Mollie
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Amsterdam-based DNB-licensed payments platform: strong European payment methods (iDEAL, SEPA), 250k+ merchants; US-VC-funded cap table.
Mollie offers EU hosting in the Netherlands, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Payments.
Assessment notes
Amsterdam-headquartered Mollie B.V. is a De Nederlandsche Bank-licensed electronic-money institution (EMI) regulated under PSD2 with PCI DSS Level 1, EU data-residency commitment, and one of the strongest European Stripe-alternative product surfaces (iDEAL, SEPA, cards, PayPal, in-person Tap to Pay, recurring); however the 2021 US$800M growth round brought TCV, General Atlantic, Blackstone, and Alkeon (all US PE/VC) onto the cap table: material US-funded ownership exposure (ownership_signal: eu_hq_us_funded, cloud_act_exposure: material) despite the strong regulatory and technical posture; a public self-serve DPA is now live but covers only the Invoicing and Disputes services, and its Annex B names Google Cloud Platform, Rapyd and OPSWAT (US-owned) among the sub-processors, so the score stays at 3.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded This listing EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Mollie
Mollie is the Amsterdam-headquartered European payments platform operated by Mollie B.V., authorised by De Nederlandsche Bank (the Dutch central bank) as an electronic-money institution (EMI) under PSD2. Founded in 2004 by Adriaan Mol, the company serves more than 250,000 businesses with a product surface covering online payments (cards, PayPal, SEPA Direct Debit, iDEAL, Bancontact, Klarna, etc.), in-person payments (terminals, Tap to Pay on iPhone), payment links, recurring/subscription billing, invoicing, and a business account. The developer experience is considered one of the strongest in the European Stripe-alternative space, with ready libraries for JavaScript, PHP, .NET, and Python and a long list of e-commerce-platform integrations.
For an EU-sovereignty audit, the listing's structural tension is the cap table. Mollie is genuinely Dutch-incorporated, DNB-regulated, GDPR-aligned, PCI DSS Level 1 certified, and commits to processing and storing payment data within European data centres under EU privacy law: all strong procurement-grade signals. But in June 2021 the company closed a US$800M growth round at a ~US$6.5B valuation, with TCV, General Atlantic, Blackstone, and Alkeon Capital (all US private-equity / late-stage growth funds) joining alongside existing European backers. The resulting cap table is heavily US-funded (ownership_signal: eu_hq_us_funded, cloud_act_exposure: material), meaning ownership-jurisdiction exposure under a strict CLOUD Act stance even though the operating entity, DNB licence, and customer-data infrastructure sit firmly in the Netherlands. Mollie remains a strong technical and regulatory choice, but procurement teams with strict ownership-chain requirements should know that the controlling capital is largely US.
Pricing is transaction-based and EU-buyer-friendly: Visa/Mastercard EEA Consumer at 1.80% + €0.25, American Express at 2.90% + €0.25, SEPA Direct Debit at €0.35 per transaction, PayPal pass-through plus €0.10, free up to 5 payouts/month, no monthly fee on the standard tier (Pay as you go), and a Pro tier at €20/month with lower variable rates. Volume customers (>€100k/month) get tailored rates. Best fit: Dutch and broader Benelux + DACH SMBs and mid-market merchants who need iDEAL and Bancontact natively, e-commerce platforms wanting a Stripe alternative with European payment-method depth, and SaaS billing teams comfortable with a US-funded but EU-regulated counter-party.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Mollie
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
NetherlandsEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
FranceEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
NorwayEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |