Back to all lessons
Awareness Lessons
last month

CJEU Rules Mandatory Public Disclosure of Shareholder Data Violates GDPR

The CJEU determined that national legislation requiring minority shareholders' personal data — including identity and contact details — to be publicly accessible breaches GDPR principles of necessity and proportionality. Even legitimate objectives such as financial transparency and anti-money laundering efforts cannot justify unrestricted public exposure of personal data when less invasive alternatives exist. This ruling reinforces that data minimisation and purpose limitation are non-negotiable, even within government-mandated disclosure frameworks. Organisations and lawmakers must assess whether each data sharing obligation is strictly necessary and proportionate, or risk legal liability under EU law.

Tactical Insight

Immediate actions

  • Audit all current data disclosure practices mandated by national legislation to identify potential GDPR conflicts.
  • Restrict public access to personal data registries by implementing role-based or need-to-know access controls.

Compliance & legal alignment

  • Conduct Data Protection Impact Assessments (DPIAs) before implementing any legislation or system that mandates broad personal data disclosure.
  • Engage Data Protection Officers (DPOs) to review regulatory obligations against GDPR Articles 5, 6, and 25 for lawful, necessary, and proportionate processing.
  • Replace unrestricted public access with tiered access models (e.g., authenticated access for verified parties only).

Long-term improvements

  • Embed privacy-by-design principles into the legislative drafting process to ensure proportionality is assessed at the policy level.
  • Establish ongoing monitoring of CJEU and national DPA rulings to proactively update data governance policies before enforcement actions occur.
  • Train legal, compliance, and product teams on evolving GDPR case law to reduce organisational exposure to non-compliance risk.