E-Evidence Regulation: A Guide to the New EU Production and Preservation Order Regime

On 18 August 2026, the EU e-Evidence Regulation (the “Regulation”) became applicable across Member States (except Denmark).  European investigative authorities now have new mechanisms to require e-commerce platforms and other providers of online services to produce or preserve data at short notice.

An Overview

The Regulation introduces two new mechanisms:

  1. the European Production Order (“EPO”) – requires a service provider to produce electronic evidence within 10 days, or in emergency cases within 8 hours, and
  2. the European Preservation Order (“EPO-PR”) – requires a service provider to preserve electronic evidence for up to 60 days (with the possibility of a 30-day extension).

An issuing authority such as a court, in criminal proceedings, may issue an EPO or EPO-PR, and thereby order a service provider offering services in the Union and established in another Member State, or if not established, represented by a legal representative in another Member State, to produce or preserve electronic evidence regardless of the location of the data.  EPOs or EPO-PRs are transmitted by central authorities through a European Protection Order Certificate (“EPOC”) or European Preservation Order Certificate (“EPOC-PR”) (as the case may be) directly to the service provider concerned.  In Ireland the central authority has been designated by the Criminal Justice (International Cooperation on Electronic Evidence and Other Matters) Act 2026 (the “2026 Act”) as the Director of Criminal Justice International Cooperation (the “Director”).

In this way the Regulation seeks to facilitate quicker cross-border access to electronic evidence, providing a faster alternative to existing mutual legal assistance and European Investigation Order procedures.

Who is in scope?

The Regulation applies to specified service providers “offering services in the Union”, regardless of where they are headquartered.  While financial services providers are notably excluded, those within scope include providers of electronic communications services, internet domain name and IP numbering services, and providers of a wide range of information society services, including social networks, online marketplaces, cloud-computing services and other hosting services that enable user communications or store or process data on behalf of users.

The service provider must offer services in the Union, which requires a substantial connection to one or more Member States.  This can mean that the service provider has an establishment in a Member State or in the absence of such an establishment, where the service provider has a significant EU user base, or targets EU markets.

What data is captured?

The Regulation covers four broad categories:

  1. subscriber data (identity, billing, registration details)
  2. data used to identify a user (IP addresses and timestamps for identification purposes only)
  3. traffic data (metadata such as message routing, device location, session logs)
  4. content data (text, voice, video, images)

Given the sensitive nature of traffic data and content data, the issuing or validation of an EPOC or EPOC-PR to obtain or preserve those data categories requires review by a judge.  Further while EPOCs for subscriber data and data requested for the sole purpose of identifying the user may generally be issued for all criminal offences, stricter requirements apply to traffic and content data.  An EPOC for such data may generally only be issued for offences punishable in the issuing State by a maximum custodial sentence of at least three years or fall within specified categories of serious offences, including cybercrime, terrorism, child sexual exploitation and non-cash payment fraud.

What are the penalties for non-compliance?

The Regulation, and the 2026 Act provide for fines up to two per cent of the total worldwide annual turnover of the in-scope service provider’s preceding financial year.  In Ireland, the Director is designated as the enforcing authority for the purposes of enforcement of the Regulation.

Irish addressee registration

Under the accompanying Directive and the 2026 Act, in-scope service providers must maintain a designated establishment or legal representative in the EU to receive and respond to EPOCs and EPOC-PRs.  Existing service providers that are established in and offer services in the EU must designate at least one establishment as their designated establishment.  Service providers that are not established in an EU Member State, but nevertheless offer services within the EU, must appoint a legal representative within a Member State in which the service provider offers its services.

Safeguards and limits

Where an EPOC is issued to obtain traffic data or content data, the issuing authority is required to notify the relevant enforcing authority.  In Ireland, as mentioned above, the enforcing authority is the Director.

Where an EPOC or EPOC-PR is incomplete, contains manifest errors or lacks sufficient information for its execution, the service provider may seek clarification.  Further where production is de facto impossible, the service provider is required to explain the reasons for such a de facto impossibility. Further a service provider can resist an EPOC where it considers that the execution of an EPOC could interfere with immunities or privileges, or with rules on the determination or limitation of criminal liability that relate to freedom of the press or freedom of expression in other media.  Where the issuing authority has notified the enforcing authority, the enforcing authority may raise one of the following grounds for refusal: privilege or press protection, a manifest breach of fundamental rights, ne bis in idem (prohibition against double prosecution) or dual criminality.

Conclusion

While the Regulation promises to facilitate quicker access to electronic evidence, practically it imposes new responsibilities on service providers and introduces a complex compliance framework to an already complicated area.  Meanwhile, in Ireland and many other EU Member States laws that govern the retention of and access by law enforcement authorities to data held by electronic communication services providers for national security, public security and criminal justice purposes continue to be reviewed, updated and scrutinised against the backdrop of evolving domestic and European case law. 

In Ireland, the Communications (Retention of Data) (Amendment) Act 2022, which was enacted with the intention that it would operate as a temporary fix to ongoing issues regarding the compatibility of Irish laws with European law requirements, has still not been replaced with a longer term solution.

This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.

Key Contacts