EU e-Evidence Regulation and Directive: What it means for e-commerce platforms
Regulation (EU) 2023/1543 (the "Regulation") and Directive (EU) 2023/1544 (the "Directive"), together the "e-Evidence Package" became fully applicable across the EU (except Denmark) on 18 August 2026.
Key takeaways
1. European investigating authorities now have new mechanisms to require e-commerce platforms and other providers of online services to produce or preserve data at short notice.
2. The manner in which and the extent to which these powers are used will vary across Europe, but penalties for non-compliance are potentially significant (up to two per cent of global turnover).
3. These powers apply to entities which have a presence in the EU, a significant EU user base or which target EU markets. It is not necessary to be incorporated or to have servers in the EU. Non-EU parent companies are in scope.
4. In scope entities should already have designated a point of contact to receive and coordinate responses to production and preservation orders.
5. Early preparation for production and preservation orders is key. Negotiation of the scope of orders may not always be possible, but pre-issue engagement with authorities will smooth the production and preservation processes.
The e-Evidence Package: An overview
The Regulation creates two new tools:
1. the European Production Order ("EPO") - which compels a service provider to produce data within 10 days, or within eight hours in an emergency; and
2. the European Preservation Order ("EPO-PR") – which requires data to be preserved for up to 60 days (extendable to 90 days) pending a formal production request.
These mechanisms are designed to provide a faster alternative to existing mutual legal assistance ("MLA") and European Investigation Order ("EIO") procedures. An "issuing authority" in one Member State which, may include a judge, investigating judge or magistrate, prosecutor or criminal investigation authority depending on the jurisdiction, can issue orders directly to a "service provider" located anywhere in the EU without having to use those MLA or EIO channels.
The Directive requires in-scope "service providers" to identify a "designated establishment" (if EU-established) or appoint a "legal representative" (if not) in a participating Member State to receive and action orders. "Service providers" already active in the EU on 18 February 2026 had to complete that designation by 18 August 2026.
The regime is intended to facilitate faster access to "electronic evidence", which includes subscriber, traffic and content data in criminal investigations, prosecutions and the execution of certain custodial sentences. It supplements, rather than replaces existing MLA and EIO channels, and does not introduce any new data retention obligation.
Which entities?
"Service providers offering services in the Union" includes providers of electronic communications services, internet domain name and IP numbering services, and a wide range of information society services, including social networks, online marketplaces, cloud-computing providers and other hosting services that enable user communications or store or process data on behalf of users.
"Offering services in the Union" requires only a substantial connection to one or more Member States. This can mean having an EU establishment, a significant EU user base, or targeting EU markets). EU incorporation or local servers are not prerequisites. Non-EU parent platforms are equally in scope.
The definition of "service provider" expressly excludes financial services. In practice, this will mean that a platform's own e-commerce or marketplace operations are in scope, but a regulated payments, e-money or lending subsidiary providing only financial services will fall outside the Regulation and Directive themselves (although parent and subsidiary entities alike will remain subject to national criminal procedures (for example production orders) and sector specific requirements to provide information or produce documents (for example under financial services, competition or data privacy legislation).
Which data?
The e-Evidence Package enables authorities to obtain four broad categories of electronic evidence:
1. subscriber data;
2. data used to identify a user (including certain IP-related data);
3. traffic data; and
4. content data.
Traffic data and content data are subject to enhanced safeguards and greater judicial oversight due to their potential impact on privacy and the confidentiality of communications.
Practical points
1. Will "service providers" be notified in advance of authorities' intention to obtain orders?
The Regulation is designed to enable authorities to serve orders directly on "designated establishments" or "legal representatives" without prior consultation. However, neither the Regulation nor the Directive contain any prohibition on authorities engaging with those entities where they are considering obtaining EPOs or EPO-PRs.
In-scope "service providers" should develop constructive relationships with relevant authorities. Where such relationships already exist, consider approaching those authorities to seek to put in place agreed protocols (which, where possible, should include commitments from authorities to share draft orders in advance of applying to a court (where necessary) or executing the order.
Advance notice will not always be provided, particularly where authorities perceive a risk of prejudice to an investigation, and the potential for negotiation may be limited (especially in advance of receipt of orders). However, early operational engagement may increase opportunities for informal pre-service discussions to identify relevant material and narrow scope, facilitate smoother execution of orders and reduce the risk of compliance difficulties once an order has been issued.
2. What are the penalties for non-compliance?
The Regulation provides for fines of up to two per cent of the worldwide annual turnover of the in scope "service providers". However, enforcement is left to individual Member States, which are responsible for implementing the relevant procedures and sanctions national law. Consequently, the level of financial exposure and the manner in which penalties are imposed may vary between Member States.
The Directive separately requires Member States to legislate to enable penalties to be imposed for breach of the designation and notification obligations. Unlike the Regulation, the Directive does not prescribe a uniform maximum penalty for breaches of its requirements. Instead, it has been left to Member States to set penalty scales for these breaches. Member States were required to transpose the Directive by 18 February 2026. However, implementation has been uneven and not all Member States appear to have adopted or notified implementing legislation. As a result, the penalties applicable to breaches of designation or notification obligations will depend on the implementing legislation in the relevant Member State, and in some jurisdictions may remain uncertain pending completion of transposition.
3. What can authorities do with the data received under orders?
The Regulation does not impose any EU-wide limitation or collateral-use restriction specific to the EPO regime itself, beyond the general requirement that personal data be processed lawfully, necessarily and proportionately under the GDPR and the Law Enforcement Directive (Directive (EU) 2016/680, which governs the processing of personal data for law enforcement and criminal justice purposes in Member States).
Evidence obtained is subject to normal admissibility and fair-trial safeguards in any criminal proceedings which may take place in receiving Member States. "Service providers" responding to EPOs should not assume any inherent restriction on downstream use once data has been lawfully produced.
4. When may orders be obtained on an emergency basis (requiring production or preservation of data within eight hours)?
The emergency procedure is intended to enable law enforcement and judicial authorities to secure access to electronic evidence where they consider that delay could significantly prejudice an investigation or the protection of individuals.
5. What happens if data required under orders is held outside the EU?
The location of data storage is not relevant to whether an EPO or an EPO-PR can be issued. The Regulation applies regardless of where the relevant data is stored, including cloud infrastructure outside the EU, provided the addressee is the provider's EU-based "designated establishment" or "legal representative".
Where compliance would breach a genuine third-country legal obligation, the addressee can lodge a reasoned objection within 10 days, triggering review by the issuing authority and, if it wishes to maintain the order, by a competent court in the issuing State.
6. How do the requirements interact and overlap with document production requirements under other UK and EU legislation?
The Regulation and the Directive are EU instruments. They do not apply in the UK, which is a third country for these purposes and relies on MLA or other bilateral arrangements to request EU-held e-evidence, and vice versa. UK authorities therefore continue to rely on their own domestic powers. "Service providers" operating both an EU-facing e-commerce business and a UK entity (or a regulated subsidiary) should expect to face parallel, differently timed and differently scoped requests under each regime, with no formal read-across or mutual recognition between them.
7. What are the practical considerations for "service providers" required to produce data relating to individuals? Do these individuals have a right to make representations? Will they be notified by the authority? Is the subject of the order allowed to tell them that production of data relating to them has been required?
There is no pre-execution right for an implicated individual (whether the account holder or a third party referenced in the data) to be notified of an EPO or an EPO-PR or to make representations to the issuing authority before an order takes effect. Post-execution notification duties under the Regulation require details to be provided to "the person whose data are being requested" not necessarily every individual referenced within the data (for example, counterparties to a conversation), and can be delayed, restricted or omitted in some cases.
The Regulation does not impose a duty on "service providers" receiving EPOs or EPO-PRs to notify affected individuals, nor does it prohibit the platform from doing so, but confidentiality obligations require the addressee to take "state-of-the-art technical and operational measures to protect the confidentiality, secrecy and integrity of the [order] and the data". Issuing authorities frequently request, and national law may separately require, that the fact of the order not be disclosed for as long as necessary to avoid prejudicing the investigation. "Service providers" responding to EPOs and EPO-PRs should treat any such confidentiality requests as binding, check whether their own privacy notices or law enforcement-request policies need updating to reflect the EPO regime, and take specific legal advice before proactively notifying an affected user.
8. How should recipients of orders identify relevant documents? Can AI tools be used for this and/or to negotiate appropriate and proportionate search terms with authorities?
The Regulation is silent on methodology. This will be a matter for the addressee's internal process, subject to meeting the applicable deadline (10 days, or eight hours in an emergency) and producing data accurately corresponding to the order's specified user/account identifier, data category and time range.
In practice, "service providers" should build a repeatable workflow. This should include stages to:
1. Confirm the order is validly issued/validated and addressed to the correct "designated establishment " or " legal representative ";
2. map the requested identifier(s) to internal account/user records;
3. scope the data to be precisely to the stated category (subscriber/traffic/content) and time range, and carry out a legal review for privilege, immunity or press-freedom flags before transmission.
AI or search/eDiscovery tooling can legitimately be used internally to locate, filter and de-duplicate responsive data at speed, particularly given the short deadlines, provided the platform retains a clear audit trail and human sign-off on what is ultimately produced. However, the Regulation does not create a right to negotiate the scope of an order with the issuing authority outside the formal clarification and reasoned-objection channels, and authorities' attitudes to and acceptance of the use of AI to comply with orders will vary.