Introduction and overview
On 18 August 2026, Regulation (EU) 2023/1543 (the e-Evidence Regulation) becomes fully applicable. Together with Directive (EU) 2023/1544 (the e-Evidence Directive), these instruments establish a new EU framework for cross-border access to electronic evidence in criminal proceedings.
The e-Evidence Regulation enables judicial authorities in one Member State to request electronic evidence directly from service providers located in another Member State. This is achieved through two principal instruments: a European Production Order Certificate (EPOC) or a European Preservation Order Certificate (EPOC-PR). The traditional channels of mutual legal assistance and the European Investigation Order will no longer serve as the primary mechanisms for obtaining such evidence.
The e-Evidence Directive requires affected service providers to designate a designated establishment or appoint a legal representative in the EU that can receive orders and ensure compliance with them.
Why act now? Just over one week remains until the rules apply. Many companies have underestimated e-Evidence or have not yet put it on the compliance roadmap. The need for action is immediate: without registration and internal procedures, companies face significant penalties and operational risk.
Scope
Determining whether a company falls within scope requires a two-step analysis:
a) Geographic nexus: Offering services in the EU
The threshold question is whether a service provider “offers” services in the Union. This requires two cumulative elements: (i) enabling persons in a Member State to use the relevant service, and (ii) maintaining a “substantial connection” to at least one Member State.
A substantial connection may arise from an establishment in a Member State, a significant number of users in a Member State, or targeted activities toward Member States. Examples include offering services in local languages or currencies, advertising locally, or providing local-language customer service.
b) Substantive nexus: Covered service providers
The e-Evidence Regulation applies to “service providers” in three categories:
- Electronic communications services (including email providers, messaging services, and VoIP providers).
- Internet domain name and IP numbering services (including domain registries, registrars, domain privacy and proxy services, and IP address allocation services).
- Other information society services that either (i) enable users to communicate with each other, or (ii) enable the storage or other processing of data on behalf of users, provided that data storage is a defining component of the service. This third category is particularly broad and may capture cloud computing providers, online marketplaces, social media platforms, and online gaming services, among others.
For a more detailed analysis of the scope, see our blog post: Reed Smith Viewpoints: Understanding the scope of the e-Evidence Regulation and Directive.
Registration obligation and appointment of an EU addressee
In-scope service providers must designate an EU addressee authorised to receive orders and ensure compliance on the provider’s behalf:
- Service providers established in the EU must designate a designated establishment.
- Service providers not established in the EU must appoint a legal representative in a Member State where services are offered.
The EU addressee must be established or reside in a Member State where the provider offers services, be subject to enforcement measures, and have the necessary powers and resources. Service providers that were already offering services in the EU on 18 February 2026 must designate or appoint their EU addressee by 18 August 2026.
Registration must be completed through the European Commission’s decentralised IT system: Commission registration portal for service providers.
Practical note: Some Member States may not yet have fully transposed the e-Evidence Directive into national law. Companies should verify the current implementation status and enforcement practice in their target Member State before finalising their registration.
Instruments under the e-Evidence Regulation
a) European Production Order Certificates
An EPOC is an order from an authority of a Member State requiring a service provider to produce specified electronic evidence. The order is transmitted directly to the EU addressee, i.e., the designated establishment or legal representative, in another Member State.
Production deadlines
- Standard case: production within 10 days after receipt of the EPOC.
- Emergency case: production without undue delay and in any event within eight hours.
b) European Preservation Order Certificates
An EPOC-PR requires the service provider to preserve (i.e., freeze) existing data to ensure it remains available for a subsequent production request.
- Standard preservation period: 60 days, extendable once by 30 days where necessary to issue a production request.
- Extended preservation: If a production request is subsequently issued, preservation continues until the data has been produced.
Key distinction from an EPOC: A preservation order freezes data but does not itself require disclosure to the requesting authority.
c) Data categories and operational preparation
The e-Evidence Regulation distinguishes four categories of electronic evidence. The requirements for issuing an EPOC may vary depending on the category.
|
Category |
Examples |
|---|---|
|
Subscriber data |
Name, date of birth, address, and billing/payment data |
|
Identifying-user data |
IP addresses and source ports, or equivalents used solely to identify the user |
|
Traffic data |
Metadata |
|
Content data |
Stored content such as text, voice messages, images, and videos |
Sanctions
Non-compliance with the e-Evidence Regulation’s production, preservation, and confidentiality obligations must be subject to effective, proportionate, and dissuasive pecuniary penalties. Member States are required to provide for penalties of up to 2% of the service provider’s total worldwide annual turnover for the preceding financial year.
The e-Evidence Directive also requires Member States to establish sanctions for breaches of the designation, appointment, and notification obligations.
What companies should do now
Given the imminent application date, we recommend that companies take the following steps without delay:
- Assess scope: Determine whether your organisation qualifies as a service provider offering services in the EU under the e-Evidence Regulation. Consider both the geographic nexus (substantial connection to the EU) and the substantive nexus (type of services offered).
- Appoint an EU addressee: Designate a designated establishment or appoint a legal representative and register the addressee through the Commission portal.
- Set up internal procedures: Create a process for receiving, formally reviewing, and responding promptly to EPOCs and EPOC-PRs, including escalation paths and 24/7 availability for emergency cases.
- Ensure data protection compliance: Document legal-basis assessments, and establish secure transfer channels, access restrictions, and audit trails for disclosures.
Client Alert 2026-162