Compliance Radar

July, 2026

News and Insights

Compliance Radar

Compliance Radar

Rules evolve. So do the consequences of non-compliance.

In recent weeks, Mexican, U.S. and European authorities have adopted decisions that are reshaping the compliance landscape, including developments in data protection, anti-money laundering, artificial intelligence and competition law.

Fines, investigations, blocked transactions and individual liability demonstrate that non-compliance has tangible consequences.

United States designates the Juárez Cartel and Los Viagras as terrorist organizations

The U.S. Department of State (DOS) designated the Juárez Cartel and Los Viagras as Foreign Terrorist Organizations (FTOs) and Specially Designated Global Terrorists (SDGTs). With these additions, eight Mexican criminal organizations are now subject to these designations.

Why does this matter to your company, even if it does not operate in the United States?

These designations entail:

  • A prohibition on providing “material support” (financial or practical assistance), to these organizations under 18 U.S.C. § 2339B.
  • The blocking of assets where there is a complementary designation by the U.S. Office of Foreign Assets Control (OFAC).
  • Increased investigations and asset seizures connected with terrorist financing.

What do we recommend reviewing?

Companies should review their due diligence processes, sanctions screening and protocols for responding to extortion, payments made under duress or contracts imposed through threats.

Particular attention should be paid to operations in areas controlled by criminal groups, where companies may be forced to pay extortion fees or right-of-passage payments, or to contract services under coercion.

From a legal standpoint, these situations are complex. In Mexico, companies may be regarded as victims of extortion or may have acted under coercion. From a U.S. perspective, however, the assessment may be different if those payments ultimately benefit an FTO.

It is therefore essential to document the circumstances, seek specialized legal advice and, where possible, implement mitigation measures.

 Mexican Football Federation fined MXN 42.8 million over FAN ID

Mexico’s Ministry of Anti-Corruption and Good Government, known by its Spanish acronym SABG, imposed a MXN $42.8 million fine on the Mexican Football Federation (FMF) for violations related to the processing of personal data through the FAN ID system.

The case is particularly relevant because it involves photographs, identification mechanisms and potentially biometric data used to control access to stadiums.

The lesson is not about football. It is about who remains accountable when something goes wrong. The FMF engaged an external technology provider, but responsibility for deciding what data would be collected and how that data would be protected remained with the FMF. Engaging a third party does not transfer legal responsibility.

What do we recommend reviewing?

Companies should review their use of facial recognition, fingerprints, intelligent video surveillance, access-control systems and identity-verification tools, as well as their privacy notices, consent mechanisms, security measures and agreements with service providers.

 Europe strengthens transparency requirements for artificial intelligence (AI)

As of August 2, 2026, the transparency obligations under Article 50 of the EU AI Act will apply. Companies will be required to inform individuals when they are interacting with certain AI systems and to label certain content generated or manipulated using AI.

These obligations may affect Mexican companies that form part of European corporate groups or develop technology for clients in Europe.

What do we recommend reviewing?

Companies should identify which AI tools are being used, for what purposes and what information is entered into them. They should also assess whether appropriate controls are in place regarding transparency, human oversight and confidentiality.

 Mexico’s National Antitrust Commission sanctions collusion in public tenders

Mexico’s National Antitrust Commission, known by its Spanish acronym CNA, imposed fines totaling MXN $59.6 million on four companies and six individuals for coordinating bidding strategies and exchanging sensitive information in public tenders for X-ray materials.

The case confirms that anticompetitive conduct does not necessarily require a formal written agreement. Discussions involving prices, discounts, customers, territories or decisions on whether to submit a bid may be sufficient to trigger an investigation.

Liability may also extend directly to executives, employees and representatives involved in the conduct.

What do we recommend reviewing?

Companies should review their bid-preparation processes, the nature of their interactions with competitors through trade associations or consortia, and whether their commercial teams understand where the legal boundaries lie.

 These developments show that a company’s risk profile may change even when its business model remains the same. An international designation, new technology or new enforcement criterion may turn a routine business practice into a significant source of liability.

An effective compliance program is not one that was drafted once and then left unchanged. It is one that is regularly reviewed, tested and supported by evidence showing that it operates effectively in practice.

Do not wait for a crisis to reveal the gaps in your compliance program.

This newsletter is intended for informational purposes only and does not constitute legal advice regarding any specific matter.

We remain at your disposal to analyze the specific impact on your operations and to assist in the implementation of the necessary measures.

Yours sincerely,

Cannizzo