Europe’s competition enforcers may now grab a company’s business emails during a surprise inspection without first asking a judge, yet they must stop at the door of an employee’s own phone. The Court of Justice of the European Union drew that line on 16 July 2026, and the ruling has already forced enforcement lawyers across the bloc to rewrite the playbook they hand to clients facing dawn raids.
The Grand Chamber decided the case after Portugal’s competition authority seized electronic correspondence from IMI, Synlabhealth and SIBS during separate investigations. The companies argued that a prosecutor’s sign-off fell short of the judicial protection guaranteed by the Charter of Fundamental Rights. The Court took a more nuanced view than either side wanted.
On business email accounts, the judges sided with the regulators. EU law, they held, does not oblige a national authority to obtain prior judicial authorisation before seizing work correspondence, provided national law defines the power precisely, limits it strictly, and guarantees a full judicial review afterwards. That review must be real rather than formal, and a prosecutor’s authorisation does not substitute for it.
The Court then reversed direction on personal devices. Where investigators seize a phone or laptop that belongs to an employee rather than the firm, a court or an independent administrative body must authorise access before anyone reads what sits inside. The judges treated the private handset as a different constitutional object altogether, one that carries a person’s family life, health data and political views alongside the odd work message.
That distinction matters far more in practice than it sounds on paper. Modern cartel evidence rarely lives in a tidy corporate inbox. Investigators chase WhatsApp threads, Signal groups and personal Gmail accounts, because executives who want to fix prices tend to avoid the systems their own compliance teams monitor. The ruling hands companies a genuine procedural weapon in exactly the place where authorities most want to look.
National authorities will feel the effect unevenly. Several member states, including Czechia, run inspection regimes built on administrative authorisation alone, and their governments now face a choice between amending domestic law and watching evidence collapse on appeal. Others already route device access through a judge and will barely notice the change. The Court’s own press service flagged the judgment as a clarification, but the practical burden lands squarely on legislatures.
Defence counsel have drawn the obvious conclusion. The first question during a raid is no longer whether the authority holds a warrant, but who owns each device on the table. Expect firms to tighten bring-your-own-device policies, to separate work and personal accounts more rigorously, and to log ownership of every handset in the building. Expect authorities, in turn, to arrive with paperwork covering both categories.
Critics of the ruling argue that it rewards evasion. If a cartel migrates to private phones precisely to raise the evidentiary bar, the Court has arguably made concealment cheaper. Supporters answer that a competition file cannot justify unlimited access to a person’s private life, and that judicial pre-authorisation costs an authority a few hours rather than a case. Both readings hold weight, and the balance will only become clear once national courts start applying the test to messy facts.
The judgment also carries a quieter message about the European Commission’s own inspections. Brussels raids operate under a different regulation, yet the reasoning about proportionality and private devices travels easily. Companies challenging Commission searches will cite this ruling within months, and the General Court will have to decide how far it stretches.
For now, the practical guidance is straightforward. Authorities keep their grab-and-go power over corporate mailboxes. Employees keep a judge between an investigator and their personal phone. Everyone else waits to see which member states amend their statutes before the first challenge tests whether the safeguards they already have count as strict enough. Companies with EU operations should audit their device policies now rather than during a raid, when the argument about ownership arrives far too late to win.




