Skip to content

Data privacy and transparency

Personal data protection and transparency, from the document to the system

A privacy notice protects nothing if the system lets everyone see everything. We bring both sides together: we draft the documents the regulations require and implement the technical measures that make them real in your systems, for companies and public institutions.

Includes

  • Privacy notices and policies
  • Data inventory and security document
  • ARCO rights request handling
  • Transparency and redacted public versions

The challenge

The rules changed in 2025, and many organizations still have old documents

In March 2025, Mexico published a new LFPDPPP (Federal Law on Protection of Personal Data Held by Private Parties), the INAI (the former national transparency and data protection authority) was dissolved and its functions were transferred to other authorities. In the public sector, the general transparency and data protection laws were also overhauled.

Privacy notices that still refer to the INAI, inventories no one keeps up to date, systems where any user can look up CURP (national ID) numbers or phone numbers: these are risks that usually surface only when a complaint or request arrives.

Our approach combines documentation with technology. We review what data you process, where it lives, who sees it and how it's protected, and we deliver both the documents and the changes to your systems.

The solution

What changes in your organization

Here's how personal data is often handled in many organizations today, and how it looks after we work together. You can contract the full package or just the part you need, in coordination with your legal department.

  • Privacy notice

    Today: The notice was written years ago, still refers to the INAI and doesn't describe what the systems actually do.

    With Exylia: Full and short-form notices updated to the 2025 rules, describing what your systems really do.

  • Data inventory

    Today: It's unclear what personal data is processed, which systems hold it or who looks it up.

    With Exylia: An inventory of what data you process, why, where it's stored and who has access, with its risk analysis.

  • Security measures

    Today: Any system user can look up CURP numbers, phone numbers or addresses, and nothing is logged.

    With Exylia: Encrypted sensitive data, role-based permissions and an access log running in your systems.

  • ARCO rights

    Today: Requests arrive by email or on paper, and follow-up depends on someone remembering.

    With Exylia: A procedure and a tool to receive, track and answer every request on time.

  • Transparency

    Today: Public versions are redacted by hand and request deadlines are tracked in scattered spreadsheets.

    With Exylia: Requests, obligations and deadlines under control, with redacted public versions prepared consistently.

  • Audit evidence

    Today: When a complaint or audit arrives, gathering proof of how data is protected takes weeks.

    With Exylia: A security document and organized evidence, ready to show what data you process and how you protect it.

Benefits

Why work with a technical team

Documents that reflect reality

The notice describes what your systems actually do, because we review the systems, not just the paperwork.

Measures implemented, not just described

Encryption, permissions and logs running on your infrastructure, ready to be demonstrated.

Lower risk in complaints and audits

Organized evidence of what data you process and how you protect it.

Trust from customers and citizens

Clearly communicating how you use data is part of your organization's reputation.

Use cases

Use cases

01

Updating to the 2025 rules

Reviewing and updating privacy notices that still refer to the former authority.

02

Security systems with sensitive data

Encryption and access logging for registries of people, vehicles and records.

03

Websites with forms

Privacy notice, consent and safekeeping of data collected online.

04

Transparency units

Tracking public information requests and deadlines, and preparing redacted public versions.

Every project follows the same process: we understand the operation, model it and validate a prototype before we build.

See how we work

Frequently asked questions

Frequently asked questions: Data privacy and transparency

What is a privacy notice and who needs one?

It's the document that tells people what personal data you collect, what you use it for, who you share it with and how they can exercise their rights. In Mexico, any company or institution that processes personal data needs one, including data collected through a website.

Is my privacy notice still valid after the 2025 reform?

It's worth reviewing. The new law changed the competent authority and clarified required content, such as expressly identifying sensitive data and distinguishing the purposes that require consent. A notice that still mentions the INAI should be updated.

What are ARCO rights?

They are individuals' rights to access, rectify, cancel or oppose the processing of their personal data. Your organization must have a procedure to receive these requests and respond within the legal deadlines.

What is the security document?

It's the document that describes the administrative, physical and technical measures you use to protect personal data, based on a data inventory and a risk analysis.

Does this service replace a lawyer?

No. It's a technical and documentation support service. We recommend that your legal department or legal counsel validate the final documents; we're happy to work in coordination with them.

Let's review how you protect the data people trust you with

Schedule an assessment and get a clear report on what you have, what's missing and where to start.