IT Law · 2026-08-11 · 15 min read
E-Evidence From 18 August 2026: Eight Hours to Hand Over User Data, and Why Most Mid-Market Companies Are Not Covered

Michael Kaiser
Co-Founder & Head of Systems, Vincency
In one week, on 18 August 2026, the E-Evidence Regulation (EU) 2023/1543 starts to apply. A prosecutor in any member state will then be able to order a service provider directly, without going through German authorities first, to hand over user data. The deadline is ten days, and eight hours in an emergency. The honest headline for most readers of this article is not the eight hours. It is that they are almost certainly not in scope, and that the reason sits in one word of the definition.
Start with the scope, not with the deadline
Coverage of this regulation tends to lead with the eight hours, which is the most alarming number in it and the least useful place to begin. The first question is binary and answerable in an afternoon: are you a service provider within the meaning of Article 3(3). If the answer is no, the rest of the regulation does not apply to you, and no amount of process design changes that.
Three categories are covered. Providers of electronic communications services, meaning telephony, messaging and email. Providers of internet domain name and IP numbering services, meaning registrars and comparable infrastructure. And other information society services that either enable their users to communicate with one another, or that store or otherwise process data for their users where the storage of data is a defining component of the service.
That third category is where every real question lives, and the word doing the work is defining. Not incidental, not present, not technically involved. Defining. Almost every company stores data for its customers somewhere. The regulation is asking a narrower question: is the storage the thing the customer is paying for.
The test, applied to real mid-market setups
| Setup | In scope? | Why |
|---|---|---|
| Company website, shop, configurator | No | No user-to-user communication, storage is not what is being sold |
| Customer portal with manuals, drawings, invoices | Normally no | Storage is incidental to the underlying product or service |
| SaaS product whose purpose is storing customer content | Yes | Storage is the defining component |
| Marketplace or portal with messaging between users | Yes | Enables users to communicate with each other |
| Hosting or managed operation for third-party clients | Usually yes | Hosting service, depending on how the contract is structured |
| Third-party SaaS you use internally | No | You are the user; the duty sits with the provider |
The row worth pausing on is the fifth. Agencies, system houses and IT service providers that host or operate systems for their clients are typically providing a service of their own, and can be addressees in their own right. That is a contract question that should be settled before an order arrives rather than after. It also means the answer for a manufacturer may be no while the answer for the partner running its platform is yes, which is exactly the kind of split that gets discovered at the wrong moment.
What can actually be demanded
If you are in scope, the next thing worth knowing is that not all data is equally exposed. The Regulation grades what may be ordered, and the grading is the main safeguard in the whole instrument.
| Category | Examples | Threshold |
|---|---|---|
| Subscriber data | Name, address, account, contract details | Available for less serious offences too |
| Traffic data | Who contacted whom, when, from where | Offence punishable by a maximum of at least three years, or defined cyber offences |
| Content data | Messages, documents, stored files | Same higher threshold |
In practice this means the routine case is a subscriber data request: who is behind this account. Those are comparatively simple to answer and are what most providers will see. Orders for traffic and content data require a genuinely serious underlying offence, and they are the ones where a provider should read the order carefully rather than reflexively comply.
Two kinds of order, and the second one collides with your deletion routines
The Regulation is named after both instruments it creates, and coverage usually only discusses one of them. Alongside the European Production Order, which requires you to hand data over, there is the European Preservation Order, which requires you to freeze it. It does not give the authority the data. It stops the data from disappearing while the authority prepares the request that will.
The addressee must preserve the specified data without delay so that it cannot be deleted or altered, for a maximum of 60 days, unless the issuing authority confirms that a subsequent request for production has been made, in which case preservation continues.
This is the obligation most likely to fail quietly in a well-run company, and the reason is counterintuitive: the better your data hygiene, the harder it is to comply. Logs that rotate after 30 days, a deletion routine that runs on schedule under your retention policy, an account purge that fires automatically after a cancellation, all of these are good practice under the GDPR and all of them will happily destroy data you have been ordered to keep. Freezing that machinery for one account, without switching it off for everyone else, is an engineering task. Nobody solves it in eight hours if they have not thought about it in advance.
The practical question to put to your own team is narrow and answerable: if we had to stop deletion for exactly one user account tomorrow, who does it, how, and does it survive the next deployment.
You may check the order, and you may not talk about it
Compliance is not unconditional. An order does not have to be executed where, for instance, the issuing authority is not competent, the prescribed form was not used or is incomplete, production is objectively impossible, for example because the data does not exist or was already deleted lawfully, or where conflicting obligations under other applicable law stand in the way. If you cannot comply, the correct move is to say so with reasons and inside the deadline, not to stay silent. Silence looks the same as refusal from the outside.
In the other direction there is a duty that catches companies out. Article 11 requires the confidentiality of the ongoing investigation to be preserved, including the fact that an order has been issued at all. The instinct of a customer-focused business is to be transparent with the affected user, and here that instinct is wrong. Whether and when the user may be informed is decided by the authority, not by you. This belongs in the written procedure, because it is exactly the kind of thing an account manager does spontaneously and in good faith.
The eight hours are an availability problem, not a legal one
Article 10(3) sets the regular deadline at ten days from receipt. Article 10(4) reduces it to eight hours in emergencies. Ten days is workable for any organised company. Eight hours is not a legal question at all, and treating it as one is the mistake worth avoiding.
Eight hours cover nights, weekends and the fortnight in August when half the company is away. Meeting them requires three concrete things, none of which a lawyer can supply. An address that someone actually monitors rather than one that forwards into a shared mailbox nobody owns. A named person with a named deputy, reachable outside office hours. And a technical export path that produces the data without a developer writing a query from scratch. That third item is the one we see fail most often: the legal analysis is done, the responsibility is assigned, and then it turns out the only way to get the data out of the system is a manual database dump that one person knows how to run.
If you are in scope, build the export before you need it, and test it once. That is an afternoon of work and it converts the eight hours from a risk into a procedure.
The designated addressee
The Regulation travels with Directive (EU) 2023/1544, which requires every service provider offering services in the Union to designate an establishment or a legal representative in the EU to receive and act on orders. The transposition deadline for member states expired on 18 February 2026. Germany created its framework with the Electronic Evidence Implementation Act, promulgated in March 2026, with individual provisions taking effect on 18 August; the Federal Office of Justice is the national point of reference.
For a company established in Germany, this is mostly administrative. The establishment exists; what is missing is the formal designation and a service address that works. For a provider outside the EU that offers services into the Union, it is a genuine obligation with a genuine cost, and it is the point at which some providers will discover they need an EU presence they had not planned for.
Three deadlines in four months, and which of them is yours
E-Evidence does not arrive alone, and the sequence matters more than any single date. Read as a block, the picture is less alarming than each individual headline suggests, because the three obligations hit three different kinds of company.
| Date | What | Who it is actually for |
|---|---|---|
| 2 Aug 2026 | AI Act transparency duties, Article 50 | Anyone running a chatbot, voice agent or generated imagery |
| 18 Aug 2026 | E-Evidence production and preservation orders | Communication, hosting and storage services only |
| 11 Sep 2026 | Cyber Resilience Act reporting duties | Manufacturers of products with digital elements |
| 2 Dec 2026 | Machine-readable marking of AI output | Providers of generating systems, and their customers by extension |
A machine builder is in scope for the Cyber Resilience Act and out of scope for E-Evidence. A SaaS company is the reverse. Almost everyone is in scope for the AI Act transparency duties, because almost everyone now runs an assistant somewhere. Reading the three as one wave of regulation produces paralysis; reading them as three separate questions produces, in most cases, one item of actual work.
What to do this week
- Answer the scope question in writing. Do we offer a service where storage is the defining component, or where users communicate with each other. One paragraph, dated, filed. For most companies this closes the topic permanently.
- If yes, designate the addressee. An establishment or representative in the EU, with a service address that a named person monitors.
- Assign a person and a deputy. Reachable outside office hours, because the emergency deadline does not respect the calendar.
- Build and test the export. Subscriber data for one account, produced without improvisation. Do it once, in daylight.
- Write down who checks the order. Which category of data, which issuing state, which threshold. Compliance is not the same as compliance without reading.
- Settle it with your service providers. If a partner hosts or operates your platform, agree in writing who receives an order and who produces the data.
Conclusion
E-Evidence is a significant shift in how cross-border investigations reach data, and it is a smaller event for the mid-market than the headline number suggests. The eight hours are real, but they only bind companies whose product is communication or storage. For everyone else the correct output of this article is a dated paragraph saying we checked and we are not in scope, which is worth having when someone asks in six months. For the companies that are in scope, the work is not legal. It is an address someone reads, a person who answers, and an export that runs on a Saturday. If you want that assessment made against your actual systems rather than a checklist, that is what a first conversation is for.
Frequently asked questions about the E-Evidence Regulation
When does the E-Evidence Regulation start to apply?
On 18 August 2026. Regulation (EU) 2023/1543 entered into force on 18 August 2023, but its application was deferred by three years. It applies directly in every member state and needs no national statute to take effect. Germany built the surrounding framework with its Electronic Evidence Implementation Act, promulgated in March 2026, whose individual provisions likewise take effect on 18 August.
Is my company a service provider under the Regulation?
Only if you offer one of three categories. First, electronic communications services: telephony, messaging, email. Second, internet domain name and IP numbering services, meaning registrars and comparable providers. Third, other information society services that enable their users to communicate with each other, or that store or otherwise process data for their users where the storage of data is a defining component of the service. The word defining carries the entire distinction. A manufacturing or advisory business normally does not meet it.
Does my customer portal or web shop fall under it?
As a rule, no. A portal where customers download manuals, drawings or invoices does store data, but storage is not what the customer is buying. It is incidental to the actual service. It is different where the storage is the product itself: a document archive, a cloud drive, a collaboration platform, a tool with user accounts in which users deposit their own content. It is also different where users can communicate with each other through your system, for example through a messaging feature or a chat between marketplace participants.
What data must I hand over, and under what conditions?
The Regulation distinguishes three categories. Subscriber data, meaning master data such as name, address and account, may be requested even for less serious offences. Traffic data and content data face a higher threshold: they require suspicion of an offence punishable in the issuing state by a custodial sentence of a maximum of at least three years, or certain computer and internet offences grounded in Union law. That gradation is the most important practical safeguard in the Regulation.
What is a European Preservation Order and what do I have to do?
The Regulation creates two instruments. A production order requires you to hand data over; a preservation order only requires you to preserve the specified data without delay so that it cannot be deleted or altered. Preservation runs for a maximum of 60 days, unless the issuing authority confirms that a subsequent request for production has been made, in which case it continues. In practice this is the more demanding duty, because it collides with your own deletion routines: log rotation, scheduled deletion runs under your retention policy and automatic account purges will destroy exactly the data you have been ordered to keep. Halting deletion for one account without switching it off for everyone else is an engineering task, not a legal one.
May I tell the affected user?
Not as a matter of course. Article 11 requires the confidentiality of the ongoing investigation to be preserved, including the fact that an order has been issued at all. Whether and when the user may be informed is decided by the authority. For a customer-focused business this is counterintuitive, because the natural instinct is transparency towards the customer. That is precisely why it belongs in a written procedure: it is the kind of disclosure a support team otherwise makes spontaneously and in good faith.
Do I have to comply with every order?
No, compliance is not unconditional. An order does not have to be executed where, among other things, the issuing authority is not competent, the prescribed form was not used or is incomplete, production is objectively impossible, for example because the data does not exist or was already deleted lawfully, or where conflicting obligations under other applicable law stand in the way. What matters is how you respond: if you cannot comply, say so with reasons and inside the deadline. Silence is the wrong move, because from the outside it looks identical to refusal.
What does the eight-hour deadline mean in practice?
The regular deadline under Article 10(3) is ten days from receipt of the order. In emergencies Article 10(4) shortens it to eight hours. Eight hours include nights, weekends and shutdown periods, which makes the deadline a question of reachability rather than law. Anyone in scope needs an address that is actually monitored, a named person with a deputy, and a technical route to export the data inside that window. The last point is the one most often underestimated: an export that only engineering can assemble by hand is not available on a Saturday evening.
Do I need to designate a representative in the EU?
If you are a service provider under the Regulation, yes. The accompanying Directive (EU) 2023/1544 requires every service provider offering services in the Union to designate an establishment or a legal representative in the EU to receive orders. The transposition deadline for member states expired on 18 February 2026. For a company established in Germany this is usually a formality, because the establishment already exists; the actual work is designating it and registering a service address that functions.
What are the penalties for non-compliance?
Article 15 allows member states to impose financial penalties of up to 2 percent of total worldwide annual turnover of the preceding financial year. In Germany a breach of the cooperation duties is framed as a regulatory offence. Realistically the penalty is not the first risk: a provider that fails to respond because nobody reads the inbox first has proceedings on its hands, and then has to explain why a legally mandated service address went unattended.
Sources, status and note: Primary sources: Regulation (EU) 2023/1543 on European Production and Preservation Orders for electronic evidence, in particular Article 3(3) (definition of service provider), Articles 5 and 6 (conditions and data categories), Article 10(3) and (4) (ten days, eight hours in emergencies) and Article 15 (penalties, up to 2 percent of total worldwide annual turnover); and Directive (EU) 2023/1544 on designated establishments and legal representatives, transposition deadline 18 February 2026. Germany: the Electronic Evidence Implementation Act, promulgated March 2026, with individual provisions applying from 18 August 2026; national reference point Federal Office of Justice. The scope assessments in the table are our reading applied to typical mid-market setups and do not replace an individual legal review; the storage criterion in Article 3(3) requires a case-by-case assessment. This article reflects the position as of 11 August 2026 and is a general overview, not legal advice; for binding information, consult a law firm specialising in IT and criminal procedure law. Transparency: Michael Kaiser is a co-founder of Vincency and the founder of ArkeonTech, and Vincency builds and operates systems for the companies this article describes, which can itself be relevant to the fifth row of the scope table.
Related insights