21.08.2026
Since 18 August 2026, new EU rules govern cross-border access to electronic evidence. For companies, this raises one question in particular: can they themselves become the addressee of such orders, or can their data be disclosed by an external service provider?
Both are possible. The new E-Evidence Regulation (EU) 2023/1543 directly applies to certain providers of digital services. Its practical relevance, however, extends well beyond those providers. Companies using cloud services, messaging services, email services or other digital platforms may also be indirectly affected if corporate data stored with those providers becomes relevant to criminal investigations.
Who can be directly subject to an order?
The Regulation covers, in particular, providers of:
- electronic communications services, such as messaging, email and internet access services;
- internet domain name and IP numbering services; and
- other information society services for which the storage of data is a defining component of the service, such as cloud services, social networks or online marketplaces.
Financial services are excluded. The same applies, in particular, to companies that use online services solely to communicate with their own customers and to services where data storage is merely ancillary.
The Regulation does not provide for any minimum company size or turnover threshold. Smaller or specialised providers may therefore also fall within its scope.
Nor is a provider’s place of establishment the only relevant factor. Providers established outside a Member State may also be covered where they offer services in the EU and have a substantial connection to a Member State.
For service providers within scope, this means that they must be prepared to receive orders directly from judicial authorities in other EU Member States. In many cases, the previously required involvement of the authorities in the Member State where the provider is established is no longer necessary.
What types of orders can companies receive?
The Regulation introduces two key instruments.
A European Production Order, transmitted by means of a European Production Order Certificate (EPOC), can require a service provider to produce electronic evidence that is already stored. As a rule, the provider must comply within ten days. In emergency cases, the deadline is reduced to just eight hours.
A European Preservation Order, transmitted by means of a European Preservation Order Certificate (EPOC-PR), can require a provider to preserve specified data for an initial period of 60 days. This period may be extended by a further 30 days. The purpose is to prevent data from being deleted before a subsequent production request is received.
An important distinction is that both instruments relate only to data that already exists. They cannot be used to require ongoing surveillance of communications or indiscriminate data retention.
The terminology above reflects the English version of Regulation (EU) 2023/1543, which distinguishes between the European Production/Preservation Orders themselves and the EPOC/EPOC-PR certificates used to transmit them.
What data can be requested?
The Regulation distinguishes between four relevant categories:
- subscriber data, such as a name, address or email address;
- data requested for the sole purpose of identifying the user, such as IP addresses and time stamps;
- traffic data, such as information about the sender, recipient or location; and
- content data, including stored text, images, videos or voice recordings.
For companies, this classification matters because the requirements for issuing an order differ depending on the type of data requested. These are the terms used in the English version of the Regulation.
Subscriber data and data requested for the sole purpose of identifying the user can generally be requested in investigations relating to any criminal offence. Stricter requirements apply to traffic data and content data: in particular, the order must generally be issued or validated by a judge or court and, as a rule, may only concern offences for which the maximum custodial sentence in the issuing State is at least three years.
What should service providers prepare organisationally?
For companies that fall within the scope of the Regulation, E-Evidence is therefore not merely a criminal procedure issue. It is also, and above all, a compliance and process issue.
The first step should be to determine whether the services offered fall within the scope of the Regulation. If they do, companies should in particular have clear answers to the following questions:
- Through which channel will E-Evidence orders be received?
- Who is responsible for reviewing them from a legal and technical perspective?
- Who takes over this responsibility during holidays, illness or outside normal business hours?
- How will compliance with the eight-hour deadline in emergency cases be ensured?
- Which internal systems contain the requested data?
- How can that data be preserved, extracted and securely transmitted at short notice?
- How will the company document which data was disclosed and on what legal basis?
- When can an order be challenged or compliance refused?
International corporate groups should also determine which group entity may become the addressee of an order and how orders are escalated internally.
If a service provider is unable to comply with an order for reasons beyond its control – for example because the person concerned is not a customer or because the relevant data had already been deleted before the order was received – it must inform the relevant authority without undue delay.
Where an order is unclear or contains errors that prevent it from being executed, the Regulation provides for a procedure to seek clarification or correction.
Confidentiality is mandatory
Confidentiality deserves particular attention. Service providers must ensure the confidentiality and integrity of both the orders they receive and the data they produce.
In particular, this means that a provider cannot automatically inform its customer that the customer’s data is subject to a production order. As a rule, the person concerned is informed by the issuing authority. That notification may, however, be delayed where disclosure could jeopardise the investigation.
Companies should therefore clearly define who internally may become aware of such an order and how information relating to it must be protected.
What are the consequences of non-compliance?
The short response deadlines are not merely indicative. Breaches of the obligations under the E-Evidence Regulation may result in financial penalties of up to 2% of the service provider’s total worldwide annual turnover.
At the same time, the Regulation provides an important safeguard for service providers: a provider that complies with an order in good faith should, as a general rule, not be held liable for resulting damage.
What does E-Evidence mean for companies that are not service providers themselves?
Companies outside the Regulation’s direct group of addressees should also consider its implications.
The reason is straightforward: corporate data is increasingly stored not only on companies’ own servers, but with cloud, hosting, email, messaging and platform providers. Those providers may now be required directly by a judicial authority in another EU Member State to produce such data.
An Austrian company may therefore be affected even where no investigative measure is being taken against the company itself in Austria.
For customers of cloud and IT services, this raises an important question: what may – or must – the relevant provider do when it receives a request from a public authority for customer data?
Contracts with key cloud and IT providers should therefore be reviewed to determine:
- whether, and under what circumstances, the customer will be informed of requests from public authorities;
- whether the provider will conduct a legal review of an order;
- how the provider deals with orders that are manifestly excessive or defective;
- whether the provider documents which data has been disclosed; and
- what arrangements apply to particularly sensitive or privileged data.
Contractual notification obligations will, however, always remain subject to statutory confidentiality requirements and restrictions on notifying affected persons.
Particular care is required for privileged data
E-Evidence is particularly relevant where data is subject to professional secrecy, confidentiality obligations or other statutory privileges.
The Regulation contains specific safeguards for such data. Companies should nevertheless assess whether particularly sensitive information can be adequately identified within their own IT systems and in systems operated by external providers. This may include communications with lawyers or other legally protected information.
The issue is also becoming increasingly relevant in the context of internal investigations. Investigation files and internal communications are frequently stored in international cloud environments or group-wide collaboration platforms and may therefore, in principle, become subject to a cross-border production order.
What applies specifically in Austria?
The E-Evidence Regulation has applied directly in Austria since 18 August 2026. Austrian public prosecutors and courts can therefore use the instruments provided for by the Regulation, while service providers established in Austria can become the addressees of orders issued in other Member States.
The Regulation is complemented by Directive (EU) 2023/1544. It requires service providers operating on a cross-border basis to designate a designated establishment or appoint a legal representative to act as the addressee for relevant orders. These are the terms used in the English version of the Directive.
The deadline for transposing the Directive expired on 18 February 2026. In Austria, national implementation has not yet been completed. The European Commission has therefore initiated infringement proceedings. Until implementation is complete, questions remain in particular as to the detailed rules governing the designation of addressees and national penalties.
What companies should do now
For service providers, the first step should be to assess whether their services fall within the scope of the Regulation. Where they do, responsibilities, availability, review procedures, technical access capabilities and escalation channels for E-Evidence orders should be defined and tested.
For users of cloud and IT services, the priority should instead be to review existing provider agreements and their own data architecture. Companies should know which sensitive business data is held by which providers – and what happens if one of those providers receives an official production order.
E-Evidence is therefore not relevant only to law enforcement authorities and large platform providers. The Regulation creates new operational requirements for a broad range of digital service providers – while at the same time changing the conditions under which corporate data held by external providers may become accessible to foreign law enforcement authorities.
Our team would be pleased to assist you in assessing whether your company falls within the scope of the E-Evidence Regulation, establishing internal processes for production and preservation orders, and reviewing cloud and IT agreements.

