Who owns Europe’s fintech infrastructure

By Mikolaj Slezak · Published

A licence tells you that a regulator authorised a company. It tells you nothing about who controls it. Those are two different questions, and only one of them appears in any register.

We maintain a curated control map over the catalogue: one entry per verified change of control, kept in step with the same research that fills the Status / Risk column. Of 533 active providers, 74 are not controlled by the company whose name is on the door. 29 answer to an owner in US jurisdiction — and 26 of those are European-origin companies that were bought.

Three axes, not one

Sovereignty marketing collapses into a single claim (“we are European”) three facts that move independently:

The three can point in opposite directions on the same provider, which is exactly why we keep them as separate fields instead of one sovereignty score. The sovereignty pillar explains the layering.

The number that matters: 13 carry a green residency flag

Of the 26 European-origin, US-owned providers, 13 are recorded as EEA: Yes — full data residency inside the European Economic Area. In our data that combination is not a contradiction; it is the normal case, and it is the point.

Residency answers where the bytes live. Ownership answers who can lawfully be ordered to produce them. A US parent is subject to US law wherever the servers are, which is the conflict that GDPR Chapter V and Article 48 on one side and the CLOUD Act on the other have never resolved. Nothing about a Dutch or Finnish data centre removes a US parent from that jurisdiction.

Concretely, in this catalogue: Tink (Sweden, PI licence, EEA: Yes) is owned by Visa. Aiia (Denmark, PI) is owned by Mastercard. SurePay (Netherlands) is owned by FIS. Striga (Luxembourg, EMI) is owned by Lightspark. Global Payments Europe (Czechia, PI) is owned by Global Payments. Namirial (Italy) is a qualified trust service provider owned by Bain Capital. Each of those is a genuine EEA-resident operation with a genuine EEA licence, and each has an American ultimate parent. Both facts are true, and a buyer deserves to see both.

Both card schemes bought into account-to-account

The most-repeated sovereignty argument in European payments is that account-to-account rails route around Visa and Mastercard. At the scheme level that argument holds — see the honest map of European card schemes. One layer up it gets less comfortable.

Visa acquired Tink, Currencycloud (an IBAN sponsor) and Featurespace (fraud monitoring). Mastercard acquired Aiia and BVNK. Marqeta owns Transact Payments, one of the BIN sponsors a European card programme can actually sign with. Global Payments owns both Worldpay and Global Payments Europe. Put plainly: two of the best-known Nordic open-banking aggregators, sold as the European alternative to cards, belong to the two American card schemes.

That is not an accusation of wrongdoing. It is a structural fact that changes what “bypassing the card schemes” means in a procurement document.

Where control concentrates

Foreign control is not spread evenly. It clusters in categories where a European vendor became the obvious consolidation target. The table below is recomputed from the catalogue on every build, so it cannot drift away from the data:

CategoryForeign-ownedWhich providers (and their owner)
Payment terminals & SoftPOS3 of 6CCV → Fiserv; Ingenico → Apollo Global; phos → Ingenico (Apollo)
Verification of Payee1 of 4SurePay → FIS
Treasury & cash management1 of 6Cobase → Corpay
E-invoicing & tax compliance2 of 13Basware → Accel-KKR; Pagero → Thomson Reuters
Crypto / digital-asset infra6 of 41Bitstamp → Robinhood; BVNK → Mastercard; Membrane Finance → Paxos; Metaco → Ripple and 2 more
Tokenization – X-Pays2 of 16MeaWallet → Teya; Transact Payments → Marqeta
Core banking4 of 35Avaloq → NEC; CREALOGIX → Vencora; Finastra → Vista Equity; Striga → Lightspark
Tokenization – Non-X-Pays1 of 9MeaWallet → Teya
Cross-border payments / FX4 of 39Alpha Group → Corpay; BVNK → Mastercard; Currencycloud → Visa; WorldFirst → Ant Group
Investment infrastructure1 of 10WealthKernel → Alpaca

European-origin active providers per category; foreign-owned means a verified ultimate parent outside the EU (including the UK, which is outside the EEA for data purposes). Recomputed from the catalogue on every build - see how we verify.

Two rows deserve reading twice. Payment terminals and SoftPOS: half of the European-origin names in the category answer to a foreign owner, and two of those roll up to the same American private-equity house, because Ingenico (Apollo-owned) itself acquired the Bulgarian SoftPOS specialist phos. Verification of Payee: this is not an optional product. The Instant Payments Regulation makes the payee check mandatory for euro credit transfers, and the European market leader, SurePay, now belongs to FIS.

The reverse deserves saying just as plainly, because it is good news from the same data: in the categories at the core of this catalogue — BaaS, BIN sponsorship, IBAN issuing — acquisition by a non-European owner is the exception, not the rule.

Ownership is not a label — ask EUROe

If a change of control reads like a compliance footnote, consider what happened to a euro stablecoin. Membrane Finance was a Finnish EMI with full EEA residency and a MiCA authorisation, and it issued EUROe — for a while one of the most-cited euro-denominated stablecoins in the MiCA conversation. Paxos, a US issuer, acquired it. As of 18 September 2026 EUROe is being decommissioned: redemption-only at 1:1, no new issuance, with the old domain now pointing at the Paxos redemption notice.

Nothing about the Finnish licence, the residency flag or the MiCA token changed. The owner changed, and the product ended. We caught it in a routine liveness scan and corrected every page where we had still been listing EUROe as available — the method is in how we verify, and live risk flags sit on the Radar.

It is not only America

11 providers have an ultimate owner outside both the EU and the US. Ant Group owns MultiSafepay (Netherlands) and WorldFirst (UK). NEC owns Avaloq; Vencora (Canada) owns CREALOGIX; Param (Turkey) owns Twisto; Prosus (South Africa) owns iyzico; Apex Group (Bermuda) owns Tokeny. And post-Brexit, a UK owner is a non-EEA owner for data purposes: Nordigen belongs to GoCardless, Valitor to Rapyd, MeaWallet to Teya.

The other direction: Europe’s banks are buying the rails back

The same map records 34 providers under European ownership, and the buyer list is striking: mostly incumbent banks and, in two cases, states. Societe Generale owns Treezor; Credit Agricole owns Okali; UniCredit owns Vodeno and Aion Bank; BNP Paribas owns Kantox; Santander owns Ebury and Getnet Europe; Groupe BPCE owns Payplug; Banco Sabadell owns PAYCOMET; Citadele owns Klix; Raiffeisen Bank International owns AKCENTA; SEB owns AirPlus. D-Trust belongs to Bundesdruckerei, the German federal printer, and PagoPA is state-held in Italy.

So the honest summary is not “Europe is losing its infrastructure”. It is that consolidation runs in both directions at once, and which direction applies to your vendor is a question of fact you can check before you sign.

What to ask before you sign

  1. Who is the ultimate parent, and in which jurisdiction does it sit? Not the brand, not the local entity — the top of the chain.
  2. Which legal entity signs my contract, and where is it licensed? Look it up yourself in the licence register; the signing entity is often not the one in the marketing.
  3. Which parent-side requests could reach my data, and what is the provider’s documented answer? Ask for the process, not for a reassurance.
  4. What happens to this product if the parent repositions? EUROe is the template for this question.
  5. Is there a portability and exit clause with real timelines? Ownership risk is contract risk.

The sovereignty scorecard turns these into a score across eight axes, and if you would rather have the shortlist done for you, request a match — we hand-pick three verified providers and disclose the ownership of each. Free, neutral, no pay-to-rank.

How we track this — and what it does not say

Every entry in the control map comes from the same source-first method as the rest of the catalogue: a verified acquisition or holding, recorded with a date in the provider timeline and reflected on the provider profile. Minority stakes, venture positions and holdings we could not confirm are deliberately not recorded. So the 415 providers with no recorded change of control should be read as exactly that — no recorded change of control — and not as proof of independence.

We also do not rank providers by their owner. US ownership is not a disqualification and European ownership is not a guarantee; a US-owned vendor with a real EEA licence and EEA-resident processing may well be the right answer for a given project. What we refuse to do is leave the fact off the page. Corrections are welcome and land on the same day: report a correction.

Sources

The primary law and official registers behind this page. We check claims against these, not against vendor marketing (how we verify).

More insights

Europe's summer 2026 licence growth was almost all MiCA - and in Germany it was led by local cooperative banks, not crypto firms. How to read a register count.

Source-verified coverage of 21 IBAN country codes - the UK leads with 17, Lithuania 9; Poland, Austria and Portugal have zero dedicated issuers. Only 15 verified IBAN sponsors document SEPA Direct Debit, where IBAN discrimination actually bites.

The EBA, ESMA and FCA registers rebuilt into one index: Germany has overtaken Lithuania at the top as MiCA authorisations land - and a licence is not sovereignty.