New Mexico: An Overview of Data Protection & Data Privacy Law

Published يوليو 29, 2024

Contributors

Anas Baig

Product Marketing Manager at Securiti

Usman Tariq

Data Privacy Analyst at Securiti

CIPP/US

Data protection laws are built to empower individuals to take better control of their data. These laws further provide individuals with clear privacy rights. Globally, regulatory bodies are recognizing the need for comprehensive data privacy laws. In fact, most countries have either proposed bills or have already established laws.

However, not every country or state in the US has a comprehensive privacy regulation in place. The state of New Mexico is also one such region that has yet to enact a comprehensive law. Although the state has a Privacy Protection Act, it is limited to protecting individuals’ social security numbers. Now, the question remains: What must businesses do in the absence of a comprehensive privacy bill or law?

The following guide aims to inform businesses about the current state of privacy laws in New Mexico and clarify how to ensure compliance.

Current State of Privacy Laws in New Mexico

Privacy Protection Act

The law is applicable to commercial businesses that sell, lease, or intend to sell or lease products or services to consumers. The definition further includes an agent of a business or an agent of a non-profit organization that promotes services to that organization.

The Privacy Act prohibits businesses from requiring customers to provide their social security number as a condition to lease or purchase a product or service. Businesses may only acquire or use a social security number if the consumer consents to its acquisition or use. The law requires businesses to develop internal policies for the protection of consumers’ social security numbers, such as limiting access to the social security number to authorized individuals only or holding personnel responsible for releasing the information to an unauthorized person.

The act further provides a comprehensive set of provisions restricting businesses from using social security numbers in certain situations. For instance, businesses cannot make social security numbers available to the public, require their use over the Internet without a secure connection, or refuse to transact business because of the refusal to provide the number.

Apart from the Privacy Protection Act, New Mexico further has a Data Breach Notification law. The law dictates organizations notify the concerned regulatory authorities and impacted individuals regarding the security breach. It further governs businesses to remove any personally identifiable information (PII) if it has served its business purpose and is no longer needed. Businesses must also implement robust security measures appropriate to the nature of the PII to protect it against unauthorized access, abuse, or destruction of data.

Despite the absence of a comprehensive privacy law, businesses operating in the state of New Mexico must familiarize themselves with any sectoral and federal regulations. Non-compliance with those regulations may result in legal consequences.

Share

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox

Videos

Spotlight Talks

Latest

View More

From Trial to Trusted: Securely Scaling Microsoft Copilot in the Enterprise

AI copilots and agents embedded in SaaS are rapidly reshaping how enterprises work. Business leaders and IT teams see them as a gateway to...

The ROI of Safe Enterprise AI View More

The ROI of Safe Enterprise AI: A Business Leader’s Guide

The fundamental truth of today’s competitive landscape is that businesses harnessing data through AI will outperform those that don’t. Especially with 90% of enterprise...

Understanding Data Regulations in Australia’s Telecom Sector View More

Understanding Data Regulations in Australia’s Telecom Sector

1. Introduction Australia’s telecommunications sector plays a crucial role in connecting millions of people. However, with this connectivity comes the responsibility of safeguarding vast...

Data Security Governance View More

Data Security Governance: Key Principles and Best Practices for Protection

Learn about Data Security Governance, its importance in protecting sensitive data, ensuring compliance, and managing risks. Best practices for securing data.

ROPA View More

Records of Processing Activities (RoPA): A Cross-Jurisdictional Analysis

Download the whitepaper to gain a cross-jurisdictional analysis of records of processing activities (RoPA). Learn what RoPA is, why organizations should maintain it, and...

Managing Privacy Risks in Large Language Models (LLMs) View More

Managing Privacy Risks in Large Language Models (LLMs)

Download the whitepaper to learn how to manage privacy risks in large language models (LLMs). Gain comprehensive insights to avoid violations.

Comparison of RoPA Field Requirements Across Jurisdictions View More

Comparison of RoPA Field Requirements Across Jurisdictions

Download the infographic to compare Records of Processing Activities (RoPA) field requirements across jurisdictions. Learn its importance, penalties, and how to navigate RoPA.

Navigating Kenya’s Data Protection Act View More

Navigating Kenya’s Data Protection Act: What Organizations Need To Know

Download the infographic to discover key details about navigating Kenya’s Data Protection Act and simplify your compliance journey.

Gencore AI and Amazon Bedrock View More

Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock

Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...

DSPM Vendor Due Diligence View More

DSPM Vendor Due Diligence

DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...

What's
New