Seventeen natural persons, who were minority shareholders of a public limited liability company, brought proceedings before the Satversmes tiesa (the Constitutional Court of Latvia)
They challenged national legislation requiring information on shareholders to be included in the public companies register.
How it connects
References
Related across sources
Full text
Facts — Seventeen natural persons, who were minority shareholders of a public limited liability company, brought proceedings before the Satversmes tiesa (the Constitutional Court of Latvia). They challenged national legislation requiring information on shareholders to be included in the public companies register. The information made publicly available included shareholders’ identity and contact details, as well as information concerning the class, number and nominal value of their shares and the number of votes attached to them. The information could be accessed online and downloaded in bulk by any person without identification or the need to demonstrate a legitimate interest. The data subjects argued that such disclosure constituted an unjustified and disproportionate interference with their rights, particularly because they were neither beneficial owners nor members of the company’s management bodies and did not exercise control over the company. The national legislation pursued several objectives, including ensuring transparency and protecting third parties, combating money laundering and terrorist financing, and facilitating the implementation of sanctions. The Constitutional Court stated the proceedings and referred questions to the CJEU. In particular, whether Directive 2017/1132 required such disclosure and whether Articles 5 and 6 GDPR permitted national legislation providing unrestricted public access to that personal data. Holding — Directive 2017/1132 The Court first held that Article 14(d) Directive 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. Legal basis The Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR. (i) The purposes must be sufficiently determined by law Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under Article 6(1)(c) GDPR, which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. (ii) The purpose limitation and minimisation principles The Court recalled that, pursuant to Article 6(3) GDPR, the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in Article 5(1)(b) GDPR. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under Article 5(1)(c) GDPR. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. The Court also acknowledged that public access could contribute to combating money laundering and terrorist financing. However, unrestricted access was not strictly necessary, since those objectives could be achieved through less intrusive measures, such as limiting access to persons demonstrating a legitimate interest. Practical difficulties in verifying such an interest could not justify a broader interference with fundamental rights. Similarly, although public access could facilitate the implementation of sanctions, unrestricted disclosure was not necessary. Less intrusive alternatives included limiting disclosure to persons subject to sanctions or granting access to other shareholders’ information only where a legitimate interest was demonstrated. Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. Holding — Directive 2017/1132 The Court first held that Article 14(d) Directive 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders. Shareholders do not, merely by holding shares, participate in the administration, supervision or control of a company within the meaning of that provision. In particular, minority shareholders are generally not authorised to represent or bind the company or perform management or supervisory functions. Legal basis The Court recalled that any processing must comply with the principles under Article 5 GDPR and satisfy one of the lawful bases under Article 6 GDPR. (i) The purposes must be sufficiently determined by law Since the disclosure of the shareholders’ personal data was required by national law, the Court considered that the processing had to be assessed under Article 6(1)(c) GDPR, which permits processing where it is necessary for compliance with a legal obligation to which the controller is subject. (ii) The purpose limitation and minimisation principles The Court recalled that, pursuant to Article 6(3) GDPR, the legal basis must determine the purpose of the processing, pursue an objective of public interest and be proportionate to the legitimate aim pursued. First, regarding the determination of the purpose, the Court held that the national court must verify whether the purposes of the processing could be identified with sufficient certainty from the wording of the legislation or its legislative context. This assessment was also relevant under the purpose limitation principle in Article 5(1)(b) GDPR. Second, regarding necessity and proportionality, the Court referred to the data minimisation principle under Article 5(1)(c) GDPR. It considered that making shareholders’ identity, contact details and information about their shareholdings publicly accessible constituted a serious interference with their rights. Such information could reveal aspects of their financial situation and investments and was accessible to a potentially unlimited number of persons. The possibility of downloading the information in bulk further increased the risk of retention, dissemination and misuse. As regards transparency and the protection of third parties, the Court found that disclosing the personal data of all shareholders, particularly minority shareholders, was neither appropriate nor necessary because those shareholders generally cannot represent or bind the company. The Court also acknowledged that public access could contribute to combating money laundering and terrorist financing. However, unrestricted access was not strictly necessary, since those objectives could be achieved through less intrusive measures, such as limiting access to persons demonstrating a legitimate interest. Practical difficulties in verifying such an interest could not justify a broader interference with fundamental rights. Similarly, although public access could facilitate the implementation of sanctions, unrestricted disclosure was not necessary. Less intrusive alternatives included limiting disclosure to persons subject to sanctions or granting access to other shareholders’ information only where a legitimate interest was demonstrated. Finally, the Court noted that the legislation lacked sufficient safeguards against abuse because the data were accessible online and could be downloaded in bulk by unidentified users. Consequently, the Court held that Articles 5 and 6 GDPR, read in light of Articles 7 and 8 CFR, preclude national legislation requiring the personal data of all shareholders, including minority shareholders, to be publicly accessible without conditions such as demonstrating a legitimate interest. Comment — Share your comments here!