Qubit Conference®
Back to Insights
Uncategorized

Where does transparency end and intrusion into privacy begin?

The diagnosis is clear: the amendment to the Commercial Register Act opened access to the Collection of Deeds without any meaningful filter, exposing individuals to a direct risk of identity theft and misuse of signature specimens, national identification numbers and…

Jan Golais

Jan Golais

DPO expert, Judicium

Sep 16, 2026

13 min read
Where does transparency end and intrusion into privacy begin?

The diagnosis is clear: the amendment to the Commercial Register Act opened access to the Collection of Deeds without any meaningful filter, exposing individuals to a direct risk of identity theft and misuse of signature specimens, national identification numbers and scans of identity documents of company representatives.

There are already police cases in which such data have been used to establish companies or gain access to them, subsequently causing losses to the state and businesses.

The Ministry of Justice legitimises the current situation by distinguishing between “making data accessible” and “publishing” them, and by referring to practices in certain EU Member States. However, the internal causality is political: a preference for the formal publicity of documents over the principles of data minimisation and proportionality under the GDPR, without compensating access controls.

What is at stake is the credibility of public administration, the security of identities, including those of people in senior positions and members of security services, and the consistency of a supervisory regime that sanctions excessive disclosure elsewhere, for example when municipalities publish contracts without sufficient redaction, while the state itself makes complete personal data available in the Collection of Deeds without redaction to anyone, including users abroad.

As members of the professional community, we have a duty to say this clearly: we have failed to protect privacy in the legislative process, and the scope and conditions of access to the Collection of Deeds must be corrected immediately.

1. How the Problem Works and Where the Decision-Making Tension Lies

What was made accessible, and to whom

The Collection of Deeds on Slovensko.sk contains, among other things:

  • scans of identity cards,
  • identification data of shareholders, directors and other company representatives,
  • national identification numbers,
  • signature specimens,
  • telephone numbers.

Following the amendment, access is available without registration to anyone, including foreign entities.

Previously, access required registration and documents were delivered by email.

Security reality: multiple police units are dealing with cases in which personal data of company representatives were misused to establish companies or gain access to existing companies, causing economic damage.

The Ministry’s rhetoric: “making accessible does not equal publishing”, “the situation has not changed”, and “the same practice exists in some EU Member States”.

The conflict of principles: publicity of corporate documents versus Article 5 of the GDPR, including the principles of data minimisation, integrity, confidentiality, purpose limitation and proportionality.

Systemic inconsistency in supervision

Supervisory authorities sanction municipalities and businesses for failing to redact signatures or national identification numbers in published contracts.

At the same time, the state makes full personal data available in the Collection of Deeds without redaction, creating a double standard and undermining the authority of the regulatory system.

Risk implications

Identity risk: identity theft and fraudulent legal acts carried out without the knowledge of the individuals concerned.

Damage: economic losses for the state and businesses, as well as reputational damage to public administration.

Increased exposure: people in senior public positions and members of security services have specific risk profiles. Uncontrolled access increases the threats associated with those profiles.

Political and procedural causes

The legislative process failed to take sufficient account of security requirements and the principle of proportionality.

The Ministry of Justice has chosen a defensive interpretation and a comparative alibi, pointing to other countries, instead of addressing the scope and conditions of access.

2. Next Steps

Ministry of Justice

  • Urgently amend the relevant decree or methodology governing the Collection of Deeds and introduce redaction of sensitive data, including national identification numbers, signature specimens, scans of identity documents and telephone numbers.
  • Temporarily restrict public access to documents containing such sensitive elements until a proper redaction process is implemented.

Office for Personal Data Protection

  • Initiate proceedings assessing whether access to the Collection of Deeds complies with Articles 5 and 32 of the GDPR and issue binding measures on data minimisation.
  • Publish guidance on mandatory redaction of personal data in publicly accessible registry documents.

NCZI / administrator of Slovensko.sk

  • Implement access layers, including registration, authentication through eID, access logging, rate limiting and geographic restrictions on bulk downloading.
  • Deploy an automated redaction pipeline using OCR and PII detection to remove or mask sensitive information before publication.

Police Force

  • Establish a contact channel for company representatives affected by identity theft and centralise reports linked to misuse of data originating from the Collection of Deeds.
  • Publish quarterly overviews of misuse cases to inform the Ministry of Justice and the supervisory authority.

Professional community

  • Prepare a minimum standard for balancing the publicity of corporate documents with the protection of privacy.

3. Recent Judgment in a Similar Case

Case: C-798/24, Jautiva
Court: Court of Justice of the European Union, First Chamber
Date of judgment: 3 September 2026
Procedure: Preliminary ruling under Article 267 TFEU
Referring court: Satversmes tiesa, Constitutional Court of Latvia

Relevant legislation:

  • Article 14(d) of Directive (EU) 2017/1132 relating to certain aspects of company law,
  • Articles 5 and 6 GDPR,
  • Articles 7 and 8 of the Charter of Fundamental Rights of the European Union,
  • the principles of purpose limitation, data minimisation, necessity and proportionality.

The official text is published as the Judgment of the Court in Case C-798/24, Jautiva. The version currently available on CURIA is marked as provisional.

4. Factual Background

The proceedings were initiated by 17 minority shareholders of a Latvian public limited company.

They challenged Latvian legislation under which information about shareholders of public limited companies was made publicly available through the register.

For shareholders who were natural persons, the disclosed information included in particular:

  • first and last name,
  • personal identification number or date of birth,
  • identity document number and date of issue,
  • issuing country and authority,
  • contact address,
  • email address,
  • class, number and nominal value of shares,
  • number of voting rights attached to the shares.

The data were available online without any requirement to prove identity or legitimate interest and could also be downloaded in bulk.

The applicants argued that this created a high risk of misuse and that, once published, subsequent storage, combination and dissemination of the data could no longer be effectively controlled.

5. Objectives Invoked by the Latvian Legislature

The Latvian legislation pursued three objectives:

  1. ensuring a transparent business environment and protecting third parties,
  2. preventing money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction,
  3. providing information necessary for the application of national, international and EU sanctions.

The Constitutional Court of Latvia asked, in particular, whether Directive 2017/1132 requires the disclosure of information about all shareholders and whether the GDPR permits general, unconditional public access to such information.

6. Does EU Law Require Disclosure of All Shareholders?

The Court of Justice answered no.

Article 14(d) of Directive 2017/1132 concerns persons who participate in the administration, supervision or control of a company.

According to the Court, that concept cannot be interpreted as automatically including every shareholder of a public limited company.

It follows that:

  • ownership of shares alone does not amount to participation in the management or control of a company,
  • the Directive does not require Member States to publish information about every shareholder,
  • in particular, no such obligation can be inferred in relation to minority shareholders without an actual managerial or controlling role.

The Court based this conclusion on the wording, context and purpose of Article 14 of Directive 2017/1132.

7. Assessment Under the GDPR and the Charter

The Court recalled that the rights to privacy and protection of personal data under Articles 7 and 8 of the Charter are not absolute.

An interference may be permissible where it:

  • is provided for by law,
  • respects the essence of the fundamental rights concerned,
  • pursues a legitimate objective,
  • is appropriate and necessary,
  • complies with the principle of proportionality,
  • includes adequate safeguards against misuse.

In the case at hand, disclosure was provided for by law and, according to the Court, did not interfere with the essence of the rights guaranteed by Articles 7 and 8 of the Charter.

Nevertheless, it constituted a serious interference with privacy and data protection.

The seriousness of that interference resulted in particular from the fact that the disclosed data could make it possible to build a profile of an individual, including estimates of their financial circumstances, investment preferences, the sectors in which they invest and the specific companies with which they are associated.

Access was potentially available to an unlimited number of persons, including persons pursuing objectives entirely unrelated to the public interests invoked by the legislation.

8. Assessment of the Individual Objectives

Transparent business environment

The Court stated that disclosure of information about all shareholders, particularly minority shareholders, appeared to provide no useful contribution to the protection of third parties or business transparency.

The legislation therefore did not appear to constitute an appropriate or necessary means of achieving that objective.

The situation may be different for persons who actually manage, represent or control a company, or for beneficial owners under specific AML legislation.

AML/CFT

Preventing money laundering and terrorist financing is a legitimate objective of general interest recognised by EU law.

However, that objective alone does not entitle a Member State to create a register that makes information about all shareholders available indiscriminately to anyone.

The Court pointed to the existence of less intrusive alternatives, in particular limiting access to persons able to demonstrate a legitimate interest.

Unrestricted access for every user was not shown to be strictly necessary in relation to minority shareholders.

Sanctions

The need to enforce sanctions likewise cannot automatically justify disclosure of information about all shareholders.

The Court pointed to the possibility of narrower solutions, such as limiting disclosure to persons appearing on sanctions lists or persons relevant to investigations into sanctions evasion.

Blanket disclosure of information about all minority shareholders was therefore not proportionate to the stated objective.

9. Insufficient Safeguards

A significant problem was the absence of effective technical and organisational safeguards:

  • there was no requirement to demonstrate a legitimate interest,
  • users were not required to identify themselves,
  • the information was searchable online,
  • the data could be downloaded in bulk,
  • there was no effective control over subsequent use,
  • the data could be stored, combined and disseminated further.

The Court specifically noted that allowing bulk downloading, including by unidentified users, increases the risk of misuse and intensifies the interference with the rights of the individuals concerned.

The core of the judgment can be summarised as follows:

EU law does not require Member States to publish information concerning all shareholders of public limited companies, including minority shareholders.

At the same time, the GDPR, read together with Articles 7 and 8 of the Charter, precludes national legislation that makes the personal data of all shareholders available online to an unlimited number of persons without any condition, such as a requirement to demonstrate a legitimate interest, where such blanket disclosure is not necessary and proportionate to the objectives pursued.

11. Relationship with the Luxembourg Business Registers Judgment

The judgment is thematically linked to the judgment of 22 November 2022 in Joined Cases C-37/20 and C-601/20, Luxembourg Business Registers, which concerned unrestricted public access to information about beneficial owners.

The common line of case law is clear:

  • a legitimate public objective is not sufficient on its own,
  • the necessity of the specific scope of disclosure must be demonstrated,
  • a distinction must be made between the general public, public authorities, obliged entities and persons with a legitimate interest,
  • anonymous and unrestricted internet access constitutes a particularly serious interference,
  • the possibility of bulk downloading further increases that interference,
  • legislation must include safeguards against misuse.

The press release itself expressly notes that the applicants relied on the Luxembourg Business Registers judgment.

12. Practical Significance for the GDPR and Public Registers

The judgment is significant beyond shareholder registers.

Where personal data are disclosed by law, the following elements must be assessed separately:

  1. The precise purpose of disclosure
    It is not enough simply to invoke transparency, AML or the public interest.
  2. The categories of persons concerned
    A distinction must be made between a controlling person, a beneficial owner, a member of a statutory body, a majority shareholder and a passive minority investor.
  3. The scope of the data
    Personal identification numbers, dates of birth, identity document data, contact addresses or email addresses require specific justification.
  4. The categories of recipients
    Access by a public authority or an obliged entity cannot automatically be equated with access by the general public.
  5. The access regime
    It matters whether access is anonymous, subject to registration, dependent on demonstrating a legitimate interest, or individually approved.
  6. The technical method of access
    Bulk downloading, API access, search engine indexing and other forms of automated data collection increase the intensity of the interference.
  7. Safeguards
    Access logs, restrictions on further use, search limitations, protection of high-risk individuals and effective objection mechanisms may all be relevant.

13. Preliminary Significance for Slovak Law

The judgment does not mean that every public register or every statutory disclosure of personal data is automatically unlawful.

It does mean, however, that neither the Slovak legislature nor the operator of a public register can simply rely on the argument that disclosure is “in the public interest”.

In the Slovak context, it would be necessary to examine in particular:

  • whether EU law expressly requires disclosure or merely permits it,
  • whether only the data necessary for the specific purpose are made public,
  • whether there is a reason to make the data available to everyone or only to certain categories of users,
  • whether the same objective could be achieved through a less intrusive measure,
  • whether a distinction is made between persons with actual influence and passive minority owners,
  • whether the technical design of the register enables disproportionate profiling or bulk collection of data.

The judgment may also be relevant when assessing disclosure of information about shareholders, donors, recipients of public funds or persons connected with grants and subsidies.

However, the outcome must always depend on the specific legislation, the purpose, the scope of the data and the access regime.

The judgment cannot be mechanically applied to every instance of publication in the public interest.

14. Conclusion

C-798/24 reinforces the principle that statutory disclosure of personal data must not only have a formal legal basis, but must also be substantively necessary, proportionate and accompanied by adequate safeguards.

The most important message is the rejection of a model in which the personal and financial data of all minority shareholders are made available anonymously, online and for bulk download without any requirement to demonstrate a legitimate interest.

Share this article LinkedIn X Email

Hear more from our speakers

Join Qubit Conference® Slovakia 2026 - November 11-12

Get Tickets