Cross-border m and a italy is entering a decisive phase in 2026, as expanded foreign investment screening, converging fintech licensing rules and heightened data protection scrutiny reshape how inbound buyers approach Italian tech and financial-technology targets. For corporate acquirers, private equity sponsors and fintech founders weighing an entry into the Italian market, the difference between a clean deal and a stalled one now turns on early regulatory mapping and disciplined structuring. This practitioner guide sets out decision-ready guidance on choosing a deal structure, sequencing regulatory clearances, running targeted due diligence and governing post-merger integration for regulated fintech and technology assets.
It is written for in-house counsel and commercial decision-makers who need legal precision without the noise, and every procedural point is anchored to primary Italian and EU sources.
Quick stats and headline regulatory changes for 2026
- FDI screening expansion. Italy’s Golden Power regime has broadened in scope and sector coverage, catching more technology and fintech deals than in prior years.
- Licensing convergence. Bank of Italy supervision of payment institutions and e-money institutions increasingly intersects with change-of-control review in M&A.
- Data and AML scrutiny. The Garante (Italian Data Protection Authority) and anti-money-laundering obligations now sit at the centre of fintech diligence, not the periphery.
- Governance expectations. Buyers of regulated targets face growing expectations around board composition, reserved matters and fit-and-proper standards.
Market and Regulatory Overview for Buyers: The 2026 Snapshot
Italy remains one of Europe’s most attractive destinations for inbound technology and fintech investment, combining a large domestic consumer base, a maturing payments ecosystem and a growing pipeline of scale-up targets seeking international partners. For anyone approaching cross-border m and a italy in 2026, the commercial thesis is often sound; the execution risk sits almost entirely in the regulatory layer. Understanding which authorities have jurisdiction, and when their clearances bite, is the single most important planning task before signing.
The Italian M&A environment for tech and fintech
Buyer appetite in 2026 is driven by consolidation in payments, embedded finance, lending platforms and enterprise SaaS. Valuations have normalised from earlier peaks, and sellers increasingly accept structured consideration, earn-outs, deferred tranches and escrow arrangements, where regulatory approvals introduce timing risk. For strategic acquirers, the attraction is licensed infrastructure and customer relationships that would take years to build organically. For private equity, the draw is a fragmented market ripe for buy-and-build. In both cases, the regulated nature of fintech assets means the legal workstream cannot be treated as a downstream confirmation exercise; it shapes the deal from the first term sheet.
Key regulators and their roles
A successful cross-border m and a italy transaction in the fintech and tech sector typically engages several authorities, each with a distinct remit:
- Bank of Italy (Banca d’Italia). Prudential supervisor for payment institutions, e-money institutions and other regulated intermediaries; relevant to licensing continuity and change-of-control notifications.
- CONSOB. The securities regulator, engaged where the target is listed or where public takeover, disclosure and mandatory-offer rules apply.
- AGCM (Italian Competition Authority). Reviews merger notifications against turnover thresholds.
- Presidency of the Council of Ministers and the Ministry of Enterprise and Made in Italy. Central to the foreign investment screening and Golden Power process; the Golden Power procedure is coordinated by the Presidency of the Council of Ministers, with relevant ministries involved according to the sector concerned.
- Garante per la Protezione dei Dati Personali. The data protection authority overseeing GDPR compliance, cross-border transfers and DPIA expectations.
- EU interfaces. The European Commission’s merger and FDI frameworks sit above and alongside the Italian regimes and can be triggered in parallel.
FDI, Golden Power and how 2025–26 changes affect deals
Italy’s foreign direct investment (FDI) screening framework, commonly referred to as Golden Power, allows the government to review, condition or block acquisitions of control or significant holdings in companies operating in strategic sectors or those deemed to carry national interest. The sector scope and notification triggers have been progressively expanded, and technology and fintech assets, particularly those involving critical infrastructure, sensitive data or dual-use technology, increasingly fall within the net. Buyers should treat a Golden Power assessment as a standing item on every inbound checklist and consult official guidance from the Presidency of the Council of Ministers early.
In practice, the safest approach is to assume screening applies until analysis confirms otherwise, and to build a suspensive condition into the sale and purchase agreement accordingly.
Deal Structuring Options: Acquisition vs Joint Venture vs Greenfield
The structuring decision is where the most value, and the most risk, is created in any cross-border m and a italy deal. For fintech and tech targets, the choice between a share purchase, an asset purchase, a joint venture or a greenfield build must be made against three variables: the fate of regulated licences, the transfer of legacy liabilities, and the speed with which the buyer needs to be operational. Getting this wrong can turn a straightforward acquisition into a licensing crisis at closing.
Share purchase vs asset purchase: tax, liabilities and licences
A share purchase transfers the legal person intact. Its principal advantage for regulated fintech assets is licensing continuity: authorisations held by the target company generally survive the change of ownership, subject to change-of-control notification and, in some cases, prior consent from the relevant regulator. The trade-off is that the buyer inherits the full history of liabilities, tax exposures, regulatory breaches, employment claims and contractual obligations, even those not surfaced in diligence.
An asset purchase, by contrast, allows the buyer to identify assets and leave defined liabilities behind, reducing legacy exposure, although under Italian law the transfer of a going concern (azienda) carries certain mandatory rules on the assumption of specified liabilities, including tax and employment obligations, that cannot simply be contracted away. Licences generally do not transfer automatically with assets and may require fresh authorisation, novation or regulator consent, which can materially delay the point at which the acquired business can lawfully operate. Third-party contracts, customer agreements, processor arrangements, cloud and licensing deals, frequently contain change-of-control or assignment clauses that require counterparty consent.
For fintech assets whose core value is a live licence, an asset deal can be commercially self-defeating unless carefully engineered.
Joint venture structures for entering Italy
A joint venture (JV) offers a middle path for buyers who want market access without the full cost and risk of outright acquisition. Common structures include:
- Minority JV. The foreign investor takes a minority stake alongside a local partner, relying on contractual protections rather than control.
- 50/50 corporate JV. Equal ownership with balanced governance, deadlock mechanics and reserved matters, attractive where both partners contribute complementary assets.
- Contractual JV. A cooperation governed by contract without forming a new company, useful for time-limited or narrow-scope collaborations.
- Corporate JV. A newly incorporated Italian vehicle jointly owned, holding the combined business and any transferred licences.
A joint venture in Italy is often preferable where the target’s founders or local shareholders bring regulatory relationships, market knowledge or licence access that the buyer cannot quickly replicate, and where full acquisition would trigger disproportionate screening or integration risk. It also allows a staged commitment: the investor can test the partnership and the market before committing full capital.
Hybrid and staged acquisition strategies
Between the JV and the full acquisition sits a spectrum of hybrid and staged structures. Option-to-buy arrangements, put and call mechanics and phased equity purchases allow a buyer to acquire an initial stake, secure governance rights, and increase ownership over time as regulatory approvals are obtained or performance milestones are met. This is particularly useful in cross-border m and a italy transactions where Golden Power or Bank of Italy clearance introduces uncertainty: the buyer can secure economic exposure and control rights while deferring the steps that require clearance until conditions are satisfied.
Care is needed, however, to ensure that governance and option rights secured at the first stage do not themselves amount to an acquisition of control that triggers screening or notification obligations prematurely.
When to use earn-outs and escrow for regulatory-contingent exposures
Where regulatory approvals, licence transfers or unresolved compliance items create contingent risk, earn-outs and escrows allow parties to bridge valuation gaps and allocate risk sensibly. A portion of consideration can be held in escrow pending confirmation that a licence has transferred cleanly or that a regulatory remediation has been completed. Earn-outs can tie deferred consideration to the target retaining its authorisation or achieving post-closing performance. These tools are not merely commercial niceties in the fintech context, they are risk-management instruments that keep a deal financeable while approvals remain outstanding.
| Criteria | Acquisition (share/asset) | Joint Venture | Greenfield (new set-up) |
|---|---|---|---|
| Speed to market | Fast, target already operational | Moderate, depends on partner alignment | Slow, build from scratch |
| Control | High (full or majority) | Shared, governed by contract | Full |
| Regulatory approvals | FDI, merger control, sectoral consents likely | May reduce FDI/merger triggers depending on stake | Fresh licensing from first principles |
| Licensing continuity | Preserved in share deal; uncertain in asset deal | Depends on which entity holds the licence | New authorisation required |
| Cost and capex | High upfront | Shared with partner | Lower upfront, higher over time |
| Execution risk | Legacy liabilities; clearance timing | Partner and deadlock risk | Market-entry and ramp-up risk |
| Cultural integration | Demanding, two organisations merge | Ongoing partnership management | Minimal, single culture from start |
| Best when | Target holds valuable live licences and market share | Local partner brings regulatory access or knowledge | No suitable target; buyer wants full control of build |
Regulatory Approvals and Licensing: A Stepwise Playbook for Cross-Border M&A Italy
The regulatory workstream is the critical path in most fintech transactions. The following stepwise playbook sets out the principal clearances relevant to a cross-border m and a italy deal, the triggers to watch, and the practical drafting steps that keep the transaction protected while approvals are pending. Timelines below are general planning guidance; verify current thresholds and procedures against the cited primary sources for each deal.
FDI and foreign investment screening
Under Italy’s Golden Power regime, acquisitions of control or significant holdings in strategic sectors, or in companies with national interest characteristics, trigger a notification and clearance requirement. The scope and thresholds have been expanded in recent years, drawing in more technology and fintech targets. Buyers should notify the relevant government authorities as required and should assume a multi-week to multi-month review window where remedies or conditions are contemplated. The practical rule: identify FDI exposure before signing, build a suspensive condition into the SPA, and do not complete transfer steps until clearance is obtained.
AGCM merger control
Where the applicable turnover thresholds are met, the transaction must be notified to the AGCM for pre-merger clearance. Straightforward deals meeting the criteria for a simplified (short-form) procedure can move faster, while transactions raising competition concerns face a fuller Phase II review over a longer period. Buyers should assess notifiability early, prepare the notification in parallel with due diligence, and include a merger-control condition precedent where clearance is required before closing. Consult AGCM guidance for the current thresholds and procedural steps applicable to your transaction.
Bank of Italy and sectoral licences
For fintech targets, the Bank of Italy is often the most consequential regulator. Payment institutions, e-money institutions and other authorised intermediaries are subject to change-of-control rules: the acquisition of a qualifying holding in a licensed entity typically requires prior authorisation from the Bank of Italy, and fit-and-proper assessment of the proposed acquirer. PSD2-derived requirements around payment services, safeguarding of client funds and operational resilience must be assessed against the target’s authorisation. A buyer should confirm the exact scope of the target’s licence, the fit-and-proper requirements applicable to new controllers, and whether the acquisition requires supervisory clearance before completion. Where prior authorisation is needed, this becomes a condition precedent, not an afterthought.
CONSOB triggers
Where the target is listed or has publicly traded securities, CONSOB rules on public takeovers, insider information and mandatory offer thresholds may apply. Crossing a mandatory-offer threshold can compel a bid for remaining shares, and disclosure obligations attach to the acquisition of significant holdings. Buyers of listed fintech targets must map these obligations at the term-sheet stage, since they materially affect deal cost and structure. Refer to CONSOB guidance and the Consolidated Law on Finance (TUF) for the applicable thresholds and disclosure timing.
Data protection and cybersecurity
Fintech businesses process substantial volumes of personal and financial data, making GDPR compliance a core diligence and closing item. The Garante’s guidance is relevant to cross-border data transfer mechanisms, data protection impact assessments (DPIAs) and the handling of personal data during the transaction itself. A buyer should verify that the target has valid transfer mechanisms for any international data flows, that DPIAs exist where required, and that customer information and notification frameworks are sound. Unresolved data issues should either be remediated before closing or made the subject of a specific condition or indemnity.
AML and KYC obligations
Anti-money-laundering (AML) and know-your-customer (KYC) obligations are central to any fintech transaction. Regulated targets must maintain robust customer due diligence, transaction monitoring and reporting of suspicious transactions to the Financial Intelligence Unit for Italy (UIF), which operates within the Bank of Italy. Buyers should assess the maturity of the target’s AML framework, review any past regulatory correspondence on compliance failings, and confirm source-of-funds diligence on the transaction consideration itself. AML weaknesses are both a regulatory red flag and a licensing risk.
Action items: pre-signing filings and conditionality drafting
- Map all regulatory triggers, FDI, AGCM, Bank of Italy, CONSOB, before drafting the SPA.
- Draft suspensive conditions precedent for each required clearance, with clear responsibility and cost allocation.
- Agree interim covenants restricting the target from taking actions that could jeopardise licences or clearances between signing and closing.
- Prepare notifications in parallel with diligence to avoid post-signing delay.
- Build long-stop dates that realistically reflect multi-month review windows.
Targeted Due Diligence and Regulatory Compliance for Fintech and Tech
Due diligence in a cross-border m and a italy fintech deal must be sharper and more technical than in a conventional acquisition. The value of the target sits in its licences, its technology and its data, and each of these carries specific red flags that generic corporate diligence will miss. The following areas deserve dedicated workstreams.
Legal and regulatory due diligence
Confirm the full scope and validity of every licence and authorisation the target holds, and review all regulatory correspondence for open enquiries, warnings or remediation orders. Verify fit-and-proper standing of key personnel and any conditions attached to authorisations. Corporate records, shareholder registers and filings can be verified through the Business Register (Registro delle Imprese). Any gap between the licence the target claims to hold and the activities it actually conducts is a material red flag.
Technical due diligence
Assess the target’s technology stack, code ownership and dependencies. Review code escrow arrangements, SaaS and licensing contracts, cloud infrastructure and the geographic location of data, and the resilience of critical APIs and third-party integrations. Concentration risk, over-reliance on a single cloud provider, processor or upstream API, should be identified and priced.
Data protection and security due diligence
Examine cross-border transfer mechanisms, the existence and adequacy of DPIAs, breach history and incident response capability, and the contractual terms governing third-party processors. A history of unreported breaches or absent transfer safeguards is a closing-condition matter.
Financial and commercial due diligence
For payments and lending businesses, scrutinise merchant and acquiring arrangements, payment service provider (PSP) pipelines, revenue concentration and the quality of recurring income. Understand how the economics change if a key commercial relationship terminates on change of control.
Contractual due diligence
Review customer service-level agreements, change-of-control and assignment clauses, termination rights and any provisions that could be triggered by the transaction. Change-of-control clauses in key customer or supplier contracts can materially alter deal value and must be identified before signing.
Corporate Governance, Employment and Post-Merger Integration in Italy
Closing a deal is the beginning, not the end. For regulated fintech targets, corporate governance in Italy and post-merger integration determine whether the acquisition delivers its thesis. Governance remedies protect the investor’s position, employment rules protect the workforce and integration discipline preserves the value that justified the price.
Governance mechanics for regulated targets
The Italian Civil Code (Codice Civile) governs corporate forms, board composition and the transfer of shares and quotas, and it provides the framework within which investors negotiate protections. For minority positions and joint ventures, investors should insist on reserved matters requiring their consent, veto rights on strategic decisions, board appointment rights, approval thresholds for capital raises and disposals, and clear exit mechanics such as drag-along, tag-along, put and call rights. For regulated entities, board composition must also satisfy supervisory expectations, and reserved matters should be drafted so that the investor cannot inadvertently be treated as exercising control that triggers additional regulatory obligations.
Where the interpretation of statutory governance rules is finely balanced, buyers should take specific Italian counsel before finalising the shareholders’ agreement.
Employment law and employee transfer rules
Italian employment law affords significant protections to employees, including the rules on the transfer of undertakings under Article 2112 of the Civil Code, which can carry employee relationships across to a buyer on existing terms, together with obligations around information and consultation with employee representatives and applicable collective bargaining structures. In an asset deal in particular, the transfer of the business unit (ramo d’azienda) can automatically transfer the associated workforce. Buyers should map headcount, collective agreements, consultation obligations and any retention exposure early, and should factor consultation timelines into the closing plan.
Integration milestones
Post-merger integration for a regulated fintech asset follows a distinct sequence: confirm licence continuity and complete any post-closing regulatory notifications, harmonise compliance frameworks and AML systems, integrate IT and data infrastructure in a manner that preserves data protection compliance, and align legal and contractual arrangements. Each milestone should have an owner and a deadline, and compliance remediation identified in diligence should be tracked to completion.
Cultural and retention tactics for tech teams
The people are frequently the asset. Founders, engineers and compliance leads carry institutional knowledge and regulatory relationships that cannot be bought separately. Retention packages, earn-out participation, clear role definitions and sensitive handling of cultural integration protect against the value erosion that follows key-person departures. In fintech, losing the individuals who hold the target’s regulatory relationships can be as damaging as losing the licence itself.
Tax, Cash Repatriation and Structuring Pitfalls
Tax structuring should be settled before signing, not reverse-engineered afterwards. Cross-border transactions carry withholding, permanent-establishment and interest-deductibility considerations that can materially affect after-tax returns and the efficiency of cash repatriation.
Common tax traps in acquisitions
The choice between an asset deal and a share deal has significant tax consequences. Asset deals may offer a step-up in the tax basis of acquired assets but can attract registration and transfer taxes, while share deals preserve historic tax positions, including latent exposures. Buyers should model both structures on an after-tax basis, assess permanent-establishment risk arising from the acquisition and integration model, and consider the interest-deductibility limits applicable to debt-funded structures under Italian and EU rules.
Repatriation mechanisms and timing
Plan cash repatriation, through dividends, interest or intra-group arrangements, at the structuring stage, taking account of withholding tax, applicable double tax treaty relief and relevant EU directives affecting cross-border flows. Timing matters: distributable reserves, regulatory capital requirements applicable to licensed entities and safeguarding obligations can all constrain the movement of cash out of a regulated fintech target.
Practical Deal Checklist and Templates
Use the following quick-reference checklist to keep a cross-border m and a italy fintech transaction on track from term sheet to integration.
Pre-signing
- Map FDI/Golden Power exposure and confirm notification requirements against current official guidance.
- Assess AGCM merger-control notifiability against current thresholds.
- Confirm the target’s licence scope and Bank of Italy change-of-control requirements.
- Complete legal, regulatory, technical, data and financial due diligence.
- Select the structure (share, asset, JV, hybrid) and confirm tax treatment.
Signing to closing
- File all required regulatory notifications and track clearance progress.
- Satisfy conditions precedent and observe interim operating covenants.
- Complete employee information and consultation obligations.
- Finalise escrow and earn-out mechanics for contingent exposures.
Post-closing
- Complete post-closing regulatory notifications and any licence re-approvals.
- Execute the integration plan against defined milestones and owners.
- Complete compliance remediation identified in diligence.
- Implement retention and governance arrangements.
Conclusion
Cross-border m and a italy in the fintech and technology sector rewards buyers who treat the regulatory workstream as central rather than incidental. In 2026, expanded FDI screening, converging licensing supervision, sharper data protection scrutiny and evolving governance expectations mean that structure, clearances and diligence must be planned together from the first term sheet. Choose the structure that fits the target’s licence profile and liability history, sequence FDI, merger control, Bank of Italy and CONSOB clearances into the transaction timeline, run technically rigorous due diligence, and govern integration with the same discipline as the deal itself. Buyers who do so convert Italy’s commercial opportunity into a clean, defensible transaction.
This guide is general information and not legal advice; before acting on any point, obtain advice tailored to your specific transaction.
Need Legal Advice?
This article was produced by Global Law Experts. For specialist advice on this topic, contact Andrea Marchetti at WH Partners, a member of the Global Law Experts network.
Sources
- Normattiva, Italian Legislation Portal (Codice Civile & Company Law)
- Presidency of the Council of Ministers, Golden Power / Foreign Investment Screening
- Ministry of Enterprise and Made in Italy
- Bank of Italy (Banca d’Italia), Prudential Supervision & Payment Services
- Italian Competition Authority (AGCM), Merger Control Guidance
- CONSOB, Commissione Nazionale per le Società e la Borsa
- Garante per la Protezione dei Dati Personali, Italian Data Protection Authority
- Registro delle Imprese / InfoCamere, Business Register
- European Commission, Merger Control


Italy

