LINK Mobility Group
Norway · linkmobility.com · 33 vendors
Resilience scores
- Digital Sovereignty: 9
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Adobe Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Dealfront — Technology — Germany
- and 30 more
Services catalogue
3 services in catalogue across 2 categories; runs on 33 sub-vendors.
- LINK Mobility
- mobile gateway
- SMS service
Insights
Last updated 2026-07-03 · revision 2
33 direct vendors, 330 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 2
- Germany: 2
- Denmark: 2
Subvendors by controlling owner country (sample)
- Australia: 5
- Moldova: 1
- Finland: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
LINK Mobility Group exhibits high migration readiness, primarily driven by its modern and API-centric technology stack. The use of cloud platforms like Microsoft Azure and Firebase, coupled with extensive REST API integrations (e.g., MyLINK SMS API, MyLINK Email API), indicates a highly modular and flexible architecture conducive to migration. The adoption of modern programming languages and frameworks such as Python, .NET (C#), and Angular, along with key technologies like CPaaS, Generative AI (OpenAI/Gemini integration), Agentic AI, and Webhook/Callback Delivery Systems, suggests a forward-looking and adaptable infrastructure. The presence of a no-code chatbot builder also points to a platform designed for ease of deployment and integration. Explicit GDPR compliance is a positive factor, as it implies structured data handling practices that can streamline migration efforts. Despite these strengths, certain unknowns prevent a perfect score. Information on specific data residency requirements and the broader regulatory environment is not provided, which are crucial considerations for migration planning. While the tech stack is modern, it's not explicitly stated if the entire architecture is fully cloud-native, containerized, or microservices-based, which could introduce some complexities. The vendor lock-in risk remains unknown due to the conflicting vendor data (e.g., "Total Vendors: 0" vs. "Total Services: 27"), making it challenging to assess the potential for vendor-related migration hurdles. Financial stability data is also missing, which could impact the ability to fund a large-scale migration project.
Compliance
10 in-scope frameworks identified; showing 3.
ePrivacy Directive — Partially Compliant
The ePrivacy Directive (and its national implementations) is directly applicable to LINK Mobility in two critical ways: (1) as a provider of electronic communications services, LINK is subject to confidentiality of communications, traffic data, and location data requirements; (2) as a CPaaS provider enabling marketing SMS/email campaigns for 50,000+ customers, LINK's platform is used to send electronic marketing communications subject to ePrivacy consent requirements. Risk is Medium because: (1) LINK's core business (SMS/email marketing campaigns) is the primary use case regulated by ePrivacy; (2) the company explicitly references ePrivacy-related consent management in its Privacy Notice; (3) the ePrivacy Regulation (replacing the Directive) is pending and may impose stricter requirements; (4) enforcement of cookie consent and electronic marketing rules varies by member state. Partially Compliant because the company demonstrates awareness and consent management capabilities but full compliance across all 18 jurisdictions cannot be confirmed.
Evidence: https://www.linkmobility.com/legal/privacy, https://www.linkmobility.com/legal/terms-and-conditions, https://docs.linkmobility.com/regulatory-guidelines
GDPR (source) — Compliant
LINK Mobility is headquartered in Norway (EEA), operates in 18 countries across Europe, and processes large volumes of personal data as both a Data Controller and Data Processor on behalf of 50,000+ customers. The company explicitly references GDPR throughout its Privacy Notice, has appointed a named DPO (Jan Wieczorkiewicz), publishes legal bases for all processing activities, maintains Standard Contractual Clauses for non-EEA transfers, and publishes Technical and Organisational Measures (TOMs). Risk is rated Medium rather than Low because: (1) as a CPaaS provider acting as Data Processor for 50,000+ customers, LINK handles end-user personal data at massive scale including potentially special categories of data; (2) the company operates across 18 jurisdictions with varying national implementations; (3) enforcement risk is elevated given the volume and sensitivity of communications data processed; (4) any breach or non-compliance by a downstream customer could implicate LINK as processor. The company's demonstrated compliance infrastructure mitigates but does not eliminate this risk.
Evidence: https://www.linkmobility.com/legal/privacy, https://www.linkmobility.com/legal/privacy/sub-processors, https://www.linkmobility.com/legal/privacy/information-security, https://a.storyblok.com/f/151608/x/16df9e6296/toms_20nov2023.pdf, https://www.linkmobility.com/
EECC — Assessment Required
LINK Mobility explicitly self-identifies as 'a provider of electronic communications services under the European Electronic Communications Code (EECC)' in its Privacy Notice. The EECC governs providers of electronic communications networks and services across the EU. Risk is High because: (1) LINK explicitly operates under this framework; (2) EECC compliance is mandatory for electronic communications providers in all EU member states where LINK operates; (3) non-compliance can result in significant regulatory sanctions from national telecommunications regulators (e.g., Ofcom in UK, BNetzA in Germany, ARCEP in France, AGCOM in Italy); (4) EECC requirements include end-user protection, number portability, emergency services access, security obligations, and data retention; (5) LINK operates in 18 countries, each with national EECC transposition laws; (6) the company's telecommunications metadata retention obligations (referenced in Privacy Notice) directly reflect EECC/national law requirements. Assessment Required because the specific compliance status across all 18 jurisdictions cannot be confirmed from public sources.
Evidence: https://www.linkmobility.com/legal/privacy, https://docs.linkmobility.com/regulatory-guidelines, https://www.linkmobility.com/about-us, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018L1972
Financials
Three-year financials
- 2023: revenue NOK 6,300M, equity NOK 3,900M
- 2022: revenue NOK 5,548M, EBIT NOK -200M, equity NOK 4,000M
- 2021: revenue NOK 4,283M, EBIT NOK -275M, equity NOK 4,200M
Financial Resilience Score: 6/10
LINK Mobility demonstrates moderate financial resilience underpinned by strong top-line growth, a diversified enterprise customer base (~50,000+ customers with no material single-customer concentration), and structural tailwinds in enterprise messaging and CPaaS adoption across Europe. Adjusted EBITDA has grown consistently from ~NOK 508M in FY2021 to ~NOK 810M in FY2023, indicating operational leverage as the business scales. However, resilience is constrained by persistent statutory net losses driven by heavy amortization of acquired intangibles, finance costs, and FX exposure across multi-currency operations. Net interest-bearing debt has risen to ~NOK 2,400M, with net debt/adjusted EBITDA in the 3.0–3.5x range—relatively high for a growth CPaaS company. The successful 2023 bond refinancing strengthened the capital structure and represented an important milestone, but debt refinancing risk remains in a higher-rate environment. Supplier concentration (dependence on MNOs for message termination) and MNO-driven pricing pressure—particularly in Germany and France in 2022–2023—directly compress gross margins. Competition from larger, better-capitalized global CPaaS peers (Twilio, Sinch, Infobip, Bird) is a meaningful strategic risk. Overall, LINK is a growing but leveraged business with a diversified customer base and clear deleveraging path, warranting a moderate resilience score.
Key strengths: Consistent revenue growth (high single-digit organic, mid-teens reported), Growing adjusted EBITDA (NOK 508M → 810M FY21–FY23), Highly diversified customer base (~50,000+ enterprise customers, no material single customer), Strong geographic diversification across 18+ European countries, Successful 2023 bond refinancing strengthened capital structure, Light capex model (software platform), Structural growth tailwinds from A2P messaging and rich channels (RCS, WhatsApp, Viber)
Risk factors: Persistent statutory net losses since re-listing, Elevated leverage (~3.0–3.5x net debt/adjusted EBITDA), MNO price increases squeezing SMS gross margins (Germany/France), Supplier concentration with mobile network operators, Competition from larger global CPaaS players (Twilio, Sinch, Infobip, Bird), Debt refinancing risk in a higher-rate environment, FX exposure across EUR/GBP/SEK/DKK revenues and partly EUR-denominated debt, Ownership overhang from Abry Partners stake reduction, Integration and working capital costs from acquisition-driven growth
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.