Case C-568/26, Kamokė – who decides how much a regulator may take?
A court authorises an inspection. The authority then walks in and decides for itself how much to carry out. The Lithuanian court hearing the challenge wants to know whether the authorisation was the limit, or merely the beginning.
Facts
I.T. is in dispute with the Lietuvos bankas, the competent supervisory authority for financial markets in Lithuania, before the Regionų administracinis teismas Šiaulių rūmai. The authority had obtained a court order to conduct an inspection. What the referring court puts in issue is not the order but what followed it: whether the authority alone determines the scope of the data it collects, or whether that scope must be defined in advance by the specific subject matter of the inspection, together with criteria for selecting what is taken. The question is framed against Articles 7, 8 and 52 of the Charter, Article 69 of Directive 2014/65 on markets in financial instruments, and the principles of proportionality, data minimisation and purpose limitation in Article 5 GDPR. (Kamokė is a fictitious case name assigned under the Court’s anonymisation practice; it does not correspond to any party.)
Questions Referred
According to the Official Journal notice, the Regionų administracinis teismas Šiaulių rūmai asks:
Must Articles 7, 8 and 52 of the Charter of Fundamental Rights of the European Union, Article 69 of Directive 2014/65/EU of the European Parliament and of the Council, read in conjunction with the principles of proportionality, data minimisation and purpose limitation enshrined in Article 5 of Regulation (EU) 2016/679, be interpreted as conferring on the competent financial markets supervisory authority, which has obtained a court order to conduct an inspection, the exclusive power to decide on the scope of the data to be collected, or do the articles referred to above require that the scope of the data to be collected be clearly defined by the specific subject matter of the inspection and the criteria for selecting data for collection, while respecting the principle of proportionality between the right of the supervisory authority to conduct the inspection and the right of the person under inspection to data protection and to an effective remedy?
Sources
OJ notice C/2026/4395 (EUR‑Lex) · Case file on CURIA · Directive 2014/65/EU · Regulation (EU) 2016/679 (GDPR)
Comment
The question offers the Court a binary, and the way it is drafted tells you which half the referring court thinks is right. Either the court order is a licence whose scope the holder fills in afterwards, or it is a boundary drawn in advance around a stated subject matter. Put that way, it is the same problem this site reported from Sofia earlier today in C‑546/26, Ministar na zdraveopazvaneto, where access to a national health database is granted to whole categories of professional with no technical filter and the scope of reading left to each reader’s judgement. Two Member States, two entirely different sectors, one structural question: may the party holding the authorisation also decide how far it reaches?
The Court’s answer in a comparable setting was no. In Case C‑439/19, Latvijas Republikas Saeima (ECLI:EU:C:2021:504) it held that the GDPR — in particular Article 5(1), Article 6(1)(e) and Article 10 — precludes national legislation obliging the body responsible for a register of driving penalty points to make those data accessible without the person requesting access having to establish a specific interest in obtaining them. The requirement is not procedural fussiness. It exists because purpose limitation and data minimisation are meaningless if the person deciding what is necessary is the same person who wants the data.
There is a second consideration the referring court builds into its own phrasing, and it is the sharper one: the right to an effective remedy. A defined scope is what makes challenge possible. If the inspection decision says only that an inspection may take place, there is nothing for the person inspected to argue about — no excess to point to, because no limit was ever stated. Proportionality review needs a measure to review, and an authorisation that delegates its own extent supplies none. That is why the second half of the question asks not only for a defined subject matter but for “the criteria for selecting data for collection”: criteria are what turn a supervisory judgement into something a court can examine after the fact.
Article 69 of Directive 2014/65 hands supervisors an extensive toolkit precisely because market abuse is hard to detect, and nobody expects a financial regulator to name every document in advance. But the tension the reference exposes is not between supervision and privacy in the abstract. It is about where the necessity assessment happens — before the inspection, in a reasoned decision open to challenge, or during it, in the mind of the official carrying it out. Financial supervisors across the Union work from authorisations drafted in the broad style; if the Court holds that Articles 7, 8 and 52(1) of the Charter require the scope to be fixed at the point of authorisation, a good deal of inspection practice will have to be rewritten in narrower terms.