What Does the E-Evidence Regulation Cover – And Who Does It Apply To?
From 18 August 2026, Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings – the e-Evidence Regulation, or EEVO for short – will become directly applicable in all Member States, including Germany, following a three-year transitional period. This date is no longer a distant prospect: in Germany, the implementing legislation, the Electronic Evidence Implementation and Enforcement Act (Elektronische-Beweismittel-Umsetzungs- und Durchführungsgesetz, EBewMG), was promulgated in March 2026; the Federal Office of Justice (Bundesamt für Justiz) has been designated as the central authority, while the Federal Network Agency (Bundesnetzagentur) is responsible for technical regulation.
Before turning to the EEVO itself, a look at the position under the law as it currently stands helps put matters into context. With the EEVO, the legislator responds to a state of affairs that has proven increasingly “very difficult” over the years. Cross-border access to electronic evidence has so far been governed by the classic mutual legal assistance procedure: a foreign authority had to submit a request to the competent German authority, which would then examine it and, where appropriate, issue its own order – only at that point was a service provider under any obligation to produce data. Depending on the case, this route could take weeks or months, while the request itself remained without consequence for the service provider in the meantime. A foreign request received directly by a service provider did not, on its own, give rise to any obligation to review or respond – it could, and generally had to, remain unanswered as long as no German order had been issued.
In this two-part publication, we now present the EEVO, which addresses precisely this point. The first part covers its basic structure – the new instruments EPOC and EPOC-PR, the range of service providers concerned, and the scope of application. The second part will then set out the applicable deadlines, the review obligations that apply, and the sanctions that may follow non-compliance.
In addition to these two articles, we have created a cheat-sheet that provides a quick overview of the key deadlines and review steps.
>> Read cheat-sheet <<
Two New Instruments: EPOC and EPOC-PR
At the heart of the EEVO are two new types of order that allow law enforcement authorities in one Member State to address service providers in another Member State directly in future – without the previously customary detour via mutual legal assistance proceedings. The European Production Order (EPOC) requires a service provider to produce specified electronic evidence, such as content, traffic, or subscriber data. The European Preservation Order (EPOC-PR) operates a step earlier: it merely requires the service provider to preserve data for a specified period so that it is not deleted before a production order, where applicable, follows.
For affected companies, this means one thing above all: both types of order take immediate effect. Unlike before, no separate involvement of a German authority is required – an order issued by another Member State becomes binding as soon as it reaches the designated point of contact within the company. What was previously described as a passive role thus becomes an active obligation to act. Whereas a service provider was previously permitted to leave a foreign request unanswered without consequence, it is now directly obligated in its own right from the moment an EPOC or EPOC-PR is received.
Who Is Subject to the EEVO?
The EEVO addresses service providers with a connection to the EU under Article 2(1) EEVO, irrespective of whether they are established in the EU at all. This marks an important difference from many other pieces of European legislation: a cloud provider without any European establishment can be just as affected as a German company. Under Article 3(3) EEVO, this covers in particular providers of electronic communications services (such as messaging or VoIP services), domain name registries and registrars, as well as other information society services – a category under which the Regulation expressly includes platform operators such as social networks and file-hosting services, as well as hosting providers and cloud services.
The addressee of an order is, as a general rule, the controller within the meaning of Article 4(7) GDPR, i.e. whoever determines the purposes and means of the processing. Only exceptionally may an EPOC be addressed directly to a processor: where the controller cannot be identified by the issuing authority despite reasonable efforts, or where the investigation would otherwise be jeopardized (Article 5(6) EEVO).
When Is There a “Connection to the EU”?
The Regulation first requires that the services be accessible to persons in a Member State – identifiable, for example, by language, currency, or targeted marketing. That alone, however, is not sufficient. In addition, there must be a substantial connection to one or more Member States, such as an establishment carrying out genuine economic activity, a significant number of users, or activity that is clearly directed at the relevant Member State. Mere technical accessibility of a website is expressly not sufficient for this purpose under Recital 29 EEVO – a service that happens to also be accessible from Germany does not thereby automatically fall within the scope of the Regulation.
Who Receives the Orders?
Once the question of whether a provider is covered has been resolved, the practical question remains of where an order is actually to be sent. Under Article 3(1) of Directive (EU) 2023/1544, every service provider must designate an establishment or a legal representative for the receipt of EPOCs and EPOC-PRs – by 18 August 2026 at the latest, or within six months of commencing service provision in the EU. Orders are, as a general rule, addressed exclusively to this designated point of contact (Article 7(1) EEVO). If it fails to respond in time in an emergency, or if no point of contact has yet been designated, the authority may exceptionally address another establishment of the company (Article 7(2) EEVO).
In practice, it is therefore advisable for the function internally responsible for EPOC/EPOC-PR matters – such as Legal or Compliance – to correspond to the externally designated point of contact and to be genuinely reachable. Otherwise, there is a risk that an emergency order with a particularly short deadline ends up with a group entity that is unprepared and consequently unable to respond in time.
This sets out the legal framework. What this looks like in practice – which specific deadlines apply, when an order may be refused, and what consequences follow non-compliance – is the subject of the second and final part of this series.
Would you like to assess whether, and to what extent, your company is subject to the EEVO, or do you need support in designating a point of contact for receiving orders? We would be glad to assist you with the legal assessment and with preparing for 18 August 2026.

