Skip to content
Case Law · CJEU ·798/24 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Seventeen natural persons, who were minority shareholders of a public limited liability company, brought proceedings before the Satversmes tiesa (the Constitutional Court of Latvia)

They challenged national legislation requiring information on shareholders to be included in the public companies register.

CJEU

How it connects

€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Jul 14, 2026 Application Scope: Temporal and Territorial Dimensions Social Media Controllers
2023 The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Dominika Kuźnicka-Błaszkowsk — Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza ·full text Dec 30, 2023 Right of Access Procedures Right of Access Right to Restriction
EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Mutual Assistance Between Member States for AI Oversight Social Media
Guidelines 2/2019 processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects 1 Adopted Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Version 2.0 8 October… Guidelines ·EDPB Oct 16, 2019 Child Consent Fairness & Transparency Social Media

Full text

Facts — Seventeen natural persons, who were minority shareholders of a public limited liability company, brought proceedings before the Satversmes tiesa (the Constitutional Court of Latvia). They challenged national legislation requiring information on shareholders to be included in the public companies register. The information made publicly available included shareholders’ identity and contact details, as well as information concerning the class, number and nominal value of their shares and the number of votes attached to them. The information could be accessed online and downloaded in bulk by any person without identification or the need to demonstrate a legitimate interest. The data subjects argued that such disclosure constituted an unjustified and disproportionate interference with their rights, particularly because they were neither beneficial owners nor members of the company’s management bodies and did not exercise control over the company. The national legislation pursued several objectives, including ensuring transparency and protecting third parties, combating money laundering and terrorist financing, and facilitating the implementation of sanctions. The Constitutional Court stated the proceedings and referred questions to the CJEU. In particular, whether Directive 2017/1132 required such disclosure and whether Articles 5 and 6 GDPR permitted national legislation providing unrestricted public access to that personal data. Holding — Directive 2017/1132 The Court first held that Article 14(d) Directive 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. Legal basis The Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR. (i) The purposes must be sufficiently determined by law Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under Article 6(1)(c) GDPR, which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. (ii) The purpose limitation and minimisation principles The Court recalled that, pursuant to Article 6(3) GDPR, the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in Article 5(1)(b) GDPR. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under Article 5(1)(c) GDPR. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. The Court also acknowledged that public access could contribute to combating money laundering and terrorist financing. However, unrestricted access was not strictly necessary, since those objectives could be achieved through less intrusive measures, such as limiting access to persons demonstrating a legitimate interest. Practical difficulties in verifying such an interest could not justify a broader interference with fundamental rights. Similarly, although public access could facilitate the implementation of sanctions, unrestricted disclosure was not necessary. Less intrusive alternatives included limiting disclosure to persons subject to sanctions or granting access to other shareholders’ information only where a legitimate interest was demonstrated. Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. Holding — Directive 2017/1132 The Court first held that Article 14(d) Directive 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. Legal basis The Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR. (i) The purposes must be sufficiently determined by law Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under Article 6(1)(c) GDPR, which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. (ii) The purpose limitation and minimisation principles The Court recalled that, pursuant to Article 6(3) GDPR, the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in Article 5(1)(b) GDPR. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under Article 5(1)(c) GDPR. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. The Court also acknowledged that public access could contribute to combating money laundering and terrorist financing. However, unrestricted access was not strictly necessary, since those objectives could be achieved through less intrusive measures, such as limiting access to persons demonstrating a legitimate interest. Practical difficulties in verifying such an interest could not justify a broader interference with fundamental rights. Similarly, although public access could facilitate the implementation of sanctions, unrestricted disclosure was not necessary. Less intrusive alternatives included limiting disclosure to persons subject to sanctions or granting access to other shareholders’ information only where a legitimate interest was demonstrated. Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. Comment — Share your comments here!