Ruling [CJEU] ¦ CJEU Draws the Line on Public Shareholder Data in the Fight Against Money Laundering

Ruling [CJEU] ¦ CJEU Draws the Line on Public Shareholder Data in the Fight Against Money Laundering

Minority shareholders are not automatically part of a company’s control structure

The Court of Justice of the European Union (CJEU) has ruled that EU company law does not require Member States to make personal information about every shareholder of a public limited liability company publicly available. The ruling is particularly significant for minority shareholders, whose names, contact details and holdings had been placed in an online companies register accessible to unidentified users and capable of bulk downloading.

The judgment clarifies the relationship between company register transparency, data protection and financial crime prevention. It confirms that the fight against money laundering, terrorist financing, proliferation financing and sanctions evasion remains a recognised public-interest objective. It also makes clear that those objectives do not automatically justify unrestricted public access to detailed information about individuals who hold shares but do not participate in the company’s management, supervision or control.

Under Article 14(d) of Directive 2017/1132, Member States must disclose information about persons who represent a company or take part in its administration, supervision or control. The Court held that this provision does not cover all shareholders simply because shareholders may exercise certain powers through the general meeting.

Shareholders are not appointed to office or removed from office in the same way as members of management or supervisory bodies. Their status arises from ownership of shares. The Court therefore distinguished the position of shareholders from that of directors, supervisory board members and other persons whose functions directly affect the company’s dealings with third parties.

The distinction is especially important for minority shareholders. Unless they hold a specific role or possess rights that enable them to exercise meaningful control, they are not, in principle, authorised to represent the company, bind it in dealings with third parties, or perform management and supervisory functions.

Company-register transparency does not require indiscriminate disclosure

EU company law seeks to protect the interests of members and third parties and to promote legal certainty in cross-border business. Public access to core corporate information allows counterparties to verify a company’s constitutional documents and identify the persons authorised to act on its behalf.

The Court found that publishing information about every shareholder does not materially advance those aims. A minority shareholder’s identity and investment position generally do not tell a creditor, supplier or contracting party who has authority to bind the company. Nor does the disclosure of the shareholder’s contact details or voting position necessarily improve the reliability of commercial dealings.

The ruling does not prevent Member States from maintaining shareholder registers or collecting shareholder information. It addresses the separate question of whether such information must be made available to the public without restriction. National authorities may continue to require companies to record ownership information where that information is needed for corporate administration, regulatory supervision or financial crime controls. The critical issue is who may access it, for what purpose and under what safeguards.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"The Court of Justice of the European Union has ruled that EU company law does not require Member States to publish personal and investment data relating to every shareholder of a public limited liability company. Minority shareholders who do not participate in management, supervision or control are not automatically subject to the disclosure rules applicable to company officers and representatives.

The judgment also limits the use of unrestricted public access as a tool against money laundering, terrorist financing and sanctions evasion. Shareholder data may still be collected and accessed by competent authorities and obliged entities for defined compliance purposes, but public disclosure must be necessary, proportionate and supported by safeguards such as legitimate interest requirements and restrictions on bulk access."

The anti-money laundering objective is legitimate, but not unlimited

The Court accepted that public access to ownership information can contribute to a less favourable environment for money laundering and terrorist financing. Greater visibility of corporate ownership may help identify links between companies, individuals and economic sectors. It may also assist in detecting concealed interests, nominee arrangements and potential conflicts of interest.

That recognition does not end the analysis. The processing must still comply with the GDPR principles of lawfulness, purpose limitation and data minimisation, and the relevant national law must satisfy the proportionality requirements of the Charter.

The Court treated the publication of the information as a serious interference with privacy and data protection rights. The data covered more than a person’s identity. It also included contact details, the class and number of shares, their nominal value and the voting rights attached to them. Taken together, those details could allow users to build a profile of an individual’s wealth, investment strategy and links to particular companies or economic sectors.

The risk is increased when the information is accessible on the internet to an unlimited audience, including unidentified users, and can be downloaded in bulk. Once copied and redistributed, the information may be used for purposes unrelated to financial crime prevention. The individual may have little practical ability to monitor subsequent uses or obtain effective protection against misuse.

Financial crime controls should target the relevant risk

A central message of the judgment is that anti-money laundering measures must be connected to the actual risk addressed. The general availability of information about all shareholders, including persons with no beneficial ownership or control, was not considered strictly necessary for preventing money laundering or terrorist financing.

The Court pointed to the existing framework under Directive 2015/849, which assigns a primary role to public authorities and obliged entities such as banks and other financial institutions. These entities are required to conduct customer due diligence (CDD), identify beneficial owners, understand ownership and control structures, assess risk and report suspicious transactions where appropriate.

That framework is materially different from unrestricted public disclosure. Access by a competent authority or an obliged entity for a defined compliance purpose is more closely connected to the prevention of financial crime than access by any unidentified member of the public.

The judgment therefore supports a risk-based approach (RBA). Information should be available to those who need it for customer due diligence, supervision, investigations or reporting obligations. Broader access may be justified where the requester can demonstrate a legitimate interest. But a blanket rule allowing anyone to obtain detailed personal data about every shareholder goes further than necessary where less intrusive tools can achieve the same compliance objective.

Beneficial ownership remains distinct from share ownership

The ruling also reinforces the distinction between a shareholder and a beneficial owner. Share ownership may be relevant to an analysis of control, but not every shareholder is a beneficial owner for anti-money laundering purposes. A minority shareholder may have no ability to control the company, direct its decisions or benefit from it in a way that triggers beneficial ownership treatment.

That distinction matters for financial institutions and other obliged entities. Customer due diligence cannot stop at the name appearing in a shareholder register. Institutions must assess the ownership and control structure in substance, identify the natural person or persons who ultimately own or control the customer, and investigate situations in which formal ownership does not reflect effective control.

At the same time, the absence of beneficial ownership status does not make shareholder information irrelevant in every case. A minority holding may form part of a wider ownership arrangement, be combined with voting agreements or other rights, or become significant when assessed alongside family, corporate or contractual connections. The judgment does not eliminate the need to examine shareholder data. It limits the justification for exposing such data indiscriminately to the public.

Sanctions screening calls for focused disclosure

The Court reached a similar conclusion concerning sanctions implementation. Public access to detailed information about all shareholders may contribute to transparency, but it is not necessarily required to enforce national, international or EU sanctions.

Less intrusive measures may include targeted disclosure concerning persons listed on sanctions regimes, combined with controlled access to information about other shareholders where the requester can demonstrate a legitimate interest. Such an approach is more closely aligned with the purpose of sanctions screening, which is to identify designated persons, property and control relationships rather than publish the financial profiles of unrelated individuals.

For companies and financial institutions, sanctions compliance still requires attention to direct and indirect ownership and control. A person may be subject to restrictions even where assets are held through intermediaries or third parties. However, the need to perform that analysis does not by itself support an unrestricted public database containing detailed information about every shareholder.

What the judgment means for registers and compliance functions

Companies register operators may need to reassess whether their access models meet GDPR and Charter requirements. The fact that a register can technically verify or publish data does not establish that unrestricted access is legally necessary. Administrative difficulty in checking whether an applicant has a legitimate interest is not, by itself, sufficient justification for dispensing with access controls.

Possible safeguards include differentiated access rights, requester identification, legitimate interest assessments, limits on bulk downloads, monitoring of searches, restrictions on data reuse and stronger controls for contact details and other information capable of revealing an individual’s financial position. The appropriate design will depend on national law and the precise regulatory purpose, but the direction is clear: the more intrusive the disclosure, the stronger the justification and safeguards must be.

Companies should also review the data they submit to public registers and distinguish information required for corporate validity from information collected for anti-money laundering or sanctions purposes. Those functions may require different access arrangements. A public register designed to support commercial certainty should not automatically become an unrestricted financial intelligence resource.

Financial institutions should not interpret the judgment as a reason to reduce ownership and control checks. They should continue obtaining shareholder and beneficial ownership information through reliable sources and assess it in the context of the customer’s structure, activities, geography and transaction profile. The important change concerns the assumption that all such information should be freely available to everyone.

A narrower model of transparency

The judgment does not reject transparency in corporate ownership. It rejects the assumption that transparency always means unrestricted publication of every available personal detail.

For financial crime prevention, effective transparency depends on relevance, accuracy, purpose and controlled access. Information about directors, authorised representatives, beneficial owners and persons exercising actual control may serve a different function from information about passive minority shareholders. Treating these categories as identical can create substantial privacy risks without producing equivalent enforcement benefits.

The Court’s approach requires legislators and regulators to connect each disclosure measure to a defined objective and demonstrate why the measure is necessary. Where targeted access, legitimate interest requirements or authority-to-authority sharing can achieve the same result, indiscriminate public disclosure is unlikely to satisfy the GDPR’s proportionality standard.

The wider consequence is a more disciplined balance between corporate transparency and financial crime controls. Ownership information remains essential to detecting illicit finance, but access to it must reflect the nature of the risk and the role of the person concerned. For minority shareholders without management or control functions, unrestricted publication of identity, contact and investment data crosses that line.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • InfoCuria ¦ Case C-798/24 [Jautiva] ¦ Link
  • EUR-Lex ¦ Case C-798/24 [Jautiva], Judgment of the Court (First Chamber) of 3 September 2026 ¦ Link
  • EUR-Lex ¦ Directive 2017/1132 relating to certain aspects of company law (codification) ¦ Link
  • EUR-Lex ¦ Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) ¦ Link
  • EUR-Lex ¦ Charter of Fundamental Rights of the European Union ¦ Link
  • EUR-Lex ¦ Directive 2015/849 AMLD ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.