Trustly
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Swedish open-banking A2A payment innovator (Trustly Group AB, 2008), $10B annual volume, 33+ markets; Nordic Capital + BlackRock PE owned.
Trustly offers EU hosting in Sweden, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Payments.
Assessment notes
Trustly Group AB (Stockholm, founded 2008) is the leading European open-banking 'Pay by Bank' / account-to-account payments specialist (Swedish-Finansinspektionen-supervised payment institution + UK FCA authorised + EU PSD2, ISO 27001 + SOC 2 + TÜV Saarland + GDPR certifications, ~US$10B annual processed across 275M transactions and 9,000+ merchants) but ownership is a US/Nordic PE consortium (Nordic Capital majority since 2018, BlackRock Private Equity Partners US co-investor), an IPO at ~US$10B is being explored, and the 2022 Finansinspektionen €11M AML-deficiency fine remains a flag; ownership_signal: eu_hq_us_funded, cloud_act_exposure: material; no public DPA or sub-processors list accessible at audit.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded This listing EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Trustly
Trustly is a Swedish open-banking payments innovator operated by Trustly Group AB in Stockholm, founded in 2008 and the leading European specialist in account-to-account (A2A) "Pay by Bank" transactions: the alternative payment rail that bypasses card schemes entirely by initiating direct bank transfers from consumer accounts. The company processes approximately US$10B annually across 275M transactions, connects 9,000+ merchants to 650M consumer bank accounts globally, and operates in 33+ markets across Europe and North America. Offices span Stockholm (HQ), Örebro, Gzira (Malta), London, Helsinki, Barcelona, Lausanne, Luxembourg, Lisbon, Izmir (Turkey), Ottawa, San Carlos (California), and Vitória (Brazil).
Regulatory and compliance posture is strong: Trustly holds a Swedish payment-institution licence supervised by Finansinspektionen plus a UK Authorised Payment Institution licence from the FCA, and provides cross-border services under PSD2. Certifications confirmed on the public site include ISO 27001, SOC 2, TÜV Saarland accreditation, and GDPR alignment. Open-banking expertise predates the regulatory codification: Trustly was building bank-account-to-merchant rails for 13 years before PSD2 made A2A a regulated category.
The ownership and history side complicate a procurement-grade audit. Nordic Capital (a Stockholm-based Nordic PE firm) acquired Trustly from Bridgepoint in 2018; BlackRock Private Equity Partners (US, the private-equity arm of the world's largest asset manager) joined as a co-investor. An IPO was actively explored in 2021 at a rumoured €9B valuation but was put on hold in 2022 after the Swedish Finansinspektionen imposed a SEK 130M (~€11M) fine for serious anti-money-laundering deficiencies. As of late 2024 / 2026 Nordic Capital is again exploring options including sale or IPO at approximately US$10B. The BlackRock co-investment plus the AML fine history plus non-EU offices (Ottawa, San Carlos, Izmir, Vitória) result in ownership_signal: eu_hq_us_funded and cloud_act_exposure: material despite the strong Swedish regulatory anchoring.
Pricing is enterprise / volume-negotiated; no public per-transaction tier. Best fit: Swedish, Nordic, and broader EU retailers, gambling operators (Trustly is dominant in regulated gaming), and B2B platforms wanting open-banking-native A2A rails as a Stripe / PayPal alternative.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Trustly
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
-
OpenTerms of Servicewww.trustly.com/legal-hub…
Alternatives in this category
-
NetherlandsEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
FranceEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
NorwayEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |