[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYL1gwjsq_ah83hrzRA6rBQPfOTHzhHm4r5ZzRCVlBb4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"47153180-8c94-4899-8910-cc832ca82a16","cjeu-rules-mandatory-public-disclosure-of-shareholder-data-violates-gdpr","de43a16e-484a-48d6-883e-e4097c9210a6","CJEU Rules Mandatory Public Disclosure of Shareholder Data Violates GDPR","The CJEU determined that national legislation requiring minority shareholders' personal data — including identity and contact details — to be publicly accessible breaches GDPR principles of necessity and proportionality. Even legitimate objectives such as financial transparency and anti-money laundering efforts cannot justify unrestricted public exposure of personal data when less invasive alternatives exist. This ruling reinforces that data minimisation and purpose limitation are non-negotiable, even within government-mandated disclosure frameworks. Organisations and lawmakers must assess whether each data sharing obligation is strictly necessary and proportionate, or risk legal liability under EU law.","**Immediate actions:**\n- Audit all current data disclosure practices mandated by national legislation to identify potential GDPR conflicts.\n- Restrict public access to personal data registries by implementing role-based or need-to-know access controls.\n\n**Compliance & legal alignment:**\n- Conduct Data Protection Impact Assessments (DPIAs) before implementing any legislation or system that mandates broad personal data disclosure.\n- Engage Data Protection Officers (DPOs) to review regulatory obligations against GDPR Articles 5, 6, and 25 for lawful, necessary, and proportionate processing.\n- Replace unrestricted public access with tiered access models (e.g., authenticated access for verified parties only).\n\n**Long-term improvements:**\n- Embed privacy-by-design principles into the legislative drafting process to ensure proportionality is assessed at the policy level.\n- Establish ongoing monitoring of CJEU and national DPA rulings to proactively update data governance policies before enforcement actions occur.\n- Train legal, compliance, and product teams on evolving GDPR case law to reduce organisational exposure to non-compliance risk.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5 – Principles relating to processing of personal data (data minimisation, purpose limitation)","GDPR Article 6 – Lawfulness of processing","GDPR Article 25 – Data protection by design and by default","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST Privacy Framework PR.DS-P1 – Data processing limited to identified purpose","NIST SP 800-53 AC-3 – Access Enforcement","CIS Control 3 – Data Protection","ISO\u002FIEC 27001:2022 – A.5.34 Privacy and protection of personally identifiable information","ITIL Service Design – Information Security Management (proportionality in data handling)","published","2026-09-08T11:20:20.112382+00:00","2026-09-08T11:20:19.864+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-798\u002F24_-_Jautiva&diff=52928&oldid=0","cjeu-c-798-24-jautiva-3ad798","CJEU - C-798\u002F24 - Jautiva",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]