New Mexico
New Mexico Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Under the New Mexico Data Breach Notification Act, N.M. Stat. Ann. 57-12C-1 et seq., businesses must notify affected residents within 45 calendar days of discovering a breach. The clock starts on the date of discovery, not the date the breach occurred. The New Mexico Attorney General must also be notified for any breach affecting even one resident.
If your business handles personal information belonging to New Mexico residents, a data breach triggers specific legal obligations under the New Mexico Data Breach Notification Act. N.M. Stat. 57-12C-1 et seq. sets out who must notify, what triggers the duty, and how quickly action is required. New Mexico was one of the later states to adopt a breach notification law, enacting the statute in 2017. However, the law includes modern provisions such as biometric data coverage and a firm 45-day notification deadline.
This guide covers the full scope of New Mexico's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, penalties, exemptions, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With New Mexico's Breach Notification Law
New Mexico's law applies to any person, business, or government agency that owns or licenses personal identifying information of New Mexico residents. The statute uses the term "person" broadly to include corporations, partnerships, LLCs, associations, and other entities.
The law also applies to third-party data processors. When a person or business that maintains data on behalf of another entity discovers a breach, it must notify the data owner within 24 hours of discovery. This 24-hour third-party notification requirement is faster than what most states mandate and ensures the data owner can begin the 45-day notification clock promptly.
Out-of-state businesses that handle personal information of New Mexico residents are subject to the law.
What Qualifies as a Breach
Under N.M. Stat. 57-12C-2, a "security breach" means the unauthorized acquisition of unencrypted computerized data, or encrypted computerized data together with the confidential process or key, that compromises the security, confidentiality, or integrity of personal identifying information maintained by a person.
Good Faith Exception
A good faith acquisition of personal identifying information by an employee or agent of the person for a legitimate business purpose does not constitute a security breach, provided the personal identifying information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Encryption Safe Harbor
New Mexico provides a safe harbor for encrypted data. If the compromised personal identifying information was encrypted and the encryption key or confidential process was not also acquired, notification is not required. If both the encrypted data and the key were compromised, the safe harbor does not apply.
Personal Information That Triggers Notification
New Mexico's definition of personal identifying information is notably broad for a state that enacted its law in 2017. Under N.M. Stat. 57-12C-2, personal identifying information means an individual's first name or first initial and last name combined with one or more of the following:
- Social Security number
- Driver's license number
- Government-issued identification number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the financial account
- Biometric data (fingerprint, voice print, retina or iris image, or other unique biological characteristics used to authenticate a specific individual)
The inclusion of biometric data places New Mexico among the states with more comprehensive protection, recognizing that biometric identifiers cannot be changed once compromised.
Personal identifying information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
The 45-Day Notification Timeline
New Mexico imposes a firm 45-day deadline for breach notification under N.M. Stat. 57-12C-6. Notification must be made no later than 45 calendar days following discovery of the security breach.

The clock starts from the date of discovery, not the date the breach occurred. This distinction matters because breaches are often discovered weeks or months after the initial unauthorized access.
When Delay Is Permitted
Notification may be delayed beyond the 45-day deadline only if:
- A law enforcement agency determines that notification will impede a criminal investigation and requests a delay. Notification must happen promptly after law enforcement determines disclosure no longer compromises the investigation.
- The entity needs time to determine the scope of the breach and restore the reasonable integrity of the data system, though this must still fall within the 45-day window unless a law enforcement delay applies.
The law enforcement exception is the only basis for extending the 45-day deadline. Internal investigation alone is not sufficient justification to exceed it.
Who Must Be Notified
Affected Individuals
Every New Mexico resident whose unencrypted personal identifying information was or is reasonably believed to have been acquired by an unauthorized person must be notified. The notification must include:
- The date, estimated date, or estimated date range of the security breach
- A description of the personal identifying information that was part of the breach
- Contact information for the person or business sending the notice
- Contact information for the consumer reporting agencies
- Advice directing the individual to review account statements, monitor credit reports, and consider placing a security freeze on their credit files
New Mexico Attorney General
The New Mexico Attorney General must be notified of any security breach affecting New Mexico residents. The statute requires AG notification when one or more New Mexico residents are affected, making it one of the broadest AG notification triggers.
The notification to the AG must include:
- A description of the security breach
- The approximate number of New Mexico residents affected
- A copy of the notification provided to individuals
- Steps taken to address the breach
Consumer Reporting Agencies
When a breach affects more than 1,000 New Mexico residents, the entity must also notify the nationwide consumer reporting agencies. The notification must include the timing, distribution, and content of the notification to individuals.
How to Provide Notification
New Mexico permits the following notification methods:
- Written notification sent by mail to the last known address of the individual
- Electronic notification if the entity's primary means of communication with the individual is by electronic means, consistent with the E-SIGN Act ()
- Telephone notification
Substitute Notice
Substitute notice is available when:
- The cost of providing notification would exceed $50,000
- The affected class exceeds 100,000 New Mexico residents
- The entity does not have sufficient contact information
Substitute notice must include all of the following:
- Email notification to individuals for whom the entity has an email address
- Conspicuous posting of the notice on the entity's website
- Notification to major statewide media outlets
New Mexico's substitute notice thresholds ($50,000 cost and 100,000 affected individuals) are moderate, falling between the low thresholds of states like New Hampshire and the high thresholds of states like California.
Enforcement and Penalties
New Mexico's breach notification law is enforced by the New Mexico Attorney General under the Unfair Practices Act (N.M. Stat. 57-12-1 et seq.). A violation of the Data Breach Notification Act constitutes an unfair practice.
The Attorney General may seek:
- Injunctive relief to stop ongoing violations
- Civil penalties as provided under the Unfair Practices Act
- Restitution for affected consumers
There is no private right of action for breach notification violations. Only the Attorney General can bring enforcement actions under the statute. Individuals may pursue common law claims such as negligence, but not under the breach notification law itself.
Exemptions
New Mexico provides significant exemptions for entities that comply with equivalent federal breach notification frameworks:
GLBA-Regulated Financial Institutions
Financial institutions that maintain notification procedures as part of an information security program established under the Gramm-Leach-Bliley Act are exempt from New Mexico's breach notification requirements, provided those procedures are at least as thorough as the state statute.
HIPAA-Covered Entities
Healthcare entities and their business associates that comply with HIPAA's breach notification requirements (as outlined in the HITECH Act) are deemed in compliance with New Mexico's law.
These exemptions are broader than some states provide and fully exclude qualifying entities from the state statute rather than requiring parallel compliance.
Data Security Obligations
Beyond breach notification, New Mexico requires that any person who owns or licenses personal identifying information of New Mexico residents must implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect it from unauthorized access, destruction, use, modification, or disclosure. This general data security mandate applies regardless of whether a breach occurs.
Businesses that collect personal identifying information must also take reasonable steps to destroy or arrange for the destruction of records containing personal identifying information that are no longer needed, by shredding, erasing, or otherwise modifying the information to make it unreadable or indecipherable.
This article provides general legal information about New Mexico data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in New Mexico for guidance specific to your situation.
More New Mexico Laws
Frequently Asked Questions
How long does a business have to notify New Mexico residents of a data breach?
New Mexico law requires notification no later than 45 calendar days after discovery of the breach. The clock starts on the date of discovery, not the date the breach occurred. The only exception to this deadline is if law enforcement requests a delay because notification would impede a criminal investigation. Internal investigation alone is not a basis for exceeding the 45-day deadline.
Does New Mexico require businesses to notify the Attorney General after a data breach?
Yes. The New Mexico Attorney General must be notified of any breach affecting New Mexico residents. The notification must include a description of the breach, the approximate number of affected residents, a copy of the individual notification, and the steps taken to address the breach. Consumer reporting agencies must also be notified when 1,000 or more residents are affected.
Does New Mexico's breach notification law cover biometric data?
Yes. New Mexico includes biometric data in its definition of personal identifying information. This covers fingerprints, voice prints, retina or iris images, and other unique biological characteristics used to authenticate a specific individual. A breach of biometric data combined with a name triggers the full 45-day notification requirement.
Are HIPAA-covered entities exempt from New Mexico's breach notification law?
Yes. Healthcare entities and their business associates that comply with HIPAA's breach notification requirements under the HITECH Act are exempt from New Mexico's Data Breach Notification Act. GLBA-regulated financial institutions with qualifying information security programs are also exempt. These entities follow their respective federal frameworks instead.
Can individuals sue for a breach notification violation in New Mexico?
No. New Mexico's breach notification law does not create a private right of action. Only the Attorney General can enforce the statute under the Unfair Practices Act. Individuals may pursue common law claims such as negligence, but cannot sue directly under the Data Breach Notification Act.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
United States Code Title 15
§ 7001General rule of validityIn forcecited in 17 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Cited in 132 court opinionsMost recently applied by a court: 2026
Leading cases: Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530) · Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144) · Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
New Mexico Statutes Annotated 1978, Chapter 57
§ 57-12-1Short titleIn forcecited in 7 of our articles
Chapter 57, Article 12 NMSA 1978 may be cited as the "Unfair Practices Act".
Official text (excerpt) · as of 2026-07-30 · Read the full section at nmonesource.com
Cited in 239 court opinionsMost recently applied by a court: 2026
Leading cases: Romero v. Philip Morris Inc. (New Mexico Supreme Court 2010, 148 N.M. 713) · Cordova v. World Finance Corp. of NM (New Mexico Supreme Court 2009, 146 N.M. 256) · Quynh Truong v. Allstate Insurance (New Mexico Supreme Court 2010, 147 N.M. 583)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: New Mexico Data Privacy Laws: Breach Notification, AG Enforcement & 2026 Legislation, New Mexico Biometric Privacy Laws: Collection, Consent & Penalties (2026), New Mexico Lemon Law (2026): How to Qualify & Get a Refund
§ 57-12C-1Short titleIn forcecited in 6 of our articles
This act [57-12C-1 to 57-12C-12 NMSA 1978] may be cited as the "Data Breach Notification Act".
Official text (excerpt) · as of 2026-07-30 · Read the full section at nmonesource.com
Cited in 1 court opinionsMost recently applied by a court: 2022
Leading cases: Charlie v. Rehoboth McKinley Christian Health Care Services (District Court, D. New Mexico 2022)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Explore the law
The laws cited above reference these related sections in their own text:
- New Mexico Statutes Annotated 1978, Chapter 57 § 57-12C-12 — State of New Mexico and political subdivisions exempted. view in our statute record · read at the official source
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- N.M. Stat. 57-12C - Data Breach Notification Act(nmonesource.com).gov
- New Mexico Attorney General(nmag.gov).gov
- N.M. Stat. 57-12-1 et seq. (Unfair Practices Act)(nmonesource.com)