Christian Paredes, Field Compliance Officer at SAP Mexico, reviews a year of regulatory transformations with Líder Legal: the new personal data law without yet published regulations, the integration of artificial intelligence such as Joule under new transparency rules, and a sectoral mosaic that is shifting as attempts are made to map it, with the dissolution of the IFT and the disappearance of the INAI in between. Paredes explains why no regulatory framework—not even the European one—should be the anchor of a global compliance program, what lessons the Mexican transition offers for other compliance officers in the region, and how far the cross-border cooperation between regulators that he himself predicted a year ago has actually progressed.
The new Federal Law on the Protection of Personal Data celebrated its first anniversary in March, but its regulations have yet to be published. What has it meant for SAP to operate under the text of the law without these regulations, and what specific gray area concerns them most while they are being resolved?
It has meant operating under a new law and, at the same time, with previous secondary regulations that must be interpreted in light of the new framework and only where compatible. This situation requires careful analysis, but it doesn’t prevent us from moving forward. Furthermore, for a global company like SAP, our benchmark is not simply the minimum requirements of any one jurisdiction. We have global privacy and data protection standards, and we strive to incorporate these principles from the design stage of our products and services. SAP, for example, publicly states that data protection and privacy must be built in by design and by default.
That said, I want to clarify something that’s often repeated in the market but is incorrect: a regulatory vacuum doesn’t suspend the obligation. What’s lost isn’t the requirement itself; it’s the predictability. And compliance doesn’t guarantee absolute legal certainty—that doesn’t exist—but rather operational predictability. That’s the real service it offers.
The gray area that worries me most? Data retention periods and deletion. The law introduced the concept, but the operational details—how the period is defined, how it’s documented, what constitutes valid destruction, and how it’s proven to the authorities—are exactly what a regulation should address. When you ask a business to set retention periods without a clear regulatory framework, each department creates its own.
If I had to point to one area that requires special attention, it would be data lifecycle management: retention, blocking, and deletion. The new law stipulates that when data is no longer necessary for its intended purposes, it must be deleted after being blocked, where applicable, once the applicable retention period has expired.
The challenge for organizations is to translate this principle into concrete processes: defining deadlines, documenting them, applying them consistently, and being able to demonstrate that effective controls are in place. This becomes even more relevant when dealing with large volumes of information, backups, and technological systems that are part of complex lifecycles.
One of the most concrete obligations of the new law is to explicitly state in the privacy notice when data is used for automated decision-making or profiling, without vague phrases like “among others.” With AI products like Joule becoming increasingly integrated into SAP’s business, how did you translate this legal obligation into practice?
I would say that translating these obligations doesn’t begin with the privacy notice. It begins with the inventory and governance. And here I apply the same method as always: see, organize, and govern.
First, we need to know which systems process personal data, what they use it for, and, when automation is involved, what role the system plays in a decision. A tool that helps draft a document is not the same as a system that participates in a decision that could have a significant impact on a person.
From there comes the second part: classifying the risk and defining the appropriate controls. This includes transparency, data protection, traceability, and, where appropriate, effective human oversight.
This approach is very much in line with what we do at SAP. Our Global AI Ethics Policy establishes principles such as privacy and data protection, human oversight and decision-making, transparency and explainability, and accountability. Furthermore, SAP has ethical impact assessment processes for AI use cases and governance mechanisms for those that present the greatest risks.
And for me, there’s a fundamental idea: we can’t govern what we don’t know. That’s why, before asking ourselves how to write the privacy notice, we need to be able to answer much more basic questions: what data does the system use, for what purpose, what does the model do, what level of human intervention exists, and who is responsible for that decision?
Transparency shouldn’t just be a written obligation. It should be a consequence of truly understanding our own processes.
And let me clarify something about the “among others.” That phrase was never a drafting problem; it was a symptom of a lack of understanding. “Among others” was used because it wasn’t clear exactly what the system did. The new law closed that loophole, and I think it was the right thing to do. A privacy notice is a declaration to the data subject and to the relevant authorities. If it’s vague, what you’re really declaring is that you don’t know your own processes.
Mexico still lacks a federal law on artificial intelligence; instead, there is a patchwork of sector-specific regulations—COFEPRIS in health, CNBV in finance, IFT in telecommunications. For a company like SAP, which sells AI solutions to clients in all these sectors simultaneously, is this regulatory patchwork more of a compliance risk or an opportunity to differentiate itself from less prepared competitors?
Let me begin with a clarification, because it illustrates the point better than any argument: the IFT no longer exists. It was dissolved in October 2025, and its functions were assumed by the Telecommunications Regulatory Commission, a decentralized body of the Digital Transformation and Telecommunications Agency. In other words, the mosaic isn’t just fragmented: it shifts as you’re mapping it. That’s the real difficulty, more than the fragmentation itself.
Risk or opportunity? I would say it’s both, but the order matters. First, it’s a compliance and risk management challenge; then it can become an opportunity for differentiation.
For companies that develop or implement technology, this means we need the ability to monitor changes and quickly translate them into our processes and solutions.
But I would avoid building a different compliance program for each sector. That doesn’t scale. What works best is to build a common governance framework—use case inventory, risk classification, human oversight, traceability, data protection, and third-party management—and then incorporate the specific requirements of each industry.
At SAP, this approach is part of our Responsible AI model. Our global policy establishes common principles for the development, implementation, sale, and use of AI systems, and includes impact assessment and governance processes for use cases.
That’s where I see an opportunity: companies that build trust and governance by design are better prepared to adopt AI responsibly and scale it. Regulations may change; good governance remains.
Last year you participated in the “Global Governance and Regulatory Risks” panel at the Mexico 2025 Foro Gerencias Legales. Given everything that has happened since then—the new data law, the disappearance of the INAI, the regulatory vacuum surrounding AI—what from what you said a year ago would you no longer stand by today?
Two things have changed my perspective.
The first has to do with the institutional transition in data protection. A year ago, I saw the change primarily as an institutional transition: the authority changes, but the need to protect data remains. Today, I would say it’s more complex.
An authority does not only provide supervisory powers. Over time, it also generates criteria, experience, precedents, and a practical interpretation of regulations. When an institutional transition occurs, this knowledge must be reconstructed, and that naturally takes time.
The second point is more difficult for me to grasp, because I held it with considerable conviction, and it relates to my perception of international frameworks. A year ago, I saw Europe as a particularly stable benchmark. Today, I believe the lesson is that no single regulatory framework should be our sole anchor. Technology evolves, economic priorities shift, and regulations evolve as well. Therefore, for a global company, it is more sustainable to build its own capabilities: identifying use cases, assessing risks, protecting data, maintaining human oversight, and documenting decisions.
At SAP, we have precisely that approach. Our global AI ethics policy is updated to reflect technological and regulatory developments, and takes into account international frameworks such as UNESCO, OECD, NIST, the EU AI Act, and ISO/IEC 42001.
The lesson I take away is simple: you shouldn’t build governance around a law; you should build capacities that allow you to respond responsibly when laws change. You can’t anchor your program to a jurisdiction. You have to anchor it to your own principles and capabilities—inventory, risk classification, human oversight, traceability.
A year ago you predicted that cross-border regulatory collaboration between regulators would be a key trend. A year later, have you seen any concrete examples of that collaboration in practice, or is it still more of an expectation than a reality?
I saw concrete examples, yes, but not where I expected them.
What did happen was regulatory convergence and coordinated statements. The Global Privacy Assembly issued a joint declaration on privacy and AI-generated images earlier this year, endorsed by dozens of authorities, including Mexico. The Ibero-American Data Protection Network has promoted common tools for international data transfers. And in Europe, the European Data Protection Board’s work program for 2026-2027 includes joint guidelines on the interaction between the AI framework and the data regime. This is no small matter: it’s the framework from which standards subsequently emerge.
What hasn’t happened, or at least not yet, is operational cooperation: coordinated investigations, genuine exchange of case files, and agreed-upon sanctions between jurisdictions for the same offense. We’re still at the stage of joint statements rather than joint cases.
But there is a third way that does work, and which almost no one calls regulatory cooperation because it’s not public: contractual cooperation. Today, the most effective vehicle for harmonizing standards in Latin America is a contract with a multinational client, with its clauses, audits, and supplier requirements. The market is moving faster than treaties.
So my conclusion would be: regulatory cooperation is progressing, but the harmonization of standards is also being driven by the market. And that is precisely the direction we are seeing at SAP: building global standards that can be adapted to local requirements. Our global AI ethics policy, for example, establishes common principles for the development, implementation, sale, and use of AI, and explicitly recognizes the need for adaptive governance and collaboration with multiple stakeholders.
This year the Foro Gerencias Legales México 2026 includes a specific panel on “Global Governance from Mexico: New Standards of Transparency, Taxation, and Corporate Responsibility.” What will you say to other compliance officers in the region who haven’t yet experienced this Mexican regulatory transition firsthand?
Four things, and I say them without drama, because it is not an apocalyptic warning but a field lesson.
- First: your program cannot depend on the existence of the regulator. If your compliance framework was designed around the criteria of a specific authority, the day that authority disappears, you’ll be left without a compass. The program must be defensible to any authority, including one that doesn’t yet exist.
- Second: The risk lies in the transition, not in the new regulation. The worst non-compliance I’ve seen didn’t stem from misinterpretation, but from inaction. “Let’s wait for the regulations,” “let’s wait until they appoint the head of the agency,” “let’s wait and see how they impose sanctions.” In compliance, waiting isn’t a strategy: it’s a decision, and it has consequences.
- Third: Document the reasoning, not just the outcome. In a regulatory vacuum, what protects you is not being right—that will be determined later—but being able to demonstrate that you made the decision methodically, with information, and with professional judgment. The record of the decision is as valuable as the decision itself.
- Fourth: This is not a Mexican anomaly. It is the new regional normal. Several jurisdictions in Latin America are redesigning their institutional architectures while simultaneously attempting to regulate artificial intelligence. Mexico simply arrived at that combination first.
And I’ll close with something I repeat ad nauseam: Well-designed compliance doesn’t stifle innovation; it enables innovation with confidence and at scale. Ethics and money are not mutually exclusive. In an environment of regulatory uncertainty, the organization that can explain its decisions is the one that can secure contracts, participate in tenders, and withstand an audit. That’s not a cost. It’s market access.
The conversation with Christian Paredes reveals a recurring pattern under different regulatory guises: data law, artificial intelligence, telecommunications, and even Mexican regulators themselves all changed simultaneously over the past year, and his interpretation is that legal certainty is no longer a reliable foundation for a regional compliance program. Hence, his central thesis—building one’s own capabilities instead of being anchored to a law or an authority—permeates every answer, from data lifecycle management to Joule governance.
This shift also explains why, according to Paredes, cross-border regulatory cooperation is currently progressing more rapidly through contractual rather than institutional channels: while regulators coordinate joint statements, it is the clauses of a multinational client that ultimately harmonize standards across the region. The message for other compliance officers in Latin America who will, sooner or later, face their own version of the Mexican transition is to document the reasoning with the same rigor as they document the outcome: in a regulatory environment that is constantly evolving as it is being mapped, this record is the only constant.