Worldline
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
French payment giant (Worldline SA, Paris-listed WLN), #4 PSP worldwide, 18k employees, free float ~73% anchored by Bpifrance and French banks.
Worldline is a European service hosted in France, with at most minor, transient US exposure under the CLOUD Act. It is listed under Payments.
Assessment notes
Worldline SA (Paris la Défense, French SA carved out of Atos in 2014 and fully independent since 2022 when Atos divested its remaining stake) is publicly listed on Euronext Paris (WLN) with ownership_signal: eu_owned, the world's #4 payment-services provider with 1.4M+ merchant clients across 170+ countries, 18,000 employees, and a deep certification stack (ISO 9001 + 14001 + 22301 + 27001:2022 + ISAE 3402 + ISAE 3000 + PCI-DSS). Since the ~€500M March 2026 capital increase the register is no longer near-total free float: Bpifrance Participations 9.6%, Crédit Agricole SA 9.5%, BNP Paribas 7.9% plus SIX Group (diluted from 10.5%) together hold 27.5% of capital and 36.6% of voting rights, leaving a free float of roughly 73%. That anchor block is French state and French banking capital, so it reinforces rather than weakens the EU-ownership case. The published subcontractor list names no US entity, so cloud_act_exposure: minor holds on the unavoidable global card schemes alone.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Worldline
Worldline is the largest French and one of the largest European payment-services providers, operated by Worldline SA at Tour Voltaire, 1 Place des Degrés, 92059 Paris la Défense Cedex. Founded in 2014 as a carve-out from Atos and trading as WLN on Euronext Paris, the company became fully independent of Atos in 2022 when the latter completed the sale of its remaining stake; as of 2026 the free float is roughly 73% with no single controlling shareholder: after the March 2026 capital increase, Bpifrance Participations (9.6%), Crédit Agricole SA (9.5%), BNP Paribas (7.9%) and SIX Group together hold 27.5% of the capital and 36.6% of the voting rights, an anchor block of French state and French banking capital. The product spans in-store, online, and omnichannel payment acceptance plus an issuing-and-acquiring stack for banks, cross-border services, open-banking infrastructure, and digital-currency rails, serving 1.4M+ merchant clients across 170+ countries with ~18,000 employees and a #4 global PSP ranking by volume.
Compliance posture is exceptional and oriented to regulated industries and public-sector procurement. Worldline carries ISO 9001:2015 (quality management), ISO 14001:2015 (environmental), ISO/IEC 27001:2022 (information security), ISO 22301:2019 (business continuity), ISAE 3402 and ISAE 3000 assurance reports (the audit framework used by financial-services suppliers globally), and PCI-DSS at the highest tier. National-grade certifications across many of its 170+ operating countries are also in place. The corporate compliance page makes the regulated-supplier story explicit; recent activity (May 2026) includes the finalisation of the Electronic Data Management divestment to SIX (Swiss financial-markets infrastructure) and a March 2026 rights issue, both signs of an active restructuring posture under the post-Atos independent governance.
Pricing is enterprise-grade and negotiated; no consumer-grade pricing page applies. Worldline sells through its Merchant Services, Financial Services, and Mobility & e-Transactional Services divisions and is the recommended choice for EU public-sector procurement, banks, retailers operating across multiple EU markets, and any organisation needing a Euronext-listed, fully-independent French alternative to US PSPs. Together with Adyen (NL), Worldline rounds out the directory's two-pillar EU public-listed-PSP shortlist; Mollie (NL) sits below them as the SMB / DNB-licensed e-money option.
Sub-processor map · none disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Worldline
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
NetherlandsEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
FranceEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: No -
-
NorwayEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |