The EU e-Evidence Package: An Overview for Service Providers
Regulation (EU) 2023/1543 and Directive (EU) 2023/1544 – what applies, whom it reaches, and how to prepare before 18 August 2026.
The EU e-Evidence package changes how criminal-justice authorities reach across borders for digital data, and it lands squarely on the desks of service providers this summer. This overview sets out what the framework requires and what you should prepare before it applies.
What is the EU e-Evidence package?
The package establishes the first EU-wide framework for cross-border access to electronic evidence in criminal proceedings, and it rests on two linked instruments. Regulation (EU) 2023/1543 sets the substantive rules on production and preservation orders, while Directive (EU) 2023/1544 governs the designation of establishments and legal representatives.
Together, they let an authority in one Member State request data directly from a provider established in another. The Regulation applies directly from 18 August 2026, whereas the Directive had to be transposed by 18 February 2026, however, there have been delays in transposition of the Directive. Together the Directive and the Regulation are the EU e-Evidence package and it binds every Member State except Denmark while reaching providers far beyond the European Union’s borders.
Who counts as a service provider?
The Regulation defines “service provider” broadly and captures three categories:
- electronic communications services,
- internet domain-name and IP-numbering services, and
- other information-society services that let users communicate or that store and process their data.
This third, catch-all category pulls in cloud providers, hosting companies, and social networks, because storage need only be a defining component of the service rather than its main purpose, so even a single chat feature can bring a provider into scope.
Territorial reach is equally wide. The rules apply wherever a service is genuinely usable in a Member State and the provider shows a substantial connection to the EU — an establishment, a significant number of users, or activities targeted at the Union. No turnover or size threshold applies, so a start-up outside the EU can fall within scope just as readily as a global platform. Only if your business is limited to one member state without any cross-border implications, you may be off the hook.
What are EPOC and EPOC-PR?
The Regulation introduces two orders. A European Production Order (EPOC) compels a provider to hand over specified data, and it must be met within 10 calendar days, or within 8 hours in emergencies. A European Preservation Order (EPOC-PR) instead compels a provider to freeze data so that it cannot be deleted or altered, for 60 days and extendable by a further 30 or until the data is produced, if the provider is put on notice that the EPOC has been issued.
Both orders target data already held when the order arrives, so neither creates a general retention duty. Authorities issue them on standard certificates and transmit them through a dedicated decentralised IT system built on e-CODEX, which is the the flagship project of EU e-Justice providing an interoperable solution for cross-border exchange of judiciary data, allowing all Member States to communicate with each other through their existing national systems.
How does an EPOC travel from order to response?
The workflow below shows a simplified workflow for an EPOC from issue to delivery, and where the parallel notification to the enforcing authority fits in.
EPOC Workflow Overview
| Step | Process Step & Description |
|---|---|
| 1 |
Order Issued
Issuing authority draws up the EPOC on the standard certificate.
|
| 2 |
Transmission
Order travels via the decentralised IT system (e-CODEX).
|
| 3 |
Receipt
Designated establishment or legal representative receives the order.
|
| 4 |
Log & Verify
Check the certificate, signature, issuing authority, and data requested.
|
| ⇉ |
In parallel – for traffic or content data, the enforcing authority is notified and may object within 10 days (suspensive effect) or 96 hours in an emergency case.
|
| 5 |
Produce Data
Within 10 days, or 8 hours in an emergency case.
|
What data is covered, and whom must you designate?
The Regulation sorts electronic evidence into subscriber data, traffic data, and content data, and it ties each to a threshold. Authorities may request subscriber data, and data sought solely to identify a user, for any offence, whereas traffic and content data require an offence punishable by at least three years or a listed offence such as cybercrime, terrorism, or child sexual abuse. An order may only seek data that authorities could obtain in a comparable domestic case, so the Regulation speeds up access without widening what may be sought.
Every in-scope provider must also offer a clear point of contact. A provider established in the EU names a designated establishment in a Member State where it operates, whereas a provider with no EU establishment appoints a legal representative in the Union. Either way, you file the Service Provider Notification Form, and that designated establishment or legal representative then serves as the single point of contact for receiving, and where appropriate contesting, EPOCs and EPOC-PRs.
How do you respond, and what safeguards apply?
A disciplined intake process keeps you within the tight deadlines, and it protects you where an order is flawed.
Your intake should include at least the following:
- Log and verify each order, confirming the correct certificate, a valid signature, the issuing authority, and the data requested.
- Meet an EPOC within 10 days, or 8 hours in an emergency, and preserve EPOC-PR data immediately for 60 days, which can be extended for another 30 days.
- Request clarification where an order is incomplete or obviously erroneous, since the deadline restarts once a corrected order arrives.
- Notify the issuing authority without undue delay if you cannot comply in full or on time.
Review sits at the heart of the framework. For traffic or content data not used solely to identify a person, the enforcing authority in your Member State (where you have designated an establishment or appointed a legal representative) is notified in parallel, and this notification carries suspensive effect. That authority may raise limited grounds for refusal – immunities, fundamental-rights conflicts, or threats to freedom of expression – and service providers may flag the same concerns, so you should also check for conflicts with other obligations, particularly rules imposed by non-EU jurisdictions.
What should service providers do now?
Preparation cannot wait until August. You should run a scope check, name your designated establishment or legal representative, and map the subscriber, traffic, and content data you hold. Then design a documented response workflow, connect to and test the decentralised IT system, and train your staff, because an 8-hour emergency drill will reveal gaps long before a real order does.
What are the key takeaways?
The EU e-Evidence package reshapes cross-border access to digital data, and it applies from 18 August 2026 across every Member State but Denmark. It reaches any provider that offers in-scope services in the Union, and it obliges each to appoint a designated establishment or legal representative and to answer EPOCs and EPOC-PRs within demanding deadlines. The Regulation neither widens the data authorities may seek nor imposes new retention duties, yet it accelerates and streamlines the process dramatically. Providers that map their data, build a robust workflow, and rehearse now will meet these obligations with confidence rather than scramble.
Prepare with confidence
Rickert.law advises service providers on e-Evidence readiness, from scope assessments and designations of legal representatives or designated establishments through workflow design and staff training. We invite you to prepare your organisation before the Regulation becomes applicable.
Secure a consultation with Rickert.lawFrequently Asked Questions on the E-Evidence Package
Regulation (EU) 2023/1543 becomes directly applicable from 18 August 2026. Providers should be ready to receive and answer orders from the application date.
The framework binds every Member State except Denmark. Providers offering services across the Union should assume it applies wherever they reach EU users.
An EPOC compels production of specified data within 10 days, or 8 hours in emergencies. An EPOC-PR instead freezes data for 60 days, extendable by 30, so that evidence survives until a production order follows.
Providers established outside the Union fall within scope where their service is usable in a Member State and shows a substantial connection, such as targeting or a significant user base. For example, a US-based provider can therefore receive an order despite having no EU office.
Production orders carry a 10-day deadline, which shrinks to 8 hours in emergency cases, while preservation orders require immediate action on receipt.
The package imposes no general data-retention obligation, and both orders reach only data already held when the order arrives.
A provider established in the EU names a designated establishment, whereas a provider without one appoints a legal representative in the Union. Each is filed through the Service Provider Notification Form and serves as the single point of contact for EPOCs and EPOC-PRs. Also appointment of several designated establishments, for example, for particular types of data or services, is possible.
Providers may seek clarification of an incomplete or erroneous order, and they may flag limited grounds such as immunities or fundamental-rights conflicts. The enforcing authority reviews traffic and content data in parallel and may itself raise grounds for refusal.
This article provides a general overview of the EU
e-Evidence package and does not constitute legal advice. For guidance on your
specific circumstances, please contact Rickert.law.