Non-mandatory register data – a “right to be forgotten” in the commercial register
- Federal Court of Justice strengthens the “right to be forgotten” in the electronic commercial register.
- Non-mandatory register data does not have to remain publicly accessible indefinitely.
- Federal Court of Justice allows document replacement to protect personal register data.
- Data protection in the commercial register: less data, same purpose.
Facts
By decision of 18 February 2026 (II ZB 2/25), the Second Civil Senate of the Federal Court of Justice further specified the processing of personal data in the electronic commercial register. Two applicants, who had acted as managing directors of companies involved in a GmbH & Co. KG, sought to have earlier commercial register filings replaced in the register folder. Those filings contained their private addresses and handwritten signatures and were electronically accessible to anyone via the joint register portal of the German federal states. The applicants justified their request by pointing to the risks of mass data retrieval and criminal threats since the register was digitised.
Specifically requested was the replacement of the existing filings with new versions in which
- only the business address is included instead of the private address,
- instead of the depicted signature, only “signed” together with the name in print,
are included. The register court (Hamburg Local Court) and the Higher Regional Court of Hamburg denied such a claim, citing the publicity and evidentiary function of the commercial register and an alleged duty to keep an unaltered document history.
The Federal Court of Justice set aside both decisions and referred the matter back to the Hamburg Local Court – with instructions not to reject the requested document replacement for the reasons previously given.
Core statements of the BGH
The Federal Court of Justice first clarifies that both the applicants’ private addresses and their signatures are personal data within the meaning of the GDPR, processed by the register court.
Decisive, however, is the classification of these data by the Federal Court of Justice as non-mandatory. They are personal data that are not required to be entered in the commercial register.
For such data, there is no general basis under register law to store them permanently in the register folder after consent has been withdrawn.
The official headnote of the Federal Court of Justice therefore reads:
“There is no general basis under register law for permanently storing, in the commercial register folder, personal data contained in filings to the commercial register that are not to be entered in the commercial register (so-called non-mandatory data) after the filer has withdrawn consent.”
The Federal Court of Justice classifies the applicants’ request as an exercise of the right to erasure under the GDPR.
In essence, it states:
- The term “erasure” used in the GDPR must be interpreted autonomously and means rendering the data unrecognisable in such a way that the embodied information can in fact no longer be perceived.
- The right to erasure is to be understood normatively as a “right to be forgotten” and is not limited to merely deleting individual data records, as the corresponding heading in the GDPR also describes.
- The data subject can determine the scope of their erasure request themselves, for example by limiting it
- to specific data or types of data,
- to specific forms or purposes of processing,
- or to specific storage locations.
This means that a selective erasure request is permissible that relates solely to the electronically accessible register folder (document view in the portal), without having to cover all other official file holdings.
The Federal Court of Justice further emphasises that erasure within the meaning of the GDPR is not limited to removing data from existing documents. The “desired outcome” of rendering the data unrecognisable can also be achieved by replacing documents with ones that no longer contain the relevant data.
“Right to be forgotten” in practice
The Federal Court of Justice’s decision highlights, for legal and notarial practice, the need for careful drafting and submission of register documents so that personal data are not disclosed beyond what is legally required.
Especially in corporate transactions, a wealth of information typically ends up in the register folder, in particular private addresses and also signatures, e.g. of shareholders or corporate bodies. The decision shows that these data are not automatically necessary and do not have to be publicly accessible “just like that”.
The decision therefore sets a clear framework: The transparency of the commercial register ends where non-mandatory personal data are not required for the register’s purpose.
In practice, this means:
- Existing filings should be reviewed for non-mandatory data and, if necessary, cleaned up by means of document replacement.
- Future register filings should be designed consistently with data minimisation in mind.
- The GDPR “right to be forgotten” can be implemented in the commercial register through targeted document replacement – without undermining the legally required publicity.
Please feel free to contact us.
From the newsletter
“Corporate Law, Deals & Capital Markets” Subscribe to the newsletter
here