Pages

▼

Wednesday, 7 October 2026

The interplay between corporate transparency and personal data protection: A new stage in the CJEU’s case law

 



Dr Samira Allioui, Centre d'études internationales et européennes, Université de Strasbourg

Photo credit: Alexas Fotos, via Wikimedia Commons

On 3 September 2026, the Court of Justice of the European Union (the Court) delivered its judgment in Case C-798/24, Jautiva, addressing the compatibility of unrestricted public access to shareholder information with European Union (EU) company law and data protection rules. The CJEU ruled on the conflict between, on the one hand, the right to the protection of personal data and, on the other, national legal provisions—derived from European Union law—requiring the public disclosure of information regarding the shareholders of public limited companies. The Jautiva case addresses precisely where that boundary lies. This approach is not new; it follows on from the WM and Sovim judgment of 2022 (Joined Cases C‑37/20 and C‑601/20), in which the CJEU had already called into question public access to ultimate beneficial owner (UBO) registers and where the judges had already cast doubt on unrestricted public access to beneficial ownership registers.

WM and Sovim SA v. Luxembourg Business Registers (LBR): an ode to business confidentiality?

As a reminder, in the WM and Sovim judgment, the CJEU had already called into question public access to registers of beneficial owners. The judgment represented a serious setback to European Union efforts to promote fiscal and financial transparency and to enhance the effectiveness of the fight against money laundering. Making beneficial ownership registers public was one of the key tools for identifying a company’s true owner and, in doing so, lifting (at least in part) the veil on illicit schemes that facilitate money laundering and tax evasion.

The cases in question concerned the transposition into Luxembourg law of Article 30(5), first subparagraph, point (c) of the 2015 money laundering Directive, as amended in 2018 (the Fifth Anti-Money Laundering Directive or "5AMLD"). In accordance with 5AMLD, the legislation had structured the Luxembourg Register of Beneficial Owners (RBE) so that information regarding the beneficial owners of registered entities could be stored and made available; access to this data was open to any member of the general public. In certain exceptional circumstances and on a case-by-case basis, a beneficial owner or registered entity could request the register administrator—LBR—to restrict access to specific authorities or entities. After a beneficial owner and a company challenged decisions by the LBR rejecting their requests to restrict public access to information concerning them, the referring court—the Luxembourg District Court—considered that the disclosure of such information could entail a disproportionate risk of infringing the fundamental rights of the beneficial owners concerned. It therefore asked the Court, inter alia, to verify the validity of the EU provisions regarding access to information on beneficial owners.

The Court first noted that, since the data in question includes information on identified natural persons—namely the beneficial owners of companies and other legal entities established within the territory of Member States—access to that data by any member of the general public infringes the fundamental right to respect for private life.

Furthermore, making such data available to the general public constitutes the processing of personal data. Such disclosure represents a serious interference with the fundamental rights enshrined in Articles 7 and 8 of the EU Charter of Fundamental Rights (CFR), given the potential for subsequent use of the disclosed information.

Admittedly, the Court had already had the opportunity to point out that certain data processing operations—even those that do not reveal significant information about individuals' private lives—can nonetheless constitute an infringement of their privacy when the data, taken as a whole, expose individuals to a "risk of profiling." However, it is important to point out that in those cases, the Court reached this conclusion either by highlighting the “sensitive nature of the information that such data may reveal” or because the data in question made it possible to draw very precise conclusions regarding the individuals’ daily habits, activities, and social relationships (the Digital Rights judgment, para 27).

However, as Advocate General Pitruzella noted in his Opinion on the case (at para 101), the risk of profiling enabled by the public nature of the registers was limited, both because it was not possible to conduct searches by individual and because identifying a person’s investments provides only a limited insight into their assets.

The concept of "legitimate interest": an inadequate remedy for the lack of public access to registers in WM and Sovim SA

When examining the justification for this interference, the Court confirmed that the provision regarding public access to the information complies with the principle of legality, does not infringe the essence of the fundamental rights, pursues an objective of general interest, and can be considered appropriate for achieving that objective.

However, the Court held that the interference could not be considered limited to what is strictly necessary. In this regard, the Court compared the amended provisions with the previous provision, which required organizations or individuals to demonstrate a "legitimate interest" before gaining access to information on beneficial owners. Furthermore, the Court held that any difficulty in precisely defining the circumstances and conditions under which such a "legitimate interest" arises does not justify the EU legislature providing the general public with access to that information.

In addition, the Court emphasized that the interference at issue is not proportionate stricto sensu. Thus, the optional provisions allowing Member States to make information on beneficial owners available subject to online registration and to provide, in exceptional circumstances, for an exemption from public access to that information are not, in themselves, capable of demonstrating either a fair balance between the general interest objective pursued and the fundamental rights enshrined in Articles 7 and 8 of the Charter of Fundamental Right (CFR), or the existence of sufficient safeguards enabling the persons concerned to effectively protect their personal data against the risk of abuse.

Consequently, the amended point (c) of the first subparagraph of Article 30 of the AML Directive—which requires Member States to ensure that information on the beneficial owners of companies and other legal entities incorporated within their territory is accessible to any member of the general public in all circumstances—is invalid.

The Court emphasized that the EU legislature had not struck the right balance regarding the fight against money laundering. There were fears at the time that this would "have fraudsters rubbing their hands with glee," and these rulings sparked anger among activists, who were shocked that a court would side with the leaders of tax havens at the expense of public transparency. Others, however, maintained that this represented a victory for data protection and the rule of law within a highly politicized context.

While in WM and Sovim SA v LBR, the Court annulled the 5AMLD provision granting the public access to beneficial ownership registers, Jautiva applies the same logic to a different dataset: declarations by shareholders of public limited companies.

Following the WM and Sovim judgment, several registers went beyond what the ruling required by withdrawing entire datasets. In several Member States, this practice remained effectively suspended while national regimes based on "legitimate interest" were being established.

Background of the Jautiva case: a clarification of public access to shareholder information

The Jautiva case arose when 17 minority shareholders of a public limited company challenged legislation requiring shareholder information to be made publicly available online. For natural persons, this information included their identity and contact details, as well as the class, number, and nominal value of the shares held and the associated voting rights. This information was accessible to unidentified users and could therefore be downloaded in bulk.

To justify this disclosure regime, Latvia cited three main objectives: preventing money laundering and the financing of terrorism and proliferation; ensuring a transparent economic environment and protecting third parties; and facilitating compliance with national, international, and EU sanctions.

To determine whether EU company law required such disclosure and whether unrestricted access was compatible with the GDPR (Articles 7 and 8 of the CFR), the Latvian Constitutional Court referred the matter to the Court. In its request, the Constitutional Court, among others, sought clarification, as to whether EU company regulation requires information on every shareholder of a joint-stock company to be made publicly available and whether such disclosure of personal data is permissible under the GDPR.

Article 14 of the Company Law Directive requires the disclosure of information concerning certain persons who represent a company or participate in its administration, supervision, or control. In its reasoning, the Court rejected the argument that this concept extends to any shareholder. Indeed, whereas persons involved in the administration or supervision of a company are appointed to specific roles and exercise corresponding powers, shareholder status derives from holding a stake in the share capital. In particular, minority shareholders do not exercise management or supervisory functions simply by virtue of holding shares, nor do they generally represent the company or bind it in dealings with third parties. The Court therefore concluded that the Company Law Directive does not require information concerning every shareholder to be made available to the public.

Disproportionate access but legitimate objectives

Next, the Court examined whether Latvia could nonetheless provide for unrestricted public access under its national law. While the objectives cited by Latvia could constitute legitimate objectives of general interest, this did not exempt the disclosure regime itself from meeting the requirements of necessity and proportionality laid down in the GDPR and the CFR.

The Court held that such public disclosure constituted a serious interference with the rights protected by Articles 7 and 8 of the CFR. The information made public could enable the creation of a profile regarding a person’s financial situation, the sectors in which they invest, and the companies in which they hold shares. These concerns were heightened by the fact that the information was accessible online to a potentially unlimited number of people and could subsequently be stored and disseminated (§71).

In light of recent events in Latvia, where several public databases were subjected to cyberattacks and large-scale personal data breaches, the observation made by the Court in paragraph 72 is particularly relevant:

"The potential consequences for the data subjects resulting from any misuse of their data are aggravated by the fact that, once such data have been made accessible to the public, they can not only be freely consulted but also stored and disseminated, and that, in the event of such successive processing operations, it becomes increasingly difficult—if not impossible—for those persons to defend themselves effectively against misuse."

Regarding corporate transparency

The Court considered that the disclosure of information concerning all shareholders—particularly minority shareholders who do not exercise management or control functions—did not appear necessary for the protection of third parties.

Objectives related to combating money laundering and complying with sanctions regimes did not justify unrestricted access either. Given the existence of less intrusive solutions—such as limiting access to persons who can demonstrate a legitimate interest and, for sanctions purposes, adopting more targeted disclosure methods—the existence of a recognized public interest objective does not, in itself, justify making personal data freely accessible to everyone.

Necessity and proportionality

In WM and Sovim v LBR, the Court held that unrestricted public access to beneficial ownership information constituted a serious interference with the rights protected under Articles 7 and 8 of the CFR and went beyond what was strictly necessary for AML purposes.

Jautiva applies the same proportionality considerations in the context of registered shareholders which is relevant in particular for minority shareholders who may neither qualify as beneficial owners under applicable thresholds nor exercise control over the company. The judgment does not prevent Member States from maintaining company registers or providing access to shareholder information. However, it does confirm that the manner in which personal data are made available must remain consistent with the GDPR principles of purpose limitation, data minimisation and proportionality. It should be noted that Directive 2024/1640, part of the sixth money laundering package (adopted after the WM and Sovim judgment), already provides for access to beneficial ownership information by members of the public who can demonstrate a legitimate interest, alongside the access available to competent authorities and obliged entities. In other words, the current EU AML framework has already moved towards a more restricted model of access.

Legitimate interest and the limitations surrounding access to ownership-related personal data

Jautiva confirms that access to such information cannot be treated as unlimited and remains subject to the requirements of necessity, proportionality and data protection. Here, the Court reiterates that transparent is not an end in itself by holding that the Company Law Directive does not require the disclosure of information relating to all shareholders, including minority shareholders. In addition to that, it held that the GDPR precludes national legislation making personal data relating to shareholders of public limited liability companies available to the general public where access is not subject to any conditions, such as demonstration of a legitimate interest.

It is surprising that the legitimacy of the objectives provided by Latvian law has not been called into question. More precisely, Latvian law provided for public access to data concerning all shareholders of a public limited company, including minority shareholders, for the purposes of combating money laundering, terrorist financing and the proliferation of weapons of mass destruction, as well as implementing international and European sanctions.  

The dual scope of the decision

First, it should be noted that the tools available to obliged entities to fulfil their due diligence obligations, and to competent authorities, are not called into question by the judgment. Second, the imposition of sanctions or the pursuit of AML/CFT objectives does not justify unlimited public access. Indeed, the Court advocates instead for the implementation of differentiated access regimes based on the objective pursued and the status of the requester. However, it is worth considering who will henceforth be able to claim a legitimate interest justifying access to this information.

By confirming that the disclosure obligations imposed by European Union company law cannot be interpreted as automatically extending to information concerning all shareholders—and that national measures providing for broader public access to such information remain subject to the GDPR as well as the principles of necessity and proportionality—the Jautiva judgment marks a new milestone in Court case law regarding the interplay between corporate transparency and the protection of personal data.

Conclusion

Given that these are distinct legal categories—potentially entailing different obligations regarding access, reporting, and disclosure for investors, international groups, and companies—the judgment underscores the importance of clearly distinguishing between the exercise of corporate functions, the holding of shares, the exercise of control, and the status of beneficial owner.

On the one hand, the judgment clarifies that a national regime authorizing unlimited and unconditional online access to the personal data of all shareholders must meet a strict test of necessity and proportionality. On the other hand, the judgment provides an important clarification regarding corporate transparency: EU law does not require the public disclosure of information concerning every shareholder of a public limited company simply by virtue of their status as a shareholder.

More specifically, the significance of this judgment does not lie in pitting the protection of privacy against transparency as mutually exclusive values. Rather, the judgment requires that any disclosure obligation be based on a legal basis and remain proportionate to the objective pursued.

No comments:

Post a Comment