Summary
- Regulation (EU) 2023/1543 becomes applicable on 18 August, creating direct cross-border production and preservation orders.
- Communications, hosting, marketplace, domain, and other service providers can fall within the regime even when headquartered outside the EU.
- Ordinary production requests generally carry a 10-day deadline, falling to eight hours in emergencies, with penalties for non-compliance.
Technology companies offering communications, hosting, marketplace, domain, and other online services in the European Union are entering a new compliance regime in which judicial authorities can demand electronic evidence across borders directly rather than relying primarily on slower cooperation between national governments.
Regulation (EU) 2023/1543 becomes applicable on 18 August, introducing European Production Orders and European Preservation Orders for electronic evidence used in criminal proceedings. The European Commission says the framework is designed to make access to data faster when evidence is held by a service provider or its legal representative in another member state.
The scope extends beyond traditional telecommunications businesses. Covered services can include internet access, interpersonal communications, domain-name and IP-numbering providers, social networks, online marketplaces, hosting businesses, and other services storing or processing data for users.
Under a European Production Order, requested data generally has to be transmitted within 10 days, while emergencies can reduce the deadline to eight hours. Preservation Orders require specified information to be retained without delay, giving authorities time to seek its subsequent production before routine deletion or retention schedules remove it.
Cross-border requests move closer to operations
The framework changes the practical relationship between law enforcement and the companies holding digital records. Traditional mutual legal-assistance procedures can require authorities to route requests through governments and legal systems before reaching a provider, whereas the EU framework allows an issuing authority in one participating state to address an order more directly to a designated establishment or legal representative.
Speed sits at the centre of the regulation because useful electronic evidence can disappear quickly. Account details change, logs are overwritten, and users can delete content long before a conventional international request reaches the company holding it, making preservation a technical as well as a legal requirement.
For providers, faster access moves more operational responsibility into internal legal, security, privacy, and trust-and-safety processes. An eight-hour deadline cannot be handled as an occasional request reaching a general legal inbox; organisations need reliable processes for authenticating orders, identifying affected data, checking whether objections apply, protecting confidentiality, and responding within the statutory period.
The rules also require providers offering services in the EU to maintain a designated establishment or legal representative for receiving and complying with orders, including businesses headquartered elsewhere. International cloud and online-service companies can therefore fall within the regime even where their corporate centre and much of their infrastructure sit outside Europe.
Compliance depends on architecture as well as lawyers
Electronic evidence can include subscriber information, identifying data, traffic records, and content such as messages. The operational task consequently crosses several internal systems because customer identity, account records, content, logs, billing information, and infrastructure metadata are rarely stored in one place or controlled by one team.
Providers must also protect the confidentiality, secrecy, and integrity of orders and the information produced or preserved. Responding efficiently requires a workable inventory of where different categories of data sit, who can retrieve them lawfully, which retention rules apply, and how each action is recorded for audit or challenge.
The framework contains safeguards rather than giving every investigating authority unrestricted access to every category of data. Certain requests require judicial involvement and notification to the competent authority in the state where the provider’s designated establishment or representative sits, while the regulation sets out grounds on which enforcement can be challenged or refused.
Individuals affected by Production Orders also retain information and remedy rights, placing further pressure on providers to distinguish a technically possible disclosure from a legally valid one. That becomes especially complicated where a service spans several jurisdictions or customer information is distributed across multiple infrastructure regions.
Member states must provide financial penalties that can reach 2% of a service provider’s total worldwide annual turnover for non-compliance, giving the regime considerably more weight than a voluntary cooperation framework. Electronic evidence therefore joins privacy, cybersecurity, and platform regulation as an operational compliance issue rather than remaining a specialist part of criminal procedure.
As the rules begin to apply, the immediate test for service providers will be whether legal authority, data architecture, security controls, and round-the-clock response processes can function together when a cross-border request arrives. The deadline may be written into legislation, but meeting it depends on systems and organisational design long before the first urgent order reaches the business.












