Legal Insights
5. May 2026
Jonas Doser
Laura Emmeluth
Since the entry into force of the DiRUG (Act implementing the Digitalisation Directive) and the DiREG (Act supplementing the provisions for the implementation of the Digitalisation Directive), the Commercial Register has been fully and freely accessible to the public in electronic form. The personal data stored there can thus be extracted and consolidated on a large scale through automated processes. This facilitates the creation of detailed personal and financial profiles and significantly increases the risk of targeted criminal offences. The Federal Court of Justice (BGH) recently had to rule (once again) on whether personal data in the Commercial Register may be deleted or replaced.
When applying the GDPR in the context of the Commercial Register, a distinction must first be made. For personal data that is legally required for registration and entry, processing is based on a legal obligation pursuant to Art. 6(1)(c) GDPR. Consent is neither necessary nor valid for this purpose. For additional, non‑mandatory (“extra‑mandatory”) information – such as private addresses or signatures of shareholders or legal representatives in documents contained in the registry file – consent is required pursuant to Art. 6(1)(a) GDPR. If this consent is revoked (which is possible at any time pursuant to Art. 7(3) GDPR), there is no longer a legal basis for the continued storage and public availability of the personal data.
Against this background, the BGH held in its decision of 18 February 2026 (II ZB 2/25) that data subjects may request that relevant registration documents in the registry file be replaced with redacted versions that do not include private addresses or handwritten signatures. A specific “legal interest” is not required for such a request for deletion or replacement. In particular, the fact that identical data is available in other registry files does not preclude a request for deletion.
The applicants were the managing directors of two limited liability companies (GmbHs) that served as limited partners in a GmbH & Co. KG. As part of the registration of the limited partnership and a subsequent change in the ownership structure, electronic filings were submitted to the Commercial Register. These filings included, among other things, the applicants’ home addresses and handwritten signatures and were accessible to the public via the Joint Register Portal as part of the Commercial Register’s registry file.
The applicants requested that the registry court replace the relevant filings with new versions in which the private home addresses were replaced by business addresses and the handwritten signatures by a “signed” notation with the name reproduced in text form. The registry court and the appellate court rejected the motion on the grounds that there was no legal interest in replacing the documents, since the applicants’ home addresses and signatures were already contained in other, uncontested registry documents. The applicants filed a petition for review with the BGH against this decision.
The BGH granted the appeal. The Court first clarified that Article 17(1) GDPR does not require a legal interest in protection beyond the statutory conditions for erasure and that the right to erasure may only be restricted for the reasons specified in Article 17(3) GDPR. The fact that identical data exists in other registry files neither deprives the specific request for erasure of its legal interest nor constitutes an abuse of rights, since reducing the number of storage locations already minimises the risk of abusive data use, and the data subject is entitled to selectively determine the scope of their request for erasure.
The request for the replacement of documents is to be classified as a request for erasure because redacting the data by using revised substitute documents constitutes a permissible form of “rendering the data unusable”. There is no longer any justification under Art. 6(1) GDPR for the continued storage of this data beyond what is required by law, since the consent originally contained in the submission has been effectively revoked and there is no other legal basis for the continued storage of information not required by law.
The BGH therefore overturned the decisions of the lower courts and instructed the registry court not to reject the requested replacement of filings for the reasons stated above.
In its decision of 23 January 2024 (II ZB 7/23), the BGH ruled that a managing director of a GmbH has no right under Article 17(1) GDPR to have his date of birth and place of residence deleted from the Commercial Register. That decision concerned mandatory information. The BGH’s latest decision now brings new movement to the issue but applies only to non‑mandatory information. Taken together, these two rulings demonstrate that, for legally required registry data, the protection of personality rights takes a back seat to the principle of register publicity, whereas for non‑mandatory personal data there is a right to erasure under data protection law.
The ruling has immediate practical implications for registry courts, legal counsel, notaries, and for managing directors and shareholders whose personal data is publicly accessible in Commercial Register filings. It is now clear that:
For filings already on record with the Commercial Register, the ruling establishes a clear procedure for correcting data protection violations: Data subjects may request that the registry court replace their applications with corrected versions, provided that the original version contains personal data that is not required to be part of the application or entry and is therefore “excessive”. The registry court does not need to receive a separate revocation of consent in advance, as this is “implied” by the request for deletion. Especially where individuals are mentioned multiple times in the Commercial Register, they are not required to have all documents replaced at once – which could entail significant effort. As the BGH clearly states, the existence of identical data in other registry files does not preclude even a single request for deletion.
Personal data that goes beyond what is required by law – in particular, home addresses and handwritten signatures – should, wherever possible, not be included in the registry file in the first place. Current notarisation and register law deliberately provides leeway for this. For example, under Section 42(3) of the Notarisation Act (BeurkG), electronic copies may be created in excerpt form, in which private residential addresses are replaced by business addresses and signatures are merely indicated or reproduced in text form (“signed” together with the name).
You are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.