EU E-evidence · Regulation (EU) 2023/1543
The EU E-evidence Regulation (EU) 2023/1543 has applied since August 18, 2026. It lets a law enforcement authority in one EU member state order a service provider in another country to hand over electronic data, or preserve it, on deadlines as short as eight hours. It applies to any provider offering services to users in the EU, wherever the provider is based. This page covers what the regulation requires, who it covers, and where member-state readiness stands.
Until now, a foreign authority that wanted data from you usually went through mutual legal assistance: government to government, slow, often months.
EU E-evidence replaces that route inside the EU. From August 18, 2026, an authority in any member state can send a binding order directly to your company. The order arrives through a government system, and the deadline to act on it is measured in days or hours.
Two things about this are new for your team:
You are likely in scope if both of these are true:
That covers communication services, cloud and SaaS platforms, online marketplaces, crypto exchanges, fintechs, telecoms, and most consumer platforms.
Where you are headquartered does not matter. A US company with EU users is in scope. A provider with no establishment in the EU must appoint a legal representative there to receive orders on its behalf.
The regulation creates two binding instruments:
European Production Order
EPOCHand over the data.
European Preservation Order
EPOC-PRPreserve the data while a production request follows.
The penalty for non-compliance is set by each member state, up to 2% of your total annual worldwide turnover.
An order you never see still counts against you. That detail matters more than any other on this page, and the next section explains why.
The regulation uses a home-base model:
One registration, one portal. You will not operate 27 systems.
That is the design. The ground looks different: the Commission's readiness list of August 27 shows four member states ready in any capacity, and where a state's system is not operational, Article 19(5) of the Regulation moves transmission to the most appropriate alternative means. Where the portal does exist, it sits outside the tools your team uses today. Someone has to watch it, because a binding order can arrive at any hour, and the clock starts when the order arrives, not when you notice it. An unwatched channel plus an eight-hour emergency deadline is how a company fails this regulation without ever deciding to.
Five things, in order:
Kodex is the network where law enforcement data requests get handled. More than 40,000 law enforcement agents across Europe work through it today.
Kodex is the network for law enforcement data requests, and for EU E-evidence it operates a receiving endpoint registered to your designated establishment. Orders are addressed to you, certificates are issued in your name, and every decision on every order stays with you. Where a member state's system is not operational, Article 19(5) of the Regulation moves transmission to the most appropriate alternative means, and the Commission's contingency guidance lists secure platforms run for law enforcement data requests among them. In practice, that means:
Orders reach you inside the process you already run
EU E-evidence orders land in the same Kodex queue as the requests your team handles now. There is no separate portal to watch.
Every deadline is tracked
Kodex tracks the clock on every order, flags emergencies, and escalates over email, Slack, and PagerDuty as a window closes.
The whole lifecycle is covered
Production orders, preservation orders, deadline updates, grounds for refusal, withdrawals, extensions, and correspondence, all on one record.
It works where the government system does not
API integration where a state's system is live, and an Article 19(5) path where it is not. Evidence over 25MB cannot move through the government system at all; that path is permanent.
Can we just use the government portal?
Yes. It is a working option. The cost is operational: it is one more system to log into and monitor, outside your existing workflow, and the deadlines run whether or not anyone is watching it. Companies with steady request volume usually decide the portal is the riskier path.
Can we build our own intake instead?
Yes, and the regulation allows it. You would be building intake, routing, and deadline tracking from scratch while orders are already flowing. Kodex already runs across Europe, so the practical question is whether building buys you anything that adopting does not.
Our member state's portal isn't ready. Does that delay anything?
No. Your obligations started on August 18 regardless. Where a state's system is not available, Article 19(5) of the Regulation requires transmission by the most appropriate alternative means, and the Commission's contingency guidance lists secure provider platforms among them. The issuing authority selects the channel. What you control is having an endpoint to nominate when asked, as Germany's BKA has already asked providers to do.
How do we know if we're in scope?
If you offer services to EU users and hold electronic data about them, assume you are in scope and confirm the details. The guide below includes a scoping walkthrough.
What happens if we miss a deadline?
You have failed to execute a binding order. Member states set the penalties, up to 2% of total annual worldwide turnover.
Everything on this page, in depth: the full legal requirements, the home-base model, the deadlines in operational terms, and a readiness checklist. Written for the legal, compliance, and trust & safety teams that will own this.
New to this area? Start with the complete guide to law enforcement data request management.
We use cookies to keep the site running, understand how it's used, and measure our marketing. You choose what to allow — read more in our Privacy Policy.