Ithaque Sécurité — EU court permits host-state security authorisation subject to safeguards

Case
Ithaque Sécurité SAS v État belge
Court
Court of Justice of the European Union
Date Decided
10 September 2026
Citation
ECLI:EU:C:2026:738
Topics
freedom to provide services, private security, authorisation, proportionality

Background

Ithaque Sécurité SAS, a French private-security company, was hired by Française des Jeux to ensure the proper conduct of a lottery draw in Bruges, Belgium, in December 2021. Belgian authorities told Ithaque that it needed Belgian authorisation and had to pay a EUR 1,000 application fee.

Ithaque declined, arguing that its French authorisation should be recognised in Belgium, and performed the work without Belgian authorisation. Belgium subsequently imposed a EUR 15,000 administrative fine. In Ithaque’s action to annul that fine, the Brussels Court of First Instance asked whether Article 56 TFEU generally requires Belgium to allow security firms established in another Member State to operate, subject only to limited checks.

The Court’s Holding

The Court held that Article 56 TFEU does not preclude a Member State from requiring a private-security undertaking established in another Member State to obtain administrative authorisation before providing services in its territory, and from penalising non-compliance. Such a requirement restricts the freedom to provide services, but may be justified by the protection of public order given the nature of private-security activities.

The authorisation regime is lawful only if it does not impose conditions or checks equivalent to those required for establishment, gives due account to equivalent conditions already met in the undertaking’s Member State of origin, and does not impose disproportionate fees or unnecessary or disproportionate guarantees. It is for the referring court to determine whether Belgium’s procedure, documents requested, EUR 1,000 fee, and any guarantee requirement satisfy those conditions in Ithaque’s case.

Key Takeaways

  • Host Member States may require prior authorisation for cross-border private-security services.
  • They must avoid duplicating supervision and conditions already satisfied in the provider’s Member State of establishment.
  • Application fees must reflect processing costs and must not be excessive or unreasonable.
  • A guarantee requirement cannot be justified if equivalent protection is already provided in the Member State of origin.

Why It Matters

The judgment confirms that unharmonised private-security services remain subject to host-state regulation, while preserving Article 56 TFEU’s protection against duplicative and disproportionate barriers to cross-border services.

For security providers, an authorisation issued at home is not automatically sufficient abroad. But host authorities must conduct a service-focused, proportionate assessment that recognises equivalent safeguards already verified in the provider’s home Member State.

✉️ Get tomorrow’s cases before your first coffee
Daily Case Law is our free morning digest — the most substantive new decisions, filtered to your jurisdictions and topics, each linking back here for the full analysis.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top