GDPR · ART 3MX / CZ

Does GDPR apply to a banking startup in Mexico serving Czechia?

Based inMexico
ServesCzechia
Sectorbanking
Typestartup
CHECK

Short answer

GDPR may apply if the activity intentionally targets or monitors people in Czechia.

Article 3(2) can reach an organisation outside the EEA when its processing relates to offering goods or services to people in the EEA, whether paid or free, or monitoring their behaviour there. A website merely being reachable from Czechia is not enough on its own; targeting and the processing activity matter.

01 · The decisive tests

Headquarters do not settle the question.

01

EEA establishment

The organisation is based outside the EEA. Check whether it has a stable EEA arrangement connected to this processing before moving to the targeting tests.

Check facts
02

Offering goods or services

Look for intentional direction toward people in Czechia: market-specific language, currency, delivery, campaigns, customers or other evidence. Payment is not required.

Primary route
03

Monitoring behaviour

Ask whether behaviour in Czechia is tracked or profiled—for example through persistent online tracking, behavioural analysis or location monitoring.

Check activity
04

Mere accessibility

A website that can simply be opened from Czechia does not, by itself, prove intentional offering under the EDPB’s guidance.

Not enough alone

02 · Sector context

What a banking operation should map.

A banking startup commonly handles customer identity, account, transaction and financial-risk information. Inventory the individual processing activities rather than giving the entire business one territorial answer.

Being early-stage is not an Article 3 exemption. Map where people are located and why their data is processed.

03 · If a trigger applies

Turn scope into an operating plan.

  1. 1
    Map the processing

    Record the people, purposes, data, systems and locations connected to Czechia.

  2. 2
    Assign controller and processor roles

    Article 3 applies to specific processing activities, not just a brand or group label.

  3. 3
    Check representative requirements

    An organisation caught by Article 3(2) may need a written representative in the Union, subject to Article 27’s limited exceptions.

  4. 4
    Operationalise the duties

    Choose the records, request handling, breach response and review workflows required for the processing.

04 · Common questions

Questions for this scenario.

Does being based in Mexico keep this organisation outside GDPR?+

Not necessarily. Article 3(2) can apply to an organisation outside the EEA when relevant processing concerns intentionally offering goods or services to people in the EEA or monitoring their behaviour there.

Does a service need to be paid for before GDPR can apply in Czechia?+

No. Article 3(2)(a) expressly covers an offering of goods or services whether or not payment by the person is required.

Does operating in banking decide territorial scope?+

No. Sector alone is not an Article 3 trigger. It changes the kinds and risks of data involved—such as customer identity, account, transaction and financial-risk information—but establishment, offering and monitoring facts decide territorial scope.

Primary material

Read the source,
not only the summary.

Knowing the rule is the start.

Make the interpretation
repeatable.