CJEU - C-798/24 - Jautiva
CJEU rules against public access to minority shareholders' personal data under GDPR.
Summary
The Court of Justice of the European Union (CJEU) ruled that national legislation making minority shareholders' personal data publicly accessible violates GDPR. The court found that such broad disclosure, including identity and contact details, is a serious interference with fundamental rights and is neither necessary nor proportionate for objectives like transparency or combating financial crime.
Full text
Help CJEU - C-798/24 - Jautiva: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 08:11, 8 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators298 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 08:11, 8 September 2026 CJEU - C-798/24 Jautiva Court: CJEU Jurisdiction: European Union Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 6(1)(c) GDPR Article 6(3) GDPR Article 7 CFRArticle 8 CFRArticle 14(d) Directive 2017/1132 Decided: 03.09.2026 Parties: Latvijas Republikas Saeima Case Number/Name: C-798/24 Jautiva European Case Law Identifier: ECLI:EU:C:2026:679 Reference from: Latvijas Republikas Saeima Language: 24 EU Languages Original Source: AG OpinionJudgement Initial Contributor: bms The CJEU held that Articles 5 and 6 GDPR preclude national legislation making minority shareholders’ personal data publicly accessible. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources English Summary Facts Seventeen natural persons, who were minority shareholders of a public limited liability company, brought proceedings before the Satversmes tiesa (the Constitutional Court of Latvia). They challenged national legislation requiring information on shareholders to be included in the public companies register. The information made publicly available included shareholders’ identity and contact details, as well as information concerning the class, number and nominal value of their shares and the number of votes attached to them. The information could be accessed online and downloaded in bulk by any person without identification or the need to demonstrate a legitimate interest. The data subjects argued that such disclosure constituted an unjustified and disproportionate interference with their rights, particularly because they were neither beneficial owners nor members of the company’s management bodies and did not exercise control over the company. The national legislation pursued several objectives, including ensuring transparency and protecting third parties, combating money laundering and terrorist financing, and facilitating the implementation of sanctions. The Court was asked, in particular, whether Directive 2017/1132 required such disclosure and whether Articles 5 and 6 GDPR permitted national legislation providing unrestricted public access to that personal data. Holding The Court first held that Article 14(d) Directive 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. Regarding the GDPR, the Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR. Since the disclosure was required by national law, the processing had to be assessed under Article 6(1)(c) GDPR. Pursuant to Article 6(3) GDPR, the legal basis must pursue an objective of public interest and be proportionate to the legitimate aim pursued. The Court also referred to the principles of purpose limitation under Article 5(1)(b) GDPR and data minimisation under Article 5(1)(c) GDPR. The national court must therefore establish whether the purposes of the processing are sufficiently determined by law and whether the disclosure is necessary and proportionate to those purposes. The Court considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. Moreover, the possibility of downloading the information in bulk increased the risk of subsequent retention, dissemination and misuse. As regards transparency and the protection of third parties, the Court considered that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. The Court acknowledged that public access could contribute to combating money laundering and terrorist financing. However, unrestricted access was not strictly necessary because those objectives could be achieved through less intrusive measures. In particular, access could be limited to persons demonstrating a legitimate interest. The Court stressed that practical difficulties in verifying such an interest cannot justify a broader interference with fundamental rights. Similarly, although transparency could facilitate the implementation of sanctions, unrestricted disclosure was not necessary. Less intrusive measures could include limiting disclosure to persons subject to sanctions or allowing access to other shareholders’ information only where a legitimate interest is demonstrated. Finally, the legislation lacked sufficient safeguards against abuse because the data were available online and could be downloaded in bulk by unidentified users. Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. Comment Share your comments here! Further Resources Share blogs or news articles here! Retrieved from "https://gdprhub.eu/index.php?title=CJEU_-_C-798/24_-_Jautiva&oldid=52928" Categories: CJEUEuropean UnionArticle 5(1)(a) GDPRArticle 5(1)(b) GDPRArticle 5(1)(c) GDPRArticle 6(1)(c) GDPRArticle 6(3) GDPR2026 This page was last edited on 8 September 2026, at 08:11. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers