CJEU - C-798/24 - Jautiva
CJEU rules against public access to all shareholder data, citing GDPR.
Summary
The Court of Justice of the European Union (CJEU) has ruled that national legislation requiring public access to the personal data of all shareholders, including minority shareholders, is not compliant with GDPR. The court emphasized that such broad disclosure constitutes a serious interference with fundamental rights and is not always necessary or proportionate, especially when minority shareholders do not actively participate in company management. Less intrusive measures, like limiting access to those with a legitimate interest, are preferred.
Full text
Help CJEU - C-798/24 - Jautiva: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 10:26, 8 September 2026 view sourceLs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators396 editsTag: Visual edit← Older edit Revision as of 12:57, 8 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators303 editsTag: Visual editNewer edit → Line 105: Line 105: <u>Directive 2017/1132</u><u>Directive 2017/1132</u> The Court first held that Article 14(d) Directive 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorized to represent or bind the company or perform management or supervisory functions.The Court first held that Article 14(d) Directive 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. <u>Legal basis</u><u>Legal basis</u> The Court recalled that any processing must comply with the principles under [[Article 5 GDPR]] and satisfy one of the lawful bases under [[Article 6 GDPR]]. Since the disclosure was required by national law, the processing had to be assessed under [[Article 6 GDPR|Article 6(1)(c) GDPR]]. Pursuant to [[Article 6 GDPR|Article 6(3) GDPR]], the legal basis must pursue an objective of public interest and be proportionate to the legitimate aim pursued.The Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR. ''<u>(i) The purposes must be sufficiently determined by law</u>''''<u>(i) The purposes must be sufficiently determined by law</u>'' Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under Article 6(1)(c) GDPR, which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. ''<u>(ii) The purpose limitation and minimisation principles</u>''''<u>(ii) The purpose limitation and minimisation principles</u>'' The Court also referred to the principles of purpose limitation under [[Article 5 GDPR|Article 5(1)(b) GDPR]] and data minimisation under [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The national court must therefore establish whether the purposes of the processing are sufficiently determined by law and whether the disclosure is necessary and proportionate to those purposes.The Court recalled that, pursuant to Article 6(3) GDPR, the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in Article 5(1)(b) GDPR. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under Article 5(1)(c) GDPR. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. The Court considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. Moreover, the possibility of downloading the information in bulk increased the risk of subsequent retention, dissemination and misuse.As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. As regards transparency and the protection of third parties, the Court considered that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company.The Court also acknowledged that public access could contribute to combating money laundering and terrorist financing. However, unrestricted access was not strictly necessary, since those objectives could be achieved through less intrusive measures, such as limiting access to persons demonstrating a legitimate interest. Practical difficulties in verifying such an interest could not justify a broader interference with fundamental rights. The Court acknowledged that public access could contribute to combating money laundering and terrorist financing. However, unrestricted access was not strictly necessary because those objectives could be achieved through less intrusive measures. In particular, access could be limited to persons demonstrating a legitimate interest. The Court stressed that practical difficulties in verifying such an interest cannot justify a broader interference with fundamental rights.Similarly, although public access could facilitate the implementation of sanctions, unrestricted disclosure was not necessary. Less intrusive alternatives included limiting disclosure to persons subject to sanctions or granting access to other shareholders’ information only where a legitimate interest was demonstrated. Similarly, although transparency could facilitate the implementation of sanctions, unrestricted disclosure was not necessary. Less intrusive measures could include limiting disclosure to persons subject to sanctions or allowing access to other shareholders’ information only where a legitimate interest is demonstrated.Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Finally, the legislation lacked sufficient safeguards against abuse because the data were available online and could be downloaded in bulk by unidentified users. Consequently, the Court held that [[Article 5 GDPR|Articles 5]] and [[Article 6 GDPR|6 GDPR]], read in light of [https://fra.europa.eu/en/eu-charter/charter/title/title-ii-freedoms Articles 7] and [https://fra.europa.eu/en/eu-charter/charter/title/title-ii-freedoms 8 CFR], preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest.Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. == Comment ==== Comment == Revision as of 12:57, 8