Skip to content
Case Law · GDPRhub EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

CJEU - C‑258/23 to C‑260/23 - Imagens Médicas Integradas

Imagens Médicas Integradas S.A., several companies in the SIBS group and Synlabhealth II S.A.

GDPRhub

How it connects

10 of 13 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 13 paragraphs

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

A. (the controllers) are a number of companies in the medical field. Between 2021 and 2022, the national competition authority conducted several investigations under the authorisation of the Public Prosecutor’s Office. The information seized included employees’ emails and internal documents. The controllers objected to the competition authority seizing employees’ emails, and filed an appeal with the Tribunal da Concorrência, Regulação e Supervisão (Competition, Regulation and Supervision Court, Portugal). According to the controllers, the seizures were illegal, as they infringed their right to secrecy of correspondence. The competition court decided to stay proceedings and refer questions to the CJEU concerning the lawfulness of the seizure of emails of employees during investigations carried out by the competition authority. The competition court referred the following questions: Do the business records at issue in this case, which are transmitted by email, constitute “correspondence” for the purposes of Article 7 CFR?

§

Does Article 7 CFR preclude business records arising from email communications between managers and employees of undertakings from being seized in the course of an investigation into agreements and practices prohibited under Article 101 TFEU (ex Article 81 [EC]) [or, in Case C 260/23, Article 102 TFEU (ex article 82 [EC])]? ’ In his initial opinion, the AG stated that Article 7 of the EU Charter of Fundamental Rights (CFR) must be interpreted as not precluding national law from allowing the national competition authority to seize (among other information) employees’ emails related to the investigation without prior judicial authorisation. However, there must be a strict legal framework for the authority’s powers, with adequate and effective safeguards against abuse and arbitrariness. The Court requested the AG to issue a supplementary opinion following the judgement in Landeck (C-548/21), in which the CJEU assessed the Law Enforcement Directive in relation with Articles 7, 8 and 52(1) CFR.

§

The AG was asked to provide his opinion on how Article 8 CFR applies, in particular when the records and emails contain personal data. Advocate General Opinion — The AG first noted that Article 8 CFR is closely related to Article 7 CFR, and the two rights may be difficult to distinguish clearly. The AG also noted that the seizure of emails by a national competition authority limits the right to data protection under Article 8 CFR if said emails contain personal data under Article 4(1) GDPR. Article 8 CFR, however, is not absolute, and may be limited in accordance with Article 52(1) CFR. For example, the national competition authority may process personal data in the emails under Article 6(1)(e) GDPR in conjunction with Article 6(3) GDPR; since the seizure was permitted under national law, the AG concluded that the processing meets the first requirement of Article 52(1) CFR (provided by law).

§

The AG then noted that the competition authority did not collect an unlimited amount of data during its investigations, meaning the essence of Article 8 CFR was not affected. According to the AG, the seizure of emails was the least restrictive way of pursuing the objective of identifying anticompetitive practices. This case is different to that of Landeck, as it did not involve full access to individuals' mobile phone data. In principle, the emails exchanged between employees is of business nature, and therefore the processing is proportionate. Finally, the AG stated that the national competition authority did not need prior judicial authorisation to seize the emails under Article 8 CFR, as he stated in his opinion regarding Article 7 CFR. The AG reached a similar conclusion to his first opinion; Article 8 CFR must be interpreted as not precluding national law from allowing the national competition authority to seize (among other information) employees’ emails related to the investigation without prior judicial authorisation.

applies Art. 7Art. 8
§

However, there must be a strict legal framework for the authority’s powers, with adequate and effective safeguards against abuse and arbitrariness. Holding — First question — Regarding the first question, the CJEU held that Article 7 CFR must be interpreted as meaning that the concept of “communications” includes business-related emails exchanged between employees and managers through an enterprise’s email system. The professional nature of an email, its content, whether it has been read or deleted, or an internal prohibition on personal use do not remove it from the protection afforded by Article 7 CFR. Personal data contained in or generated by such communications is also protected under Article 8 CFR. Second and third questions — Regarding the second and third questions, the CJEU examined them together and reformulated them as asking whether Articles 7 and 8 CFR preclude the seizure, without prior judicial authorisation, of employees’ and managers’ emails during an inspection carried out at an enterprise’s business premises by a national competition authority investigating potential infringements of Articles 101 or 102 TFEU.

§

The CJEU found that searching and seizing such emails constitutes an interference with the rights to privacy and data protection. Under Article 52(1) CFR, such interference is permissible only where it is provided for by law, respects the essence of those rights, pursues an objective of general interest recognised by the EU and complies with the principle of proportionality. The CJEU considered that detecting infringements of EU competition law and preserving undistorted competition in the internal market constitute objectives of general interest. It also found that access to professional emails may be necessary because such communications are a primary source of evidence of anticompetitive conduct and no equally effective, less intrusive alternative may be available. However, the national legal framework must contain clear and precise rules limiting the scope of the inspection and the subsequent processing of the data.

applies Art. 52(1)
§

In particular, searches must be based on a duly reasoned inspection decision and reasonable grounds for suspecting an infringement. The information collected must be relevant to the predefined subject matter of the investigation, may not be used for unrelated purposes and must be processed in accordance with the GDPR, including the applicable rules on storage and transfers. The absence of prior authorisation by a judge does not, in itself, render the seizure unlawful when the inspection takes place at business or commercial premises. Nevertheless, national law and practice must provide adequate and sufficient safeguards against abuse and arbitrariness. These safeguards must include effective ex post judicial review of both the legality and necessity of the inspection and the manner in which it was conducted, together with an appropriate remedy and the possibility of assessing the admissibility of the evidence obtained.

§

In the present case, the prior authorisation granted by the independent Portuguese Public Prosecutor’s Office could contribute to the strict framework governing the scope, duration and appropriateness of the measures, but could not replace the requirement for effective ex post judicial review. The CJEU therefore held that Articles 7 and 8 CFR do not preclude the seizure, without prior authorisation by a judge, of professional emails during an inspection at an enterprise’s business premises, provided that the authority’s powers are governed by a strict legal framework and accompanied by adequate and sufficient safeguards against abuse and arbitrariness, including effective ex post judicial review. The CJEU clarified, however, that a different standard applies where the authority seeks access to phones, computers or other electronic devices belonging personally to employees or managers. Since such devices may contain private communications, location data, browsing histories, photographs or special categories of personal data under Article 9 GDPR, access may constitute a serious interference with Articles 7 and 8 CFR.

§

In such circumstances, access must be subject to prior review by a court or an independent administrative body capable of balancing the needs of the investigation against the affected individuals’ fundamental rights. Holding — First question — Regarding the first question, the CJEU held that Article 7 CFR must be interpreted as meaning that the concept of “communications” includes business-related emails exchanged between employees and managers through an enterprise’s email system. The professional nature of an email, its content, whether it has been read or deleted, or an internal prohibition on personal use do not remove it from the protection afforded by Article 7 CFR. Personal data contained in or generated by such communications is also protected under Article 8 CFR. Second and third questions — Regarding the second and third questions, the CJEU examined them together and reformulated them as asking whether Articles 7 and 8 CFR preclude the seizure, without prior judicial authorisation, of employees’ and managers’ emails during an inspection carried out at an enterprise’s business premises by a national competition authority investigating potential infringements of Articles 101 or 102 TFEU.

§

The CJEU found that searching and seizing such emails constitutes an interference with the rights to privacy and data protection. Under Article 52(1) CFR, such interference is permissible only where it is provided for by law, respects the essence of those rights, pursues an objective of general interest recognised by the EU and complies with the principle of proportionality. The CJEU considered that detecting infringements of EU competition law and preserving undistorted competition in the internal market constitute objectives of general interest. It also found that access to professional emails may be necessary because such communications are a primary source of evidence of anticompetitive conduct and no equally effective, less intrusive alternative may be available. However, the national legal framework must contain clear and precise rules limiting the scope of the inspection and the subsequent processing of the data.

applies Art. 52(1)
§

In particular, searches must be based on a duly reasoned inspection decision and reasonable grounds for suspecting an infringement. The information collected must be relevant to the predefined subject matter of the investigation, may not be used for unrelated purposes and must be processed in accordance with the GDPR, including the applicable rules on storage and transfers. The absence of prior authorisation by a judge does not, in itself, render the seizure unlawful when the inspection takes place at business or commercial premises. Nevertheless, national law and practice must provide adequate and sufficient safeguards against abuse and arbitrariness. These safeguards must include effective ex post judicial review of both the legality and necessity of the inspection and the manner in which it was conducted, together with an appropriate remedy and the possibility of assessing the admissibility of the evidence obtained.

§

In the present case, the prior authorisation granted by the independent Portuguese Public Prosecutor’s Office could contribute to the strict framework governing the scope, duration and appropriateness of the measures, but could not replace the requirement for effective ex post judicial review. The CJEU therefore held that Articles 7 and 8 CFR do not preclude the seizure, without prior authorisation by a judge, of professional emails during an inspection at an enterprise’s business premises, provided that the authority’s powers are governed by a strict legal framework and accompanied by adequate and sufficient safeguards against abuse and arbitrariness, including effective ex post judicial review. The CJEU clarified, however, that a different standard applies where the authority seeks access to phones, computers or other electronic devices belonging personally to employees or managers. Since such devices may contain private communications, location data, browsing histories, photographs or special categories of personal data under Article 9 GDPR, access may constitute a serious interference with Articles 7 and 8 CFR.

§

In such circumstances, access must be subject to prior review by a court or an independent administrative body capable of balancing the needs of the investigation against the affected individuals’ fundamental rights. Comment — The facts and questions of the case were included in the AG's initial opinion, and not the current one. You can find the initial opinion here.