Vancouver, Canada — Beneficial ownership registers in the European Union have once again entered a period of transition, reflecting a broader struggle to balance transparency with privacy. Following successive legislative changes and court rulings, the compliance environment for corporations, investors, and families operating within the EU has become unstable and complex. Amicus International Consulting today issued an expanded advisory for clients, outlining privacy-preserving compliance strategies designed to minimize exposure while ensuring lawful operations across borders.
A Shifting Legal Landscape
The original design of EU beneficial-ownership registers under the Fourth and Fifth Anti-Money Laundering Directives (AMLD4 and AMLD5) envisioned wide public access. The goal was to create transparency that would allow regulators, journalists, and civil society groups to trace illicit finance, corruption, and tax evasion. However, in 2022, the Court of Justice of the European Union (CJEU) ruled that unfettered public access violated the fundamental right to privacy enshrined in the EU Charter of Fundamental Rights.
This landmark decision required member states to restrict public access. Yet, the European Commission and national legislatures continue to push for a balance between transparency and privacy. In 2024 and 2025, several reforms introduced layered access models. These new frameworks distinguish between categories of requesters. Regulators retain full access. Financial institutions conducting due diligence are granted limited but functional access. Journalists and NGOs may petition for access if they can demonstrate a legitimate interest.
The result is a patchwork environment where rules vary not only between EU states but also within the interpretation of national registries. Corporations must therefore adapt compliance practices to different access models, often without clear guidance on how privacy rights are to be safeguarded in practice.
The Transparency-Privacy Tension
Transparency remains a cornerstone of EU anti-money laundering policy. The Commission argues that corruption, terrorist financing, and tax evasion can only be addressed if authorities and civil society can “follow the money.” Critics, however, highlight that transparency should not come at the expense of personal safety and data protection.
Beneficial ownership data reveals who ultimately controls corporate entities, and this data can be highly sensitive. For family-owned businesses, it exposes generational wealth patterns. For investors in politically unstable regions, it reveals affiliations that could endanger family members. For politically exposed persons (PEPs), it heightens the risks of being targeted by hostile actors.
Amicus notes that privacy-preserving compliance does not mean secrecy or evasion. It means carefully balancing disclosure obligations with legitimate privacy protections recognized under EU law and the GDPR.
Privacy-Preserving Compliance Steps
Amicus International Consulting advises clients to adopt a set of privacy-preserving steps that align with both regulatory expectations and privacy rights. These include:
Threshold-Driven Disclosure: EU law sets thresholds, often 25 percent ownership or significant control, for beneficial ownership reporting. Entities should disclose only those individuals who meet the threshold, avoiding over-disclosure of minority shareholders.
Data Minimization: Registries often request information fields beyond statutory requirements. Companies should provide only mandatory data, limiting optional details that increase exposure.
Confidentiality Designations: In many jurisdictions, beneficial owners can request confidentiality where disclosure would create a disproportionate risk, such as in cases involving minors, PEPs, or security threats. Amicus guides clients in making these petitions.
Cross-Jurisdiction Harmonization: Entities operating across multiple EU states should align disclosures internally to avoid inconsistencies that could raise suspicion or cause reputational harm.
Internal GDPR Compliance: Beneficial ownership data held within a corporation must be handled according to GDPR principles of purpose limitation, security, and minimal retention. This ensures that disclosure obligations do not create internal privacy liabilities.
Layered Structuring: Holding companies, family trusts, and investment vehicles can be structured to manage disclosure obligations efficiently while lawfully shielding sensitive stakeholders.
Case Study: Luxembourg Investment Fund
A Luxembourg-based private equity fund managed assets on behalf of European, Middle Eastern, and Asian investors. The fund was required to file beneficial ownership disclosures with Luxembourg’s national register. Several of its investors were PEPs who requested additional safeguards due to political sensitivities.
Amicus advised the fund to structure reporting so that only ultimate beneficial owners above the threshold were disclosed, while indirect investors were recorded through layered holding companies. The firm successfully petitioned Luxembourg’s registry to classify certain ownership records as restricted access, citing disproportionate risks under the CJEU’s privacy doctrine. The fund remained fully compliant with AMLD rules while minimizing its exposure to public access petitions.
Case Study: German Mittelstand Manufacturer
A German family-owned manufacturer faced compliance challenges when regulators updated the national register system in early 2025. Journalists had previously used beneficial ownership data to investigate the firm’s political connections, creating reputational risk for family members.
Amicus recommended restructuring ownership through a family holding trust, consolidating smaller shareholder interests under a single entity. Only the trust’s controlling board members were disclosed to the registry. This approach met German disclosure obligations while shielding minor family members from unnecessary exposure. The family also secured legal advice to petition for confidentiality, citing security risks for younger stakeholders.
Divergence Between Member States
One of the most challenging aspects of compliance in 2025 is the divergence in register implementation across EU member states. France has adopted restrictive rules, granting journalists access only upon judicial approval. The Netherlands has taken a broader approach, maintaining relatively open access for civil society groups under controlled conditions.
This divergence means that a multinational firm registered in both France and the Netherlands may file similar beneficial ownership data but face different access risks in each jurisdiction. For corporations, this increases the need for harmonized internal reporting and coordinated disclosure strategies. Without harmonization, disclosures in one country may expose sensitive ownership data more widely than in another.
Cybersecurity and Data Breach Risks
Beyond access policies, beneficial ownership registers represent high-value cyber targets. Hackers, cybercriminals, and state actors seek to access these databases to identify wealthy individuals or politically sensitive stakeholders. Even with restricted access, a data breach could lead to extortion, identity theft, or reputational attacks.
Amicus recommends that corporations integrate cybersecurity hygiene into their compliance processes. Internal beneficial ownership data should be encrypted, stored securely, and accessed only by designated compliance officers. Companies should also monitor national registers for breach disclosures and prepare contingency plans for rapid response.
Case Study: Nordic Energy Consortium
A consortium of renewable energy investors operating in Denmark and Sweden faced new disclosure obligations in 2025. Some investors were family offices with strict privacy requirements under domestic law. Others were public institutions subject to their transparency codes.
Amicus developed a two-tier disclosure plan. At the national registry level, the consortium disclosed only statutory beneficial owners. Internally, it maintained a more detailed private ledger that allowed regulators to request further information under secure conditions. This layered approach balanced transparency with privacy, satisfying the needs of both public and private stakeholders.
The Role of Financial Institutions
Banks and financial institutions remain critical intermediaries in the beneficial ownership compliance chain. They are often granted registry access to perform due diligence checks. This means corporations must ensure that their disclosures align with what banks report during onboarding and ongoing monitoring.
Amicus stresses the importance of synchronizing beneficial ownership filings with banking compliance. Inconsistencies between registry disclosures and bank due diligence records can trigger suspicious activity reports, even when no misconduct exists. Privacy-preserving compliance, therefore, requires both legal structuring and operational alignment with financial partners.
Case Study: Spanish Real Estate Holding
A Spanish real estate holding company was flagged during a bank onboarding process because its beneficial ownership filing did not match the information provided in the client onboarding documents. Amicus intervened by harmonizing the ownership records across both systems. It also implemented a policy to update registry filings in tandem with banking records, preventing future mismatches.
The company’s bank rescinded its risk alert, allowing financing for a new property acquisition to proceed. The case underscored the importance of treating beneficial ownership filings not as stand-alone compliance steps but as interconnected elements of a broader risk management ecosystem.
Looking Ahead: EU Integration vs. Fragmentation
The EU’s approach to beneficial ownership registers will remain contested. On one side, the Commission pushes for harmonization across member states. On the other hand, national courts and privacy advocates demand differentiated approaches tailored to domestic legal traditions. This tension creates uncertainty for multinational corporations that must prepare for multiple scenarios.
Amicus anticipates further reforms by 2026, possibly including a new directive that will integrate beneficial ownership disclosure more closely with EU-wide anti-money laundering regulations. Until then, companies must operate within a fragmented environment, adapting structures and processes dynamically.
Amicus Guidance: The Discipline of Entity Risk Hygiene
Amicus emphasizes that privacy-preserving compliance is part of a broader discipline known as entity risk hygiene. Just as individuals practice hygiene to protect health, corporations must continuously clean, monitor, and align their entities with legal and reputational standards. This discipline requires constant adaptation, particularly in areas like beneficial ownership, where regulatory rules can change overnight due to litigation or political developments.
Entity risk hygiene includes beneficial ownership mapping, disclosure gap analysis, privacy risk review, structuring flexibility, litigation contingency planning, and cybersecurity integration. Together, these measures create resilient corporate structures capable of withstanding regulatory volatility.
Conclusion
The EU’s shifting beneficial-ownership register framework illustrates the difficulty of balancing transparency and privacy in an interconnected financial world. For corporations, investors, and families, the stakes are high: reputational damage, regulatory penalties, or privacy violations can result from missteps in disclosure.
Amicus International Consulting continues to guide clients through these complexities, offering tailored solutions that protect privacy while ensuring lawful compliance across borders. With privacy-preserving strategies, corporations can meet their obligations without exposing stakeholders to unnecessary risks, achieving stability in an unstable regulatory environment.
Contact Information
Phone: +1 (604) 200-5402
Email: [email protected]
Website: www.amicusint.ca




