[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fM2V5GhRs61MRWDW7KkQNSjGRWW3bfaGe5Rc2Qw3zy1s":3},{"article":4,"iocs":39},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"66b5187f-980f-47b0-98aa-efc88e3d4624","CJEU - C-798\u002F24 - Jautiva","cjeu-c-798-24-jautiva-f7a1fa","← Older revision Revision as of 13:05, 8 September 2026 Line 101: Line 101: The data subjects argued that such disclosure constituted an unjustified and disproportionate interference with their rights, particularly because they were neither beneficial owners nor members of the company’s management bodies and did not exercise control over the company. The national legislation pursued several objectives, including ensuring transparency and protecting third parties, combating money laundering and terrorist financing, and facilitating the implementation of sanctions. The data subjects argued that such disclosure constituted an unjustified and disproportionate interference with their rights, particularly because they were neither beneficial owners nor members of the company’s management bodies and did not exercise control over the company. The national legislation pursued several objectives, including ensuring transparency and protecting third parties, combating money laundering and terrorist financing, and facilitating the implementation of sanctions. The Constitutional Court stated the proceedings and referred questions to the CJEU. In particular, whether Directive 2017\u002F1132 required such disclosure and whether [[Article 5 GDPR|Articles 5]] and [[Article 6 GDPR|6 GDPR]] permitted national legislation providing unrestricted public access to that personal data. The Constitutional Court stated the proceedings and referred questions to the CJEU. In particular, whether [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2017\u002F1132\u002Foj\u002Feng Directive 2017\u002F1132] required such disclosure and whether [[Article 5 GDPR|Articles 5]] and [[Article 6 GDPR|6 GDPR]] permitted national legislation providing unrestricted public access to that personal data. === Holding === === Holding === Directive 2017\u002F1132 Directive 2017\u002F1132 The Court first held that Article 14(d) Directive 2017\u002F1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. The Court first held that [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2017\u002F1132\u002Foj\u002Feng Article 14(d) Directive 2017\u002F1132] does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. Legal basis Legal basis The Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR. The Court recalled that any processing must comply with the principles under [[Article 5 GDPR]] and satisfy one of the lawful bases under [[Article 6 GDPR]]. '' (i) The purposes must be sufficiently determined by law '' '' (i) The purposes must be sufficiently determined by law '' Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under Article 6(1)(c) GDPR, which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under [[Article 6 GDPR|Article 6(1)(c) GDPR]], which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. '' (ii) The purpose limitation and minimisation principles '' '' (ii) The purpose limitation and minimisation principles '' The Court recalled that, pursuant to Article 6(3) GDPR, the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. The Court recalled that, pursuant to [[Article 6 GDPR|Article 6(3) GDPR]], the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in Article 5(1)(b) GDPR. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in [[Article 5 GDPR|Article 5(1)(b) GDPR]]. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under Article 5(1)(c) GDPR. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]]. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. Line 131: Line 131: Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. Consequently, the Court held that [[Article 5 GDPR|Articles 5]] and [[Article 6 GDPR|6 GDPR]], read in light of [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FHTML\u002F?uri=CELEX:12012P\u002FTXT Articles 7] and [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FHTML\u002F?uri=CELEX:12012P\u002FTXT 8 CFR], preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. == Comment == == Comment ==","The Court of Justice of the European Union (CJEU) has ruled that national legislation requiring unrestricted public access to the personal data of all shareholders, including minority shareholders, is not permissible under GDPR. The court found that such broad disclosure constitutes a serious interference with privacy rights and is neither appropriate nor necessary for transparency or combating financial crime, especially when shareholders do not control the company. The ruling emphasizes the need for proportionality and sufficient safeguards against data misuse.","CJEU rules against unrestricted public access to all shareholders' personal data.","Help CJEU - C-798\u002F24 - Jautiva: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 12:57, 8 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators303 editsTag: Visual edit← Older edit Latest revision as of 13:05, 8 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators303 editsTag: Visual edit Line 101: Line 101: The data subjects argued that such disclosure constituted an unjustified and disproportionate interference with their rights, particularly because they were neither beneficial owners nor members of the company’s management bodies and did not exercise control over the company. The national legislation pursued several objectives, including ensuring transparency and protecting third parties, combating money laundering and terrorist financing, and facilitating the implementation of sanctions.The data subjects argued that such disclosure constituted an unjustified and disproportionate interference with their rights, particularly because they were neither beneficial owners nor members of the company’s management bodies and did not exercise control over the company. The national legislation pursued several objectives, including ensuring transparency and protecting third parties, combating money laundering and terrorist financing, and facilitating the implementation of sanctions. The Constitutional Court stated the proceedings and referred questions to the CJEU. In particular, whether Directive 2017\u002F1132 required such disclosure and whether [[Article 5 GDPR|Articles 5]] and [[Article 6 GDPR|6 GDPR]] permitted national legislation providing unrestricted public access to that personal data.The Constitutional Court stated the proceedings and referred questions to the CJEU. In particular, whether [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2017\u002F1132\u002Foj\u002Feng Directive 2017\u002F1132] required such disclosure and whether [[Article 5 GDPR|Articles 5]] and [[Article 6 GDPR|6 GDPR]] permitted national legislation providing unrestricted public access to that personal data. === Holding ====== Holding === \u003Cu>Directive 2017\u002F1132\u003C\u002Fu>\u003Cu>Directive 2017\u002F1132\u003C\u002Fu> The Court first held that Article 14(d) Directive 2017\u002F1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions.The Court first held that [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2017\u002F1132\u002Foj\u002Feng Article 14(d) Directive 2017\u002F1132] does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. \u003Cu>Legal basis\u003C\u002Fu>\u003Cu>Legal basis\u003C\u002Fu> The Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR.The Court recalled that any processing must comply with the principles under [[Article 5 GDPR]] and satisfy one of the lawful bases under [[Article 6 GDPR]]. ''\u003Cu>(i) The purposes must be sufficiently determined by law\u003C\u002Fu>''''\u003Cu>(i) The purposes must be sufficiently determined by law\u003C\u002Fu>'' Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under Article 6(1)(c) GDPR, which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject.Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under [[Article 6 GDPR|Article 6(1)(c) GDPR]], which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. ''\u003Cu>(ii) The purpose limitation and minimisation principles\u003C\u002Fu>''''\u003Cu>(ii) The purpose limitation and minimisation principles\u003C\u002Fu>'' The Court recalled that, pursuant to Article 6(3) GDPR, the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued.The Court recalled that, pursuant to [[Article 6 GDPR|Article 6(3) GDPR]], the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in Article 5(1)(b) GDPR.First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in [[Article 5 GDPR|Article 5(1)(b) GDPR]]. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under Article 5(1)(c) GDPR. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse.Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]]. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company.As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. Line 131: Line 131: Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users.Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-798\u002F24_-_Jautiva&diff=52957&oldid=52955","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F8\u002F87\u002FCjeulogo.png","2026-09-08T13:05:39+00:00","2026-09-08T14:00:23.156315+00:00",7,[18],{"name":19,"type":20},"Directive 2017\u002F1132","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},[]]