The eevidence regulation applies from 18 august 2026, and from that date competent judicial authorities in one EU Member State can issue orders directly to service providers offering services in another Member State, compelling them to hand over or preserve electronic data for criminal proceedings. Regulation (EU) 2023/1543 removes the traditional requirement to route requests through the authorities of the state where the provider sits, replacing it with a direct-order model backed by tight deadlines. It applies across the European Union with one significant exception, Denmark, which does not participate under Protocol 22 to the Treaties.
For service providers, in-house counsel and cross-border compliance teams, this is a structural change to how criminal-evidence demands arrive and how fast they must be answered.
Quick answers.
Practical take. Start counting timelines from receipt, immediately preserve the relevant data, and involve counsel promptly. Do not assume that national contact points and IT connections are fully wired up, readiness varies between Member States.
Until now, obtaining electronic evidence held by a provider in another EU country generally meant a mutual legal assistance request or a European Investigation Order, instruments that route through the authorities of the receiving state and can take weeks or months. Regulation (EU) 2023/1543 changes that. Because the eevidence regulation applies from 18 august 2026 as a directly applicable instrument, an issuing authority can now send a European Production Order or European Preservation Order straight to a provider offering services elsewhere in the Union, and the provider is legally obliged to respond within the Regulation’s deadlines.
The practical takeaway for providers is blunt: the order that lands in your legal mailbox or transmission queue may originate from a prosecutor or court in a Member State where you have no establishment and no local counsel, and the clock starts the moment you receive it. The companion Directive (EU) 2023/1544 obliges Member States to require providers to designate establishments or legal representatives and to build the national machinery, but the Regulation’s legal effect does not wait for every state to finish that work.
The Regulation’s reach is defined by the nature of the service offered in the Union rather than by where corporate headquarters sit. It captures a broad range of digital services: electronic communications services, internet domain name and IP numbering services (such as IP address assignment, domain name registries and registrars and related privacy and proxy services), and other information society services that store or otherwise process data on behalf of users, hosting, cloud infrastructure, online platforms and marketplaces among them. If a provider offers such services in the Union, it can be the recipient of an order.
Under Regulation (EU) 2023/1543, a service provider is an entity that provides one or more of the covered categories of service and offers those services in the Union. Crucially, the framework requires providers to designate an establishment or a legal representative in the Union to receive, comply with and enforce orders. That designated point of contact is where orders are directed and where the obligation to act crystallises. Providers with no establishment in the issuing state cannot rely on that absence to escape the order, the direct-order model is the entire point of the reform.
Not every data demand falls within the framework. The Regulation applies to specified data categories for the purpose of criminal proceedings, and certain services and data types fall outside its perimeter. The single most important jurisdictional limit is territorial: while the eevidence regulation applies from 18 august 2026 across the EU, it does not apply in Denmark. Denmark’s position stems from Protocol 22 to the Treaties, under which it does not participate in this area of Union justice and home affairs cooperation. In practice this means authorities cannot use European Production or Preservation Orders under this Regulation to reach providers in Denmark, and Danish authorities do not issue them. Cross-border evidence involving Denmark continues to rely on other instruments.
Compliance teams should hard-code this exception into intake logic so that Danish-facing matters are triaged correctly rather than processed as if the Regulation governed them.
The Regulation creates two distinct instruments, and confusing them is a common early error. A European Production Order compels a provider to hand over specified data. A European Preservation Order compels a provider to freeze and retain specified data so that it is not deleted or altered while the issuing authority seeks its production, typically through a later Production Order or a mutual assistance route. Understanding the difference matters because the obligations, timeframes and risks diverge sharply.
A European Production Order must be issued or validated by a competent judicial authority and must contain enough detail for the provider to identify precisely what is sought and to assess its regularity on its face. That includes the identity and contact details of the issuing authority, the legal grounds and the criminal offence at issue, a clear description of the data requested, and the applicable time limit for compliance. The order is transmitted using a standard certificate (a European Production Order Certificate). The provider is not being asked to re-adjudicate the underlying investigation, but the specificity requirements give it the information needed to scope its search narrowly and to recognise defects that may justify a challenge.
A European Preservation Order is likewise transmitted using a standard certificate and requires sufficient detail to identify the data to be preserved, together with the retention period and scope of preservation. Because preservation must take effect without delay to prevent loss, the recipient’s first duty is to lock the data down promptly and then verify the order’s contents. A Preservation Order does not, of itself, authorise disclosure, it holds the position while the issuing authority pursues production. Providers should treat it as a freeze instruction, not a production instruction, and resist the temptation to conflate the two.
| Feature | European Production Order | European Preservation Order |
|---|---|---|
| Purpose | Obtain specified content or data for a criminal investigation | Secure preservation of data to prevent loss or deletion |
| Typical timeframe for compliance | 10 calendar days (normal); 8 hours (emergency) | Immediate preservation on receipt; retention period set by the order |
| Recipient | Service providers offering services in the Union | Service providers offering services in the Union |
| Required content | Data requested, legal grounds, offence, issuer identity, time limit | Data to be preserved, retention period, scope of preservation |
| Enforcement / penalty risk | Subject to issuing and enforcing state enforcement rules | Failure subject to national preservation enforcement rules |
| Remedies for the provider | Grounds for objection on legality, scope, fundamental rights or law of a third country | Objection to narrow scope or duration; notify the issuing authority |
Speed is the defining feature of the regime, and the deadlines are the single most operationally demanding element of the fact that the eevidence regulation applies from 18 august 2026. As a general rule a European Production Order must be complied with within 10 calendar days of receipt of the certificate. Where the issuing authority certifies an emergency, situations involving an imminent threat to a person’s life or physical integrity, or to critical infrastructure, the response window collapses to 8 hours. Preservation must be effected immediately on receipt and maintained for the period specified in the order.
The word that governs every deadline is receipt. The clock does not start when the order is issued, signed or dispatched; it starts when the provider actually receives the certificate. That places a premium on being able to prove exactly when receipt occurred, because that timestamp determines whether a response is timely or late.
Consider a normal Production Order received at 14:00 on a Monday. The 10-calendar-day period runs from that receipt, so the response is due by the equivalent point ten calendar days later, including weekends and public holidays, since the count is in calendar days. A compliance team that treats the deadline as business days will miss it.
Now consider an emergency Production Order received at 22:00. The 8-hour window means the response is due by 06:00 the following morning. That timeline is impossible to meet without an out-of-hours escalation path, a pre-identified on-call reviewer and a data-retrieval process that can run at night. Providers who have not rehearsed the emergency scenario before an emergency order arrives will not meet the deadline.
Because everything counts from receipt, the provider must capture reliable proof of when it received the order. Where the decentralised IT system is used, the system’s timestamp provides that evidence. Where an order arrives by other acknowledged means, the provider should log the date, time and method and retain the header data or delivery confirmation. If a dispute later arises about timeliness, that contemporaneous record is the provider’s primary protection. It also anchors any window for raising objections, since a provider that intends to object to an order should generally do so within the compliance period.
The intended channel for transmitting and verifying orders, certificates and other communications is a decentralised IT system connecting the competent authorities of the Member States and, where relevant, service providers, a secure electronic platform designed to route orders and to provide authentication and timestamping. It is meant to give providers confidence that an order is genuine and to create an auditable record of transmission and receipt. Because the eevidence regulation applies from 18 august 2026 while national IT integration is still being completed in several states, providers need to understand both the electronic route and the fallbacks.
When an order arrives, the provider should verify the identity and competence of the issuing authority, confirm that the certificate contains the mandatory content, note the receipt timestamp, and classify the order type (Production or Preservation, standard or emergency). These checks should be a standardised intake step, not an ad hoc review, so that the response clock is understood from the first minute.
Where the issuing or receiving state is not yet fully connected to the IT system, orders may arrive by other appropriate means capable of producing a written record and allowing authentication. In that situation the provider still owes the obligations set by the Regulation; the absence of a working electronic connection does not suspend the duty. Providers should identify the relevant national contact points, record the method and time of receipt with particular care, and treat an offline delivery with the same urgency as an electronic order. Given the uneven state of national readiness in the opening months, providers should assume they may receive orders through inconsistent channels and build intake procedures that can absorb that variability.
The compressed timelines mean that a provider’s response cannot be improvised. The following playbook translates the Regulation into an escalation timeline anchored to receipt. It is a framework, not legal advice for a specific matter, jurisdiction-specific and data-specific questions require counsel.
Every step should be logged: receipt, classification, escalation, legal review, the search parameters applied, what was produced or preserved, and any objection raised. A defensible audit trail protects the provider if timeliness or the scope of disclosure is later questioned, and it demonstrates good-faith compliance. Providers should maintain template acknowledgements, a template preservation-confirmation to the issuing authority, and a standard internal escalation record so that responses are consistent across matters and across the on-call roster.
The Regulation is not toothless. Non-compliance exposes providers to enforcement, but it also preserves legitimate grounds for objection, the two must be managed together.
Enforcement of orders and pecuniary penalties for failure to comply are determined at national level, within the framework the Regulation and its companion Directive establish. A provider that ignores a valid order, misses a deadline without justification, or fails to preserve data risks penalties determined by the relevant Member State’s law, alongside the reputational and operational consequences of being treated as a non-cooperative recipient. Because sanctions are national, the specific exposure varies by jurisdiction, another reason to obtain local counsel promptly rather than assume a uniform penalty regime.
A provider is not obliged to comply blindly. The Regulation sets out circumstances in which a provider may inform the issuing authority that it cannot comply, for example where the certificate is incomplete, contains manifest errors, or does not contain sufficient information to execute the order, or where compliance would be impossible due to factual circumstances. Objections may also arise where compliance would conflict with fundamental rights, immunities and privileges, or the law of a third country, in which cases the Regulation contains dedicated review mechanisms, including a procedure for conflicts with third-country law.
The prudent course is to raise such issues promptly, in writing, to the issuing authority, and, where appropriate, through the review procedures, rather than simply failing to respond. Silence looks like non-compliance; a documented, timely objection looks like good faith.
A defining feature of the launch is the gap between legal effect and operational readiness. While the eevidence regulation applies from 18 august 2026 as a matter of directly applicable EU law, and the companion Directive (EU) 2023/1544 was to be transposed by 18 February 2026, transposition and the underlying national scaffolding, designated authorities, contact points and IT connections, have not been uniformly in place, and the Commission has pursued transposition shortcomings with several Member States.
The practical consequence is that providers should expect inconsistent delivery channels, varying levels of authority responsiveness, and some uncertainty during the opening months, and should build their intake and escalation processes to tolerate that unevenness rather than assuming a smooth, fully connected system from day one.
posted 9 minutes ago
posted 24 minutes ago
posted 40 minutes ago
posted 49 minutes ago
posted 54 minutes ago
posted 54 minutes ago
posted 60 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message