The EU e-Evidence Regulation is a European Union law that lets a judicial authority in one EU member state send an order directly to a service provider, such as an email, messaging, hosting or cloud provider, that offers services in another member state, requiring it to produce or preserve electronic data for a criminal investigation. It offers a faster alternative to country-to-country requests for much of this work. The European Commission states that the Regulation applies from August 2026. This entry is an overview for buyers, not legal advice.
At a glance
- It creates two orders: a European Production Order (hand data over) and a European Preservation Order (keep data so it can be requested later).
- Orders go straight to the provider or its EU legal representative, with short response deadlines, without a government-to-government request.
- It can reach providers headquartered outside the EU if they offer covered services in the EU.
- It is the EU’s counterpart to the US CLOUD Act; an EU-US agreement to connect the two is under negotiation, not concluded.
- For buyers, it is one more factor in which authorities can compel a provider to disclose customer data.
What problem it solves
Criminal investigations increasingly depend on data held by service providers: emails, messages, account details, login records and stored files. That data often sits with a provider in another country, and the traditional route, a mutual legal assistance request between governments, can take months. Investigators also faced different national rules on whether and how providers had to respond.
The Regulation gives EU authorities a common, faster procedure with set deadlines and safeguards, and it gives providers one framework instead of many national ones. For buyers it raises a practical question: under which legal processes can your provider be required to hand over or freeze your data, and what will it do when that happens?
How it works
The two orders. A European Production Order requires a provider to deliver specified data. The Commission describes a deadline of 10 days, or 8 hours in emergencies. A European Preservation Order requires the provider to keep specified data so a later request, such as a production order or a request under other cooperation tools, can obtain it.
Who receives them. A companion directive requires providers offering services in the EU to designate an establishment or appoint a legal representative in the EU to receive and act on these orders. That is how the Regulation reaches providers whose headquarters are outside the EU.
Which providers. It covers providers offering certain services in the EU, including electronic communications services, domain name and IP numbering services, and online services that enable communication or store data as a core feature. Cloud, hosting, email and messaging services can fall in scope depending on what they do.
Safeguards. Orders must come from or be validated by a judicial authority, with stricter rules for more sensitive data. For traffic and content data, the authority in the country where the provider is located is often notified and can refuse on set grounds, such as immunities or a manifest breach of fundamental rights.
Conflicts with other countries’ laws. If complying would conflict with the law of a non-EU country that prohibits disclosure, the provider can object, and a court in the issuing country reviews the conflict and decides whether to uphold the order.
Data categories and who can order them
The Regulation has no tiers in the certification sense; its structure is the type of data requested, which determines who may issue an order and for which offences.
| Data category | Examples | Who may issue a production order | Offence threshold | What a provider typically shows |
|---|---|---|---|---|
| Subscriber data | Name, billing details, account registration | Judge, court or public prosecutor (or another authority with judicial validation) | Any criminal offence | Law-enforcement request policy; transparency report |
| Data requested only to identify a user | IP address and related source port and timestamp | Same as subscriber data | Any criminal offence | Logging and retention practices |
| Traffic data | Source, destination, location, time and duration of communications | Judge or court (or another authority with judicial validation) | Generally serious offences, such as those punishable by at least three years, plus specified cyber and terrorism offences | Notification and objection procedures |
| Content data | Messages, files, voice, images | Same as traffic data | Same as traffic data | Encryption design and customer-key options |
Preservation orders can cover any category. Details depend on the specific order and the member states involved, so confirm with counsel.
When it matters for buyers
- When you choose cloud, SaaS, email or UCaaS providers that serve the EU. Your data may be reachable by EU authorities through the provider, wherever it is stored.
- When you hold data for EU customers or staff. Contracts and privacy notices may need to reflect how cross-border requests are handled.
- When customers ask about government access. Security questionnaires increasingly ask which governments can compel disclosure and how you respond.
- When weighing US and EU exposure together. A US-headquartered provider may face both the US CLOUD Act and EU orders; an EU provider may face EU orders and, depending on its US presence, US process.
Our governance, risk and compliance overview covers how to fold these questions into vendor reviews alongside GDPR.
Questions to ask vendors
- Which of your services are in scope of the e-Evidence Regulation, and where is your EU legal representative?
- How do you review production and preservation orders before complying, and when do you object?
- Will you notify us of orders for our data where the law allows, and do you publish a transparency report?
- Where is our data stored, and who can be compelled to disclose it, under EU, US or other law?
- Do you offer customer-managed encryption keys, and what can you actually disclose if you hold no keys?
- How would an EU-US agreement on electronic evidence change your process?
How it differs from GDPR transfer rules
GDPR governs how personal data is used and when it may leave the EU. Its rule on foreign orders says a judgment or decision from a non-EU court or agency requiring disclosure of personal data is generally recognized only when based on an international agreement, such as a mutual legal assistance treaty. The e-Evidence Regulation is different: it is an EU legal basis for EU authorities to obtain data from providers for criminal cases. One limits foreign reach into EU data; the other creates a faster internal EU route. Both bear on data sovereignty, which asks whose laws can compel access, while data residency only describes where data sits. The EU Data Act adds a similar safeguard for non-personal data held by cloud providers, and the EU-U.S. Data Privacy Framework covers commercial transfers of personal data to the US, a separate question from law-enforcement access. The proposed Cloud and AI Development Act (CADA) would add sovereignty levels for public-sector cloud.
