An EU Data Order Can Now Cross Borders Directly. The Provider May Have Eight Hours.
The EU e-Evidence Regulation now allows a judicial authority in one member state to send a production order directly to a service provider or its legal representative in another. The normal deadline is ten days. In an emergency, the provider may have eight hours.
That turns a cross-border legal process into an operational readiness problem.
The new regime is designed to replace procedures that can take months with a standard route for obtaining stored subscriber, traffic and content data. For providers, the important change is not simply that requests may arrive faster. It is that legal validation, data preservation, evidence handling, privacy review and secure delivery may all need to happen inside a deadline closer to incident response than ordinary litigation.
A court can now address the provider directly
Regulation (EU) 2023/1543 became applicable on 18 August 2026. It creates two instruments for criminal proceedings: the European Production Order and the European Preservation Order.
A Production Order requires a provider to produce specified electronic evidence. A Preservation Order requires it to prevent specified data from being deleted while a later production request is prepared. Both are issued or validated by a competent judicial authority and sent to the provider’s designated establishment or legal representative in another participating member state.
The direct route is the central change. Under older cross-border mechanisms, an authority commonly asked its counterpart in the provider’s country to obtain the data. The Commission says a European Investigation Order can take up to 120 days and mutual legal assistance averages about ten months. The new Production Order is normally due within ten days.
An emergency order is due without undue delay and no later than eight hours. The Regulation defines an emergency narrowly around an imminent threat to a person’s life, physical integrity or safety, or a threat to critical infrastructure that creates those consequences. Eight hours is not the default for every investigation, but providers cannot wait until an emergency arrives to decide who owns the process.
The data can be more sensitive than an account record
The Regulation covers electronic evidence stored by or on behalf of a service provider when the order is received. Its definitions include subscriber data, traffic data and content data.
That can mean basic identity and subscription information. It can also mean communications, location-related records, service-use metadata and stored content. The operational risk therefore depends on the service. A hosting provider, communications platform, domain service, marketplace or cloud application may hold very different evidence, but each must be able to identify and preserve the data actually covered by an order.
This is not permission for indiscriminate collection. Orders must meet the Regulation’s issuing and validation requirements, and additional safeguards apply to more sensitive categories of data. The enforcing authority can raise specified grounds for refusal, including certain fundamental-rights, immunity and privilege concerns. Providers can also report conflicts, impossibility and other problems through the prescribed process.
The important distinction is that safeguards still have deadlines. A provider cannot treat legal review, technical scoping and evidence production as separate queues that begin one after another.
The legal representative is an operational endpoint
The accompanying Directive requires providers offering services in the Union to designate an establishment or appoint a legal representative for receiving, complying with and enforcing orders. That obligation also reaches providers headquartered outside the EU when they offer covered services in the Union.
A name and postal address are not enough. The designated endpoint needs a verified intake channel, around-the-clock escalation for emergencies and an internal path to the people who can preserve and retrieve data. It must also distinguish a genuine order from fraud, route it without unnecessary disclosure and maintain an auditable record of the decisions taken.
Both the representative and the provider can be held responsible for non-compliance. Member states must provide effective sanctions, and the Regulation permits financial penalties of up to 2% of total worldwide annual turnover for persistent or systematic failure.
The deadline therefore belongs to the whole operating model, not just the legal team.
Eight hours exposes weak ownership
Many organisations can answer a data request when a product engineer, privacy lawyer and security investigator happen to be available at the same time. That is not the same as having a reliable process.
An emergency order can expose familiar gaps:
- the legal representative receives the request but cannot reach an on-call product owner;
- the data map does not show which system holds the requested field;
- retention automation deletes material before a preservation action reaches the platform;
- a query retrieves more customers, tenants or time periods than the order permits;
- the export loses timestamps, identifiers or integrity information needed to explain how it was produced;
- the provider has no secure, tested method for transferring a sensitive evidence package;
- nobody can establish whether the customer may be notified or whether confidentiality requirements apply.
These are not abstract legal defects. They are data-governance, engineering and incident-response failures that become visible under a statutory clock.
What providers should test now
- Confirm scope and ownership. Identify which services and legal entities fall within the regime, who acts as the designated establishment or representative, and which executive owns compliance.
- Build a verified intake route. Authenticate orders and issuing authorities, protect the channel from impersonation and preserve the original request and all subsequent communications.
- Create an emergency rota. Legal, privacy, security and the relevant technical teams need a 24-hour escalation path that can make and document decisions inside eight hours.
- Map evidence to systems. Maintain a current record of where subscriber, traffic and content data reside, including backups, regional stores, processors and archived platforms.
- Separate preservation from disclosure. Be able to stop deletion quickly without automatically releasing data before the order has been validated and scoped.
- Minimise the production. Retrieve only the accounts, fields and period specified. Test queries against tenant and regional boundaries before relying on them in a live case.
- Protect integrity and transfer. Record who collected the material, when and how; use approved encryption and delivery channels; and retain the evidence needed to reproduce the process.
- Exercise refusal and conflict paths. Teams should know how to raise privilege, fundamental-rights, impossibility and conflicting-law concerns without simply missing the deadline.
- Measure the clock. Run an eight-hour exercise using a realistic service and evidence request. The result should show where time was spent, not merely whether somebody eventually produced a file.
Cross-border evidence is now part of service resilience
The e-Evidence Regulation is a criminal-procedure instrument, but its practical demands resemble high-severity incident handling. The provider must verify authority, preserve volatile material, coordinate specialists, control access, keep an audit trail and deliver a defensible result under pressure.
Organisations that leave the process inside a legal mailbox will discover too late that the evidence lives in product systems, retention jobs, backups and third-party services. Those systems do not organise themselves around jurisdictional deadlines.
An EU data order can now cross a border directly. The providers that respond safely will be the ones that have already turned the legal rule into an engineered, rehearsed operational capability.
Sources and further reading
- European Commission: e-Evidence and cross-border access to electronic evidence
- EUR-Lex: Regulation (EU) 2023/1543
- EUR-Lex: Directive (EU) 2023/1544
- Eurojust: EU e-Evidence package
- Council of the EU: adoption of the e-Evidence laws
Continue the series: European National Cyber & Digital Law Series index


