view all news & events
08/10/2026

The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now – Part 2

Part 2: EEVO – Obligations, Deadlines, and Sanctions in Practice

The first part of this publication set out the basic structure of the EEVO: the two new instruments, EPOC and EPOC-PR, the range of service providers concerned, and the conditions under which a connection to the EU within the meaning of the Regulation exists. This second part now turns to the practical implementation that becomes directly relevant to service providers in an actual case: the applicable deadlines for production and preservation, the scope of the review required before execution, and the sanctions and liability consequences of non-compliance.

 

Deadlines: Production and Preservation Compared

The most striking feature is the deadlines, which are considerably shorter than those familiar from classic mutual legal assistance proceedings. For the European Production Order, the standard deadline is ten days from receipt, shortened to eight hours in emergencies (Article 10(2) and (4) EEVO). The logic underlying the European Preservation Order is different: the focus here is not on rapid production, but on freezing the status quo. The obligation to preserve the data concerned arises immediately upon receipt; the preservation itself must be maintained for 60 days and may be extended once, by 30 days, by the issuing authority (Article 11(1) EEVO). If a production order subsequently follows, the preservation obligation continues until the data is actually produced (Article 11(2) EEVO) – the two instruments can therefore be combined.

 

What Review Is Required Before Execution?

How extensive a review a service provider must carry out before execution depends largely on the category of data concerned. For an EPOC: subscriber data and traffic data used solely for user identification must be produced without further review (Article 5(3) EEVO). The position is different for anything going beyond this – for further traffic data and for content data, it must be examined whether the underlying offence falls within the catalogue of serious offences set out in Article 5(4) EEVO. For the EPOC-PR, the scope is deliberately drawn more broadly: it may be issued for any offence for which a corresponding order would be possible in a comparable domestic case under the same conditions (Article 6(3) EEVO), and it covers all categories of data.

Irrespective of the data category, the same formal review applies in both cases: is the person concerned identifiable from the information provided, and is the certificate complete and free of errors? Where there is doubt on this point, this must be indicated using the form set out in Annex III; the issuing authority must then provide clarification within five days – if it fails to do so, the obligation to execute or preserve, as applicable, lapses.

 

When May or Must Execution Be Refused?

Not every order received must actually be executed. The addressee does not have a general power to refuse – the EEVO is too heavily geared towards rapid effectiveness for that. In four narrowly defined cases, however, the addressee may, or must, refuse execution and must notify the issuing authority of this without delay: where the order is formally deficient (Article 10(6), Article 11(5) EEVO); where execution is factually impossible, for example because the person concerned is not a customer of the service provider or the data has already been lawfully deleted (Article 10(7), Article 11(6) EEVO); where there are indications of immunities, privileges, or rules on liability under press law (Article 10(5), Article 11(4) EEVO); and where there is a conflict with an obligation under the law of a third country, such as the United States or the United Kingdom (Article 17 EEVO).

The last case is likely to be the most complex in practice: the objection may be raised within ten days of receipt, and enforcement is then suspended until this procedure has concluded – the data must, however, continue to be preserved in the meantime. In the immunity and press-law cases, by contrast, the addressee does not make its own decision to refuse, but merely triggers a review by the competent authorities.

 

Sanctions and Liability: Who Bears Which Risk?

A service provider that fails, without a valid reason, to comply with an order in breach of its obligations risks fines of up to 2% of total worldwide annual turnover for the preceding financial year (Article 16(1) EEVO) – a framework that companies are likely to find familiar from other pieces of European legislation.

In practice, what is likely to matter most is whether, and how actively, a company communicates with the issuing authority: a company that promptly reports any obstacles is likely to be in a better position to rely on a recognized justification within the meaning of the provision, whereas unexplained silence increases the risk of sanctions.

The picture on liability is somewhat more reassuring: service providers are not liable to their users or third parties for damage arising solely from good-faith compliance with an EPOC or EPOC-PR (Article 15(2) EEVO) – responsibility for the lawfulness of the order remains with the issuing authority. Nor does the service provider necessarily have to bear the costs of responding to an order alone: under certain conditions, reimbursement may be claimed, to the extent that the national law of the issuing state provides for this in respect of comparable domestic orders (Article 14 EEVO).

 

What Companies Need to Do Now

All of this results in a scope of action for affected service providers that is manageable, but time critical. A point of contact ready to receive orders must be designated or appointed, internal workflows for receipt, review, preservation, transmission, and documentation must be established, and the relevant personnel should be familiar with the tight deadlines before an actual case arises. To provide a quick overview, we have summarized the key deadlines and review steps for EPOC and EPOC-PR in this one-pager.

This outlines the practical obligations arising from the EEVO. Service providers falling within the scope of the Regulation should have incorporated the deadlines, review obligations, and response duties described above into their internal processes by 18 August 2026 at the latest, in order to be able to respond in a timely and legally compliant manner in the event of an EPOC or EPOC-PR.

Would you like support in setting up or reviewing your internal processes? We would be glad to assist you in developing workflows that work in practice and to support you in preparing for 18 August 2026.

    Share

  • LinkedIn
  • XING