Who owns Europe’s fintech infrastructure
By Mikolaj Slezak · Published
A licence tells you that a regulator authorised a company. It tells you nothing about who controls it. Those are two different questions, and only one of them appears in any register.
We maintain a curated control map over the catalogue: one entry per verified change of control, kept in step with the same research that fills the Status / Risk column. Of 533 active providers, 74 are not controlled by the company whose name is on the door. 29 answer to an owner in US jurisdiction — and 26 of those are European-origin companies that were bought.
Three axes, not one
Sovereignty marketing collapses into a single claim (“we are European”) three facts that move independently:
- Origin — where the company was founded and has its head office. It never changes retroactively, and it is the weakest of the three signals.
- Data residency — where data is stored and processed. This is what most vendor pages talk about, and what our EEA data residency guide unpacks.
- Ownership and control — who ultimately decides, and under which legal system that decision-maker sits. This is the axis nobody publishes, because it requires tracking acquisitions after the fact.
The three can point in opposite directions on the same provider, which is exactly why we keep them as separate fields instead of one sovereignty score. The sovereignty pillar explains the layering.
The number that matters: 13 carry a green residency flag
Of the 26 European-origin, US-owned providers, 13 are recorded as EEA: Yes — full data residency inside the European Economic Area. In our data that combination is not a contradiction; it is the normal case, and it is the point.
Residency answers where the bytes live. Ownership answers who can lawfully be ordered to produce them. A US parent is subject to US law wherever the servers are, which is the conflict that GDPR Chapter V and Article 48 on one side and the CLOUD Act on the other have never resolved. Nothing about a Dutch or Finnish data centre removes a US parent from that jurisdiction.
Concretely, in this catalogue: Tink (Sweden, PI licence, EEA: Yes) is owned by Visa. Aiia (Denmark, PI) is owned by Mastercard. SurePay (Netherlands) is owned by FIS. Striga (Luxembourg, EMI) is owned by Lightspark. Global Payments Europe (Czechia, PI) is owned by Global Payments. Namirial (Italy) is a qualified trust service provider owned by Bain Capital. Each of those is a genuine EEA-resident operation with a genuine EEA licence, and each has an American ultimate parent. Both facts are true, and a buyer deserves to see both.
Both card schemes bought into account-to-account
The most-repeated sovereignty argument in European payments is that account-to-account rails route around Visa and Mastercard. At the scheme level that argument holds — see the honest map of European card schemes. One layer up it gets less comfortable.
Visa acquired Tink, Currencycloud (an IBAN sponsor) and Featurespace (fraud monitoring). Mastercard acquired Aiia and BVNK. Marqeta owns Transact Payments, one of the BIN sponsors a European card programme can actually sign with. Global Payments owns both Worldpay and Global Payments Europe. Put plainly: two of the best-known Nordic open-banking aggregators, sold as the European alternative to cards, belong to the two American card schemes.
That is not an accusation of wrongdoing. It is a structural fact that changes what “bypassing the card schemes” means in a procurement document.
Where control concentrates
Foreign control is not spread evenly. It clusters in categories where a European vendor became the obvious consolidation target. The table below is recomputed from the catalogue on every build, so it cannot drift away from the data:
| Category | Foreign-owned | Which providers (and their owner) |
|---|---|---|
| Payment terminals & SoftPOS | 3 of 6 | CCV → Fiserv; Ingenico → Apollo Global; phos → Ingenico (Apollo) |
| Verification of Payee | 1 of 4 | SurePay → FIS |
| Treasury & cash management | 1 of 6 | Cobase → Corpay |
| E-invoicing & tax compliance | 2 of 13 | Basware → Accel-KKR; Pagero → Thomson Reuters |
| Crypto / digital-asset infra | 6 of 41 | Bitstamp → Robinhood; BVNK → Mastercard; Membrane Finance → Paxos; Metaco → Ripple and 2 more |
| Tokenization – X-Pays | 2 of 16 | MeaWallet → Teya; Transact Payments → Marqeta |
| Core banking | 4 of 35 | Avaloq → NEC; CREALOGIX → Vencora; Finastra → Vista Equity; Striga → Lightspark |
| Tokenization – Non-X-Pays | 1 of 9 | MeaWallet → Teya |
| Cross-border payments / FX | 4 of 39 | Alpha Group → Corpay; BVNK → Mastercard; Currencycloud → Visa; WorldFirst → Ant Group |
| Investment infrastructure | 1 of 10 | WealthKernel → Alpaca |
European-origin active providers per category; foreign-owned means a verified ultimate parent outside the EU (including the UK, which is outside the EEA for data purposes). Recomputed from the catalogue on every build - see how we verify.
Two rows deserve reading twice. Payment terminals and SoftPOS: half of the European-origin names in the category answer to a foreign owner, and two of those roll up to the same American private-equity house, because Ingenico (Apollo-owned) itself acquired the Bulgarian SoftPOS specialist phos. Verification of Payee: this is not an optional product. The Instant Payments Regulation makes the payee check mandatory for euro credit transfers, and the European market leader, SurePay, now belongs to FIS.
The reverse deserves saying just as plainly, because it is good news from the same data: in the categories at the core of this catalogue — BaaS, BIN sponsorship, IBAN issuing — acquisition by a non-European owner is the exception, not the rule.
Ownership is not a label — ask EUROe
If a change of control reads like a compliance footnote, consider what happened to a euro stablecoin. Membrane Finance was a Finnish EMI with full EEA residency and a MiCA authorisation, and it issued EUROe — for a while one of the most-cited euro-denominated stablecoins in the MiCA conversation. Paxos, a US issuer, acquired it. As of 18 September 2026 EUROe is being decommissioned: redemption-only at 1:1, no new issuance, with the old domain now pointing at the Paxos redemption notice.
Nothing about the Finnish licence, the residency flag or the MiCA token changed. The owner changed, and the product ended. We caught it in a routine liveness scan and corrected every page where we had still been listing EUROe as available — the method is in how we verify, and live risk flags sit on the Radar.
It is not only America
11 providers have an ultimate owner outside both the EU and the US. Ant Group owns MultiSafepay (Netherlands) and WorldFirst (UK). NEC owns Avaloq; Vencora (Canada) owns CREALOGIX; Param (Turkey) owns Twisto; Prosus (South Africa) owns iyzico; Apex Group (Bermuda) owns Tokeny. And post-Brexit, a UK owner is a non-EEA owner for data purposes: Nordigen belongs to GoCardless, Valitor to Rapyd, MeaWallet to Teya.
The other direction: Europe’s banks are buying the rails back
The same map records 34 providers under European ownership, and the buyer list is striking: mostly incumbent banks and, in two cases, states. Societe Generale owns Treezor; Credit Agricole owns Okali; UniCredit owns Vodeno and Aion Bank; BNP Paribas owns Kantox; Santander owns Ebury and Getnet Europe; Groupe BPCE owns Payplug; Banco Sabadell owns PAYCOMET; Citadele owns Klix; Raiffeisen Bank International owns AKCENTA; SEB owns AirPlus. D-Trust belongs to Bundesdruckerei, the German federal printer, and PagoPA is state-held in Italy.
So the honest summary is not “Europe is losing its infrastructure”. It is that consolidation runs in both directions at once, and which direction applies to your vendor is a question of fact you can check before you sign.
What to ask before you sign
- Who is the ultimate parent, and in which jurisdiction does it sit? Not the brand, not the local entity — the top of the chain.
- Which legal entity signs my contract, and where is it licensed? Look it up yourself in the licence register; the signing entity is often not the one in the marketing.
- Which parent-side requests could reach my data, and what is the provider’s documented answer? Ask for the process, not for a reassurance.
- What happens to this product if the parent repositions? EUROe is the template for this question.
- Is there a portability and exit clause with real timelines? Ownership risk is contract risk.
The sovereignty scorecard turns these into a score across eight axes, and if you would rather have the shortlist done for you, request a match — we hand-pick three verified providers and disclose the ownership of each. Free, neutral, no pay-to-rank.
How we track this — and what it does not say
Every entry in the control map comes from the same source-first method as the rest of the catalogue: a verified acquisition or holding, recorded with a date in the provider timeline and reflected on the provider profile. Minority stakes, venture positions and holdings we could not confirm are deliberately not recorded. So the 415 providers with no recorded change of control should be read as exactly that — no recorded change of control — and not as proof of independence.
We also do not rank providers by their owner. US ownership is not a disqualification and European ownership is not a guarantee; a US-owned vendor with a real EEA licence and EEA-resident processing may well be the right answer for a given project. What we refuse to do is leave the fact off the page. Corrections are welcome and land on the same day: report a correction.
Sources
The primary law and official registers behind this page. We check claims against these, not against vendor marketing (how we verify).
- Regulation (EU) 2016/679 (GDPR) — Chapter V - the conditions under which personal data may leave the EEA at all.
- US Department of Justice - CLOUD Act resources — the US law that can reach data held by US-controlled providers regardless of where the servers are.
- CJEU judgment in Case C-311/18 (Schrems II) — the ruling that invalidated Privacy Shield and set the bar for assessing third-country access to transferred data.
- Regulation (EU) 2024/886 (Instant Payments Regulation) — instant euro transfers and the mandatory verification of payee, with separate dates for euro and non-euro member states.
- Regulation (EU) 2023/1114 (MiCA) — crypto-asset service provider authorisation, e-money tokens and asset-referenced tokens.
- EBA register of payment and e-money institutions (EUCLID) — the official EEA register of payment institutions, e-money institutions and account information service providers.
More insights
Europe's summer 2026 licence growth was almost all MiCA - and in Germany it was led by local cooperative banks, not crypto firms. How to read a register count.
Source-verified coverage of 21 IBAN country codes - the UK leads with 17, Lithuania 9; Poland, Austria and Portugal have zero dedicated issuers. Only 15 verified IBAN sponsors document SEPA Direct Debit, where IBAN discrimination actually bites.
The EBA, ESMA and FCA registers rebuilt into one index: Germany has overtaken Lithuania at the top as MiCA authorisations land - and a licence is not sovereignty.