Oktober 09. 2026

Personal Devices, Privacy and Prior Judicial Review: Reinforced Safeguards in Competition Investigations

Share

Competition authorities across the European Union wield formidable investigative powers, including the power to conduct dawn raids and send detailed requests for information (“RFIs”). For businesses on the receiving end, these measures can be disruptive and stressful, particularly when they reach into employees’ personal devices and messaging apps. In the modern workplace, the line between personal and business use of devices has blurred: employees routinely use personal phones for work emails and messaging, while also using work laptops for private browsing and communications. As a result, investigations increasingly risk capturing private material, creating tension with the EU Charter of Fundamental Rights (the "Charter"), which guarantees respect for private life (Article 7) and protection of personal data (Article 8). Recent rulings have brought this tension into focus: the EU General Court's judgments of 3 June 2026 in Vivendi SE v European Commission (Case T-1097/23) and Lagardère SA v European Commission (Case T-1119/23), and the EU Court of Justice’s Grand Chamber ruling of 16 July 2026 in IMI–Imagens Médicas Integradas S.A. v Autoridade da Concorrência (Joined Cases C-258/23 to C-260/23). This Legal Update analyses these judgments and the solutions offered by the European Courts, as well as identifying practical takeaways for dawn raid preparedness.

Vivendi / Lagardère: the Protection of Private Life Information in Keyword RFIs

In the context of an investigation into potential gun-jumping, the European Commission (the “Commission”) issued keyword RFIs to the companies under investigation. These required production of messages and documents from 15 custodians containing approximately one hundred keywords, including from WhatsApp, Telegram and Signal on personal devices used “for professional communications at least once”, and deleted items still accessible via backups.

Both companies challenged the RFIs. At the interim stage, the Court of Justice upheld suspension requests, notably due to potential violation of French criminal privacy rules. The Commission amended its decision to strengthen procedural protections, and most documents were ultimately provided.

On the substantive appeals, the EU General Court (the “General Court”) addressed three principal issues:

  • Misuse of investigative powers: The General Court rejected the argument that keyword RFIs require companies to conduct exploratory inspections on the Commission's behalf, reasoning that inspections are “more restrictive in nature” with “a particular intensity” for undertakings. However, the judgment did not address a key asymmetry: in keyword RFIs, the company bears obstruction-penalty risk for missing data, whereas in inspections, inspectors decide what to review.
  • Conflict with national law: The General Court dismissed claims that French criminal and employment law would prevent employers from requiring employees to permit searches of personal devices. It held that EU law takes primacy and noted that Article 122-4 of the French Criminal Code exempts acts performed “pursuant to an order from a lawful authority, save where that act is manifestly unlawful.” The Court also observed that companies under investigation have an obligation to cooperate actively with the authorities and are responsible for the conduct of persons within their sphere of influence in competition matters.
  • Protection of private life: Building on Les Mousquetaires (Case T-255/17), Meta Platforms Ireland (Case T-452/20) and Landeck (Case C-548/21), in which the courts established that serious interference with fundamental rights requires prior review by a court or independent body, the General Court acknowledged that keyword RFIs are likely to reveal private information from personal devices, creating “serious interference” with employees' privacy rights.

The General Court approved the Commission’s protections: limiting searches to personal devices used at least once for professional communications; encrypting GDPR private data for review in a virtual data room; and extending that procedure to all private-life information, and not just personal data under Article 9 GDPR (data revealing racial or ethnic origin, political opinions etc.).

As the Commission adjusted safeguards as the appeals progressed, the annulment actions were ultimately dismissed on the merits. Both judgments are nonetheless under appeal. In the meantime, keyword RFIs look set to remain a fixture of Commission practice. Indeed, as part of the ongoing revision of Regulation 1/2003, the Commission is considering new powers to impose data preservation obligations on companies under investigation, enabling it to conduct targeted searches of those datasets later in the proceedings.

Imagens: Personal Devices and Prior Judicial Review

In a Grand Chamber preliminary ruling, the EU Court of Justice (the “Court of Justice”) addressed the conditions under which national competition authorities may search and seize employees' emails during dawn raids. The case arose from inspections by the Portuguese Competition Authority. The undertakings challenged the seizures, arguing that Article 7 of the Charter, which protects private and family life, precludes seizure authorised by the Public Prosecutor’s Office rather than by a court.

The key finding was that Articles 7 and 8 of the Charter do not prevent seizure of business emails without prior court authorisation, provided domestic law establishes a “strict legal framework” with “adequate and sufficient safeguards” including effective ex post judicial review. However, where inspectors search devices belonging to individuals, access to such devices must be “subject to prior review by a court or an independent administrative body”, where relevant after being sealed. Such devices mix private and professional use, and their data can reveal a great deal about a person’s private life, meaning the interference can be “serious, or even particularly serious.”

In reaching these conclusions, the Court of Justice adopted an expansive conception of private life information:

  • Article 7 of the Charter: Business emails are protected “communications” under Article 7 regardless of whether their content is private; an employer’s prohibition on personal use does not displace that protection.
  • Article 8 of the Charter: The Court of Justice also emphasised that Article 8 of the Charter is engaged, noting that “the documents covered by the seizures at issue in the main proceedings may concern not only ‘communications’ within the meaning of Article 7 of the Charter, but also personal data, protected by Article 8 of the Charter. The fact that the information gathered was provided as part of a professional activity does not mean that it cannot be characterised as personal data.”
  • Private-life information: Crucially, the Court of Justice did not confine its concern to special category data under Article 9 GDPR. Instead, it looked at the full range of private-life information such devices hold, including traffic and location data, photographs, browsing history and private communications, which together may reveal a person's habits, residence, movements, activities and social relationships. Article 9 data was treated as an additional aggravating factor, not the trigger.

The decisive test for the Court of Justice is therefore whether access to the data by the inspectors risks a “serious, or even particularly serious” interference with Articles 7 and 8 of the Charter, assessed against private life information in a broad sense. The Court of Justice also noted that inspections should not entail “unlimited” data gathering and must be “restricted to data linked to the anticompetitive conduct.” In reaching this conclusion, it is important to understand that the Portuguese authority searched data onsite and seized only evidence it considered relevant. Other national authorities routinely seize entire mailboxes for later review offsite. Where that later practice applies, it remains questionable whether the Court of Justice would still consider that there is no unlimited data gathering, or whether stricter protections such as prior judicial review might be required.

Key Takeaways for Businesses

Both rulings extend the prior-review logic from Landeck into competition enforcement. In Vivendi / Lagardère, the General Court approved the Commission’s protective protocol for keyword RFIs; in Imagens, the Court of Justice required prior review for inspecting personal devices during national dawn raids. The Commission’s existing procedures, including its virtual data room for special-category data and its extension of protective protocols to all private-life information, may already go further than those in many Member States. Importantly, however, Imagens confirms that ex ante judicial review of inspections at business premises is not required under the Charter, provided effective ex post review is available. The General Court’s interim measures procedure has developed to reinforce that safeguard in relation to Commission inspections.

These are meaningful developments, but businesses should be realistic about their limits. Prior judicial review of access to data is likely to take weeks and one may wonder whether courts are equipped to handle the data selection process. Sealing the data may also offer little comfort to an employee whose phone has been physically removed, in particular if imaging is not available or takes several hours if not days. The seizure itself, and the resulting loss of access to personal communications, banking apps and everyday digital life, can be deeply stressful for individuals and disruptive for the business. Indeed, in a recent judgment (Cases Nos: 1735 - 1738/13/12/25 (W)) granting the UK Competition and Markets Authority permission to search and seize a personal mobile phone, the Competition Appeal Tribunal insisted on undertakings to image devices on-site where practicable, return SIM cards within two hours, return phones within 36 hours, and ensure the individual is not left without a substitute device.

Moreover, gaps remain: the Court of Justice has not specified how prior review works in practice, sealed envelopes may not be available in every regime, just as court procedures allowing for such reviews may not be. However, as of today, several key takeaways can already be drawn:

  • Private life is a growing concern. Courts are responding to calls for greater protection of private lives during competition investigations. Businesses should inform and train staff on how their personal data and devices may be handled during investigations. Well-drafted policies reduce ambiguity and help employees understand their exposure.
  • Immediate claims are critical. The protection a company can secure and its ability to obtain protection, or to challenge the outcome of an inspection, depends directly on the preparatory steps taken before any dawn raid, and the claims and reservations made during the inspection itself. Request the sealed-envelope procedure or prior review where available, challenge refusals promptly, negotiate the scope of keyword RFIs, and document the search methodology. Opportunities to preserve rights can be lost if claims are not raised on the spot. Early engagement of counsel is ever more essential.
  • Take fundamental rights issues to Luxembourg. The Court of Justice is increasingly acting as a constitutional court, applying the Charter with strict requirements on judicial review and private-life protections. National procedural autonomy is losing ground. Companies facing fundamental rights concerns under national dawn raid procedures should consider whether a reference to the Court of Justice could help obtaining effective protection.

For further information on the issues discussed in this Legal Update, or on dawn raid preparedness and responding to competition authority investigations more generally, please contact a member of the Mayer Brown EU Antitrust and Competition Group. Our team has extensive experience advising clients on dawn raid preparedness and responses across all major jurisdictions. We can assist with all aspects of competition inspections. 

 

verwandte Beratungsfelder und Industrien

Stay Up To Date With Our Insights

See how we use a multidisciplinary, integrated approach to meet our clients' needs.
Subscribe