New Mexico

New Mexico Privacy Law

New Mexico was the last state in the country to enact a breach-notification statute, and the Data Breach Notification Act it passed in 2017 is unusually specific about both the clock and the contents of the notice: forty-five calendar days, seven mandatory items, and biometric data counted as identifying information from the start. What the state does not have is a general consumer-privacy statute, and the gap matters more here than in most states because New Mexico’s Unfair Practices Act reaches only conduct connected to “the sale, lease, rental or loan” of goods or services. A federal court applied that limit to dismiss the Attorney General’s own children’s-privacy claims against Google twice, and a 2025 bill written to remove it died in committee. The state’s oldest privacy statute is narrower and stronger than either: the Genetic Information Privacy Act of 1998 requires written informed consent before genetic analysis and gives the individual a damages claim.

Sector-Specific Privacy Laws in New Mexico

Data Breach Notification Act (2017 N.M. Laws ch. 36)

House Bill 15 of the 2017 session created the Act and did four things at once. Sections 3 and 4 require a person that owns or licenses records containing personal identifying information of a New Mexico resident to arrange proper disposal by shredding, erasing or otherwise rendering the information undecipherable, and to implement and maintain reasonable security procedures appropriate to the nature of the information. Section 5 goes further than most breach statutes by reaching contracts: a person disclosing personal identifying information to a service provider is required by the Act to impose the same reasonable-security obligation on that provider by contract. Section 6 sets the notification duty and its outer limit of forty-five calendar days from discovery, and Section 7 lists the seven items a notice must carry — the notifying person’s name and contact information, the types of information involved, the date or date range of the breach, a general description of the incident, the toll-free numbers and addresses of the major consumer reporting agencies, advice to review account statements and credit reports, and advice about rights under the federal Fair Credit Reporting Act. Section 8 exempts persons subject to the federal Gramm-Leach-Bliley Act or HIPAA from the Act entirely, and Section 12 provides that nothing in the Act applies to the State of New Mexico or its political subdivisions.

Genetic Information Privacy Act (1998 N.M. Laws ch. 227)

Enacted nineteen years before the breach statute, this Act is the state’s most protective privacy law and the only one giving an individual a direct claim. Section 3 prohibits obtaining genetic information or samples for genetic analysis without first obtaining informed and written consent, and separately prohibits the analysis, collection, retention, transmission or use of genetic information without that consent, subject to ten enumerated exceptions covering criminal investigation, felon databases, identifying the deceased, parentage, newborn screening, de-identified data, court determinations of damages under the Act, medical repositories and registries, research and education where identity is not disclosed, and emergency medical treatment. Section 5 requires that genetic information or samples be destroyed promptly on the person’s request unless retention falls within four listed grounds, and subsection D preserves a religious objection even against those grounds. Section 4 prohibits insurer discrimination on the basis of genetic analysis, genetic information or genetic propensity, and bars a health insurer from treating a genetic propensity, susceptibility or carrier status as a pre-existing condition. Under Section 6 the Attorney General or a district attorney may bring a civil action, a person whose rights were violated may bring one, and the court may award actual damages plus up to $5,000 more where the violation results from willful or grossly negligent conduct, together with attorney fees and costs.

Unfair Practices Act (NMSA 1978, ch. 57, art. 12)

Section 57-12-3 declares unfair or deceptive trade practices and unconscionable trade practices in the conduct of any trade unlawful, and Section 57-12-11 lets the Attorney General, on petition in an action brought under Section 57-12-8, recover a civil penalty of up to $5,000 per violation where the court finds the practice was used willfully. The Act’s reach is narrower than the breadth of that language suggests. Section 57-12-2 defines an unfair or deceptive trade practice as a knowing misrepresentation made “in connection with the sale, lease, rental or loan of goods or services or in the extension of credit or in the collection of debts”, and defines an unconscionable trade practice by reference to the same list of transactions. House Bill 61 of the 2025 session, introduced by Representatives Chandler, Silva and Anyanonu, would have struck that transaction list from both definitions, substituted a general “regular course of the person’s trade or commerce” standard, and raised the civil penalty to $10,000 per violation with $25,000 available where the practice arises out of a declared disaster or state of emergency. It was reported with a Do Pass recommendation from the House Judiciary Committee on March 6, 2025 and then postponed indefinitely, so the transaction list and the $5,000 ceiling both remain the law.

Data Breach Notification in New Mexico

Section 6 of the Data Breach Notification Act requires notification to each New Mexico resident whose personal identifying information is reasonably believed to have been subject to a security breach, in the most expedient time possible but not later than forty-five calendar days following discovery. Subsection B supplies a harm exception: notification is not required if, after an appropriate investigation, the person determines that the breach does not give rise to a significant risk of identity theft or fraud. Section 2 defines personal identifying information as a first name or initial and last name combined with a Social Security number, driver’s license number, government-issued identification number, a financial account or card number with the code that would permit access, or biometric data — and defines biometric data as a record generated by automatic measurements of fingerprints, voice print, iris or retina patterns, facial characteristics or hand geometry used to authenticate identity durably. Substitute notice becomes available under Section 6(D)(3) where the cost of notice would exceed $100,000, the number of residents to be notified exceeds 50,000, or the person lacks a physical address or sufficient contact information. Section 10 adds the Attorney General and the nationwide consumer reporting agencies at the 1,000-resident mark, on the same forty-five-day outer limit, and requires the notifying person to tell the Attorney General how many residents were notified and to supply a copy of the notice. Section 11 lets the Attorney General sue on behalf of individuals in the name of the state for an injunction and damages for actual costs or losses including consequential financial losses, and where the court finds the violation was knowing or reckless it may impose a civil penalty of the greater of $25,000 or $10 per instance of failed notification capped at $150,000.

Residents must be notified in the most expedient time possible, but not later than 45 calendar days following discovery of the security breach. Notify the Office of the Attorney General and the nationwide consumer reporting agencies when more than 1,000 New Mexico residents are notified for a single breach. Complaints are taken by the New Mexico Attorney General, which enforces the statute.

How New Mexico Enforces Its Privacy Laws

The Attorney General sues in the name of the state. Section 11 of the Data Breach Notification Act gives enforcement to the Attorney General alone and conditions it on a reasonable belief that a violation has occurred. The action is brought on behalf of individuals and in the name of the state, and the relief available is an injunction, damages for actual costs or losses including consequential financial losses, and, on a finding of knowing or reckless violation, the civil penalty in subsection C. The Act creates no private right of action for a failure to notify.

Investigative demands run through the Unfair Practices Act. Where conduct is reached by the Unfair Practices Act, Section 57-12-8 supplies the injunction action and Section 57-12-11 the civil penalty of up to $5,000 per willful violation, recoverable by the Attorney General on petition to the court. Because the Act’s definitions in Section 57-12-2 tie both unfair-or-deceptive and unconscionable practices to the sale, lease, rental or loan of goods or services, the availability of that route in a privacy case turns on whether the residents involved paid for anything.

Recent Enforcement in New Mexico

State ex rel. Balderas v. Tiny Lab Productions — children’s app tracking, D.N.M. No. 1:18-cv-00854. The Attorney General filed suit on September 11, 2018 against a Lithuanian developer of child-directed mobile games and the advertising networks whose software development kits were embedded in them, including Google, AdMob, Twitter, MoPub, AerServ, InMobi, AppLovin and ironSource. The complaint pleaded a federal COPPA count, two counts under the Unfair Practices Act and a common-law intrusion-on-seclusion count. In a thirty-nine-page memorandum opinion issued April 29, 2020, the court dismissed the COPPA count against the six network defendants other than Google for failure to allege actual knowledge that the apps were child-directed, and held their state-law claims preempted as a result. Google’s position was different: the court found actual knowledge adequately alleged and let the COPPA claim proceed, dismissed both Unfair Practices Act counts with prejudice because no New Mexico user had purchased anything, and allowed the intrusion-on-seclusion claim to go forward, describing the question of whether a commercial entity that secretly harvests personal information commits a highly offensive act as one the court could not resolve as a matter of law. The docket records termination on December 14, 2021.

State ex rel. Balderas v. Google LLC — student data in G Suite for Education, D.N.M. No. 1:20-cv-00143. The Attorney General filed a second children’s-privacy suit on February 20, 2020, alleging that Google used G Suite for Education to monitor New Mexico students’ online activity for commercial purposes without notice to parents and without obtaining parental consent, in violation of COPPA, the Unfair Practices Act and New Mexico common law, and seeking injunctive relief, civil penalties, fees and costs. On September 25, 2020 Judge Nancy D. Freudenthal granted Google’s motion to dismiss, holding that the complaint failed to state a COPPA claim on the theory that Google could not rely on schools to act as parents’ agents in the notice-and-consent process, and that the allegations of inadequate notice and lack of authorization also failed. Having dismissed the federal claim, the court declined to exercise supplemental jurisdiction over the Unfair Practices Act and common-law claims and dismissed them without prejudice. The state was given until October 13, 2020 to amend; the docket shows the case terminated on October 29, 2020 and a notice of appeal filed in December.

Pending Privacy Legislation

Four privacy bills were introduced in the 2026 second session and none was enacted. House Bill 214, the Consumer Information and Data Protection Act, was sponsored by Representatives Serrato, Hernandez, Gonzales, Gallegos and Dow and would have created access, correction, deletion and opt-out rights with biometric data defined to exclude photographs and recordings unless generated to identify a specific individual; it was not printed and was referred to the House Regulatory Committee on January 29, 2026. Senate Bill 192, the Data Broker Privacy Act, sponsored by Senator Cervantes, would have required data brokers to register with the Economic Development Department, disclose whether they collect minors’ information or precise geolocation data, and fund an accessible deletion mechanism; it went to three Senate committees on January 29, 2026. House Bill 28, the Artificial Intelligence Transparency Act, sponsored by Representative Chandler, was not printed. Senate Bill 53, the Community and Health Information Safety and Privacy Act, got the furthest, clearing the Senate Health and Public Affairs Committee as germane and receiving a Do Pass from the Senate Judiciary Committee. Separately, House Bill 61 of 2025 would have removed the transaction limit from the Unfair Practices Act and raised its civil penalty; it too was postponed indefinitely.

Federal Privacy Laws That Apply in New Mexico

Federal privacy law applies in New Mexico by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Unfair Practices Act (NMSA 1978, ch. 57, art. 12), which the New Mexico Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach New Mexico Businesses

With no comprehensive state statute, most privacy obligations on a New Mexico business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach New Mexico businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while New Mexico itself has none, and any business holding personal information about New Mexico residents is subject to the state’s breach-notification statute described above.

New Mexico Privacy Law FAQ

How long does a business have to notify New Mexico residents of a data breach?
Section 6(A) of the Data Breach Notification Act sets an outer limit of forty-five calendar days following discovery of the security breach, within a general standard of the most expedient time possible. Section 9 allows that period to be extended where a law enforcement agency determines notification will impede a criminal investigation, or as necessary to determine the scope of the breach and restore the integrity, security and confidentiality of the data system.
Does New Mexico’s breach statute cover biometric data?
Yes, and it did so from enactment in 2017. Section 2(C)(1)(e) lists biometric data among the elements that make information “personal identifying information” when combined with a name, and Section 2(A) defines it as a record generated by automatic measurements of an identified individual’s fingerprints, voice print, iris or retina patterns, facial characteristics or hand geometry that is used to uniquely and durably authenticate identity when the individual accesses a physical location, device, system or account.
Are banks and health care providers covered by the New Mexico breach law?
Section 8 exempts them outright rather than deeming them compliant. It provides that the Act “shall not apply to a person subject to the federal Gramm-Leach-Bliley Act or the federal Health Insurance Portability and Accountability Act of 1996”. That is a broader carve-out than the compliance-deemed approach used in most states, where the entity remains within the statute and satisfies it by following the federal regime.
Why did the New Mexico Attorney General’s claims against Google under the Unfair Practices Act fail?
Because of what the Act requires a practice to be connected to. In the April 29, 2020 memorandum opinion in State ex rel. Balderas v. Tiny Lab Productions, No. 18-854 (D.N.M.), Judge Martha Vázquez held that the UPA requires a misrepresentation made “in connection with the sale, lease, rental, or loan of any goods or services”, that the apps at issue were free to download, and that under the New Mexico Court of Appeals decision in Vigil v. Taintor the Act does not reach claimants who did not purchase anything. Both UPA counts against Google were dismissed with prejudice on that ground, while the COPPA claim and a common-law intrusion-on-seclusion claim survived.
Does New Mexico give individuals a private claim over the misuse of their genetic information?
Section 6 of the Genetic Information Privacy Act provides that a person whose rights under the Act have been violated may bring a civil action for damages or other relief. The court may order actual damages, damages of up to $5,000 in addition to any economic loss where the violation results from willful or grossly negligent conduct, reasonable attorney fees and court costs, and, against an insurer that violated the consent or non-discrimination sections, may direct the insurer to provide coverage on the terms that would have applied had the violation not occurred.
Does the New Mexico breach statute apply to state and local government?
No. Section 12 states that nothing in the Data Breach Notification Act shall be interpreted to apply to the State of New Mexico or any of its political subdivisions. The exemption was written into the bill as enacted and appears in the Act’s title, which recites that it exempts New Mexico and its political subdivisions from compliance.
What penalties can the New Mexico Attorney General seek for a failure to notify?
Section 11 provides for an injunction and an award of damages for actual costs or losses, including consequential financial losses. Where the court determines that a person violated the Act knowingly or recklessly, it may impose a civil penalty of the greater of $25,000, or $10 per instance of failed notification up to a maximum of $150,000. The Attorney General brings the action on behalf of individuals and in the name of the state.

Sources

This guide describes what these documents say. Follow them to check the description against the source.

  1. Data Breach Notification Act — House Bill 15, 2017 regular session, final version statute
  2. Genetic Information Privacy Act — House Bill 331, 1998 regular session, final version statute
  3. House Bill 61 (2025) — Unfair Practices Act definitions and civil penalty legislation
  4. House Bill 61 (2025) — legislative actions legislation
  5. House Bill 214 (2026) — Consumer Information and Data Protection Act legislation
  6. House Bill 214 (2026) — legislative actions legislation
  7. Senate Bill 192 (2026) — Data Broker Privacy Act legislation
  8. Senate Bill 192 (2026) — legislative actions legislation
  9. House Bill 28 (2026) — Artificial Intelligence Transparency Act, legislative actions legislation
  10. Senate Bill 53 (2026) — Community and Health Information Safety and Privacy Act, legislative actions legislation
  11. State ex rel. Balderas v. Tiny Lab Productions — memorandum opinion on the motions to dismiss (D.N.M. Apr. 29, 2020) decision
  12. State ex rel. Balderas v. Tiny Lab Productions — docket, D.N.M. No. 1:18-cv-00854 docket
  13. State ex rel. Balderas v. Google LLC — order on Google’s motion to dismiss (D.N.M. Sept. 25, 2020) decision
  14. State ex rel. Balderas v. Google LLC — docket, D.N.M. No. 1:20-cv-00143 docket
  15. 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
  16. 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
  17. 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
  18. 15 U.S.C. 1681 — Fair Credit Reporting Act statute
  19. 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
  20. Section 5 of the FTC Act, 15 U.S.C. 45 statute

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.