GoCardless
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
London-based UK direct-debit and recurring-payments specialist (FCA-authorised); Mollie acquisition announced Dec 2025.
GoCardless offers EU hosting in the United Kingdom, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Payments.
Assessment notes
GoCardless Ltd (Sutton Yard, 65 Goswell Road, London EC1V 7EN; Companies House 07495895) is the UK direct-debit-and-recurring-payments specialist, FCA-authorised under the Payment Services Regulations 2017 (597190), but in December 2025 Dutch Mollie announced an acquisition agreement valuing the company at ~US$1.1B, the deal subject to regulatory approval and still not closed at the August 2026 re-verification, so the immediate ownership state is in transition; UK post-Brexit jurisdiction plus a historical cap-table mix (Permira UK + BlackRock US + Accel US + Balderton UK) results in cloud_act_exposure: material and ownership_signal: other (transition pending Mollie acquisition close); there is no self-serve DPA, though a versioned sub-processor list naming 23 suppliers is published.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other This listing A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 23 · 17 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About GoCardless
GoCardless is a London-headquartered UK payments platform specialising in direct debit and recurring payments, operated by GoCardless Ltd (Sutton Yard, 65 Goswell Road, London EC1V 7EN; Companies House 07495895). Founded in 2011 by Hiroki Takeuchi, Tom Blomfield, and Matt Robinson, the company is authorised by the UK's Financial Conduct Authority under the Payment Services Regulations 2017 (registration 597190) and supports a uniquely broad set of bank-to-bank schemes: Bacs (UK), SEPA Direct Debit (Eurozone), ACH (US), BECS (Australia and New Zealand), PAD (Canada), Autogiro (Sweden), and Betalingsservice (Denmark). The product is positioned as the direct-debit-and-recurring-payments alternative to Stripe/PayPal, particularly strong for subscription SaaS, B2B invoicing, charities, and any business with predictable recurring billing.
Two ownership signals matter for an EU-sovereignty audit at this time. First, the historical cap table includes Permira (UK), BlackRock (US), Accel (US), and Balderton (UK) alongside other backers: mixed-jurisdiction with material US-VC exposure that, on its own, would place GoCardless in the eu_hq_us_funded-equivalent UK band. Second, and more importantly, in December 2025 Dutch Mollie announced an agreement to acquire GoCardless for approximately US$1.1B, over 90% in Mollie shares. The deal has not closed: GoCardless's own customer FAQ still describes completion as expected in mid-2026 subject to regulatory approvals, and no completion announcement existed at the August 2026 re-verification. If the acquisition closes as announced, GoCardless will become a subsidiary of Mollie B.V. (Amsterdam, DNB-licensed EMI), shifting the primary regulatory anchor from FCA to a Dutch parent, though Mollie itself carries a US-funded cap table (TCV, General Atlantic, Blackstone, Alkeon; see Mollie's listing). Ownership signals remain in transition pending acquisition close: cloud_act_exposure: material, and no self-serve DPA, though a sub-processor list is published as a versioned PDF ("GoCardless material supplier list v2026.06", accurate as of 12 June 2026) naming 23 suppliers, among them Google Cloud, AWS, Cloudflare, Segment, Okta, Zendesk, SendGrid and LexisNexis on the US side.
Pricing in GBP is volume-tiered: Standard 1% + £0.20 (capped at £4 domestic UK), Advanced 1.25% + £0.20 (capped £5, with auto failed-payment recovery), Pro 1.4% + £0.20 (capped £5.60, with fraud protection), and Custom for >£1M annual volume. International payments run on the Wise mid-market FX engine and carry an extra 0.3% on amounts over £2,000. Branding add-ons: £50/month for bank-statement branding, £150/month for fully customised checkout. Best fit: UK and EU subscription SaaS, mid-market B2B invoicing, NGOs and membership organisations collecting recurring direct debits across multiple jurisdictions. EU procurement-grade buyers needing strict EU-controlled ownership should re-evaluate after the Mollie acquisition closes or use Mollie directly for cards/iDEAL/SEPA workflows.
Sub-processor map · 23
-
Amazon Web Services USUnited States
File storage and scale computing (data location: EU-West region)
-
Braze USUnited States
Sending operational emails
-
Celigo USUnited States
Partner connection, NetSuite integration (data location: Germany)
-
Cloudflare USUnited States
Optimisation and protection of the GoCardless website and API
-
Dun & Bradstreet USUnited States
Company credit scoring and identity verification
-
Finastra Limited USUnited Kingdom
Direct debit scheme provider software (Bacs)
-
GitHub USUnited States
Software development
-
Google USUnited States
Hosting the GoCardless Service on Google Cloud Platform and other cloud services (data location: Netherlands)
-
LexisNexis Risk Solutions USUnited States
Background and AML checks, fraud prevention
-
Looker USUnited States
Data platform and analytics
-
Mastercard Payment Services USDenmark
Payment scheme operator, chargeback processing (Betalingsservice)
-
Okta USUnited States
Employee access management and merchant authentication (2FA)
-
Provenir USUnited States
Credit decisioning
-
Segment USUnited States
Anonymous online event tracking and analytics
-
SendGrid USUnited States
Sending transactional emails
-
Zendesk USUnited States
Support ticketing software
-
Flagright non-USUnited Kingdom
Payment screening and monitoring
-
Form3 non-USUnited Kingdom
Direct debit scheme provider software (Bacs)
-
Onfido non-USUnited Kingdom
Identity verification
-
Pure JAM non-USUnited Kingdom
Support telephony service
-
Trulioo non-USCanada
Identity verification
-
Vonage USUnited States
Support telephony service
-
Wise non-USUnited Kingdom
FX services
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services | United States | File storage and scale computing (data location: EU-West region) | US |
| Braze | United States | Sending operational emails | US |
| Celigo | United States | Partner connection, NetSuite integration (data location: Germany) | US |
| Cloudflare | United States | Optimisation and protection of the GoCardless website and API | US |
| Dun & Bradstreet | United States | Company credit scoring and identity verification | US |
| Finastra Limited | United Kingdom | Direct debit scheme provider software (Bacs) | US |
| GitHub | United States | Software development | US |
| United States | Hosting the GoCardless Service on Google Cloud Platform and other cloud services (data location: Netherlands) | US | |
| LexisNexis Risk Solutions | United States | Background and AML checks, fraud prevention | US |
| Looker | United States | Data platform and analytics | US |
| Mastercard Payment Services | Denmark | Payment scheme operator, chargeback processing (Betalingsservice) | US |
| Okta | United States | Employee access management and merchant authentication (2FA) | US |
| Provenir | United States | Credit decisioning | US |
| Segment | United States | Anonymous online event tracking and analytics | US |
| SendGrid | United States | Sending transactional emails | US |
| Zendesk | United States | Support ticketing software | US |
| Flagright | United Kingdom | Payment screening and monitoring | non-US |
| Form3 | United Kingdom | Direct debit scheme provider software (Bacs) | non-US |
| Onfido | United Kingdom | Identity verification | non-US |
| Pure JAM | United Kingdom | Support telephony service | non-US |
| Trulioo | Canada | Identity verification | non-US |
| Vonage | United States | Support telephony service | US |
| Wise | United Kingdom | FX services | non-US |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications · none listed
Capability matrix
Table 2Capabilities of GoCardless
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
OpenSub-processors listgocardless.com/privacy…
Alternatives in this category
-
NetherlandsEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
FranceEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
NorwayEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |