A personal phone does not cease to be personal because it was used once for work. Yet, in a specific European Union merger investigation, a targeted information request may cover professional documents stored on it that the European Commission is entitled to require from the undertaking under investigation. That difficult balance lies at the centre of the General Court judgments in Vivendi and Lagardère.

The judgments did not recognise a general power to inspect every personal account or device. They accepted that targeted collection of professional documents could amount to a serious interference with private life and upheld the particular requests because their personal, temporal and thematic scope was limited, search criteria were defined in advance, and specific safeguards applied. The distinction matters to every company that permits BYOD or occasional professional communication through personal applications.

1. What the General Court held and where the cases stand

On 3 June 2026, the General Court, sitting as the Ninth Chamber in an extended five-judge formation, dismissed the actions in T-1097/23, Vivendi v Commission, ECLI:EU:T:2026:355, and T-1119/23, Lagardère v Commission, ECLI:EU:T:2026:356. The companies sought annulment of decisions requiring documents in an investigation into the possible early implementation of Vivendi's acquisition of Lagardère.

The Court accepted that the requests could result in large-scale disclosure of varied personal data and, taken together, permit precise conclusions about the private lives of the people concerned. It therefore treated the risk of a serious interference with Article 7 of the Charter of Fundamental Rights as real. In the circumstances before it, however, the Court found a sufficient legal basis, an objective of general interest and proportionate limitations.

The litigation is not final. On the official InfoCuria records checked on 30 August 2026, C-861/26 P, Lagardère v Commission, and C-862/26 P, Vivendi v Commission, remained pending. Both appeals were lodged on 31 July 2026. The General Court judgments are therefore the operative first-instance rulings, but they must not be presented as the Court of Justice's final answer.

2. What Article 11(3) of Regulation 139/2004 permits

Regulation (EC) No 139/2004 on merger control allows the Commission to require necessary information by a simple request or by a binding decision. When it acts by decision under Article 11(3), it must state the legal basis and purpose, specify the information required, fix a time limit, identify the possible fines and periodic penalty payments, and indicate the right to judicial review.

This power is not unlimited. The requested information must be necessary for the suspected infringement under investigation. The decision must give adequate reasons, avoid arbitrariness and not impose an objectively impossible obligation. Proportionality depends on the real breadth and burden of the request, the relevant period, the custodians, the selection criteria and the safeguards governing review and production.

Incomplete or inaccurate compliance may have serious consequences. The Regulation provides, among other measures, for fines where answers are incorrect, incomplete or misleading and for periodic penalty payments of up to 5% of average daily aggregate turnover for each working day of delay. A company can neither ignore the request nor respond with an uncontrolled bulk export of everything it can find.

3. Why the documents were requested

Vivendi notified its proposed acquisition of sole control over Lagardère in October 2022. The Commission authorised the concentration subject to conditions on 9 June 2023, then opened a formal investigation into possible early implementation. The issue was whether Vivendi had exercised decisive influence before the transaction was permitted or contrary to the applicable obligations and commitments.

By decisions of 19 September 2023, amended on 27 October 2023, the Commission requested communications from identified people for a defined period, using specified subjects and search terms. For Lagardère, for example, the relevant period ran from 1 January 2020 to 19 September 2023 and was connected to particular business and editorial decisions capable of illuminating the alleged influence.

The object of the investigation was not the private life of executives as such. The Commission was seeking commercial information linked to a specific possible infringement. The difficulty arose because that information might have passed through WhatsApp, Signal, SMS, personal email or a privately owned phone, mixing professional and private material.

4. When personal accounts and devices came within scope

The requests covered professional documents held in personal or private email accounts, mobile phones and tablets, including instant messages and SMS, provided the relevant account or device had been used at least once for professional communication. They also covered documents deleted by a sender or recipient but still accessible through a corporate system, backup or another personal or professional account or device.

The phrase "at least once" is broad, but it does not make every file on a device relevant. Professional use made work documents on the account or device potentially searchable, subject to the decision's other criteria: named custodians, dates, interlocutors, subjects and search terms. The Court did not authorise unrestricted browsing through photographs, health records, family conversations or every application installed on a phone.

Nor did the Court hold that a BYOD policy itself gives an employer a right of access. It examined a binding EU information requirement addressed to undertakings and whether a personal device could be invoked to place professional documents beyond a lawful investigation. The company's internal collection still has to comply with applicable employment and data-protection law.

5. Why this was a serious interference with private life

Professional and private information on a modern phone is rarely stored in perfectly separate compartments. One messaging application can contain client contacts beside family discussions, health information, political opinions, location data and photographs. Even if each private item is fragmentary, the combined material can reveal a detailed picture of a person's life.

The General Court did not minimise that risk. It noted that the data could be diverse, difficult to predict in advance and potentially extensive. In Lagardère, one criterion could even lead to the production of all exchanges between specified people when an exchange matched a search term. That is why the analysis did not end with the statement that the device had been used professionally; it proceeded to the conditions governing limitations on Charter rights under Article 52(1).

Recognising a serious interference has practical consequences. The Commission and the company executing the request must treat selection, transfer, access, retention and deletion as high-risk operations. Necessity, data minimisation and auditable safeguards are not optional administrative refinements.

6. The concrete limits supporting proportionality

The Court relied on the combination of several limits, not on a single formula. The requests concerned designated people, specified time periods, defined subjects and search terms linked to the suspected conduct. Personal tools were relevant only where there had been professional use, and private material was expected to be encountered incidentally rather than pursued as an investigative objective.

The decisions therefore did not grant complete and uncontrolled access to all electronic activity. According to the Court, they did not establish continuous, indiscriminate or systematic surveillance, nor an automated assessment of the entire workforce. Access within the Commission was restricted, professional secrecy applied, and the production process was subject to arrangements for sensitive material and judicial review.

These factors are cumulative. A future request involving every employee, unlimited dates, vague subjects or indiscriminate device images would not become proportionate merely because the authority cited the same legal provision. Companies should map the precise boundaries of the actual decision and document any search term that generates a disproportionate volume of unrelated private material.

7. VDR, encryption and privileged communications

A subsequent Commission decision of 24 January 2024 added a virtual data room, or VDR, mechanism for responsive documents unrelated to commercial activity that contained sensitive personal data. Instead of treating each search hit as immediately producible, the mechanism created a controlled review environment and an additional layer of separation. The Court treated this safeguard cumulatively with the restrictions already built into the requests.

Sensitive personal data were to be separated, encrypted and marked. Access, transfer and later use had to follow the applicable protocol. Encryption protects the channel and storage, but it does not replace minimisation: a properly encrypted copy can still be excessive if it contains material outside the decision's purpose.

Communications potentially protected by legal professional privilege require their own review lane. The company should identify them without disclosing the protected substance, preserve the basis of the claim and use the procedure agreed with the Commission. Privilege review, sensitive-data review and relevance review are separate questions; passing one does not answer the others.

8. The special safeguard for journalistic sources

The media context made source confidentiality particularly important. The procedure allowed journalists holding a press card to review relevant documents and redact information capable of identifying a journalistic source. If a usable non-confidential version could not be produced, the document could be withdrawn under the mechanism, with the company providing a table describing redactions and withdrawals.

This was not a generic label allowing a publisher to withhold every editorial communication. The protection had to be connected to source identification and applied through a traceable procedure. At the same time, it prevented the search process from turning an EU merger investigation into uncontrolled disclosure of confidential sources.

A Greek media company responding to a comparable request should establish a dedicated source-protection review process before collection begins, assign review to a small authorised team and agree how disputed material will be isolated. Reviewing source confidentiality only after a bulk transfer would defeat the purpose of the safeguard.

  1. Related article: Can Your Employer Read Company Email and Teams Messages? That separate workplace issue concerns an employer's access to corporate systems, employee privacy and monitoring at work. Vivendi and Lagardère concern a binding Commission measure in an EU merger investigation. They do not give employers a new general right to read messages.
  2. Ordinary workplace surveillance. Routine productivity monitoring, continuous logging, location tracking or preventive inspection of staff communications must stand on their own employment and data-protection justification. A targeted response to a specific authority decision is not a permanent monitoring programme.
  3. European e-Evidence. European Production and Preservation Orders address stored electronic evidence in criminal proceedings and obligations of service providers under a different legislative framework. Article 11(3) is a merger-control information power directed to undertakings.
  4. Live interception. Capturing communications while they occur is different from collecting stored professional documents. The judgments dealt with existing material, not real-time interception, wiretapping or covert activation of a device.
  5. Forensic imaging. A bit-for-bit image may capture deleted areas, application databases, location history and unrelated content far beyond responsive documents. The judgments did not approve routine full-device imaging. If imaging is technically necessary, its scope, isolation, filtering, access and deletion require a distinct proportionality assessment.

The same distinction applies to an inspection under Article 13 of Regulation 139/2004. A dawn raid has its own legal basis, powers and procedural setting. It should not be silently substituted for the document-production process considered in these judgments.

10. Practical BYOD checklist for a Greek company

  • Map professional channels. Record which roles may use personal email, messaging applications, phones or tablets for company matters and in which countries.
  • Separate work from private life. Use managed work profiles, dedicated applications or containers where technically feasible, without claiming ownership of the rest of the device.
  • Write a specific BYOD policy. Explain permitted use, security, preservation, collection triggers, responsible teams and what the company cannot inspect.
  • Avoid consent as the only basis. In an employment relationship, consent may not be freely given. Identify the proper legal basis and document necessity and balancing.
  • Prepare a legal-hold protocol. Define who may suspend deletion, for which custodians, data and period, and how the hold is released.
  • Preserve without browsing. A preservation step should not become a licence for managers to read private conversations.
  • Use a two-person authorisation rule. Legal and privacy or security functions should approve access to a personal tool and record the reason.
  • Predefine review lanes. Separate relevance, legal privilege, sensitive data, journalistic sources and clearly private material.
  • Control the collection environment. Use trained personnel, logged tools, encryption, access control and hashes or equivalent integrity evidence where appropriate.
  • Minimise the output. Produce responsive documents, not an unfiltered mailbox export or entire phone image, unless the legal instrument specifically and proportionately requires more.
  • Plan cross-border transfers. Identify where collection, review and hosting take place and apply the relevant transfer safeguards.
  • Inform people accurately. Give required information on purpose, scope, recipients and rights, subject to lawful restrictions needed to protect the investigation.
  • Set final retention and deletion. When the matter and any applicable legal hold end, identify the legal basis and period for every copy retained, return or securely delete unnecessary working and VDR copies, and record the outcome.

The policy must be adapted to Greek and EU law, collective arrangements, each worker's country and the actual technical design. A signature under a broad clause saying that the company may inspect everything does not cure a disproportionate practice.

11. How targeted collection avoids internal surveillance

After receiving a decision, the company should first suspend relevant deletion and create a requirement matrix. For every request it should record the legal basis, purpose, custodians, dates, applications, search terms, deadline and applicable safeguard. Collection personnel should see no more content than is necessary for technical extraction.

Processing should proceed through successive filters: technical collection, deduplication and scoping, relevance review, privilege and protected-category review, final quality control and secure production. Decisions on disputed documents should be logged. If a search term returns a disproportionate number of unrelated private files, the company should quantify the problem and promptly seek clarification or a narrower method rather than silently improvise.

An employee or executive should not hand over an unlocked device informally or decide alone what to delete. An authorised team should collect in a controlled environment, expose purely private material as little as possible and provide a process for resolving disagreements. This protects the investigation, privacy and evidential integrity at the same time.

12. Responses and judicial remedies

An Article 11(3) decision must state the right to judicial review. Where the conditions are met, an undertaking may bring an action for annulment under Article 263 TFEU and seek interim relief under Articles 278 and 279 TFEU. An action does not automatically suspend the duty to comply. Vivendi and Lagardère also pursued interim proceedings, illustrating why the remedial timetable must be organised immediately.

Before and during compliance, the company may request written clarification, a reasonable extension, technical adjustment of searches, a VDR protocol and procedures for privilege, sensitive data or journalistic sources. A request should be supported by measurable burden and risk evidence. A general statement that personal devices are inaccessible or review is difficult is not enough.

For individuals, the appropriate request for access, information, correction or complaint depends on who is the controller and at which stage. Internal collection by an employer and subsequent processing by an EU institution do not necessarily fall under the same regime: Regulation (EU) 2018/1725 applies to EU institutions, while the GDPR and relevant national rules apply on the corporate side. Any restriction of rights needs a lawful basis and should not be treated as automatic.

13. What the pending appeals mean

C-861/26 P and C-862/26 P are pending before the Court of Justice. An appeal is limited to points of law; it is not a complete retrial of the facts. On 30 August 2026, the official dockets confirmed filing and pending status, but there was no Court of Justice judgment affirming, changing or setting aside the General Court's approach.

Companies cannot disregard the two judgments because they are the most direct judicial analysis of professional documents held in personal accounts or on personal devices under Article 11(3). Because the appeals remain pending, however, any actual collection exercise requires a review of the law and case status then in force; the judgments should not be turned into an immutable policy.

14. Frequently asked questions

Does one work message allow inspection of an entire personal phone?

No. One professional use could make work documents on the account or device subject to the targeted search, but collection remained limited by people, dates, subjects, interlocutors and search terms. The judgments did not approve complete and uncontrolled access to all content.

Can an employer rely on these cases for routine WhatsApp checks?

No. Article 11(3) concerns the Commission's power in a merger investigation. Ordinary employer monitoring has a different purpose, legal basis, information duty and necessity analysis. The judgments create no general surveillance permission.

Must every search hit be delivered immediately?

The binding deadline must be respected, but procedures for relevance, legal privilege, sensitive data and journalistic sources still apply. A concrete scope or burden problem requires prompt, evidenced engagement with the Commission and, where necessary, judicial protection.

May purely private messages be deleted before collection?

Not by an individual's unilateral choice once a preservation duty applies or an investigation is reasonably foreseeable. Deletion can undermine completeness and evidential integrity. Irrelevant or protected material should be isolated through an approved review process, not made to disappear without a record.

Are the judgments final?

No. The General Court dismissed the actions on 3 June 2026, but appeals C-861/26 P and C-862/26 P, filed on 31 July 2026, remained pending at the latest official check.

15. Official sources

Legal update: The official sources and both appeal records were checked on 30 August 2026. At that review, both judgment texts on EUR-Lex were still marked “Provisional text”. This article distinguishes the operative first-instance rulings from the pending appeals and is not individual legal advice. Any real collection requires an assessment of the specific decision, applicable employment and data-protection rules, and the law in force at that time.