EU E-evidence · Regulation (EU) 2023/1543
The EU E-evidence Regulation (EU) 2023/1543 applies from August 18, 2026. It lets a law enforcement authority in one EU member state order a service provider in another country to hand over electronic data, or preserve it, on deadlines as short as eight hours. It applies to any provider offering services to users in the EU, wherever the provider is based. This page covers what the regulation requires, who it covers, and what to have in place before August 18.
Until now, a foreign authority that wanted data from you usually went through mutual legal assistance: government to government, slow, often months.
EU E-evidence replaces that route inside the EU. From August 18, 2026, an authority in any member state can send a binding order directly to your company. The order arrives through a government system, and the deadline to act on it is measured in days or hours.
Two things about this are new for your team:
You are likely in scope if both of these are true:
That covers communication services, cloud and SaaS platforms, online marketplaces, crypto exchanges, fintechs, telecoms, and most consumer platforms.
Where you are headquartered does not matter. A US company with EU users is in scope. A provider with no establishment in the EU must appoint a legal representative there to receive orders on its behalf.
The regulation creates two binding instruments:
European Production Order
EPOCHand over the data.
European Preservation Order
EPOC-PRPreserve the data while a production request follows.
The penalty for non-compliance is set by each member state, up to 2% of your total annual worldwide turnover.
An order you never see still counts against you. That detail matters more than any other on this page, and the next section explains why.
The regulation uses a home-base model:
One registration, one portal. You will not operate 27 systems.
But that one portal is the operational problem. It sits outside the tools your team uses today. Someone has to watch it, because a binding order can arrive in it at any hour, and the clock starts when the order arrives, not when you notice it. An unwatched portal plus an eight-hour emergency deadline is how a company fails this regulation without ever deciding to.
Five things, in order:
Kodex is the network where law enforcement data requests get handled. More than 40,000 law enforcement agents across Europe work through it today.
The European Commission has recognized Kodex as an alternative means of processing EU E-evidence. In practice, that means:
Orders reach you inside the process you already run
EU E-evidence orders land in the same Kodex queue as the requests your team handles now. There is no separate portal to watch.
Every deadline is tracked
Kodex tracks the clock on every order, flags emergencies, and escalates over email, Slack, and PagerDuty as a window closes.
The whole lifecycle is covered
Production orders, preservation orders, deadline updates, grounds for refusal, withdrawals, extensions, and correspondence, all on one record.
It works from day one, in any member state
API integration where a state's system is live, and a recognized manual path everywhere else. Most member states' portals are not ready; Kodex does not depend on them.
Can we just use the government portal?
Yes. It is a working option. The cost is operational: it is one more system to log into and monitor, outside your existing workflow, and the deadlines run whether or not anyone is watching it. Companies with steady request volume usually decide the portal is the riskier path.
Can we build our own intake instead?
Yes, and the regulation allows it. You would be building intake, routing, and deadline tracking from scratch against an August 18 deadline. Kodex already runs across Europe, so the practical question is whether building buys you anything that adopting does not.
Our member state's portal isn't ready. Does that delay anything?
No. Your obligations start August 18 regardless. Orders can reach you through Kodex's recognized manual path from day one, and API connections are added as each state's system comes online.
How do we know if we're in scope?
If you offer services to EU users and hold electronic data about them, assume you are in scope and confirm the details. The guide below includes a scoping walkthrough.
What happens if we miss a deadline?
You have failed to execute a binding order. Member states set the penalties, up to 2% of total annual worldwide turnover.
Everything on this page, in depth: the full legal requirements, the home-base model, the deadlines in operational terms, and a readiness checklist for the weeks before August 18. Written for the legal, compliance, and trust & safety teams that will own this.
New to this area? Start with the complete guide to law enforcement data request management.