Mastodon Skip to content
live markets
S&P 5007,707.98▲ 3.36%NASDAQ26,331.09▲ 3.18%DOW53,463.05▲ 2.52%GOLD4,578.20▲ 14.16%WTI84.33▲ 1.32%BRENT91.54▲ 2.60%EUR/USD1.1682▲ 2.07%USD/JPY158.15▼ 2.60%DXY98.79▼ 2.18%BTC$69,117▲ 5.70%ETH$2,200▲ 9.90%SOL$83.90▲ 6.70%TOTAL CRYPTO$2.42T▲ 5.75%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- bluesky ↗ Join the wire

EU e-Evidence Law Takes Effect, Enabling Cross-Border Digital Searches

A landmark EU regulation allowing police in one member state to order data directly from tech providers in another took effect on August 18, reshaping cross-border investigations.

Partner Surfshark VPN

The European Union’s e-Evidence Regulation became directly applicable on August 18, 2026, enabling law enforcement authorities in one member state to issue European production orders and preservation orders directly to service providers in another, without going through intermediaries in the target country.

The regulation represents the most significant overhaul of cross-border digital evidence gathering in EU history. Under the old system, a police force in, say, France seeking email data from a provider in Ireland would have to go through a mutual legal assistance process that could take up to 120 days. The new rules compress that timeline to 10 days, or just 8 hours in emergency situations such as terrorist threats.

What the Regulation Covers

Authorities can now request subscriber data, identification records, traffic data, and content data such as messages and photos. The location where data is stored is generally irrelevant under the new framework. Service providers that fail to comply face penalties of up to 2% of their annual worldwide turnover, or up to 5% for repeated non-compliance.

The regulation applies across all EU member states except Denmark, which secured an opt-out during negotiations. Member states were required to transpose the accompanying Directive into national law by February 18, 2026, though several countries including Ireland reported delays in completing the process.

Industry Impact

Tech companies and cloud providers face significant operational challenges. They must build systems capable of processing orders within the strict timelines, establish secure communication channels through a decentralised IT system defined by ETSI technical specifications, and handle potentially conflicting legal demands from multiple jurisdictions simultaneously.

The regulation also has implications for connected car manufacturers, whose vehicles generate vast amounts of telematics data that could fall under production orders. Automotive companies will need to evaluate their data-handling contracts with cloud and technology providers.

Privacy Concerns

Critics have raised alarms about the potential for data misuse. Baker McKenzie has warned that the regulation creates obvious potential for misuse of data and that fundamental rights are not effectively protected. Digital rights organisations have argued that the lack of mandatory judicial pre-authorization for certain categories of orders could lead to overreach.

The regulation was first proposed by the European Commission in 2018 and adopted by the Council and Parliament on July 28, 2023. It was designed to address a gap that the Council of the EU estimated was affecting 85% of all criminal investigations in Europe, where digital data plays a critical role but cross-border access remains slow and cumbersome.

With the regulation now live, enforcement agencies and service providers across the bloc are entering uncharted territory as they navigate the practical realities of a system that fundamentally alters how digital evidence crosses European borders.

Sources: European Commission; Taylor Wessing; Deloitte Ireland; Bird and Bird; LexisNexis

React to this dispatch
Share this dispatch X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Belgium Wildfire Encircled After Largest Blaze in a Century Read →