You will be redirected to the website of our parent company, Schönherr Rechtsanwälte GmbH: www.schoenherr.eu
This Legal Insight is published as part of a series focusing on dawn raids conducted by local competition authorities and their consistency with EU law.
European and national competition authorities, including the Austrian Federal Competition Authority ("FCA"), have extensive investigative powers to search and seize electronic communications and data when investigating conduct prohibited by art 101 and 102 TFEU and Section 1 and Section 5 Austrian Cartel Act ("ACA"). In its judgment of 16 July 2026, in the joined cases C-258/23 to C-260/23 (IMI), the European Court of Justice ("ECJ"), building on its 2021 Landeck ruling (C-548/21), clarified the safeguards required when public authorities interfere with the fundamental rights to private life and personal data protection under art 7 and 8 of the Charter of the Fundamental Rights in the course of antitrust investigations.
Specifically, the ECJ held that seizing data from devices belonging to the undertaking concerned and whose private use is prohibited under internal company rules does not require prior judicial approval. By contrast, accessing devices – such as mobile phones and computers – that belong to employees rather than the company, and that are used for both professional and private purposes, requires prior authorisation from a court or an independent administrative body, because such data can reveal very precise details of the data subject's private life and therefore requires special protective measures. The ECJ, in the IMI case, left open how to treat data from company-owned devices whose internal guidelines expressly permit personal use. However, following the reasoning of the ECJ, we understand from a company-friendly perspective that access to data on corporate devices used for both personal and business purposes would also require prior court approval, because such devices typically hold the same sensitive data as purely private devices.
Under Section 12(4) icw Section 11a(1)(2) Austrian Competition Act, the FCA may inspect and seize business documents accessible within or from the company during a dawn raid, subject to the fundamental-rights safeguards in Section 13(1) Austrian Competition Act. The FCA's 2022 guidelines address this by separating out employees' private data from seized data carriers. This practice no longer meets the ECJ's standard for either "bring-your-own-device" arrangements or company devices expressly permitted for private use. In both cases, these devices contain business data (which the FCA may seize pursuant to its statutory investigative powers) alongside private data (which, under IMI, requires prior court approval). The Austrian Constitutional Court has previously likewise recognized increased protection for mobile phone data in a criminal law context (VfGH, 14.12.2023, G 352/2021-46).
Going forward, the FCA must obtain explicit prior court approval before accessing data on devices used for both business and private purposes. To do so, it must give the Austrian Cartel Court sufficiently precise information on the nature of the suspected infringement and specify which data, from which identified person, to what extent and for what purpose is to be inspected and seized. Only on that basis, and after weighing interests, may the Cartel Court approve the seizure of data stored on such devices. The current legal framework falls short: an application for a dawn raid only needs to contain (i) an alleged violation of antitrust rules, (ii) a presentation of the circumstances giving rise to reasonable suspicion and (iii) an explanation why the investigation is necessary and proportionate. These minimum requirements do not meet the heightened standard the ECJ has now set for seizing data from personally owned or used devices.
Any seizure of data stored on privately owned and/or privately used electronic devices without explicit approval by the Cartel Court could, in future, result in a serious infringement on fundamental rights. This may render the investigation unlawful, require the unlawfully seized data to be excluded and result in any findings derived from it to be deemed inadmissible. In accordance with the ECJ ruling, such an infringement could not be remedied by an ex post review.
Anna
Visontai-Knor
Attorney at Law
austria vienna