EU Court of Justice requires prior authorisation for access to personal devices in dawn raids
The EU Court of Justice (CJEU) has ruled that competition authorities must obtain prior authorisation of a court or an independent administrative body before accessing personal devices of employees that have been seized during a dawn raid.
The ruling arose in response to a question referred to the CJEU in Joined Cases C-258/23 to C-260/23, IMI and others, by the Portuguese Competition, Regulation and Supervision Court, as to whether prior judicial authorisation was required for the seizure of emails between employees and managers of a company during a dawn raid on the company's premises. The Grand Chamber of the CJEU – which issues its most authoritative judgments – ruled that no such authorisation was required, provided appropriate safeguards are in place, such as the possibility of ex-post judicial review.
However, the CJEU went on to make an important qualification regarding access to data stored on employees' or company officers' personal devices. Such access, said the CJEU, may give rise to a "particularly serious" interference with employees' fundamental human rights, in particular their right to respect for their private and family life and the protection of their personal data, under Articles 7 and 8 of the EU Charter of Fundamental Rights. Access to such data is likely to reveal information about the employee's daily life habits, places of residence, travel, activities, social relationships and social circles. It could also include sensitive data that is subject to special protections under the General Data Protection Regulation, such as information on an employee's race, political opinions, religious beliefs, health and sexual orientation.
The CJEU therefore ruled that competition authorities must obtain prior authorisation of a judge or an "independent administrative body" before accessing such data. That body must have the necessary powers and provide the necessary safeguards to ensure a fair balance between the employee's human rights and the legitimate needs of the competition authority's investigation. Previous case law of the EU Courts indicates that this means that they must be able to refuse or restrict access to the data and be able to carry out their review objectively and impartially.
EU law already requires the European Commission and national competition authorities of the EU member states to obtain a warrant before carrying out a dawn raid at the homes of managers or employees of a business that is under investigation. The new requirement introduced by the CJEU does not require competition authorities to seek authorisation to access personal devices before a dawn raid on the company's premises, but rather to seek it before any data on a seized device is accessed.
The ruling is unclear whether it is nevertheless open to competition authorities to seek a blanket permission, before a dawn raid, to access personal devices during the dawn raid, or whether they must first seize or identify the relevant devices and then apply for authorisation.
However, in our view, the latter interpretation is the correct one, for two reasons. First, in the referred case the authority had already obtained a warrant, before the dawn raid, from the Portuguese Public Prosecutor – which the CJEU found to be an appropriate judicial authority – and the CJEU stated that the requirement for prior authorisation for access to personal devices was relevant precisely because it could not be ruled out that the warrant allowed such devices to be seized. Second, it is consistent with the court's statements that the reviewing judicial body must be able to give effect to the fundamental rights of the individuals who are affected by the access to their personal devices, which would not be the case, in our view, if the court does not know which individuals are affected, or the personal data to which access is sought.
This is an important development because competition authorities frequently seek access to personal devices of employees and company officers during dawn raids. The European Commission's dawn raid guidance states that its inspectors may search any personal device on the premises if it is used for business purposes, i.e., where the company has a "Bring Your Own Device" policy. While the company that was dawn raided in the referred case did not have such a policy (employees were not permitted to use the company email system for personal purposes), the CJEU's ruling indicates that the requirement for prior authorisation applies irrespective of the company's policy on using personal devices for work reasons. The key question is whether access is gained to mobile phones, computers or other IT equipment belonging not to the company under investigation, but to its managers or employees.
Moreover, while the ruling related to an investigation by the Portuguese national competition authority, it is relevant to investigations carried out by all competition authorities in the EU, including the European Commission.
The ruling means that there are different safeguards afforded to employees' personal devices during a dawn raid compared to those which apply when an authority sends an information request demanding disclosure of such data. In particular, the EU General Court ruled recently that the European Commission was entitled to require disclosure of data from any personal device that had been used at least once for business purposes (see our blog post here). The difference is likely due to the more intrusive nature of dawn raids. In the Vivendi case, procedures put in place by the European Commission allowed employees whose personal data was covered by the information request to review it in advance and provide a redacted non-confidential version, or to withdraw the document from the submission if it was not possible to provide a non-confidential version. On a dawn raid, in contrast, inspectors are able to review all documents on a device with potential relevance to the investigation, albeit in the presence of the company's lawyers.
Key takeaway
Businesses operating in the EU should update their dawn raid compliance policies to cover scenarios in which inspecting officials seek access to personal devices of employees or company officials. Businesses should be aware of their right to insist that such devices are placed in a sealed envelope and that the inspecting authority obtains no access to the data on those devices until judicial authorisation has been granted, although they may take the view that it is expedient to allow inspectors to manually review content on the device to confirm that there are no relevant communications. If judicial authorisation proceedings are pursued, businesses should also seek legal advice on their, and their employees', rights to participate in those proceedings, which are governed by national laws and may therefore vary between EU member states.