lagen.nu
EDPS yttrande 10/2026

EDPS Opinion 10/2026 on the Proposal for a Regulation on the 28th Regime Corporate Legal Framework – 'EU Inc.'.

Utgivare
Europeiska datatillsynsmannen
Antagen
2026-05-12
Språk
engelska
Ämnesord
Working Conditions
Källa
www.edps.europa.eu
Endast på engelskaEuropeiska datatillsynsmannen har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska datatillsynsmannen.

Opinion 10/2026

on the Proposal for a Regulation on the 28th Regime Corporate Legal Framework – ‘EU Inc.’

0

The European Data Protection Supervisor (EDPS) is an independent institution of the EU, responsible under Article 52(2) of Regulation 2018/1725 ‘With respect to the processing of personal data… for ensuring that the fundamental rights and freedoms of natural persons, and in particular their right to data protection, are respected by Union institutions and bodies’, and under Article 52(3)‘… for advising Union institutions and bodies and data subjects on all matters concerning the processing of personal data’.

Wojciech Rafał Wiewiórowski was appointed as Supervisor on 5 December 2019 for a term of five years. The selection procedure for a new EDPS mandate for a term of five years is still ongoing.

Under Article 42(1) of Regulation 2018/1725, the Commission shall ‘following the adoption of proposals for a legislative act, of recommendations or of proposals to the Council pursuant to Article 218 TFEU or when preparing delegated acts or implementing acts, consult the EDPS where there is an impact on the protection of individuals’ rights and freedoms with regard to the processing of personal data’.

This Opinion relates to the Proposal for a Regulation on the 28 Regime Corporate Legal Framework – ‘EU Inc.’ . This Opinion does not preclude any future additional comments or recommendations by the EDPS, in particular if further issues are identified or new information becomes available. Furthermore, this Opinion is without prejudice to any future action that may be taken by the EDPS in the exercise of his powers pursuant to Regulation (EU) 2018/1725. This Opinion is limited to the provisions of the Proposal that are relevant from a data protection perspective.

Executive Summary

On 18 March 2026, the European Commission issued a Proposal for a Regulation of the European Parliament and of the Council on the 28th Regime Corporate Legal Framework – ‘EU Inc.’ (‘the Proposal’).

The EDPS welcomes the overall objective of the Proposal to provide better conditions for starting a business and better opportunities for growth and scaling up in the EU, and to encourage more investment into EU companies, particularly in their early and growth stages.

The Proposal would require from the Member State of registration of the company to ensure that certain documents and information filed by the EU Inc. are made publicly accessible through national business registers and through the Business Registers Interconnection System (BRIS). The EDPS welcomes that the Proposal specifies in an exhaustive manner which categories of personal data must be processed in the national registers and in the BRIS.

The Proposal would require from the Commission to establish, operate and maintain an EU central interface and to further develop this interface towards a central digital register for EU Inc. companies. In this regard, the EDPS recommends further clarifying the roles of the Commission and Member States with regard to the EU central interface and the central digital register from a data protection perspective. In addition, the EDPS also recommends specifying the maximum storage period or the criteria to determine such storage period related to personal data processed in the EU central interface and in the central digital register.

The Proposal would introduce the obligation for every EU Inc. to maintain an up-to-date digital register of shares, which would contain at least the information enumerated in this provision. In this regard, the EDPS recommends ensuring that the Proposal specifies, in an exhaustive manner, which personal data should be included. The EDPS also recommends adding that access to information on beneficiaries under letter (l) of Article 54(1) of the Proposal would only be provided in accordance with the provisions in section 1 of Chapter II of Directive (EU) 2024/1640. In addition, the EDPS recommends clearly defining the ‘interested parties’ who may consult the digital register of shares. The maximum storage period (or the criteria to determine such storage period) of personal data stored in the digital register of shares should be specified.

Concerning the establishment of a system interconnecting the national electronic auction systems, the EDPS recommends to further clarify the roles and responsibilities of the entities maintaining the electronic auction platforms at national level. In addition, the EDPS recommends specifying in the enacting terms of the Proposal the maximum storage period or the criteria to determine such storage period related to personal data stored in the national auction systems operated by the Member States or other bodies.

2

THE EUROPEAN DATA PROTECTION SUPERVISOR,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (‘EUDPR’) , and in particular Article 42(1) thereof,

HAS ADOPTED THE FOLLOWING OPINION:

1. Introduction

1. On 18 March 2026, the European Commission issued Proposal for a Regulation of the th European Parliament and of the Council on the 28 Regime Corporate Legal Framework – ‘EU Inc.’ (‘the Proposal’).

2. The objective of the Proposal is to lay down rules to improve the functioning of the internal market and to create an efficient legal framework for companies and investors by: a) creating a new harmonised legal form of a limited liability company (‘EU Inc.’) provided in the legal order of every Member State; b) creating an EU central interface, based on the Business Registers Interconnection System (‘BRIS’) , for the purposes of the registration of companies taking the EU Inc. legal form, as well as for filing by EU Inc. companies; c) introducing measures to reduce obstacles to the use and acceptance of documents and information regarding EU Inc. companies including through the application of the once-only principle; d) introducing measures to reduce administrative burden in procedures covered by this Regulation throughout the lifecycle of EU Inc. companies including investment related procedures; e) removing obstacles with respect to financing of EU Inc. companies and investment in such companies; f) harmonising certain aspects of insolvency procedures applicable to specific categories of undertakings taking the legal form of EU Inc.; g) prohibiting certain discriminatory measures with respect to EU Inc. companies whose registered office is in another Member State .

3. The Proposal is accompanied by an Annex containing minimum content of the articles of association of an EU Inc. company.

4. The present Opinion of the EDPS is issued in response to a consultation by the European Commission of 18 May 2026, pursuant to Article 42(1) of EUDPR. The EDPS welcomes the reference to this consultation in Recital 86 of the Proposal.

2. General remarks

5. The EDPS acknowledges the importance of improving the functioning of the internal market and creating an efficient legal framework for companies and investors . In this regard, the EDPS notes that the overall objective of the Proposal is to provide better conditions for starting a business and better opportunities for growth and scaling up in the EU, and to encourage more investment into EU companies, particularly in their early and growth stages .

6. The EDPS remarks that the implementation of the Proposal would entail the processing of personal data. In particular, the Proposal would require the public disclosure of and crossborder access to certain information in relation to EU Inc. companies in national business registers and through BRIS. Furthermore, the EU central interface for registration of and filing by EU Inc. companies would collect company related data and forward it to the national business register . The implementation of the Proposal would also entail the processing of personal data by the Commission in the system of interconnection of electronic auction platforms .

7. Against this background, the EDPS welcomes recital 79 of the Proposal specifying that the Commission should process personal data in the context of the Proposal in accordance with the EUDPR.

8. The EDPS also notes that Article 104 of the Proposal specifies that the processing of any personal data carried out in the context of the Proposal should be subject to the Regulation (EU) 2016/679 (‘the GDPR’) and to the EUDPR. As both the GDPR and EUDPR in any case apply to the processing of personal the processing of any personal data carried out in the context of the Proposal, the EDPS recommends removing this specification from the enacting terms of the Proposal and retaining it only in the recitals.

3. Publication of personal data in the business register

9. Under the Proposal, the Member State of registration of the company must ensure that certain documents and information filed by the EU Inc. are made publicly accessible in the business register . The Proposal further sets out which documents and information should be made available at Union level through the Business Registers Interconnection System (‘BRIS’) . The EDPS welcomes that the Proposal specifies in an exhaustive manner which categories of personal data must be processed in the national registers and in the BRIS.

10. The EDPS notes that the Proposal provides for public access to information of the persons who are authorised to represent the EU Inc., the identity of the first director of an EU Inc., and the identity of the founding shareholder(s) of an EU Inc.

11. The EDPS recalls that, according to settled case law of the Court of Justice of the European Union (‘CJEU’), legislation providing for the public disclosure of personal data interferes with the rights to protection of personal life and to personal data. Any requirement to publish personal data should, in addition to being provided by law, also fulfil the other requirements arising from Article 52(1) of the Charter and Article 6(3) of the GDPR, and in particular must meet an objective of public interest and be proportionate to the legitimate aim pursued.

12. The EDPS considers that the publication of personal envisaged by the Proposal should be considered as proportionate, as it only requires publication of a limited number of personal data items relating to specific individuals that fulfil a specific role in the company. In essence, the Proposal would require public disclosure of limited personal data concerning individuals authorized to represent the company in dealings with third parties and to represent it or take part in the administration, supervision or control of that company, or having been appointed as liquidator of that company .

4. The EU central interface and the central digital register

13. The Proposal would require from the Commission to establish, operate and maintain the 16 17 EU central interface as part of the European electronic access point to BRIS . The EU central interface should securely transmit the information and documents to the business register of the Member State in which the EU Inc. company is to be registered and the business registers should automatically exchange the relevant information with the preventive control authorities . The Commission should further develop the EU central interface towards a central digital register for EU Inc. companies, building on the functionalities of the registers of the Member States and the existing interconnection infrastructure . The EDPS recommends to expressly clarify the roles of the Commission and Member States with regard to the EU central interface and the central digital register from a data protection perspective. Clearly designating the controller(s) of specific processing operation(s) from the outset provides legal certainty and helps to avoid any possible problem of interpretation in assessing the role of the actors involved . When carrying out a processing operation, the controller is the one deciding on the purpose (‘why’) and on the means to carry out such processing operation (‘how’). In this regard, the EDPS observes that EU Inc. companies may be formed directly through the EU central interface and that this interface will eventually further develop towards a central register. It would therefore be logical that the Commission be designated the role of as controller with regard to the EU central interface and to the central digital register. Personal data processed in the business registers of Member States, however, remains under the control of the Member States.

14. The EDPS recommends specifying in the enacting terms of the Proposal the maximum storage period (or at least the criteria to determine such storage period) related to personal data processed in the EU central interface and in the central digital register .

5. Digital register of shares

15. Article 54(1) of the Proposal would introduce the obligation for every EU Inc. to create upon registration and maintain an up-to-date digital register of shares, which would contain at least the information enumerated in this provision.

16. The EDPS notes that the application of this provision would entail the processing of personal data in the context of the digital register of shares such as the identity and address of all the shareholders , identity and address of a common representative of the 25 26 shareholders and the name of the beneficiaries of the shares .

17. The EDPS recalls that a legislative proposal which provides for the processing of personal data, should, as a rule, specify the categories of personal data in a comprehensive manner. Open-ended formulations (e.g., “any other relevant data”, “at least”, ...) should be avoided .

18. Against this background, the EDPS recommends deleting “at least” in Article 54(1) of the Proposal and providing instead an exhaustive list of the information to be provided by the EU Inc. The EDPS also recommends adding that access to information on beneficiaries under letter (l) of Article 54(1) of the Proposal would only be provided in accordance with the provisions in section 1 of Chapter II of Directive (EU) 2024/1640 .

19. The EDPS notes that the Proposal would provide that the digital register of shares must be accessible to any shareholder and any other interested party with a legitimate interest in accordance with the GDPR . The EDPS recommends clearly defining in the Proposal the ‘interested parties’ to which the digital register of shares, in addition to the shareholders of the EU Inc., would be accessible and deleting the reference to “with a legitimate interest, in accordance with Regulation (EU) 2016/679”. In addition, the EDPS recommends specifying in the Proposal the maximum storage period or the criteria to determine such storage period related to personal data stored in the digital register of shares, following the expiry of which the personal data should be deleted.

20. Finally, the EDPS welcomes Recital 80 specifying that, to facilitate compliance with data protection rules and ensure the implementation of proportionate data protection measures, the EU templates for the articles of association would contain provisions on data protection related to the digital register of shares.

6. The system of interconnection of electronic auction platforms

21. According to the Proposal the Member States would be required to establish and operate one or more national electronic auction platforms for the realisation of the assets of the insolvency estate in insolvency proceedings of at least EU Inc. companies that are innovative startups . The Commission would be required to establish a system interconnecting the national electronic auction systems via the European e-Justice Portal, which should serve as a central electronic access point .

7. Roles and responsibilities

22. The EDPS recalls that the concepts of controller, joint controller and processor play a crucial role in the application of data protection law, since they determine who is responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice .

23. The EDPS welcomes that the Proposal aims to clarify the role of the Commission as controller for the system for the interconnection of the national electronic auction systems and stipulates that the Commission must define the necessary policies and apply the necessary technical solutions to fulfil its responsibilities within the scope of the function of controller .

24. The EDPS recommends also clarifying the roles and responsibilities of the entities maintaining the electronic auction platforms at national level (as controllers, joint controllers or processors) in relation to the processing of personal data in the context of the system of interconnection of electronic auction platforms.

25. In line with Article 26 of the GDPR, where two or more controllers determine the purposes and means of the processing, they shall be joint controllers . Insofar as the various actors act as joint controllers, they shall in transparent manner determine their respective responsibilities for compliance with their data protection obligations, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information . In that case, the distribution of tasks between them should be laid down either by law or by an arrangement between the joint controllers.

7.1. Data storage and security of personal data

26. The EDPS welcomes the specification provided in the Proposal that with regard to the information from the interconnected national auction systems, no personal data relating to data subjects shall be stored in the European e-Justice Portal and that all such data shall be stored in the national auction systems operated by the Member States or other bodies .

27. The EDPS recalls that the principle of storage limitation requires that personal data are stored in a form that permits identification of data subjects for no longer than is necessary for the purpose for which the personal data are processed. Therefore, the EDPS recommends specifying in the enacting terms of the Proposal the maximum storage period or the criteria to determine such storage period related to personal data stored in the national auction systems operated by the Member States or other bodies, following the expiry of which the personal data should be deleted .

28. The data controllers must implement appropriate technical and organisational measures to ensure a level of security of personal data appropriate to the risk. In this context, the EDPS also welcomes that the Proposal specifies that the Commission shall implement the technical measures required to ensure the security of personal data while in transit, in particular the confidentiality and integrity of any transmission to and from the European e-Justice Portal .

7.2. Implementing acts

29. Pursuant to Articles 35(3) and 98(2) of the Proposal, the Commission should lay down, by means of implementing acts, multilingual templates for articles of association and application forms to establish and EU Inc., a detailed list of data to be transmitted to exchange information between registers and the availability of documents and information through BRIS as well as technical specifications and procedures necessary to provide for the interconnection of Member States’ national electronic auction systems, setting out, among other matters, specification of which personal data can be accessed and data protection safeguards.

8. Conclusions

31. In light of the above, the EDPS makes the following recommendations: (1) to recall that the processing of any personal data carried out in the context of the Proposal should be subject to the GDPR and to the EUDPR by way of recital only and deleting Article 104 of the Proposal; (2) to expressly clarify the roles of the Commission and Member States with regard to the EU central interface and the central digital register from a data protection perspective; (3) to specify the maximum storage period or the criteria to determine such storage period related to personal data processed in the EU central interface and in the central digital register; (5) to add that access to information on beneficiaries under letter (l) of Article 54(1) of the Proposal would only be provided in accordance with the provisions in section 1 of Chapter II of Directive (EU) 2024/1640; (6) to define in the Proposal the ‘interested parties’ to which the digital register of shares, in addition to the shareholders of the EU Inc., would be accessible and deleting the reference to “with a legitimate interest, in accordance with Regulation (EU) 2016/679”; (7) to specify in the Proposal the maximum storage period or the criteria to determine such storage period related to personal data stored in the digital register of shares, following the expiry of which the personal data should be deleted; (8) to clarify the roles and responsibilities of the entities maintaining the electronic auction platforms at national level (as controllers, joint controllers or processors) in relation to the processing of personal data in the context of the system of interconnection of electronic auction platforms; (9) to specify in the enacting terms of the Proposal the maximum storage period or the criteria to determine such storage period related to personal data stored in the national auction systems operated by the Member States or other bodies. Brussels, 12 May 2026 (e-signed) Wojciech Rafał WIEWIÓROWSKI 11

Fotnoter

  1. 1 COM (2026) 321 final 1
  2. 2 OJ L 295, 21.11.2018, p. 39. 3 COM (2026) 321 final. 4 Article 1(2) of the Proposal - ‘Business Registers Interconnection System’ (‘BRIS’) means the system of interconnection of registers operating at the Union level, composed by the business registers of the Member States, the platform and the E-Justice portal as referred to Article 22 of Directive (EU) 2017/1132. 4
  3. 5 Article 1 of the Proposal. Article 1 of the Proposal. 7 Explanatory Memorandum, p. 2. 8 Explanatory Memorandum, p. 15. 9 See for instance the reference to personal data of legal representatives and other persons that can lawfully represent a company, in recital 79 of the Proposal. 10 Article 100(1) of the Proposal. 11 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance), OJ L 119, 4.5.2016, pp. 1–88. 5
  4. 12 Article 25 of the Proposal. 13 Article 26 of the Proposal. 14 Articles 25 and 26 of the Proposal and Annex to the Proposal. 15 In its judgment of 9 March 2017, the Court of Justice of the European Union (‘CJEU’) considered that the public nature of the company register in question was intended to ensure legal certainty in dealings between companies and third parties and to protect, 15 in particular, the interests of third parties in relation to joint stock companies and limited liability companies . The CJEU considered that the interference with the fundamental rights of the persons concerned (in particular the right to respect for private life and the right to protection of personal data guaranteed by the Charter of Fundamental Rights of the Union) was not disproportionate in so far as disclosure was required only for a limited number of personal data items, and the only safeguards that joint-stock companies and limited liability companies offer to third parties were their assets. Therefore, the CJEU considered it justified that natural persons who choose to participate in trade through such a joint stock company or limited liability company should be required to disclose data relating to their identity and functions within that company. See Judgment of the Court of Justice of the European Union of 9 March 2017, Camera di Commercio, Industria, Artigianato e Agricoltura di Lecce v. Salvatore Manni, Case C-398/15, ECLI:EU:C:2016:652. See also EDPS Opinion 19/2023 on the Proposal for a Directive amending Directives 2009/102/EC and (EU) 2017/1132 as regards further expanding and upgrading the use of digital tools and processes in company law, 17 May 2023, paragraphs 11-13. 6
  5. 16 Articles 1(1) and 15 of the Proposal. 17 See: Article 22 of Directive (EU) 2017/1132 of the European Parliament and of the Council of 14 June 2017 relating to certain aspects of company law (codification), OJ L 169, 30.6.2017, pp. 46–127, ELI: http://data.europa.eu/eli/dir/2017/1132/oj 18 Article 15 and Recital 21 of the Proposal. 19 Article 34 and Recital 23 of the Proposal. 20 See EDPS Guidelines on the concepts of controller, processor and joint controllership under Regulation (EU) 2018/1725, issued on 7 November 2019, p.8. 21 Articles 16 and 17 of the Proposal. 22 See EDPS Guidance for co-legislators on key elements of legislative Proposals, issued on 7 May 2025, p.9. 23 See EDPS Guidance for co-legislators on key elements of legislative Proposals, issued on 7 May 2025, p.18. 7
  6. 24 Article 54(1)(a) of the Proposal. 25 Article 54(1)(b) of the Proposal. 26 Article 54(1)(l) of the Proposal. 27 See EDPS Guidance for co-legislators on key elements of legislative Proposals, issued on 7 May 2025, p.1 See also 28 Directive (EU) 2024/1640 of the European Parliament and of the Council of 31 May 2024 on the mechanisms to be put in place by Member States for the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, amending Directive (EU) 2019/1937, and amending and repealing Directive (EU) 2015/849 (Text with EEA relevance), OJ L, 2024/1640, 19.6.2024, ELI: http://data.europa.eu/eli/dir/2024/1640/oj 29 Article 54(2) of the Proposal. 30 Article 97 of the Proposal. 31 Article 98 of the Proposal. 8
  7. 32 See EDPS Guidelines on the concepts of controller, processor and joint controllership under Regulation (EU) 2018/1725, issued on 7 November 2019, EDPS Guidance for co-legislators on key elements of legislative Proposals, issued on 7 May 2025, p.9. 33 Article 100(1) of the Proposal. 34 Article 100(2) of the Proposal. 35 See EDPS Guidelines on the concepts of controller, processor and joint controllership under Regulation (EU) 2018/1725, issued on 7 November 2019. 36 Wirtschaftsakademie v Schleswig-Holstein See: Judgment of the Court (Grand Chamber) of 5 June 2018, case C-210/16, , paragraph 29. 37 Article 100(4) of the Proposal. 38 Article 5(1)(e) GDPR. 9
  8. 30 In this regard, the EDPS reminds the Commission of its obligation to consult the EDPS when preparing delegated or implementing acts that would impact on the protection of individuals' rights and freedoms with regard to the processing of personal data pursuant to Article 42(1) of the EUDPR.