I'd always assumed that the only party who can correlate transactions made with the same card is the card issuer.
Is this capability a feature introduced by EMVCo tokenization, or is it made possible by some earlier protocol?
(This may be of dubious legality under GDPR.)