New EU Rules on Cross-Border Access to Electronic Evidence: What Companies Need to Know


7 minute read | August.25.2026

In criminal investigations, much of the evidence that police and prosecutors need (e.g., emails, messages, account details, and files stored in the cloud) is held by private technology companies. Often, that data sits on servers in another country, or is controlled by a provider based abroad. Until now, authorities in one EU Member State usually had to ask another country for help through slow mutual legal assistance channels, which could take months. Electronic data, however, can be deleted or changed in moments, and investigations need to be fast. 

To close this gap, the EU adopted two connected instruments on 12 July 2023: Regulation (EU) 2023/1543 (“E-Evidence Regulation”) and Directive (EU) 2023/1544 (“E-Evidence Directive”). Together, they allow judicial authorities in one Member State to directly obtain electronic evidence from 
service providers offering services in the EU that are established or represented in another Member State. The storage location of the data is not decisive. 

This matters for affected businesses because they can be required to produce or preserve electronic evidence in response to orders from authorities across the EU. Without designated points of contact for authorities or a lack of responsiveness, non-compliant companies are risking penalties of up to 2% of 
the total worldwide annual turnover. 

The E-Evidence Regulation applies since 18 August 2026. To comply with the E-Evidence Directive, Member States must enact the necessary laws, regulations and administrative provisions by 18 February 2026. 

What Companies are Affected? 

The E-Evidence Regulation applies to service providers that offer services in the EU. Service providers within the meaning of the E-Evidence Regulation are: 

  • Providers of electronic communications services (e.g., telephone, instant messaging and email services); 
  • Providers of internet domain name and IP numbering services (e.g., domain registries, registrars, and related privacy or proxy services). 
  • Providers of information society services that let users communicate with each other as a defining part of the service, such as: 
    • Social networks 
    • Online marketplaces with chat functions between seller and buyer
    • Online gaming platform with chat or call functions
    • Review sections with the possibility to reply to other reviews 
  • Providers of information society services that store or process user data on their behalf as a defining part of the service, such as:
    • Cloud services
    • AI chatbots
    • Online gambling platforms  

What Companies are Not Affected? 

  • Online services that do not the focus on the mere processing or storing data, such as legal, architectural, engineering, and accounting services.
  • Web stores that exclusively provide retail services with no communication between users and where the shop owner ships directly to customers, may not be affected by the regulation, since the data stored and processed during a purchase is usually just a byproduct of the order and not a defining element of the online retail service itself.
    • However, the E-Evidence Regulation applies if the store operates similarly to an online marketplace and allows interaction between users/third-party sellers through a community forum or interactive ratings.
  • Financial services like banking services, insurance or reinsurance services. 

Ultimately, given the unclear definition of a “defining part,” classification must be determined on a case by-case basis. 

Notably, there is no exclusion for small or medium-sized companies. Businesses must therefore comply with the E-Evidence Regulation from their very first day of operation. 

Where Does This Apply? 

A provider is treated as “offering services in the EU” if two conditions are met:  

  1. it enables people or businesses in one or more Member States to use its services; and
  2. it has a substantial connection* to that Member State or those Member States.  

*A substantial connection exists where the provider has an establishment in a Member State. If it has no such establishment, the connection is assessed on practical factors, such as having a significant number of users in one or more Member States or targeting its activities toward one or more Member States. In short, simply being technically accessible from the EU is not enough. 

The rules apply to electronic evidence in criminal proceedings, for the enforcement of custodial sentences or certain detention orders. They distinguish between different categories of data:  

  • subscriber data (any data relating to the subscription of a service),
  • traffic data (information about a communication, such as its time and recipient), and 
  • content data (the actual content of messages or files).  

The more sensitive the data, the stricter the safeguards that apply. 

Key Provisions: E-Evidence Regulation  

The E-Evidence Regulation creates two main tools

  1. European Production Order (requires a provider to hand over specified electronic evidence)
  2. A European Preservation Order (requires a provider to freeze specified data so that it cannot be deleted or altered while the authority obtains it through the proper channels)  

Orders must be issued or approved by a judicial authority and are issued on standard forms known as an EPOC (for production) and an EPOC-PR (for preservation). 

The level of safeguard depends on how sensitive the data is

  • Traffic and content data require stronger judicial involvement than basic subscriber data.
    • For EPOCs, providers must comply within ten days, and within eight hours in emergencies involving an imminent threat to a person’s life or safety. 
    • In case of an EPOC-PR, the addressee shall preserve the data without undue delay.   
  • For orders seeking traffic or content data, the authorities of the Member State where the provider or the affected person is located may be notified and, in defined situations, may object (e.g., to protect immunities and privileges, press and media freedom, or fundamental rights). 
    • In case of a potential conflicts of laws of non-EU countries, the provider can object, and a court in the issuing State then reviews the order and may uphold, adapt, or withdraw it, weighing interests such as the protection of fundamental rights.  

Finally, people whose data are sought have the right to an effective remedy and can challenge the order before a court in the issuing Member State. 

Key Provisions: E-Evidence Directive 

The E-Evidence Directive addresses a practical question: Who should the order be sent to?  

The E-Evidence Directive applies to the same service providers as the E-Evidence Regulation. Its role is to make sure each provider has a clear point of contact inside the EU that can receive and act on these orders. This contact point is responsible for receiving and complying with orders and must have the powers and resources to do so. 

  • Providers established in the EU are required to designate one of their establishments as responsible. 
  • Providers that offer services in the EU but are not established there are required to appoint a legal representative in a Member State.  

Providers must inform the national authorities who their contact point is and keep that information up to date. This is happening via a central European Notification Platform.  

Penalties 

Member States must also impose penalties on providers who fail to comply with the E-Evidence Regulation and the E-Evidence Directive. Penalties for infringements of the E-Evidence Regulation can reach up to 2% of a provider’s total worldwide annual turnover. 

Implications for Companies 

For service providers, these rules create a direct legal duty to respond quickly to orders from authorities across the EU, not only in the country where the company is based.  

The E-Evidence Regulation is in effect since 18 August 2026. Companies that fall within scope should promptly implement the actions to comply. 

Important Practical Steps 

  • Confirm whether you are in scope. Most providers of online-market places, cloud, hosting, online platform, or domain services that offer services in the EU will be.
    • simple web shops will likely be exempt if they do not typically offer their users (or third-party sellers and their customers) any means to interact with each other and if they do not act as an online marketplace, community forum or if they do not allow ratings that allow users to react and respond to those ratings.
  • Designate your EU contact point. Appoint a legal representative or set up a designated establishment before the rules apply and register on the European Notification Platform.
  • Build a response process. You may have as little as ten days —or eight hours in an emergency. Clear internal procedures, responsibilities, and escalation paths should be in place now.
  • Plan for data protection and conflicts of law. Orders will often involve personal data and may create tension with laws outside the EU, so legal review should be built into the process. 

We are glad to help assess whether your organization is affected and to build a compliant framework. 

For questions and further information please contact Dr. Christian Schröder.