Beyond or within reach: CJEU Grand Chamber sets new limits on access to emails and personal devices
CJEU (Grand Chamber), judgment of 16 July 2026, Joined Cases C-258/23, C-259/23 and C-260/23 – Imagens Médicas Integradas and Others v Autoridade da Concorrência
National competition authorities may seize business emails during unannounced inspections of company premises without first obtaining court approval, the Grand Chamber of the Court of Justice of the EU (CJEU) recently held. Even where an inspection has been authorised by a public prosecutor, as in the Portuguese cases underlying the judgment, such authorisation does not dispense with the requirement for full and effective judicial review after the inspection has taken place.
The position is different, however, if investigators seek access to devices that are owned by individuals rather than the company under investigation. Although the questions referred did not make clear whether the seizure extended to devices owned by individuals, the CJEU took the opportunity to clarify that access to data stored on such devices requires prior authorisation by a court or an independent administrative authority. It will now be for the referring court to determine whether the inspections in the cases underlying the judgement should have been authorised by a court rather than the Portuguese public prosecutor and, if so, whether the evidence obtained by the Portuguese competition authority is admissible.
Although the judgment concerns national competition authorities enforcing Articles 101 and 102 TFEU under Directive (EU) 2019/1, its implications may extend beyond that context. It may offer also guidance for inspections conducted by the European Commission under Regulation (EC) No 1/2003 and, more broadly, for inspections carried out by other public authorities, including tax and data protection authorities.
Background
The judgment arose from three investigations by the Portuguese competition authority. They concerned suspected coordination on teleradiology prices, a pricing agreement for Covid-19 tests and abuse of dominance in payment processing. In each case, the Public Prosecutor’s Office, rather than an investigating judge, had authorised the seizure of business emails. The companies argued that the emails were protected “communications” under Article 7 of the Charter of Fundamental Rights (Charter) and could not be seized at all. In the alternative, they argued that only an investigating judge could authorise such a seizure.
The national court referred the matter to the CJEU. The cases were assigned to the Grand Chamber following the Landeck judgment (CJEU, judgment of 4 October 2024, Case C-548/21 – Bezirkshauptmannschaft Landeck), in which the Court required prior approval from a court or an independent body before investigators could access mobile-phone data in criminal proceedings.
What the Court held
The Court confirmed, in line with the case law of the European Court of Human Rights, that business emails held on a company system are “communications” under Article 7 of the Charter, irrespective of whether their content is professional or private. As such emails may also contain personal data, Article 8 of the Charter applies as well.
This protection, however, does not prevent competition authorities from seizing business emails if the resulting limitation of Article 7 and 8 is justified under Article 52(1) of the Charter. In this context, the Court considered that the seizure of business emails by competition authorities serves the recognised objective of protecting undistorted competition and typically remains confined to materials and individuals linked to the suspected conduct and cannot credibly be replaced by an equally effective but less intrusive means of gathering evidence.
The Court further held that EU law does not require prior court approval for inspections of business premises by competition authorities. Regulation 1/2003 and Directive (EU) 2019/1 (ECN+ Directive) leave Member States free to designate the competent authority to authorise inspections, which may be the national competition authority (NCA), a court or a public prosecutor’s office. Where national law does not require prior court approval, the NCA’s powers must be governed by a strict legal framework and safeguards against arbitrariness and abuse. The inspection must also be subject to full and effective judicial review afterwards, including review of the admissibility of the evidence obtained.
The most interesting aspect of the judgement is, however, the reservation the CJEU introduced for devices that are owned by individuals (employees or managers of the company), rather than the company itself:
- Drawing on the Landeck judgement, the Court held that the seizure of devices owned by individuals does indeed require prior approval by a court or independent administrative body. The Court reasons that such devices can contain a wide variety of sensitive personal data, including data within the meaning of Article 9 GDPR. Accessing this data without prior review by a court or an independent body can therefore interfere seriously with the rights protected by Articles 7 and 8 of the Charter. The Court further indicated that an inspection may nevertheless proceed if the devices are sealed and not accessed until the independent review is completed.
- The Court does not address whether this reservation also extends to devices that are owned by the company but are also used for private purposes by its employees or managers. Whether the seizure of such devices likewise requires prior judicial authorisation therefore remains an open question.
- Finally, the Court stopped short of extending the requirement for prior judicial authorisation to situations where the seizure of data may expose individuals to criminal liability. This approach had been suggested by Advocate General Medina but would likely have been difficult to implement in practice.
Practical implications of the judgment
The practical implications of the judgment will vary depending on both the authority conducting the inspection and the national legal framework governing the inspection.
- For Member States, which do not require prior court approval for inspections by competition authorities, such as Portugal, the judgment is consistent with Article 6 of the ECN+ Directive and does not call that approach into question as a matter of principle. The Court makes clear that the absence of a prior court order will rarely be sufficient to challenge an inspection. Instead, companies may seek to argue that the material fell outside the scope of the inspection decision, was used for purposes unrelated to the suspected infringement, or was obtained in breach of Article 7 or 8 of the Charter. That said, NCAs will need to proceed with caution when seizing devices that may belong to individuals rather than the undertaking under investigation. In such circumstances, they will either need to obtain prior judicial authorisation or ensure that the devices remain sealed pending an independent review. Failure to do so may provide grounds for challenging the admissibility of any evidence obtained from those devices.
- For Member States where court approval is in principle mandatory, such as Germany, the formal position changes little. Inspections by the German Federal Cartel Office (FCO), for instance, generally require prior court authorisation. The FCO (in administrative proceedings) or the German Public Prosecutor’s Office (in fines proceedings) may authorise an inspection without a court order only in urgent cases (Gefahr im Verzug). The judgment will not dilute that requirement. If anything, the Court’s treatment of access to devices owned by individuals as a serious interference with Article 7 and 8 of the Charter may limit the NCAs willingness to rely on such urgency exceptions.
- European Commission (EC) inspections of business premises technically fall outside the scope of the judgment and are governed by the separate regime under Regulation 1/2003. Inspections are based on a EC decision adopted pursuant to Article 20(4). Where coercive assistance may be required, the EC must seek judicial authorisation under Article 20(6) and (7), but only where this is required under the applicable national law. In such cases, the relevant NCA assists with the inspection and, where necessary, may request police support. As under the ECN+ framework, the need for prior judicial authorisation is therefore ultimately determined by national law. That said, the Court’s reasoning regarding access to devices owned by individuals may have implications for the way in which the EC exercises its inspection powers. Where there is a realistic possibility that devices belonging to individuals, rather than the undertaking under investigation, may be affected, the EC may take a more cautious approach. In such a case, the EC could seek prior judicial authorisation or ensure that any such devices remain sealed pending an independent review.
With regard to dawn raid preparedness, the judgment serves as a reminder to keep a detailed, contemporaneous record of what is searched and how. Company representatives or outside counsel should remain present while documents are reviewed and selected and should raise objections where material falls outside the inspection decision, is protected by legal privilege or contains irrelevant personal data. Company representatives or outside counsel should also object to any attempt to seize devices belonging to employees or managers, particularly where the investigating authority has not obtained prior judicial authorisation. While the judgment does not expressly address company-owned devices that are used for private purposes, such devices could arguably merit a comparable level of protection by analogy. This may be the case regardless of whether private use is permitted under company policy.
The Bigger Picture: Implications Beyond Antitrust
While the facts of the case concern inspections by competition authorities, the Court makes general statements about the scope of Articles 7 and 8 of the Charter that are potentially relevant to raids on business premises and investigations beyond antitrust law.
Article 51(1) of the Charter binds a Member State authority to the Charter whenever it is “implementing Union law”. Accordingly, national authorities are bound by the Charter in two scenarios:
- First, the measures may concern an area regulated by Union law. Apart from antitrust law, this includes namely national tax and customs authorities investigating, e.g. VAT fraud or enforcing the Union Customs Code, financial and market-supervision authorities enforcing the Market Abuse Regulation, government bodies applying EU sanctions and export-control regimes, or data-protection regulators enforcing the GDPR.
- Second, the Charter applies if national authorities act under procedural rules that transpose Union law. Landeck illustrates this principle: the Austrian criminal investigators’ access to data stored on a mobile phone was subject to review under the Charter because the relevant national rules of criminal procedure fell within the scope of the EU Law Enforcement Directive. The same applies where national authorities act based on a European Investigation Order.
Thus, in all those cases, business emails are protected by Articles 7 and 8 of the Charter, according to the reasoning of the Court.
What remains unclear is whether the same, stricter, or more lenient rules should apply if bodies other than NCAs seize business emails. Any limitation of the right to communications and protection of personal data must adhere to Article 52(1) of the Charter. As this judgment illustrates, seizure without prior judicial authorisation is not in all cases precluded, namely in investigations by NCAs into breaches of Articles 101 and 102 TFEU.
In other contexts, the proportionality assessment may differ. While the Court draws a distinction between company-owned and devices owned by individuals, it can be argued that a similar distinction needs to be made between investigations affecting the business and criminal investigations that may lead to charges against an individual. The latter scenario demands a higher degree of judicial control. This can be maintained by – as many of the relevant national frameworks do – limiting the authorities’ powers to act without prior judicial authorisation strictly to urgent cases.
For now, it is advisable to revisit device-use policies and update dawn-raid response teams as set out above, not just regarding antitrust investigations, but generally.
