A dawn raid is an unannounced inspection: competition officials arrive with an authorisation decision, seize documents and devices, image data, seal rooms and interview staff. The first hour decides the outcome β verify the scope, notify counsel, escort every inspector, mirror everything taken, preserve legal privilege, and above all never obstruct: deletion, tipping off and “lost” phones convert a survivable inspection into an aggravated case with separate fines and, in criminal regimes, prosecutions.
Dawn raids are competition enforcement’s sharpest instrument, and the moment a company’s compliance program is genuinely tested. Everything depends on preparation made months earlier: a protocol people can follow while nervous, trained reception staff, pre-mandated counsel, and clarity about what may and may not be refused. This guide walks the raid from doorbell to aftermath across the EU, TΓΌrkiye and other regimes β part of the compliance pillar of our Competition & Antitrust hub.
What powers do inspectors have?
To enter business premises (and, with judicial authorisation, homes and vehicles), examine and copy books and records in any form, image devices, seal rooms and cabinets, and ask on-the-spot questions about facts and documents. In TΓΌrkiye, refusal or obstruction triggers automatic fines and can support criminal exposure.
What can you legitimately refuse?
Genuinely privileged lawyer-client communications (in the EU: independent external counsel, not in-house), material outside the decision’s scope, and answers that would amount to admitting an infringement (limited right against self-incrimination β factual questions must still be answered).
What is the single biggest mistake?
Obstruction β deleting files, deleting chats, refusing access, warning co-cartelists. Fines for obstruction are separate and substantial (EU cases have reached tens of millions), and it destroys any later leniency or cooperation credit.
What happens in the first hour?
The clock starts at reception. Trained front-desk staff take the inspectors to a designated room, request and photograph the authorisation decision and IDs, and trigger the alert list β legal, IT, the senior site manager, external counsel β while making clear the company will cooperate fully and counsel is on the way. Inspectors may begin immediately and need not wait for lawyers, but in practice most accept a short, reasonable delay if cooperation is visible.
Immediately in parallel: IT suspends automatic deletion policies and any auto-purge on mail and messaging systems (this is protective, not obstructive, and must be documented as such); the raid team assembles escorts so no inspector is ever unaccompanied; a scribe starts the log of every room entered, every document viewed or copied, every question asked and answered. Staff not involved are told, in writing, to continue working normally, not to discuss the inspection externally, and to route any inspector contact through the raid team. The most common early failure is silence at the top β an unmanaged workforce improvises, and improvisation is where obstruction happens.
What is the scope of the decision β and why does it matter?
The authorisation defines the subject matter and purpose of the inspection: the products, the suspected conduct, the period. Inspectors may search for material within that scope anywhere on the premises, but material clearly outside it may be challenged β and “fishing” beyond the decision is one of the few grounds on which inspections have been successfully annulled or evidence excluded. Reading the decision carefully in the first fifteen minutes is therefore both a legal act and an operational one: it tells your team what documents matter.
Practicalities: keep a copy of the decision available to every escort; log any request that appears out of scope and raise it politely with the lead inspector at the time, recording the exchange rather than refusing outright; and note that authorities routinely discover a second infringement in seized material β evidence outside the original scope can generally be used to open a new investigation, which is why leniency scoping for adjacent conduct becomes urgent the same week. TΓΌrkiye’s Board and the Commission both operate this way; assume everything imaged will eventually be read.
The Commission has fined companies for broken seals (E.ON Energie, β¬38 million), diverted email accounts and incomplete answers (Suez Environnement, Czech energy cases), each time emphasising that obstruction is punished independently of whether the underlying suspicion is proven. TΓΌrkiye’s Rekabet Kurulu has fined groups for employees deleting WhatsApp messages during inspections, treating deletion as obstruction with automatic percentage-based fines β and the deleted content is often recoverable anyway, so the company ends up with both the evidence and the extra fine. The rule taught by every one of these cases: nothing found in a raid is as damaging as what you do during it.
How do privilege and personal devices work?
Privilege is narrower than most executives assume. In EU proceedings, legal professional privilege covers communications with independent external lawyers qualified in the EEA for the purpose of the defence β in-house counsel advice is not privileged. National regimes differ: TΓΌrkiye recognises attorney-client privilege for external counsel with practical limits, the UK protects in-house legal advice, and US privilege is broader still. Multi-jurisdictional groups should assume the EU standard for anything that might land in a Commission file, and route sensitive competition analysis through external counsel accordingly.
Procedure matters: privileged documents encountered during a raid are placed in a sealed envelope and the dispute resolved later, not read on the spot β insist on that process, and log each item. Personal devices used for work (BYOD phones, personal email with business content) are within reach in most regimes, and messaging apps are the first target: inspectors routinely image phones and ask for chat exports. The compliance consequence is prospective β a BYOD policy that anticipates inspection, with clear rules on business use of personal messaging, is worth more than any argument made on the day.
How should staff answer questions?
Factually, narrowly and truthfully β or not at all where they lack knowledge. Inspectors may ask on-the-spot questions about facts and about documents found: where a file is kept, what an abbreviation means, who attended a meeting. Employees must answer such questions and must not give false or misleading answers (a separate offence), but they are not obliged to provide legal characterisations or to admit an infringement, and “I don’t know β the company will provide that in writing” is a legitimate, protective answer that counsel should encourage.
Practical discipline: one company representative present for every interview, a verbatim note taken, no speculation, no explanations of context beyond the question, no jokes. Corrections should be volunteered promptly and in writing where an answer proves inaccurate β inaccuracy left uncorrected becomes misleading information. After the raid, the company should review the log and file any necessary clarifications; that memo is also the first draft of its internal-investigation scope, and often the moment the leniency clock starts running in earnest, as our leniency guide sets out.
What happens after the inspectors leave?
The consequential week. Assemble the log and mirrored materials, run a privileged internal review of what was taken to establish exposure, and decide β fast β whether to apply for leniency in each affected jurisdiction, because a raid usually means the authority already has a first applicant somewhere and the remaining reductions are being claimed in order. Simultaneously assess parallel jurisdictions: raids are often coordinated internationally, and a filing in one regime without the others is an incomplete strategy.
Then handle the organisation: preserve everything (litigation hold formalised), manage communications (employees, customers, sometimes markets β listed companies face disclosure judgments), and avoid the two classic post-raid errors β precipitate disciplinary action that creates hostile witnesses, and reassuring public statements that later conflict with the file. Finally, treat the raid as data: whatever it found, the compliance program missed it, and the remediation record you build now will be read by the same authority when it sets the fine. Companies that emerge best treat the aftermath as the beginning of cooperation and reform, not as a siege.
What should the written protocol contain?
One page for reception, one for the raid team, one for IT, and a contact card. Reception: where to seat inspectors, whom to call, what to say (“we will cooperate; our counsel is being contacted now”), and not to discuss anything else. Raid team: escort rules, scribe templates, scope checking, privilege handling, mirroring requirements, interview attendance. IT: the deletion-suspension switch, imaging support, device inventory, and a rule that no remote wipe is executed for any device on site.
Add the contact card β external counsel (with out-of-hours numbers), the general counsel, the site lead β laminated at every reception desk in every country. The whole package should be short enough to read while adrenalised, and it should be tested annually. Multi-site groups must localise it: language, local counsel, local authority powers (TΓΌrkiye’s inspection rules and automatic obstruction fines differ from the Commission’s in detail that matters on the day).
How do simultaneous multi-country raids change the response?
They compress every decision. Coordinated inspections across a group’s sites in several jurisdictions β increasingly common through authority cooperation β mean the company must run parallel protocols with local counsel at each site while a central team assembles the picture in real time. The immediate priorities are consistency (the same instructions everywhere, so no site’s conduct becomes the outlier) and speed of assessment, because the leniency queue in every affected regime is being filled during the same hours.
Practical arrangements that pay for themselves: a pre-agreed panel of local counsel with out-of-hours coverage in every country where the group has meaningful operations, a single incident-command bridge line, and a template for the first internal communication so no site improvises its own message. Groups that improvise all three routinely lose a day β and a day is a plausible difference between immunity and a 30% reduction, as our leniency guide shows.
Frequently Asked Questions
Can we refuse entry until our lawyers arrive?
No β inspections may proceed immediately, and refusal risks obstruction findings. In practice, inspectors commonly allow a short wait (30-60 minutes) if the company is visibly cooperating and counsel is genuinely en route; secure that by asking, not by blocking.
Are home searches possible?
Yes in the EU and TΓΌrkiye with judicial authorisation, where there is suspicion that business records are kept there β used sparingly but genuinely, including of executives’ homes and vehicles. Personal-device policies should assume this.
What if the raid concerns a different company?
Third parties can be inspected for evidence about others’ conduct. The same protocol applies, plus careful scope control β and it is often the moment to check whether your own contacts with the target create exposure.
Does cooperating during a raid earn any credit?
Ordinary cooperation is expected and earns nothing by itself; obstruction costs a great deal. Credit comes from leniency applications and from cooperation beyond legal duty later β the raid’s role is to preserve, not squander, those options.
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.


