EU court rejects unrestricted publication of shareholder data for sanctions and AML purposes
The ECJ ruled that sanctions enforcement, anti-money laundering and corporate transparency objectives do not justify giving the public unrestricted access to personal data on every shareholder of a listed company.
LUXEMBOURG, September 03, 2026 — European Union law bars national rules that make personal information on all shareholders of public limited companies freely available online without requiring users to demonstrate a legitimate interest, the EU’s highest court ruled.
The Court of Justice of the European Union issued the judgment in Jautiva, Case C-798/24, following a challenge brought before Latvia’s Constitutional Court by 17 minority shareholders. Latvian law required information on shareholders of public limited liability companies to be entered in the commercial register and made accessible to the general public.
The disclosed information included shareholders’ identities and contact details, the class, number and nominal value of their shares and the voting rights attached to those holdings.
Latvia cited several public-interest objectives for the disclosure regime, including corporate transparency, protection of third parties, preventing money laundering, terrorist financing and proliferation financing, and providing information necessary to enforce national, international and EU sanctions.
The court found that EU company law does not require information concerning every shareholder, including minority shareholders, to be publicly disclosed.
It also ruled that Articles 5 and 6 of the General Data Protection Regulation, read alongside EU Charter rights to privacy and data protection, preclude unrestricted public access to such information where access is not subject to conditions such as demonstrating a legitimate interest.
Advocate General Rimvydas Norkus reached substantially the same conclusion in his December 2025 opinion. He said the term covering people who participate in a company’s “administration, supervision or control” cannot be interpreted to include every shareholder and that EU law does not oblige member states to publish information on all shareholders.
Norkus also concluded that the GDPR prevents member states from making shareholder data available to any person without a legitimate-interest requirement even when the objectives include sanctions enforcement, anti-money laundering measures and corporate transparency.
The judgment does not prevent authorities from collecting or processing shareholder information for sanctions or financial-crime investigations. Instead, it limits indiscriminate public disclosure.
The ruling is significant for sanctions compliance because beneficial ownership and shareholding information remains important for identifying assets linked to designated persons. However, member states must balance access to that information against GDPR requirements and cannot rely on sanctions enforcement as a blanket justification for publishing the personal details of every shareholder online.
Regulatory Actions
Structured data extracted from official sources and validated by sanctions experts