{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/new-mexico",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-mexico.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-mexico",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-mexico/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/new-mexico/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "new-mexico",
    "frontmatter": {
      "title": "New Mexico Consumer Privacy Law",
      "description": "New Mexico has no comprehensive consumer-privacy statute — the 2026 omnibus bill died despite aggregator claims it was enacted. The operative framework is the Data Breach Notification Act (NMSA 1978, §§ 57-12C-1 to -12), the Unfair Practices Act, and the federal overlay.",
      "state": "New Mexico",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Data Breach Notification Act, NMSA 1978, §§ 57-12C-1 to -12, plus the Unfair Practices Act, NMSA 1978, §§ 57-12-1 to -26 — New Mexico has no comprehensive consumer-privacy statute",
        "appliesTo": "Any person that owns or licenses personal identifying information of New Mexico residents — no revenue or volume threshold; persons subject to GLBA or HIPAA are exempt from the breach act entirely",
        "privacyPolicyRequired": "No New Mexico statute mandates a consumer privacy policy or fixes its contents; what you publish is policed by FTC Act § 5 and the Unfair Practices Act, so a knowing policy misstatement tied to a covered transaction can create private exposure if a person loses money or property",
        "privateRightOfAction": "Not under the Data Breach Notification Act — enforcement is Attorney General-only; but the Unfair Practices Act gives a private action to a person who loses money or property from an unlawful practice, with a $100 statutory floor, possible treble damages for willful conduct, mandatory fee-shifting, and class actions",
        "regulator": "New Mexico Attorney General (New Mexico Department of Justice)",
        "bottomLine": "New Mexico has not enacted a comprehensive consumer-privacy law — the Consumer Information and Data Protection Act (HB 214) died in the 2026 session, and aggregator pages reporting a July 1, 2026 effective date are describing a dead bill. What governs today is the Data Breach Notification Act (45-day breach notice, reasonable-security, disposal, and vendor-contract duties) plus the Unfair Practices Act, which can create private damages exposure when a covered privacy-policy or breach-response misstatement causes money or property loss.",
        "lawCoverage": "baseline",
        "policyMandate": "none",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "none",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "New Mexico consumer privacy law",
        "New Mexico Data Breach Notification Act 57-12C",
        "New Mexico HB 214 Consumer Information and Data Protection Act",
        "New Mexico no comprehensive privacy law",
        "New Mexico privacy policy requirements",
        "New Mexico data breach notification 45 days",
        "New Mexico Unfair Practices Act privacy lawsuit",
        "New Mexico service provider data security contract",
        "New Mexico Attorney General privacy enforcement",
        "New Mexico privacy private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in New Mexico?",
        "heading": "Which privacy laws apply to your business in New Mexico?",
        "answerText": "There is no comprehensive New Mexico consumer-privacy law. The operative state statute is the Data Breach Notification Act, which applies to any person that owns or licenses personal identifying information of New Mexico residents — with no revenue or consumer-volume threshold — and imposes reasonable-security, disposal, vendor-contract, and breach-notification duties. Alongside it sits the Unfair Practices Act, the state's general consumer-protection statute, which makes unfair or deceptive and unconscionable trade practices unlawful and can reach data-practices misstatements tied to covered trade or commerce. One unusual carve-out matters at the threshold: the breach act appears not to apply to a person subject to the federal Gramm-Leach-Bliley Act or HIPAA, but mixed lines of business should confirm coverage before treating the entire operation as outside the act.",
        "sources": [
          {
            "id": "q1-dbna-security-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-4",
            "citation": "NMSA 1978, § 57-12C-4.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Data Breach Notification Act applies to any person that owns or licenses personal identifying information of a New Mexico resident, with no size threshold, and requires reasonable security procedures and practices.",
            "verbatimQuote": "A person that owns or licenses personal identifying information of a New Mexico resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal identifying information from unauthorized access, destruction, use, modification or disclosure.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-dbna-security-duty"
          },
          {
            "id": "q1-dbna-disposal-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-3",
            "citation": "NMSA 1978, § 57-12C-3.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A person that owns or licenses records containing personal identifying information of a New Mexico resident must arrange for proper disposal when the records are no longer reasonably needed for business purposes.",
            "verbatimQuote": "A person that owns or licenses records containing personal identifying information of a New Mexico resident shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-dbna-disposal-duty"
          },
          {
            "id": "q1-dbna-vendor-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-5",
            "citation": "NMSA 1978, § 57-12C-5.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A person that discloses personal identifying information of a New Mexico resident to a service provider under contract must require the service provider by contract to maintain reasonable security procedures and practices.",
            "verbatimQuote": "A person that discloses personal identifying information of a New Mexico resident pursuant to a contract with a service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices appropriate to the nature of the personal identifying information and to protect it from unauthorized access, destruction, use, modification or disclosure.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-dbna-vendor-duty"
          },
          {
            "id": "q1-dbna-notice-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-6(A)",
            "citation": "NMSA 1978, § 57-12C-6(A).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A person that owns or licenses elements including personal identifying information of a New Mexico resident must notify each affected resident of a security breach in the most expedient time possible and no later than 45 calendar days after discovery.",
            "verbatimQuote": "Except as provided in Subsection C of this section, a person that owns or licenses elements that include personal identifying information of a New Mexico resident shall provide notification to each New Mexico resident whose personal identifying information is reasonably believed to have been subject to a security breach. Notification shall be made in the most expedient time possible, but not later than fortyfive calendar days following discovery of the security breach, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-dbna-notice-duty"
          },
          {
            "id": "q1-upa-prohibition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-3",
            "citation": "NMSA 1978, § 57-12-3.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Unfair Practices Act declares unfair or deceptive trade practices and unconscionable trade practices unlawful in any trade or commerce, making it the general-purpose hook for privacy misrepresentation.",
            "verbatimQuote": "Unfair or deceptive trade practices and unconscionable trade practices in the conduct of any trade or commerce are unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-upa-prohibition"
          },
          {
            "id": "q1-dbna-exemptions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-8",
            "citation": "NMSA 1978, § 57-12C-8.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Data Breach Notification Act states that it does not apply to a person subject to GLBA or HIPAA; because the text is phrased by person, mixed lines of business should confirm federal-regime coverage before treating the whole operation as exempt.",
            "verbatimQuote": "The provisions of the Data Breach Notification Act shall not apply to a person subject to the federal Gramm-Leach-Bliley Act or the federal Health Insurance Portability and Accountability Act of 1996.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-dbna-exemptions"
          },
          {
            "id": "q1-hb214-status",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "New Mexico Legislature HB 214 (2026 Regular Session)",
            "citation": "New Mexico Legislature, HB 214 (2026 Regular Session).",
            "url": "https://www.nmlegis.gov/Legislation/Legislation?chamber=H&legType=B&legNo=214&year=26",
            "proposition": "The Legislature's own HB 214 page identifies the 2026 Consumer Information and Data Protection Act bill as Died (API.) and Action Postponed Indefinitely.",
            "verbatimQuote": "Current Location Died (API.)",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-hb214-status"
          },
          {
            "id": "q1-hb214-effective-dates",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HB 214 (2026), § 16",
            "citation": "HB 214 (2026), § 16.",
            "url": "https://www.nmlegis.gov/Sessions/26%20Regular/bills/house/HB0214.HTML",
            "proposition": "The July 1, 2026 date appears in the effective-date clause of the dead HB 214 bill text, not in an enacted law.",
            "verbatimQuote": "SECTION 16. EFFECTIVE DATES.-- A. The effective date of the provisions of Sections 1, 2 and 13 through 15 of this act is July 1, 2026. B. The effective date of the provisions of Sections 3 through 12 of this act is July 1, 2027.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-hb214-effective-dates"
          },
          {
            "id": "q1-hb214-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HB 214 (2026), § 3(A)",
            "citation": "HB 214 (2026), § 3(A).",
            "url": "https://www.nmlegis.gov/Sessions/26%20Regular/bills/house/HB0214.HTML",
            "proposition": "Had it passed, HB 214 would have applied to certain businesses processing personal data of at least 35,000 consumers, or at least 10,000 consumers with more than 20% of gross revenue from selling personal data.",
            "verbatimQuote": "SECTION 3. [ NEW MATERIAL ] SCOPE OF ACT--EXEMPTIONS.-- A. The Consumer Information and Data Protection Act applies to persons that conduct business in New Mexico and persons that produce products or services that are targeted to residents of New Mexico and that during the preceding calendar year did any of the following: (1) controlled or processed the personal data of at least thirty-five thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) controlled or processed the personal data of at least ten thousand consumers and derived more than twenty percent of its gross revenue from the sale of personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q1-hb214-scope"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your New Mexico privacy policy contain?",
        "heading": "What must your New Mexico privacy policy contain?",
        "answerText": "No New Mexico statute requires a general consumer privacy policy or fixes what it must say. The binding rule is instead that whatever you publish has to be true. Under Section 5 of the FTC Act, a policy that misstates how you collect, use, share, retain, or secure data is a deceptive practice, and the Unfair Practices Act reaches the same conduct as a false or misleading written statement knowingly made in connection with the sale of goods or services. Where a sectoral regime applies, that regime supplies the contents — a HIPAA covered entity, for example, must give individuals a notice of the uses and disclosures of their protected health information and of their rights and the entity's duties.",
        "sources": [
          {
            "id": "q2-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q2-ftc5-deceptive"
          },
          {
            "id": "q2-upa-deceptive-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-2(D)",
            "citation": "NMSA 1978, § 57-12-2(D).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Unfair Practices Act defines an unfair or deceptive trade practice as a false or misleading written statement knowingly made in connection with the sale of goods or services that tends to deceive — the hook that reaches a privacy policy misstating actual practices.",
            "verbatimQuote": "\"unfair or deceptive trade practice\" means an act specifically declared unlawful pursuant to the Unfair Practices Act, a false or misleading oral or written statement, visual description or other representation of any kind knowingly made in connection with the sale, lease, rental or loan of goods or services or in the extension of credit or in the collection of debts by a person in the regular course of the person's trade or commerce, that may, tends to or does deceive or mislead any person",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q2-upa-deceptive-def"
          },
          {
            "id": "q2-upa-omission",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-2(D)(14)",
            "citation": "NMSA 1978, § 57-12-2(D)(14).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Unfair Practices Act's enumerated deceptive practices include the failure to state a material fact where the omission deceives or tends to deceive — reaching material omissions in a privacy policy, not just affirmative misstatements.",
            "verbatimQuote": "(14) using exaggeration, innuendo or ambiguity as to a material fact or failing to state a material fact if doing so deceives or tends to deceive;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q2-upa-omission"
          },
          {
            "id": "q2-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520(a)(1).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q2-hipaa-notice"
          },
          {
            "id": "q2-dbna-own-procedures",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-6(F)",
            "citation": "NMSA 1978, § 57-12C-6(F).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A person that maintains its own breach-notice procedures as part of an information security policy, consistent with the act's timing requirements, is deemed compliant with the notice requirements when it follows those procedures.",
            "verbatimQuote": "A person that maintains its own notice procedures as part of an information security policy for the treatment of personal identifying information, and whose procedures are otherwise consistent with the timing requirements of this section, is deemed to be in compliance with the notice requirements of this section if the person notifies affected consumers in accordance with its policies in the event of a security breach.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q2-dbna-own-procedures"
          },
          {
            "id": "q2-upa-private-remedy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-10(B), (C)",
            "citation": "NMSA 1978, § 57-12-10(B), (C).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Unfair Practices Act private remedy is limited to a person who suffers a money-or-property loss as a result of an unlawful practice, with actual damages or $100, possible treble damages for willful conduct, and fees and costs for a prevailing complainant.",
            "verbatimQuote": "Any person who suffers any loss of money or property, real or personal, as a result of any employment by another person of a method, act or practice declared unlawful by the Unfair Practices Act may bring an action to recover actual damages or the sum of one hundred dollars ($100), whichever is greater. Where the trier of fact finds that the party charged with an unfair or deceptive trade practice or an unconscionable trade practice has willfully engaged in the trade practice, the court may award up to three times actual damages or three hundred dollars ($300), whichever is greater, to the party complaining of the practice. C. The court shall award attorney fees and costs to the party complaining of an unfair or deceptive trade practice or unconscionable trade practice if the party prevails.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q2-upa-private-remedy"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with service providers say?",
        "heading": "What must your contracts with service providers say?",
        "answerText": "New Mexico has one mandatory vendor-contract clause, and it is statutory, not best practice. A person that discloses personal identifying information of a New Mexico resident to a service provider under a contract must require, by contract, that the service provider implement and maintain reasonable security procedures and practices appropriate to the nature of the information. The duty attaches to any vendor that receives, stores, maintains, licenses, processes, or is otherwise permitted access to personal identifying information through its services.",
        "sources": [
          {
            "id": "q3-dbna-flowdown",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-5",
            "citation": "NMSA 1978, § 57-12C-5.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A business that discloses personal identifying information of a New Mexico resident to a service provider under contract must require by contract that the service provider implement and maintain reasonable security procedures and practices.",
            "verbatimQuote": "A person that discloses personal identifying information of a New Mexico resident pursuant to a contract with a service provider shall require by contract that the service provider implement and maintain reasonable security procedures and practices appropriate to the nature of the personal identifying information and to protect it from unauthorized access, destruction, use, modification or disclosure.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q3-dbna-flowdown"
          },
          {
            "id": "q3-service-provider-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-2(E)",
            "citation": "NMSA 1978, § 57-12C-2(E).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The act defines a service provider broadly as any person permitted access to personal identifying information through its provision of services — capturing hosting, processing, storage, and access-only vendors alike.",
            "verbatimQuote": "\"service provider\" means any person that receives, stores, maintains, licenses, processes or otherwise is permitted access to personal identifying information through its provision of services directly to a person that is subject to regulation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q3-service-provider-def"
          },
          {
            "id": "q3-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=(f)%20Oversee%20service%20providers%2C%20by%3A,continued%20adequacy%20of%20their%20safeguards.",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "(f) Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; (2) Requiring your service providers by contract to implement and maintain such safeguards; and (3) Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q3-glba-safeguards"
          },
          {
            "id": "q3-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2)(i)-(ii)(D).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,with%20respect%20to%20such%20information%3B",
            "proposition": "HIPAA requires a written business-associate contract that establishes permitted uses and disclosures, requires safeguards and breach reporting, and requires subcontractor flow-down terms.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate. The contract may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity, except that: (A) The contract may permit the business associate to use and disclose protected health information for the proper management and administration of the business associate, as provided in paragraph (e)(4) of this section; and (B) The contract may permit the business associate to provide data aggregation services relating to the health care operations of the covered entity. (ii) Provide that the business associate will: (A) Not use or further disclose the information other than as permitted or required by the contract or as required by law; (B) Use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract; (C) Report to the covered entity any use or disclosure of the information not provided for by its contract of which it becomes aware, including breaches of unsecured protected health information as required by § 164.410; (D) In accordance with § 164.502(e)(1)(ii), ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate agree to the same restrictions and conditions that apply to the business associate with respect to such information;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q3-hipaa-baa"
          }
        ]
      },
      {
        "slug": "security-and-disposal",
        "label": "What data security and disposal duties does New Mexico impose?",
        "heading": "What data security and disposal duties does New Mexico impose?",
        "answerText": "Two standing duties apply to any person that owns or licenses personal identifying information of New Mexico residents, breach or no breach. First, a reasonable-security duty: implement and maintain reasonable security procedures and practices appropriate to the nature of the information. Second, a disposal duty: when records containing personal identifying information are no longer reasonably needed for business purposes, arrange for proper disposal — shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable.",
        "sources": [
          {
            "id": "q4-dbna-security",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-4",
            "citation": "NMSA 1978, § 57-12C-4.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A person that owns or licenses personal identifying information of a New Mexico resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information.",
            "verbatimQuote": "A person that owns or licenses personal identifying information of a New Mexico resident shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal identifying information from unauthorized access, destruction, use, modification or disclosure.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q4-dbna-security"
          },
          {
            "id": "q4-dbna-disposal",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-3",
            "citation": "NMSA 1978, § 57-12C-3.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "Records containing personal identifying information must be properly disposed of — shredded, erased, or rendered unreadable — once no longer reasonably needed for business purposes.",
            "verbatimQuote": "A person that owns or licenses records containing personal identifying information of a New Mexico resident shall arrange for proper disposal of the records when they are no longer reasonably needed for business purposes. As used in this section, \"proper disposal\" means shredding, erasing or otherwise modifying the personal identifying information contained in the records to make the personal identifying information unreadable or undecipherable.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q4-dbna-disposal"
          },
          {
            "id": "q4-dbna-exemptions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-8",
            "citation": "NMSA 1978, § 57-12C-8.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Data Breach Notification Act says its provisions do not apply to a person subject to GLBA or HIPAA; confirm federal-regime coverage for mixed lines of business before treating security and disposal functions as exempt.",
            "verbatimQuote": "The provisions of the Data Breach Notification Act shall not apply to a person subject to the federal Gramm-Leach-Bliley Act or the federal Health Insurance Portability and Accountability Act of 1996.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q4-dbna-exemptions"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "What must you do after a data breach in New Mexico?",
        "heading": "What must you do after a data breach in New Mexico?",
        "answerText": "A person that owns or licenses personal identifying information of New Mexico residents must notify each resident whose information is reasonably believed to have been subject to a security breach — in the most expedient time possible and no later than 45 calendar days after discovery. Notice is excused if an appropriate investigation determines the breach does not give rise to a significant risk of identity theft or fraud. If a single breach requires notice to more than 1,000 New Mexico residents, you must also notify the office of the attorney general and the nationwide consumer reporting agencies on the same 45-day clock. And a vendor holding data it does not own owes the data's owner notice of any breach within the same 45 days.",
        "sources": [
          {
            "id": "q5-dbna-notice-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-6(A)",
            "citation": "NMSA 1978, § 57-12C-6(A).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A person that owns or licenses personal identifying information of New Mexico residents must notify each affected resident of a security breach in the most expedient time possible and no later than 45 calendar days after discovery.",
            "verbatimQuote": "Except as provided in Subsection C of this section, a person that owns or licenses elements that include personal identifying information of a New Mexico resident shall provide notification to each New Mexico resident whose personal identifying information is reasonably believed to have been subject to a security breach. Notification shall be made in the most expedient time possible, but not later than fortyfive calendar days following discovery of the security breach, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-notice-duty"
          },
          {
            "id": "q5-dbna-risk-of-harm",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-6(B)",
            "citation": "NMSA 1978, § 57-12C-6(B).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "Resident notification is not required if, after an appropriate investigation, the person determines the breach does not give rise to a significant risk of identity theft or fraud.",
            "verbatimQuote": "Notwithstanding Subsection A of this section, notification to affected New Mexico residents is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-risk-of-harm"
          },
          {
            "id": "q5-dbna-maintainer-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-6(C)",
            "citation": "NMSA 1978, § 57-12C-6(C).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A person that maintains or possesses computerized personal identifying information it does not own must notify the data's owner or licensee of any security breach within 45 calendar days of discovery, subject to the same risk-of-harm exception.",
            "verbatimQuote": "Any person that is licensed to maintain or possess computerized data containing personal identifying information of a New Mexico resident that the person does not own or license shall notify the owner or licensee of the information of any security breach in the most expedient time possible, but not later than forty-five calendar days following discovery of the breach, except as provided in Section 9 of the Data Breach Notification Act; provided that notification to the owner or licensee of the information is not required if, after an appropriate investigation, the person determines that the security breach does not give rise to a significant risk of identity theft or fraud.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-maintainer-notice"
          },
          {
            "id": "q5-dbna-breach-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-2(D)",
            "citation": "NMSA 1978, § 57-12C-2(D).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A security breach is the unauthorized acquisition of unencrypted computerized data — or encrypted data plus the key — that compromises personal identifying information, excluding good-faith acquisition by an employee or agent for a legitimate business purpose.",
            "verbatimQuote": "\"security breach\" means the unauthorized acquisition of unencrypted computerized data, or of encrypted computerized data and the confidential process or key used to decrypt the encrypted computerized data, that compromises the security, confidentiality or integrity of personal identifying information maintained by a person. \"Security breach\" does not include the good-faith acquisition of personal identifying information by an employee or agent of a person for a legitimate business purpose of the person; provided that the personal identifying information is not subject to further unauthorized disclosure",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-breach-def"
          },
          {
            "id": "q5-dbna-pii-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-2(C)",
            "citation": "NMSA 1978, § 57-12C-2(C).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "Personal identifying information means a resident's name combined with specified unprotected identifiers or biometric data, and excludes information lawfully obtained from publicly available sources or government records lawfully made available to the general public.",
            "verbatimQuote": "\"personal identifying information\": (1) means an individual's first name or first initial and last name in combination with one or more of the following data elements that relate to the individual, when the data elements are not protected through encryption or redaction or otherwise rendered unreadable or unusable: (a) social security number; (b) driver's license number; (c) government-issued identification number; (d) account number, credit card number or debit card number in combination with any required security code, access code or password that would permit access to a person's financial account; or (e) biometric data; and (2) does not mean information that is lawfully obtained from publicly available sources or from federal, state or local government records lawfully made available to the general public;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-pii-def"
          },
          {
            "id": "q5-dbna-contents",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-7",
            "citation": "NMSA 1978, § 57-12C-7.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The breach notice to residents has statutorily fixed contents: notifying person's contact information, types of information involved, dates, a general description, consumer reporting agency contacts, account-review advice, and federal Fair Credit Reporting Act rights.",
            "verbatimQuote": "Notification required pursuant to Subsection A of Section 6 [57-12C-6 NMSA 1978] of the Data Breach Notification Act shall contain: A. the name and contact information of the notifying person; B. a list of the types of personal identifying information that are reasonably believed to have been the subject of a security breach, if known; C. the date of the security breach, the estimated date of the breach or the range of dates within which the security breach occurred, if known; D. a general description of the security breach incident; E. the toll-free telephone numbers and addresses of the major consumer reporting agencies; F. advice that directs the recipient to review personal account statements and credit reports, as applicable, to detect errors resulting from the security breach; and G. advice that informs the recipient of the notification of the recipient's rights pursuant to the federal Fair Credit Reporting.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-contents"
          },
          {
            "id": "q5-dbna-ag-cra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-10",
            "citation": "NMSA 1978, § 57-12C-10.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "A breach requiring notice to more than 1,000 New Mexico residents also requires 45-day notice to the office of the attorney general and the nationwide consumer reporting agencies, including the number of residents notified and a copy of the resident notice.",
            "verbatimQuote": "A person that is required to issue notification of a security breach pursuant to the Data Breach Notification Act to more than one thousand New Mexico residents as a result of a single security breach shall notify the office of the attorney general and major consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. Section 1681a(p), of the security breach in the most expedient time possible, and no later than forty-five calendar days, except as provided in Section 9 [57-12C-9 NMSA 1978] of the Data Breach Notification Act. A person required to notify the attorney general and consumer reporting agencies pursuant to this section shall notify the attorney general of the number of New Mexico residents that received notification pursuant to Section 6 of that act [57-12C-6 NMSA 1978] and shall provide a copy of the notification that was sent to affected residents within forty-five calendar days following discovery of the security breach, except as provided in Section 9 of the Data Breach Notification Act.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-ag-cra"
          },
          {
            "id": "q5-dbna-methods",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-6(D), (E)",
            "citation": "NMSA 1978, § 57-12C-6(D), (E).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "Resident breach notice may be sent by U.S. mail, qualifying electronic notice, or substitute notice when statutory cost, volume, or contact-information thresholds are met; substitute notice requires email where available, website posting where applicable, and written notice to the attorney general and major New Mexico media outlets.",
            "verbatimQuote": "D. A person required to provide notification of a security breach pursuant to Subsection A of this section shall provide that notification by: (1) United States mail; (2) electronic notification, if the person required to make the notification primarily communicates with the New Mexico resident by electronic means or if the notice provided is consistent with the requirements of 15 U.S.C. Section 7001; or (3) a substitute notification, if the person demonstrates that: (a) the cost of providing notification would exceed one hundred thousand dollars ($100,000); (b) the number of residents to be notified exceeds fifty thousand; or (c) the person does not have on record a physical address or sufficient contact information for the residents that the person or business is required to notify. E. Substitute notification pursuant to Paragraph (3) of Subsection D of this section shall consist of: (1) sending electronic notification to the email address of those residents for whom the person has a valid email address; (2) posting notification of the security breach in a conspicuous location on the website of the person required to provide notification if the person maintains a website; and (3) sending written notification to the office of the attorney general and major media outlets in New Mexico.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-methods"
          },
          {
            "id": "q5-dbna-delay",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-9",
            "citation": "NMSA 1978, § 57-12C-9.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "Notification may be delayed if law enforcement determines it would impede a criminal investigation, or as necessary to determine the breach's scope and restore the data system's integrity, security, and confidentiality.",
            "verbatimQuote": "The notification required by the Data Breach Notification Act may be delayed: A. if a law enforcement agency determines that the notification will impede a criminal investigation; or B. as necessary to determine the scope of the security breach and restore the integrity, security and confidentiality of the data system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-delay"
          },
          {
            "id": "q5-dbna-exemptions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-8",
            "citation": "NMSA 1978, § 57-12C-8.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Data Breach Notification Act says its provisions do not apply to a person subject to GLBA or HIPAA; confirm coverage for mixed lines of business before treating all notification duties as federally displaced.",
            "verbatimQuote": "The provisions of the Data Breach Notification Act shall not apply to a person subject to the federal Gramm-Leach-Bliley Act or the federal Health Insurance Portability and Accountability Act of 1996.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q5-dbna-exemptions"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Who enforces these laws — and can consumers sue?",
        "heading": "Who enforces these laws — and can consumers sue?",
        "answerText": "The Data Breach Notification Act is enforced exclusively by the attorney general, who may sue on behalf of individuals and in the name of the state, with courts empowered to issue injunctions and award damages for actual costs or losses, including consequential financial losses; for knowing or reckless violations, the court may add a civil penalty of the greater of $25,000 or, for failed notification, $10 per instance up to $150,000. The act gives consumers no private right of action — but the Unfair Practices Act does: a person who loses money or property as a result of an unlawful deceptive or unconscionable practice may sue for actual damages or $100, whichever is greater, with up to treble damages for willful conduct and mandatory attorney fees for a prevailing complainant. The attorney general polices the Unfair Practices Act as well.",
        "sources": [
          {
            "id": "q6-dbna-ag-enforcement",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-11(A), (B)",
            "citation": "NMSA 1978, § 57-12C-11(A), (B).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The attorney general enforces the Data Breach Notification Act by suing on behalf of individuals and in the name of the state, and the court may issue an injunction and award damages for actual costs or losses, including consequential financial losses.",
            "verbatimQuote": "When the attorney general has a reasonable belief that a violation of the Data Breach Notification Act has occurred, the attorney general may bring an action on the behalf of individuals and in the name of the state alleging a violation of that act. B. In any action filed by the attorney general pursuant to the Data Breach Notification Act, the court may: (1) issue an injunction; and (2) award damages for actual costs or losses, including consequential financial losses.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-dbna-ag-enforcement"
          },
          {
            "id": "q6-dbna-civil-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12C-11(C)",
            "citation": "NMSA 1978, § 57-12C-11(C).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "For knowing or reckless violations of the Data Breach Notification Act, the court may impose a civil penalty of the greater of $25,000 or, for failed notification, $10 per instance up to a maximum of $150,000.",
            "verbatimQuote": "If the court determines that a person violated the Data Breach Notification Act knowingly or recklessly, the court may impose a civil penalty of the greater of twentyfive thousand dollars ($25,000) or, in the case of failed notification, ten dollars ($10.00) per instance of failed notification up to a maximum of one hundred fifty thousand dollars ($150,000).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-dbna-civil-penalty"
          },
          {
            "id": "q6-upa-private-remedy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-10(B), (C)",
            "citation": "NMSA 1978, § 57-12-10(B), (C).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Unfair Practices Act gives any person who suffers a loss from an unlawful practice a private action for actual damages or $100, whichever is greater, up to treble damages (or $300) for willful conduct, and mandatory attorney fees and costs for a prevailing complainant.",
            "verbatimQuote": "Any person who suffers any loss of money or property, real or personal, as a result of any employment by another person of a method, act or practice declared unlawful by the Unfair Practices Act may bring an action to recover actual damages or the sum of one hundred dollars ($100), whichever is greater. Where the trier of fact finds that the party charged with an unfair or deceptive trade practice or an unconscionable trade practice has willfully engaged in the trade practice, the court may award up to three times actual damages or three hundred dollars ($300), whichever is greater, to the party complaining of the practice. C. The court shall award attorney fees and costs to the party complaining of an unfair or deceptive trade practice or unconscionable trade practice if the party prevails.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-upa-private-remedy"
          },
          {
            "id": "q6-upa-deceptive-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-2(D)",
            "citation": "NMSA 1978, § 57-12-2(D).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Unfair Practices Act defines an unfair or deceptive trade practice as a false or misleading representation knowingly made in connection with covered goods, services, credit, or debt-collection transactions in the regular course of trade or commerce.",
            "verbatimQuote": "\"unfair or deceptive trade practice\" means an act specifically declared unlawful pursuant to the Unfair Practices Act, a false or misleading oral or written statement, visual description or other representation of any kind knowingly made in connection with the sale, lease, rental or loan of goods or services or in the extension of credit or in the collection of debts by a person in the regular course of the person's trade or commerce, that may, tends to or does deceive or mislead any person",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-upa-deceptive-def"
          },
          {
            "id": "q6-upa-intent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-2 annotations",
            "citation": "NMSA 1978, § 57-12-2 annotations (Richardson Ford Sales, Inc. v. Johnson).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "New Mexico annotations state that intent to deceive is not an element of an unfair or deceptive trade practice, but a knowing representation is required.",
            "verbatimQuote": "Intent to deceive not element of \"unfair or deceptive trade practice\" but a knowing representation is required.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-upa-intent"
          },
          {
            "id": "q6-upa-class-action",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-10(E)",
            "citation": "NMSA 1978, § 57-12-10(E).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The Unfair Practices Act expressly authorizes class actions, with statutory damages for the named plaintiffs and actual damages for each class member.",
            "verbatimQuote": "In any class action filed under this section, the court may award damages to the named plaintiffs as provided in Subsection B of this section and may award members of the class such actual damages as were suffered by each member of the class as a result of the unlawful method, act or practice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-upa-class-action"
          },
          {
            "id": "q6-upa-ag-action",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-8(A), (B)",
            "citation": "NMSA 1978, § 57-12-8(A), (B).",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "The attorney general may bring an action in the name of the state against unlawful trade practices whenever proceedings would be in the public interest, and may seek temporary or permanent injunctive relief and restitution without posting bond.",
            "verbatimQuote": "Whenever the attorney general has reasonable belief that any person is using, has used or is about to use any method, act or practice which is declared by the Unfair Practices Act to be unlawful, and that proceedings would be in the public interest, he may bring an action in the name of the state alleging violations of the Unfair Practices Act. The action may be brought in the district court of the county in which the person resides or has his principal place of business or in the district court in any county in which the person is using, has used or is about to use the practice which has been alleged to be unlawful under the Unfair Practices Act. The attorney general acting on behalf of the state of New Mexico shall not be required to post bond when seeking a temporary or permanent injunction in such action. B. In any action filed pursuant to the Unfair Practices Act, including an action with respect to unimproved real property, the attorney general may petition the district court for temporary or permanent injunctive relief and restitution.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-upa-ag-action"
          },
          {
            "id": "q6-upa-civil-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "NMSA 1978, § 57-12-11",
            "citation": "NMSA 1978, § 57-12-11.",
            "url": "https://nmonesource.com/nmos/nmsa/en/4423/1/document.do",
            "proposition": "In an attorney general action, a court finding willful use of an unlawful practice may award the state a civil penalty of up to $5,000 per violation.",
            "verbatimQuote": "In any action brought under Section 57-12-8 NMSA 1978, if the court finds that a person is willfully using or has willfully used a method, act or practice declared unlawful by the Unfair Practices Act, the attorney general, upon petition to the court, may recover, on behalf of the state of New Mexico, a civil penalty of not exceeding five thousand dollars ($5,000) per violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-upa-civil-penalty"
          },
          {
            "id": "q6-hb214-status",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "New Mexico Legislature HB 214 (2026 Regular Session)",
            "citation": "New Mexico Legislature, HB 214 (2026 Regular Session).",
            "url": "https://www.nmlegis.gov/Legislation/Legislation?chamber=H&legType=B&legNo=214&year=26",
            "proposition": "The Legislature's own HB 214 page identifies the 2026 Consumer Information and Data Protection Act bill as Died (API.) and Action Postponed Indefinitely.",
            "verbatimQuote": "Current Location Died (API.)",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-hb214-status"
          },
          {
            "id": "q6-hb214-effective-dates",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HB 214 (2026), § 16",
            "citation": "HB 214 (2026), § 16.",
            "url": "https://www.nmlegis.gov/Sessions/26%20Regular/bills/house/HB0214.HTML",
            "proposition": "The July 1, 2026 date appears in the effective-date clause of the dead HB 214 bill text, not in an enacted law.",
            "verbatimQuote": "SECTION 16. EFFECTIVE DATES.-- A. The effective date of the provisions of Sections 1, 2 and 13 through 15 of this act is July 1, 2026. B. The effective date of the provisions of Sections 3 through 12 of this act is July 1, 2027.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/new-mexico#src-q6-hb214-effective-dates"
          }
        ]
      }
    ]
  }
}
