USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

New Mexico Privacy & Data Security Laws

Every statute below can apply to a business handling New Mexico residents' data, depending on your revenue, the number of New Mexico consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Data Security & Breach Notification · 1

Varies by state
New Mexico data breach notification law
NM Breach Notification
Verify details

Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

State breach-notification statute (citation pending verification)

On the Horizon — Proposed, Not Yet Law · 1

New Mexico
New Mexico comprehensive privacy bill ("CHISPA")

Would have been one of the strictest state privacy laws nationally: a 15,000-consumer threshold, a ban on geofencing sensitive locations, and a private right of action ($2,500–$7,500 per violation). It died procedurally rather than on the merits, which makes a 2027 reintroduction likely.

Status: Dead for the 2026 session. Introduced Jan 21, 2026 and triple-referred (SCC/SHPAC/SJC); the Senate Health and Public Affairs Committee reported it with a Do Pass recommendation on Feb 5, 2026, but action was then postponed indefinitely and the bill never cleared its remaining referrals before New Mexico's 30-day session adjourned Feb 19, 2026. Re-verified Sep 11, 2026 — nmlegis.gov now records the bill's location simply as "Died".