A recently announced bank-fintech joint venture in the Greek market offers a useful case study in three regulatory issues that any embedded finance structure operating in the EU now needs to confront: how the product is classified, who in the merchant chain needs a license, and how much of today’s compliance build will survive the next eighteen months of EU legislative change.

Embedded finance — the practice of offering credit, payments, or insurance products at the point of sale through a non-financial merchant’s own channel — has become one of the fastest-growing categories of retail financial services in Europe. A recently announced 50/50 joint venture between a major Greek bank and an Estonian fintech platform, structured to launch Buy Now Pay Later (BNPL), sales finance, and consumer lending products in Greece, illustrates why the legal groundwork for such ventures is considerably more complex than the commercial rationale suggests. Three issues in particular deserve close attention from any institution structuring, partnering in, or plugging into an embedded finance platform: regulatory classification, credit intermediation licensing exposure across the merchant ecosystem, and the transitional risk created by two major pieces of EU legislation currently in motion.

  1. Regulatory Classification Is the Threshold Question — and It Is Not Self-Evident

Before any conduct-of-business rule can be applied, a foundational question must be answered: under which legal regime does the product actually sit? This is not a formality. The answer determines applicable capital adequacy requirements, the competent supervisory authority, reporting obligations, and whether the entity falls within the open banking and strong customer authentication regime at all.

In the Greek transaction referenced above, the parties elected to pursue authorization as a “Credit Company” under Article 153 of Law 4261/2014 — the general banking law — rather than as a payment institution or electronic money institution under Law 4537/2018, which transposes the revised Payment Services Directive (PSD2). That is a deliberate structuring choice with real consequences. A payment institution license would bring the entity within the EBA’s PSD2 register, subject it to strong customer authentication obligations, and expose it to the interoperability requirements — including mandatory API access for third-party providers — that define open banking. A Credit Company authorization sits outside that regime entirely, with a different capital and supervisory framework attached.

This classification exercise becomes genuinely difficult when the underlying product is structurally hybrid, as BNPL and embedded lending products typically are. Regulatory commentary on Germany’s implementation of the new EU Consumer Credit Directive is instructive here: whether an arrangement is treated as credit intermediation (triggering a licensing requirement) or as the supplier’s own point-of-sale financing (triggering only a lighter registration obligation) turns entirely on the specific structure of the deal — who is the consumer’s contracting counterparty, who bears the credit risk, and whether payment claims are assigned to a third party. Two commercially indistinguishable BNPL products can therefore fall under entirely different licensing regimes purely as a function of contractual architecture. For a multi-product embedded finance platform, this means classification is not a one-time exercise completed at incorporation; each product line — BNPL, sales finance, consumer credit — may need to be independently tested against multiple possible characterizations, and the answer may diverge across jurisdictions if the platform later expands beyond its initial market.

You can read the article on Lexology here: Embedded Finance in Greece: Regulatory Classification, Credit Intermediation Risk, and a Moving Compliance Target – Lexology