What changed
Regulation (EU) 2023/1543 on European Production Orders for Electronic Evidence became fully applicable on 18 August 2026. The Regulation replaces the Mutual Legal Assistance Treaty process, which was the primary mechanism for cross-border law enforcement access to digital evidence and typically took 12 to 18 months per request. Under the new framework, judges and prosecutors in any EU Member State can now issue a European Production Order (EPO) or European Preservation Order (EPPO) directly to any provider of electronic communications, hosting, messaging, domain-name, or IP-address services that has users in the EU - regardless of where the company is established. EPOs require the provider to disclose specified data (subscriber data, access data, transaction data, or content data) within 10 days as a standard deadline, or within 8 hours in emergency cases. Service providers operating in the EU on or before 18 February 2026 were required to designate a contact point in an EU Member State by 18 August 2026. The designated contact point is responsible for receiving, assessing, and executing or challenging production and preservation orders. Content data orders are subject to a higher threshold: they require judicial certification in the issuing state confirming the order is necessary and proportionate. The Regulation interacts directly with the GDPR: service providers may challenge or refuse execution of an EPO where compliance would conflict with applicable EU or Member State law, including the GDPR.
The companion Directive (EU) 2023/1544, requiring Member States to designate national executing authorities and create an enforcement framework for EPOs and EPPOs, applied from 18 February 2026. Non-compliance with a valid EPO can result in financial penalties under national implementing law. The Regulation was designed to address the use of cloud and cross-border digital infrastructure in criminal investigations, but its scope is broad: any company offering email, messaging, cloud storage, web hosting, domain-name registration, VoIP, or IP-address services to users in the EU falls within scope if it receives an EPO or EPPO. The BfDI (Federal Commissioner for Data Protection and Freedom of Information, Germany) maintains a dedicated topic page on the e-Evidence Regulation, noting its interaction with data protection obligations. The ePrivacy Directive 2002/58/EC is one of the instruments the Regulation explicitly derogates from in the law enforcement access context, placing the e-Evidence framework within the broader EU privacy and digital law landscape.
What it means for your business
If your company offers electronic communications, hosting, messaging, email, VoIP, domain-name registration, or IP-address services to users in the EU: The e-Evidence Regulation now applies. If your company was operating before 18 February 2026, your EU-designated contact point should already be in place as of 18 August 2026. If you have not yet designated a contact point, do so immediately and notify the competent national authority. Establish internal procedures for receiving, logging, and responding to EPOs and EPPOs, including the standard 10-day and emergency 8-hour execution deadlines. For content data orders: Build a legal review step into your response workflow - content data EPOs require judicial certification from the issuing state, and you may challenge orders that conflict with GDPR obligations or are otherwise unlawful. For data minimisation and retention: Review your GDPR data minimisation and retention policies in light of the obligation to disclose data on receipt of a valid EPO: data you do not hold cannot be disclosed. Assess your GDPR obligations with Verdaio\'s GDPR Quick Check.