R3D flagged from the start: FMF built a mandatory biometric intake pipeline and never built the consent architecture to match it.
The Steelman: Biometrics Aren't a Normal Checkbox
Regulators have the better argument on the narrow legal question. Facial biometrics are irreversible in a way a password or even a government ID number is not — you can reissue a passport, you cannot reissue a face. Mexican law classifies biometric data as sensitive precisely because a breach or misuse carries consequences a user cannot undo. FAN ID was also not optional in any meaningful sense: fans who wanted to attend a match had to register, meaning FMF held effective monopoly leverage over anyone who wanted to walk into a stadium it controlled. A checkbox on a signup form, without any mechanism to verify the person clicking it was the data subject, is a thin substitute for meaningful consent in that context — particularly for a system used by minors attending matches with their families. If any deployment of facial recognition warrants a higher consent bar than an ordinary loyalty-app signup, a mandatory stadium-entry system is it.
The Catch: Enforcement Without a Constitution Behind It
What should give pro-innovation observers pause is not the ruling on FAN ID's merits — it is who is doing the ruling, and how they got the job. SABG did not exist as a data-protection authority until this year. Mexico's Senate approved the "Simplificación Orgánica" constitutional reform on November 28, 2024, dissolving seven autonomous constitutional bodies, including INAI, and folded personal-data enforcement into SABG — a cabinet-level anti-corruption secretariat that answers to the executive branch, not an independent body with fixed-term commissioners subject to legislative confirmation. The new legal architecture, the LFPDPPP and LGPDPPSO, took effect March 21, 2025, the same week INAI's powers formally transferred. SABG's own communications describe data protection as "historically sidelined" and now a stated enforcement priority — which is a defensible improvement in stated intent, but it is also exactly the kind of framing an agency uses right before its first big, headline-friendly case.
That is the tension worth naming: a genuinely under-enforced area of law (biometric consent) is now being enforced by a body that traded judicial-style independence for direct executive control, on its very first major action, against a federation whose national reputation gave the case built-in press coverage.
None of that makes the FMF finding wrong on the facts — the consent failure looks real, and R3D's 2022 warnings suggest it was foreseeable. But a regulator with no constitutional insulation from the political branch, opening its enforcement record with the single largest fine in its short history, deserves scrutiny on consistency going forward, not just applause for the headline number. Data-protection enforcement built on due process, published standards, and predictable proportionality is good for innovation, because it lets companies plan around clear rules. Enforcement that looks selective, or that arrives from an agency whose independence has already been publicly debated, invites exactly the kind of regulatory-risk premium that discourages legitimate biometric services — from airport security to fraud prevention — from launching in Mexico at all.
What to Watch
FMF has administrative and judicial remedies available to challenge the resolution, per SABG's own statement, and whether it exercises them will be the next signal. So will SABG's next few cases: if the agency applies the same consent-and-disclosure standard to government biometric programs — voter ID, security-camera networks, state-level facial recognition — with the same rigor it applied to a sports federation, that will do more to establish its legitimacy than any single fine. If FAN ID turns out to be the only target, the record-fine headline will have said more about publicity than about privacy.