E-Evidence
EU e-Evidence Regulation: Compliance, Legal Response & 24/7 Representation
The EU e-Evidence framework obliges hosting providers, SaaS and cloud providers, messaging services, telecommunications companies, as well as registries, registrars, and privacy/proxy services to produce electronic evidence to European law enforcement authorities. All service providers that enable their users to communicate or store data are affected, regardless of whether they are established inside or outside the European Union.
From the statutory deadline on 18 August 2026, strict rules will apply to law enforcement access to data. Failure to meet deadlines or non-compliance risks severe fines. Rickert.law secures your e-Evidence compliance from a legal perspective: We analyze your applicability, organize or appoint the legally required legal representative, assist with regulatory registration, and represent you in reviewing official orders.
The e-Evidence Legal Framework: Core Requirements for Service Providers
The EU e-Evidence framework – consisting of Regulations (EU) 2023/1543 and (EU) 2023/1544 as well as national implementing legislation (such as the German EBewMG) – governs cross-border cooperation between law enforcement authorities and IT service providers.
Key Challenges at a Glance
Extremely Short Response Deadlines
For standard European Production Orders (EPOC), a strict deadline of 10 calendar days applies. In emergency cases (Emergency Disclosure Requests / EDR), this window shrinks to just 8 hours.
Preservation Orders (EPOC-PR)
Authorities can order the immediate “freezing” of subscriber, traffic, or content data. Service providers are obligated to preserve the data immediately for 60 days (extendable by a further 30 days upon request) to prevent deletion.
No General Data Retention Obligation
The Regulation does not impose a general data retention obligation on companies. Orders always target data that is already lawfully held at the time the order is received.
Existential Penalty Risks
Tension Between e-Evidence and GDPR
Overhasty data transfers to foreign authorities out of fear of tight deadlines risk severe data protection violations. An upfront legal assessment resolves this conflict of laws.
Legal Services for the EU e-Evidence Regulation
Interdisciplinary Expertise for Complex Questions
We offer your company modular legal support – from the initial strategic assessment to establishing legally sound anchors and providing legal representation in active proceedings.
1. Scope Assessment (Applicability Review)
Whether a business model falls under the definition of a “service provider” requires case-by-case legal evaluation. Within a concise legal assessment, we determine whether your specific services are in scope, which data categories (subscriber, traffic, or content data) are targeted, and whether exceptions or territorial rules apply to your organization.
2. Regulatory Registration & Notification Processes
In-scope service providers must be registered with the competent European authorities using the official Notification Form for Service Providers. We assist with and execute the formal registration of your contact details and points of contact – on request also for a transparent fixed fee.
3. Designated Establishment (for EU-Based Providers)
For internationally operating corporate groups with multiple locations in the EU, there is an obligation to designate a single European establishment as the primary point of contact. We provide strategic counsel on selecting the leading designated establishment and structuring the optimal allocation of responsibilities within your corporate group.
4. e-Evidence Legal Representative for Non-EU Providers
Providers without an establishment in the EU that offer services in the European market are legally required to designate a formal Legal Representative in an EU Member State.
Your Solution Through Rickert.law
Through our law firm's subsidiary, IT.LAW GmbH, we assume the role of your official e-Evidence Legal Representative. This ensures full regulatory reachability by law enforcement authorities without requiring you to set up your own infrastructure in Europe.
5. Internal Business Processes & Emergency Escalation
e-Evidence requires seamless workflows at the intersection of IT, customer support, and legal. We assist you in designing internal operational processes:
- Role and permissions management for accessing subscriber, traffic, and content data.
- Organization of escalation chains for 8-hour emergency requests.
- Clear allocation of responsibilities for data disclosure approvals.
6. Legal Representation in Active Proceedings
Beyond preventive compliance advisory, we actively represent you vis-à-vis authorities:
Legal review of orders to ensure data is disclosed only when a valid legal obligation exists.
- Negotiation and communication with issuing and enforcing domestic and foreign authorities, as well as drafting reasoned objections (e.g., regarding fundamental rights violations or immunities).
- Legally sound defense against invalid orders and filing of legal remedies.
- Support during regulatory audit requests and defense against potential fine proceedings.
Operational 24/7 Response & Emergency Desk (Optional via EviGate)
Managing extremely tight response windows – particularly the 8-hour emergency deadline – requires a seamless combination of IT infrastructure and on-call legal emergency support. We adapt flexibly to your technical setup: We can integrate our legal review directly into your existing IT infrastructure, or you can utilize our turnkey platform EviGate.
The 24/7 Emergency Desk
Regardless of whether you use your own systems or deploy EviGate, you can outsource the operational and legal handling of incoming production and preservation orders to us:
- Deadline monitoring & emergency operations: Orders are immediately logged, and emergency protocols are triggered.
- 24/7 ad-hoc legal review: Our attorneys work directly with your technical emergency team, reviewing orders on an ad-hoc basis for formal and substantive validity and raising immediate objections with authorities whenever concerns arise.
- Legally compliant data disclosure: Data is released in your name and on your behalf only after a successful legal review.
If your organization lacks a direct connection to the official e-CODEX decentralised system or an adequate deadline tracking tool, EviGate is available as an optional turnkey solution: EviGate GmbH is a specialized joint venture between Rickert Rechtsanwaltsgesellschaft mbH and IT specialist nGENn GmbH (further information at evigate.eu and ngenn.de). nGENn GmbH provides the technical emergency platform and authority interfaces, while Rickert.law delivers legal evaluation and representation.
Our Tailored e-Evidence Consulting
Whether you want to proactively secure your company, require a Legal Representative in the EU, or are looking for an outsourced 24/7 intake point – whether integrated into your existing IT infrastructure or platform-backed via EviGate – we offer the exact cooperation model tailored to your technical and organizational requirements.
Contact us for an initial legal assessment of your situation. Together, we will discuss the mandatory regulatory steps for your organization and how to seamlessly implement your legal and technical integration.
GDPR.Ninja
GDPR steht für: General Data Protection Regulation und bezeichnet die Datenschutz-Grundverordnung, welche seit dem 25.05.2018 unmittelbare Geltung in allen EU-Mitgliedsstaaten entfaltet. Wir möchten für Sie kurz die wesentlichen Aspekte der neuen Regelungen hervorheben und Ihnen unseren Beratungsansatz vorstellen.