EU Court Limits Unrestricted Public Access to Shareholder Data in Latvia

The Court of Justice of the European Union has ruled that EU law does not require information on all shareholders of public limited liability companies, including minority shareholders, to be made public, and that unrestricted online access to personal shareholder data can breach EU data-protection rules.
The judgment, delivered on 3 September 2026 in Case C-798/24 Jautiva, arose from a reference by Latvia’s Constitutional Court. Seventeen minority shareholders challenged Latvian rules requiring shareholder information to be placed in the public part of the companies register.
Latvian register exposed extensive shareholder data
For shareholders who are natural persons, the Latvian regime could make available names, personal identification numbers or dates of birth, identity-document details, contact addresses and email addresses. The register also contained the class, number and nominal value of shares held and the voting rights attached to them. The information was accessible online and could be downloaded in bulk, including by unidentified users.
Latvia identified three objectives for the disclosure regime: maintaining a transparent business environment and protecting third parties; preventing money laundering, terrorist financing and proliferation financing; and providing information needed to implement national, international and EU sanctions.
Court finds unrestricted access disproportionate
The Court held that Directive (EU) 2017/1132 does not require disclosure of information relating to all shareholders of public limited liability companies, including minority shareholders.
It further found that making the data publicly available constituted a serious interference with privacy and data-protection rights. The Court noted that the information could be used to build a profile of a shareholder’s wealth, investments and economic interests and, once publicly available, could be retained and redistributed by an unlimited number of people.
For AML/CFT, proliferation-financing and sanctions objectives, the Court concluded that allowing any person to access minority-shareholder data without demonstrating a legitimate interest was not shown to be strictly necessary or proportionate. It pointed to less intrusive alternatives, including limiting access to persons able to demonstrate a legitimate interest and, for sanctions purposes, restricting disclosure requirements to data concerning persons included on sanctions lists.
The Court also highlighted the absence of sufficient safeguards where shareholder data could be accessed online and downloaded in bulk by unidentified users.
National proceedings continue
The ruling is a preliminary ruling on the interpretation of EU law. The Court of Justice does not decide the underlying Latvian constitutional dispute itself; Latvia’s Constitutional Court must resolve the national case in accordance with the EU Court’s interpretation.
The decision adds another important boundary to Europe’s corporate-transparency framework: AML, proliferation-financing and sanctions objectives can justify access to ownership information, but they do not automatically justify unrestricted public disclosure of personal data. Registers and regulated firms will increasingly need to distinguish between information necessary for competent authorities and obliged entities and information that can lawfully be made available to the general public.



