Skip to content

Logistics and distribution

Cross-border Mexico shipments: privacy rules for logistics records

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Mexico's private-sector data protection law may apply to logistics records created in Mexican operations, including driver details in transport documents, customs correspondence, GPS traces and consignee contacts. Before licensing cross-border records, map which entity created each record and where it was processed, separate the personal data, and have Mexican counsel review notices, consent and transfers.

Key takeaways

  • Cross-border freight records often carry personal data about drivers, customs contacts and receivers even when the shipment is purely commercial.
  • Mexico's private-sector law centers on a privacy notice, consent rules and individuals' rights of access, rectification, cancellation and opposition, known as ARCO rights.
  • Mexico recently replaced its private-sector data protection law and reorganized oversight, so older summaries, templates and contract language may describe outdated rules.
  • Which law applies depends on the entity that collected a record and where it was processed, and counsel decides that deal by deal.
  • Lane, equipment, crossing delay and exception fields can often be separated from personal data and reviewed on their own.

Which cross-border records contain personal data?#

Cross-border shipment records contain personal data wherever a person is named, pictured, located or reachable, which in Mexico freight is more often than general counsel expect. A northbound load can generate an electronic invoice with transport details, a customs entry, a transfer move across the bridge, GPS traces from two carriers and a signed delivery receipt in the United States.

The table below lists the record families that most often hold personal data. Many of them live outside the TMS, in shared mailboxes, document folders and messaging apps used by dispatch teams on both sides of the border.

Which cross-border records contain personal data?
RecordUsual sourcePersonal data it can carry
Carta Porte complement to electronic invoicesMexican carrier or your Mexican entityDriver names, license numbers, tax identifiers, vehicle plates
Customs entries (pedimentos) and broker correspondenceMexican and US customs brokersContact names, signatures, importer representative details
Transfer and drayage movesBorder transfer carriersDriver names, phone numbers, gate-in and gate-out times
GPS and ELD tracesTelematics on Mexican and US equipmentLocation trails that reveal a driver's routine
Delivery appointments and receiptsReceivers and consignee docksReceiver names, signatures, direct phone numbers
Dispatch chats and email threadsOperations teams on both sidesPersonal phones, photos of IDs and documents, voice notes

What does Mexico's private-sector privacy law generally require?#

Mexico's private-sector data protection law generally requires a company that decides how personal data is used to give individuals a privacy notice, process data only for the purposes described, meet consent rules that vary with the type of data, protect it with security measures and honor ARCO rights. Transfers of personal data to third parties are generally addressed in the notice and can require consent, subject to exceptions.

Mexico recently replaced its private-sector data protection statute with a new law and moved oversight away from the former independent data protection authority. Older guides, vendor templates and even some current contracts may still cite the previous statute or regulator, so Mexican counsel should confirm the current text, the authority now responsible and any implementing rules before a review is finalized.

Sensitive personal data needs extra care. Health details, such as a driver's medical fitness results or drug test outcomes, are treated as sensitive under Mexican law and face stricter consent rules, so they should be excluded from any package rather than cleaned.

The practical point for licensing is purpose. A privacy notice written for transport, invoicing and customs compliance may not describe licensing records to an AI developer. Whether a new purpose needs fresh notice, consent or simply exclusion of the personal data is a question counsel answers for each record family.

Does Mexican law reach records your US company holds?#

Mexican law may reach records your US company holds when a Mexican entity collected them, when processing happened in Mexico, or when your company processes data on behalf of a Mexican controller. A US brokerage that never operated in Mexico can still hold Mexican driver details sent by a partner carrier, and those details may come with obligations attached.

US privacy laws may apply to the same package for different people, such as US receivers, employees or contacts. The safest working assumption is that both regimes are in play until counsel narrows it.

Does Mexican law reach records your US company holds?
ScenarioQuestions for counsel
Your Mexican subsidiary dispatches Mexican driversDoes its notice cover secondary uses, and how was data transferred to the US parent?
A Mexican partner carrier sends driver and unit details to your US brokerageWho is the controller, and does the partner agreement allow onward use?
Your US team keeps years of customs broker emailAre the contacts business contact data, and what confidentiality terms apply?
Receivers in Mexico sign delivery receipts that you scanCan signatures and names be removed, or should the images be excluded?
Your telematics vendor stores traces for equipment running in MexicoWhere is the data processed, and what do the vendor terms allow?

Which review steps come before licensing cross-border records?#

The review steps for cross-border records follow the same order every time: map, read, separate, confirm and document. Skipping the mapping step is the most common mistake, because records from Mexican and US entities end up mixed in one export with no way to apply different rules to each.

  • Map each record family to the entity that created it and the country where it was stored and processed.
  • Collect the privacy notices your Mexican entity or partners gave drivers, employees and customer contacts, and note the purposes and transfers they describe.
  • Read partner carrier, customs broker and customer contracts for confidentiality and data use terms.
  • Separate personal fields from operational fields and decide, field by field, whether to remove, generalize or exclude.
  • Exclude images of IDs, licenses, signatures and handwritten documents unless counsel clears a narrow use.
  • Ask Mexican counsel to confirm which law and authority currently apply and whether any notice or consent step is needed.
  • Record the conclusion and its basis so the release authorization can point to it.

Which operational fields usually survive review?#

Operational fields that describe the freight and the process, rather than the people, usually survive review once identifiers are removed. Lanes at city or state level, the port of entry, equipment type, commodity class, crossing wait and dwell durations, and exception codes such as missing paperwork, secondary inspection or seal mismatch are typical examples.

Resolution notes are often the most valuable records and the most delicate. A note explaining how a dispatcher cleared a document mismatch with a customs broker teaches an AI team how cross-border exceptions get solved, but the note often names the broker's agent and the driver. Cleaning those notes is slower than dropping them, and usually worth it.

Many cross-border records are in Spanish or mix both languages. Buyers differ on whether that is an advantage, so language mix should be stated in the fit check and confirmed with a buyer rather than assumed either way.

Illustrative: a brokerage with a Monterrey subsidiary#

Illustrative: a fictional US freight brokerage runs a McLeod TMS in Texas and owns a small Monterrey subsidiary that issues electronic invoices with Carta Porte details for Mexican legs. Dispatchers on both sides coordinate transfer drivers through messaging groups, and customs broker emails sit in a shared mailbox going back many years.

Counsel maps the records and finds three groups: US-side load and exception records, the subsidiary's invoices and transport documents, and the messaging exports. The brokerage decides to license US-side exception records and crossing durations with names and phone numbers removed. It excludes the invoice files, all messaging exports and every scanned receipt, and holds the subsidiary's other records until Mexican counsel confirms whether the subsidiary's privacy notice covers the use.

The package is smaller than first imagined but clean. The subsidiary also updates its privacy notice for future records, so the question is simpler next time.

How SourceX handles cross-border records#

SourceX treats each supplier entity separately in the Rights step of the SourceX five-step transaction, so a US parent and a Mexican subsidiary each get their own review and signer. Nothing is shared during the initial fit check, which asks only about systems, years of history, record families and known restrictions.

For any package that proceeds, the SourceX Evidence Packet records which jurisdictions counsel reviewed, which fields were removed or generalized and who authorized release, so the supplier and the buyer hold the same written record.

Frequently asked questions

Are contacts at Mexican business customers personal data?

Often, yes. The name, email and phone number of an individual at a customer can be personal data even in a business setting, and whether any business contact treatment applies is a question for Mexican counsel. The practical default is to remove those fields, since they rarely add value to a licensed package.

Do we need consent from every driver in our Mexican records?

Not necessarily. The answer depends on what the original privacy notice said, the type of data and whether personal data remains after preparation. Removing driver identifiers and excluding document images often avoids the question entirely, but counsel should confirm the approach before release.

Does removing names make the records anonymous?

Not always. GPS traces, rare lanes, unit numbers and dates can point back to a specific driver even without a name. Treat location and timing as identifying until they are coarsened, and have counsel confirm whether the prepared records still count as personal data under each law that may apply.

What about records our customs broker holds about our shipments?

Records the broker keeps in its own systems are the broker's to manage, and you cannot license them. Your own copies of correspondence and entries may be reviewable, but broker contracts and confidentiality terms can restrict them, so read those agreements first.

Does the new Mexican law change what we need to do?

It changes where to look more than the basic approach. Privacy notices, consent and ARCO rights remain central, but definitions, procedures and the authority responsible should be checked against the current text. Update notice templates and contract references that still cite the old statute, and ask Mexican counsel to confirm any transition rules.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify