Knock First, Ask Later: Dawn Raid Authorisation after Imagens
One question that has repeatedly arisen before the EU courts is the degree to which the law should require authorities to obtain judicial authorisation before conducting unannounced inspections (ex ante authorisation). We now have some clarity from the CJEU: ex ante authorisation of unannounced inspections is not required as a matter of EU law, provided the relevant domestic law contains sufficient safeguards and allows for effective ex post judicial review. However, where authorities seize data that is held on mobile phones, computers or other storage systems which are used for both private and professional purposes in the course of such an inspection, ex ante authorisation must be sought before that data can be accessed. This briefing outlines how this may impact Irish businesses and regulators.
No legal wrong can be proven without evidence, and in this digital age, digital evidence is king. This is true across the legal system; from the criminal sphere where cases with no digital evidence are now the exception rather than the norm, to the regulatory sphere where increasingly digitised business practices pose a range of new challenges for enforcement agencies.
Where evidence of anticompetitive conduct was previously found in letters, contracts or handwritten notes, it now resides in emails, instant messages and cloud-based storage platforms. This has been both a blessing and a curse for regulators. While a business executive may have been slow to sign their name to a headed letter with questionable content, that same caution can be conspicuously absent when committing information to writing in a casual WhatsApp chat or informal email to a colleague. This has made such spaces key sources of information in regulatory investigations, but has heightened privacy concerns, particularly where the line between a personal and business device is now so often blurred.
As difficult as this has been to navigate for regulators, it has proven to be an even greater minefield for domestic courts, which have had to assess privacy issues in disputes relating to dawn raids executed in line with EU and Member State law, while those same issues are being carefully scrutinised by the European Court of Human Rights (“ECtHR”). And the question of mandatory ex ante authorisation has been front and centre in many such disputes.
By its decision in the joined cases of Imagens Médicas Integradas, Synlabhealth II and SIBS (Joined Cases C-258/23 to C-260/23) (“Imagens”), the Court of Justice of the European Union (“CJEU”) has taken a significant step toward clarifying the position for regulators and businesses alike, in the context of competition law investigations.
The ECtHR Position and the Prelude to Imagens
Regulatory authorities across the EU have quietly watched the ECtHR criticise their exercise of unannounced inspection powers in a series of rulings, each of which has served to highlight frailties in the EC’s approach to privacy issues in the context of competition investigation dawn raids. Understanding that line of ECtHR jurisprudence is key to understand the ruling in Imagens.
In Menarini Diagnostics v Italy, the ECtHR accepted that administrative authorities could impose financial penalties (which would be classified as criminal in nature under the European Convention of Human Rights (“ECHR”)), provided the rights of the entity under investigation were sufficiently safeguarded – namely, by way of access to a comprehensive ex post judicial review of any such fine.
Later decisions applied a similar logic in the context of dawn raids. In Delta Pekárny, the ECtHR criticised a dawn raid carried out by the Czech Competition Authority’s for failing to respect the right to a private and family life, home, and correspondence (in accordance with Article 8 ECHR) on the basis that Czech law did not at the time provide an effective remedy enabling the company which had been raided to obtain a concrete and substantive judicial assessment of the necessity and proportionality of the search. The ECtHR adopted a similar tone in Vinci Construction, criticising the French competition regulator for seizing a large volume of digital data during a dawn raid, including legally privileged documents and documents unrelated to the subject matter of the investigation.
The combined effect of these (and other) decisions meant that an unannounced inspection would only be ECHR compliant if domestic law sufficiently safeguarded the rights of an investigation subject by facilitating substantive and effective ex post judicial review of the inspection, particularly in respect of the proportionality of the inspection and of claims of legal professional privilege.
The Irish Position
Irish courts have also acknowledged the tension between the invasive nature of statutory inspection powers and the strong protections for privacy rights afforded by the Irish Constitution and the ECHR. In addressing the tension, the courts have sought to balance those privacy protections against the legitimate public interest in ensuring effective regulatory enforcement. Similar to the approach taken by the CJEU, an assessment of the proportionality of the inspection (both in scope and process) has been the Irish courts’ key tool when undertaking this balancing act.
In CRH plc v Competition and Consumer Protection Commission, the Competition and Consumer Protection Commission (“CCPC”) seized 96 gigabytes of digital content from the investigation subject, including the contents of the entire email inbox of one of its senior executives on foot of a search warrant made under the Competition and Consumer Protection Act 2014 (the “2014 Act”). Under the 2014 Act, a search must be for the purposes of obtaining information which may be required in relation to a matter under investigation under the 2014 Act. The Supreme Court considered that in seizing the entire inbox of an executive, the CCPC had, on the balance of probabilities, seized materials not covered by the search warrant and had exceeded the powers of seizure conferred on it by the 2014 Act. Notably, it was not the fact of having seized irrelevant information that was fatal to the CCPC’s case; the court recognised this was inevitable. Instead, it was the disproportionate volume of information seized and the review of that information that was unjustifiable, in the court’s view. Although it was not unlawful to take or copy documents outside what was expressly relevant, any interference with the right to privacy had to be proportionate to the legitimate aim pursued, and a searched party had to be able to ensure that the lawfulness of a seizure could be actually and effectively reviewed after the fact.
The more recent decision of the High Court in the case of Commission for Communications Regulation v Eircom Limited is also instructive. There, the Commission for Communications Regulation (“ComReg”) had seized a considerable number of documents from Eircom’s business premises. The raid had not, under the relevant statute, required prior judicial authorisation. That statute did, however, provide for a mechanism through which ComReg could apply to the High Court for a its determination of issues arising in respect of irrelevant or legally privileged materials which may have been seized as part of the raid.
Such issues did ultimately arise, and ComReg applied to the High Court seeking its approval of a “Step Plan” in accordance with which ComReg would review the seized material. Having engaged in a fine balancing exercise, the High Court held that whilst Eircom’s statutory rights were clear, so too was ComReg’s regulatory mandate. The statute could not be read as requiring ComReg to ensure Eircom’s confidentiality was guaranteed at all times, as this was simply not practically possible in all cases in the course of the lawful exercise of ComReg’s regulatory functions.
While the judgment does not explicitly speak in terms of “proportionality”, it is clear that this is the crux of the court’s decision: an intrusion on rights, proportionate to a legitimate purpose sought to be achieved and made subject to sufficient safeguards, will be lawful.
Irish law therefore requires that unannounced inspection powers are exercised within a clear legal framework and remain subject to substantive and effective ex post scrutiny, rather than demanding mandatory ex ante judicial authorisation. Indeed, many Irish regulatory regimes already explicitly provide for ex post judicial oversight of a regulator’s review of materials seized in the course of such inspections (as in the ComReg case discussed above). This is closely aligned with the ECtHR’s position.
Squaring the Circle: The CJEU’s decision in Imagens
It was against a background of irreconciled EU, ECtHR, and domestic positions that Imagens came before the CJEU.
Imagens arose from an investigation launched by the Portuguese Competition Authority (the “Competition Authority”) into several undertakings in the health sector in connection with suspected breaches of Articles 101 and 102 TFEU. The Competition Authority sought and was granted prior authorisation to carry out dawn raids from the Portuguese Public Prosecutor’s Office (which, under Portuguese law, was the judicial authority with jurisdiction for such matters). During the raids, the Competition Authority examined employee emails and computer files considered relevant for the purposes of its investigations, seizing over 1.4 million documents in total.
The companies concerned challenged the legality of the raids before the Portuguese courts. This challenge turned on two key arguments. First, an argument that an inappropriate level of prior authorisation had been obtained, made by reference to a provision of domestic law which provided that prior authorisation by an investigating judge (rather than merely by a judicial authority, such as the Public Prosecutors Office) was required for inspections which were intended to be carried out at the home of a natural person, in a banking institution, in a law firm or in a medical practice. And second, an argument that business emails exchanged between employees and managers of an undertaking by means of that undertaking’s messaging service were “communications” for the purposes of Article 7 of the Charter of Fundamental Rights of the European Union (the “Charter”) and that their seizure infringed rights protected by Articles 7 and 8 of the Charter. Taking these points together, it was argued that authorisation by the Portuguese Public Prosecutor’s Office was not enough; prior authorisation by an investigating judge should have been required before the raids could be undertaken and the relevant emails seized.
The Portuguese court stayed the domestic proceedings and referred three questions to the CJEU. In summary, the first question asked whether business emails exchanged between employees and managers of an undertaking by means of that undertaking’s messaging service were “communications” for the purposes of Article 7, while the second and third questions asked whether Article 7 must be interpreted as precluding the seizure of business emails exchanged between employees and managers of an undertaking, during an inspection carried out by a competition authority as part of an investigation into infringements of Article 101 or Article 102 TFEU and authorised in advance by a judicial authority such as the Portuguese Public Prosecutor’s Office. Of relevance to the CJEU’s determination was the fact that each of the undertakings in question also imposed as part of their employee’s contracts of employment terms of use for work devices and services. Namely, work emails were to be limited to “functional use”, meaning that use for any employee’s personal and private purposes was prohibited.
By its judgment, the CJEU held that business emails exchanged between employees and managers of an undertaking by means of that undertaking’s messaging service were “communications” for the purposes of Article 7 of the Charter and thus attracted the privacy protections afforded by the Article.
However, the CJEU noted the fundamental rights enshrined in Articles 7 and 8 of the Charter are not absolute rights and must be considered in relation to their function in society. As such, limitations to those rights are permissible if they are (i) provided for by law, (ii) respect the essence of the Charter rights, (iii) genuinely meet objectives of general interest recognised by the European Union, and (iv) respect the principle of proportionality.
That the seizure was provided for by law and met objectives of general interest to the EU was uncontroversial.
In relation to respect for the essence of the Charter rights, the CJEU noted that domestic Portuguese and European law (e.g., the GDPR): (a) restricted the seizure of data to data linked to the investigation, and (b) prohibited the use of that data for purposes other than identifying conduct the subject of the investigation. It followed that the seizure could not be regarded as interfering with the essence of Article 8 of the Charter.
Finally, in relation to proportionality, the court held that in the investigation and detection of anticompetitive practices contrary to Articles 101 and 102 TFEU, no other means which are as effective and less prejudicial to the Article 7 and 8 rights present themselves as a satisfactory alternative to the seizure of documents resulting from emails exchanged between the managers and employees of the undertaking targeted by inspections carried out by a competition authority. The court also found it relevant that the seizure was subject to domestic law procedural safeguards intended to ensure the security, integrity and confidentiality of the data. Taking all of this into account, the court considered that the seizure was proportionate to the aims it sought to achieve.
The CJEU then made reference to the case law of the ECtHR providing that a lack of ex ante authorisation of a raid may be counterbalanced by effective ex post judicial review. The CJEU also acknowledged that neither Article 20(6) and (7) of Regulation No 1/2003 nor Article 6(3) of Directive 2019/1, concerning inspections conducted at the business premises of undertakings by the Commission and the national competition authorities respectively, mandated ex ante authorisation of unannounced inspections by a judicial authority or independent administrative body. On these bases, the CJEU concluded that EU law did not preclude the domestic law of a Member State from permitting relevant authorities from conducting unannounced inspections without ex ante authorisation by a judicial authority or independent administrative body. This was subject to one key caveat: domestic legislation and practice must provide adequate and sufficient safeguards against abuse and arbitrariness in the form of a full ex post judicial review of the measures at issue.
The CJEU did, however, draw a clear distinction between inspections limited to the seizure of material on devices belonging to the undertaking in question and inspections which may lead “to the seizure of mobile telephones, computers or any other computer storage medium belonging, not to the undertakings whose premises are being inspected, but to natural persons such as their managers and employees.” The CJEU held that “[i]f, during inspections conducted by a competition authority at the business premises of an undertaking, investigators are required to seize mobile telephones, computers, or any other computer storage medium belonging not to that undertaking but to its managers and employees, access to the data contained in those devices must, where appropriate after being sealed, be subject to prior review by a court or an independent administrative body” (emphasis added).
The CJEU went on to state that such a court or independent administrative body “must have all the powers and provide all the guarantees necessary in order to reconcile the various legitimate interests and rights at issue” and that it “must be able to strike a fair balance between, on the one hand, the legitimate interests relating to the needs of the investigation and, on the other hand, the fundamental rights to respect for private life and protection of personal data of the persons whose data are concerned by the access”
Life after Imagens
Imagens marks the CJEU's first comprehensive attempt to reconcile the operational realities of modern regulatory investigations with the privacy protections guaranteed by Articles 7 and 8 of the Charter, and in doing so, it closes a gap between the Union's competition enforcement framework and the ECtHR's steadily hardening jurisprudence on dawn raids. By confirming that business communications sent through an undertaking's own messaging systems attract Charter protection, yet can still be lawfully seized without ex ante judicial authorisation provided effective ex post review is available, the CJEU has, in effect, aligned EU competition enforcement with the ex post review standard the ECtHR has long demanded in this area, and that the Irish courts applied in both the CRH and ComReg cases.
The most consequential aspect of the judgment by far, however, is the new ‘personal devices redline’ drawn by the CJEU. Where an inspection extends to mobile phones, laptops or other storage media belonging to individual managers or employees rather than the undertaking itself, ex post review will no longer suffice; access to that data (as opposed to seizure) must be subject to prior authorisation by a court or independent administrative body. In other words, regulators can seize the data, but in relevant circumstances, need ex ante authorisation before they access it. This distinction has no clean equivalent in either the existing EU competition enforcement framework or in Irish statute, and in addition it may be challenging to implement this in practice given that recent working practices often combine corporate and digital assets. There is a growing body of Irish case law, emanating from the criminal law, regarding the distinction between the physical and digital spaces which echoes the approach taken by the CJEU in Imagens (see The People (DPP) v. Quirke). That line of case law acknowledges that privacy concerns are markedly stronger in digital spaces due to the manner in which modern society lives through devices which record huge amounts of personal information. This case law continues to have a significant impact on, for example, search warrants executed in criminal investigations, and may now be in closer alignment with the regulatory position post-Imagens.
For European law, Imagens should be read as a floor rather than a ceiling. It confirms that Member States remain free to legislate for ex ante authorisation across the board (and several already do so), but it establishes that the Charter itself does not compel that approach outside the personal-device context. For Irish law, the decision sits comfortably alongside the court’s emphasis in the CRH and ComReg decisions on proportionality and effective ex post scrutiny, but it also raises questions about whether inspection powers under Irish law should distinguish between data held on company-owned systems and data held on personal devices used for work purposes, a matter Imagens now elevates to one of Charter compliance rather than good practice. In time, the Oireachtas may need to consider whether existing statutory search and seizure powers require amendment to expressly provide for independent authorisation (likely judicial in an Irish context) before personal devices are accessed.
In the immediate term it is important not to overstate the protection Imagens affords to regulated entities more broadly: seizure of business communications on company systems remains lawful without prior judicial sign-off, and the real battleground, as CRH already demonstrated, will continue to be the proportionality of what is taken and reviewed, not whether it can be taken at all. Employers should also revisit device and email usage policies in light of the judgment.
This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.




Select how you would like to share using the options below