Regulation (EU) 2023/1543 – the e-Evidence Regulation – will apply across the European Union from 18 August 2026. After a three-year transition period, judicial authorities in one Member State can request electronic evidence directly from service providers in another, in most cases without involving the authorities of the provider’s country of establishment.
Providers’ obligations will take effect on schedule. Many of the national frameworks the Regulation depends on – transposing legislation, designated competent authorities, national procedural rules – are not yet in place. (For an overview of Member State implementation, please see our tracker here.) That gap is the defining feature of the position providers are in today, and it is why the practical answer to “what applies now” turns on where a provider’s “addressee” (see below) sits.
The new instruments
The investigative instruments introduced by the e-Evidence Regulation share one structural feature that shapes everything else: they are not addressed to the service provider, but to a specific recipient the provider must have in place within the EU – a designated establishment, or an appointed legal representative. The Regulation and the Directive call this recipient the addressee. In practice it functions as the provider’s contact point for the two new orders introduced by the e-Evidence Regulation:
The European Production Order, transmitted to the addressee as a European Production Order Certificate (EPOC), requires production of specified electronic evidence within 10 days, and within 8 hours in emergencies. It covers subscriber data, data requested for the sole purpose of identifying a user, traffic data and content data. For traffic and content data, the Regulation applies thresholds relating to the seriousness of the offence and, as a rule, requires notification of the enforcing authority in the addressee’s Member State, which may raise a limited set of grounds for refusal.
The European Preservation Order, transmitted as a European Preservation Order Certificate (EPOC-PR), requires the addressee to preserve specified data for 60 days, extendable once, pending a later request for production – whether by EPOC, European Investigation Order or mutual legal assistance.
The addressee must assess every incoming order to decide how to respond, but its ability to challenge one is deliberately limited: the grounds are confined to those the Regulation provides, and it is not for the addressee to re-examine the underlying investigative decision. Limited grounds, however, do not mean a light burden. Within 10 days – in emergency cases 8 hours – the addressee has to confirm that the certificate is complete and authentic, identify precisely which data are covered, establish whether those categories exist and can be produced, and recognise the cases that trigger separate procedures, whether a conflict with third-country law or a question of immunities, privileges or media freedom. That is a demanding exercise under time pressure, and it can only be performed reliably where the workflow, the escalation paths and the responsible individuals have been defined in advance.
The organisational framework
The Regulation is flanked by Directive (EU) 2023/1544 (“e-Evidence Directive”), which supplies the architecture without which the Regulation cannot function.
Article 3(1) of the Directive creates the obligation mentioned above that every service provider offering services in the Union must designate an establishment or appoint a legal representative in the EU. The addressee must have the powers and resources to receive, comply with and enforce European Production Orders and European Preservation Orders. Providers and their addressees can be held liable jointly for non-compliance with such orders. The Regulation sets the framework for sanctions, including a ceiling of 2% of total worldwide annual turnover for certain infringements, but the penalties themselves are laid down in national implementing law – one more reason the current state of transposition across Member States matters commercially and not merely formally.
Providers have a degree of choice about where to designate, but it is subject to certain limitations. Where the provider has an establishment with legal personality in the Union, the Member State of establishment is responsible; where it has none, responsibility falls to the Member States in whose territory services are offered. The designation of addressees must then be notified to the central authority of the relevant Member State by 18 August 2026, or within six months of beginning to offer services in the EU.
Both concepts driving that analysis – “establishment” and “offering services in a Member State” – are defined in the e-Evidence Regulation and Directive, but the definitions do not resolve every case. Whether a provider has an establishment in a given Member State, and whether a particular service is offered there rather than merely accessible from there, are questions on which the texts leave real room for argument and on which national authorities have not yet developed a settled practice. That is a source of legal uncertainty. It is also, for providers who approach it deliberately, a genuine margin of interpretation: the same corporate footprint can often support more than one defensible designation structure.
One threshold question is easier. Under Article 1(5)(2) of the Directive, the framework does not apply to service providers established in a single Member State that offer their services exclusively in that Member State. Purely domestic providers therefore fall outside it – but the exemption is narrow, and any cross-border offering removes it.
The notification itself is substantive rather than administrative. As we set out in our article on the publication in April of the Commission’s notification tool, providers must list every in-scope service offered in the EU together with the data types, categories and identifiers available for each, specify whether they will connect to the decentralised IT system via the web interface or the messaging API, and complete a separate form for each Member State in which a designation is made.
Transposition remains incomplete
The Directive should have been transposed in all Member States by 18 February 2026. It was not. We analysed the position at the transposition deadline in February, and the Commission opened infringement proceedings against most Member States shortly afterwards.
Six months on, the picture has improved but remains patchy. Eleven Member States have adopted implementing legislation (Croatia, the Czech Republic, Denmark, Estonia, Finland, Germany, Ireland, Italy, Lithuania, Slovakia and Sweden); six have draft legislation available (Belgium, Luxembourg, the Netherlands, Portugal, Romania and Spain); ten show no publicly available developments. Our e-Evidence Implementation Tracker is updated as the position changes.
What applies now: two situations
In late July, the Commission services published a Q&A on legal contingency addressing this fragmentation directly. It is expressly informal and without prejudice to any position the Commission may take later – only the CJEU can interpret EU law authoritatively – but it is the clearest available indication of how the transitional period is expected to be handled. Two situations need to be distinguished.
Where the addressee is located in a Member State that has transposed the e-Evidence Directive. The Regulation applies in full. Authorities in other Member States having finalised transposition can address EPOCs and EPOCs-PR to that addressee, deadlines run from receipt, and the notification, enforcement and conflict-of-laws mechanisms operate as designed. An incomplete IT system does not suspend any of this: where communication through the decentralised IT system is not yet possible, Article 19(5) e-Evidence Regulation provides for transmission by the most appropriate alternative means, and the substantive obligations – including the 10-day and 8-hour deadlines – apply to orders received that way.
Where the addressee would otherwise be located in a Member State that has not tranposed the e-Evidence Directive, if implementation had occurred. Here the position differs. Orders must be addressed to a designated establishment or legal representative, and it is national law transposing the Directive that governs how such an addressee is designated. A provider that has been unable to designate therefore cannot presently be addressed with an EPOC or EPOC-PR; the narrow emergency exception in Article 7(2) e-Evidence Regulation, which permits an order to be sent directly to the provider, does not extend to this scenario. The Commission also considers it risky for authorities in Member States that have not notified their competent authorities under Article 31(1) e-Evidence Directive to issue orders at all, and takes the view that orders should not be sent to addressees in Member States that have not yet nominated enforcing authorities.
On penalties, the Commission encourages central authorities to refrain – at least for an initial period – from sanctioning providers under Article 5 e-Evidence Directive where the provider intends to designate in a Member State that has not yet transposed, while noting that central authorities may ask providers to confirm where they intend to designate.
Two qualifications follow. This is a snapshot rather than a settled position: each transposition that enters into force moves a Member State from the second category into the first, and will do so without notice to providers that have not prepared. And the Q&A is guidance, not law – it binds neither national authorities nor courts. That said, it carries real weight. It comes from the institution responsible for the framework, it is directed at precisely the authorities who would otherwise act, and a provider that follows it and can document a genuine intention to designate stands in a considerably stronger position than one that has simply done nothing.
The technical layer
Communication between authorities and providers runs through the decentralised IT system: national systems are interconnected via e-CODEX access points. Member States may either build their own back-end system or use the reference implementation software developed by the Commission, known as JUDEX. To date, none has built its own. Every Member State is relying on JUDEX, which turns what the legislator framed as a choice into a single de facto backbone for the entire framework.
That convergence cuts both ways. Providers face one technical target rather than various national variants, which materially reduces the integration burden and makes interface behaviour predictable across Member States. It also concentrates the framework’s entire communication layer in a single system, and it means that what now determines whether a given Member State is genuinely reachable is the pace of national roll-out rather than the software itself.
Providers connect either through a web-based interface or through a messaging API – a choice that must already be declared in the notification form. A market of third-party platforms offering managed connectivity and order-handling has also emerged, which can be a sensible route for providers unwilling to build and maintain an API integration themselves. Whichever route is chosen, the sequencing matters: access credentials for JUDEX are issued by the central authority once notification has been made, so the technical connection cannot be completed before the designation is in place.
The architecture, interfaces and workflows are defined in ETSI TS 104 144, a technical specification published by ETSI, key elements of which were made binding by Commission Implementing Regulation (EU) 2025/1550. The Commission’s e-Evidence page links to the current version (1.4.1) and hosts a user manual for the reference software’s provider web interface as well as guidance on contingency arrangements for periods when the system is unavailable.
Providers should plan on the basis that this layer is still moving. Specifications have been revised repeatedly, and integration costs fall on the provider. Designing a process that assumes the decentralised IT system will be available is not, at this stage, safe – which is why the Article 19(5) e-Evidence Regulation fallback and the contingency guidance matter operationally, not only legally.
What providers should be doing now
For anyone who has not yet engaged with the package: the designation and notification deadline is in one week, therefore the work needs to happen quickly.
Scoping. Establish whether the services offered fall within the material scope of the Regulation at all. Our e-Evidence Scoping Tool gives a structured first assessment.
Entity and service mapping. Determine which entities offer which services in which Member States. This drives where designation is legally possible and where it is required, and for pan-European groups, or any provider with several EU entities, it is usually the step that takes longest.
Designation and notification. Settle the designation structure, designate the addressee, and notify the relevant central authority. Because the notification is service-by-service and Member State-by-Member State, it forces decisions on data categories, identifiers and connectivity that are better made deliberately than under time pressure.
Operational readiness. Design the intake, triage and response workflow: how an incoming EPOC is authenticated and logged, who conducts the review, how the 10-day and 8-hour clocks are tracked, how responses are signed and transmitted, and how conflicts with third-country law – in practice, most often US disclosure restrictions – are escalated and resolved under Article 17 e-Evidence Regulation.
How we can help
We have been advising service providers on e-Evidence implementation and compliance projects for over a year, across telecommunications, cloud, platform and technology clients. That work means we know where the difficulties actually arise: in scoping service models that do not map neatly onto the Regulation’s categories; in designation strategy for multi-entity groups; in the level of detail the notification form demands; and in turning the Regulation’s deadlines into a workflow a compliance team can run under pressure.
We can advise on whether your services fall within scope, whether and where an addressee must be designated, how to complete the notification, and how order handling should operate once the first EPOCs arrive. Further material is available on our EU e-Evidence Package trending topic page.

For further information, please contact:
Lewin Rexin LL.M., Partner, Bird & Bird
lewin.rexin@twobirds.com




