Prosecutors and judges in the European Union can request, starting from August 18, 2026, the retention or transmission of electronic evidence directly from service providers located in other member states. The new system is intended for investigations and criminal proceedings in which messages, user data, traffic information, or other digital records are stored in a jurisdiction other than the one in which the crime is being investigated.
In short, a European preservation order can compel a provider to prevent the deletion or modification of data that may be requested later in the investigation. A European disclosure order can compel the provider to transmit data about subscribers, user identification, traffic, or content, under different conditions for each category. Requests can be addressed directly to the designated headquarters or legal representative of the provider in the EU, reducing dependence on traditional cooperation procedures between national authorities. For more sensitive data, stricter conditions are required, and the state in which the provider is located can be informed and may invoke certain grounds for refusal. The affected individuals have the right to be informed and to appeal, and the orders must respect necessity, proportionality, data protection, and procedural rights.
Electronic evidence has become important in almost all types of criminal investigations. Messages, location data, IP addresses, account information, and files stored in the cloud can help identify a person, reconstruct an activity, or demonstrate the connection between participants in a crime.
The problem arises when the authority conducting the investigation is in one member state, while the provider or its legal infrastructure is in another. Traditional judicial assistance procedures may require the request to be transmitted through the authorities of the other state before the data reaches investigators.
The new regulation creates two instruments. The European preservation order aims to temporarily preserve data, while the European disclosure order aims to obtain it.
A preservation order may be necessary when there is a risk that the data will be deleted based on the provider's usual policy or modified before the procedures for obtaining them are completed. The provider must retain the specified data, without the order automatically authorizing the transmission of the content to investigators.
The authority must subsequently issue a disclosure order or use another legal mechanism to effectively obtain the data. If this step is not taken within the stipulated timeframe, the obligation to preserve ceases.
The disclosure order allows for the direct request of data from the provider. The regulation distinguishes between subscriber data, data requested solely for user identification, traffic data, and content data.
Subscriber data may include names, addresses, contact information, and data associated with the opening of an account. Identification data can help establish the person using a specific IP address, number, or account at a given time.
Traffic data can describe the route, time, duration, origin, or destination of a communication. Content data includes messages, audio recordings, images, documents, and other information communicated or stored by the user.
The more sensitive the data, the stricter the conditions for issuing the order. Requests regarding traffic and content are subject to additional requirements regarding the seriousness of the crime, judicial validation, and notification of the authorities in the provider's state.
The regulation does not allow the use of orders for any act and any information. The authority must demonstrate that the data is necessary and proportionate to the purpose of the investigation or criminal procedure.
The order must identify the issuing authority, the provider, the person or account targeted, the category of data, the relevant period, and the grounds for the request. The provider should not be obliged to search in a general and undifferentiated manner for all the information it holds.
Orders can also be used for the enforcement of custodial sentences, under the conditions of the regulation. The system is not intended for civil, commercial, or administrative disputes.
Targeted service providers may include electronic communications services, online platforms, social networks, hosting services, cloud providers, online marketplaces, and other companies that store data for users.
A company providing services in the EU must have a designated headquarters or a legal representative who can receive and execute orders. This point of contact allows the authority not to depend on the physical location of the server.
The provider must respond within the established deadlines. Emergency situations, in which there is an imminent danger to the life, physical integrity, or safety of a person, benefit from shorter deadlines.
Receiving an order does not mean that the provider must execute it regardless of the content. The company may signal technical impossibility, insufficient information, the existence of a legal conflict, or other reasons provided for by the regulation.
For certain categories of data, the authority in the state where the provider is located receives a notification. It may invoke grounds for refusal related to immunities, privileges, press freedom, national security, fundamental rights, or other protections provided for by the regulation.
The rules pay attention to information protected by professional secrecy. Data of lawyers, doctors, journalists, parliamentarians, or other protected professions cannot be treated as ordinary information if covered by recognized privileges or immunities.
The provider must maintain the confidentiality of the order when its disclosure would jeopardize the investigation. This obligation cannot permanently eliminate the affected person's right to be informed and to contest the measure.
The person whose data has been obtained must, in principle, be informed by the issuing authority. Notification may be delayed when this is necessary to protect the investigation or other legitimate interests.
Affected individuals have the right to an effective remedy. They can challenge the legality, necessity, or proportionality of the order and may invoke violations of their rights.
The data obtained must be used for the purpose for which they were requested and managed according to the rules on data protection and criminal procedure. The regulation does not transform providers into investigative authorities and does not require them to establish the guilt of users.
The system can shorten the time needed to obtain evidence in cross-border cases. Speed does not eliminate, however, the obligation of the authorities to explain the connection between the data and the crime being investigated.
Written communications will continue to be made through a secure decentralized information system. The obligation to use this system exclusively begins on a separate date, after the adoption and implementation of the necessary technical acts.
Until then, authorities and providers can use the channels permitted by the regulation. These must provide security, authenticity, and the possibility of verifying the transmitted documents.
The regulation applies together with the directive that obliges providers to designate a headquarters or legal representative in the EU for receiving orders. Member states had to introduce the necessary national rules for this component.
The new mechanism does not eliminate existing judicial cooperation tools. Authorities can continue to use European investigation orders, judicial assistance, and international agreements when these are more appropriate.
Latest News
22:59
22:45
22:38
22:29
22:05
See more news