Webinar replay · August 6, 2026

EU e-Evidence Prep Talk: your questions, answered

EU e-Evidence Prep Talk: your questions, answered

The questions we got, and what the panel said

An hour of Q&A with no deck, and the questions were better than the ones we seeded. Here are the answers, summarized. This is the panel's operational read, not legal advice, and the scope questions belong with your own counsel.

Are we in scope if we're US based with no EU entity?

If you have customers or business operations in the EU, expect it to apply. The clearer tell is your existing mail. If you already receive MLAT requests or have any international law enforcement presence, plan on registering.

When does the 10-day clock start?

When the request arrives in whatever inbox the member state defined and you registered for. Web interface, API, Kodex, email. Receipt starts it. Whether the clock stops while you wait on enforcing authority approval is unsettled, and the Commission has raised it too, so have a written playbook for that case rather than a theory.

What's the difference between the issuing and the enforcing authority?

The issuing authority is running the investigation and needs the data. The enforcing authority comes in when the request reaches outside that jurisdiction, or asks for a category like content data that triggers an extra approval. It's usually also the member state where your legal entity sits. For a lot of Kodex customers that's Ireland.

Does the regulation apply retroactively to requests we already have?

No. It shouldn't convert requests received before August 18 into EPOCs or put them under the new deadlines. That reading comes from Article 34.

Are request volumes going to jump?

Kodex customers already see 15% to 30% annual increases in EU requests with no regulation in place, measured across hundreds of thousands of requests over two years. For after the 18th, the range being used in the project groups and in SIRIUS conversations runs from 30% to 300%. Nobody is forecasting a decrease.

Is the 2% fine real?

It's in the regulation and it's there to make providers hit the deadlines. It's also a figure that appears across many EU regulations. Whether it gets enforced on day one is a separate question, and member states being behind on their own obligations is the basis for the hope that there's an introduction period. Fines have landed under GDPR, the OSA and the DSA.

What are the technical paths on day one?

Three shapes are emerging. Member states with reference implementation infrastructure and an API path. Member states with neither, where email, existing intake channels and Kodex carry the traffic. And member states with a reference implementation, no API, and no appetite for alternatives. Expect a hybrid for a while.

Where are the member states?

Ireland looks like it wants a contingency period on August 18, with multiple intake paths. The Netherlands has moved tentatively to Q1 next year after setting out to build their own API. Sweden informally looks likely to start outside the DIS. Ireland, Germany and the Netherlands are the only three with real signal, and the API timelines are slipping partly because each member state is waiting for the others to go first.

We only get a handful of EU requests. Do we need anything?

The smaller teams are often under the most pressure, because there's no dedicated function and a junior analyst ends up making a critical call about sharing data. Getting the intake path and the operating procedure right matters as much at low volume as at high, and it's hard to derive either from reading the regulation.

Full transcript

The complete hour, lightly cleaned. Speaker names and timestamps included so you can jump to a moment in the recording above.

Copy transcript

John Weeke 00:00 We are live, everybody. Welcome to the first EU e-Evidence Prep Talk. I am John Weeke, your moderator today, and we have collected five of the foremost experts at Kodex when it comes to everything EU e-Evidence. Wanted to get together today to have a little conversation, share our knowledge, ask some questions, and find out what we should collectively be doing, and individually as companies be doing, to prepare for this big date coming up in less than two weeks. Ten days, I believe. So to introduce our panel, we've got three folks from the Kodex product team led by Jesse Goodman, Ike, and Avery, on the product and technical side. They've been going deep not only on Kodex's solution, but also talking to officials, talking to different companies, trying to figure out what the heck is going on. And then on the customer and growth side, we've got Mike and James. Mike, who leads our revenue function, and James, who if you are located in the EU or spend any time on LinkedIn, you've probably seen plenty. He has been having tons of conversations with folks out there. The format we're thinking today, we've got no slides, and we want this to be more of a quick rapid fire conversation and Q&A. Full disclosure, even on this panel, we're not all gonna necessarily agree with each other on what the right take should be. Maybe that's a good thing. We're trying to figure this out together. So EU e-Evidence goes live on August 18th. We're trying to figure out what this new world looks like. Let's say you've registered, it is 2:00 AM on a Sunday, and you've just received an emergency request from Bulgaria into the system. It is up to you to respond. How does this work in this new world, Jesse?

Jesse Goodman 03:05 Thanks, John. Hey, everybody. Good to see you today. Appreciate you joining. So in this new world, what does this look like? We've obviously been working with all of our customers, with the member states, with ETSI, to understand the regulation and build systems and tools to be able to support this. A lot of our customers have been focusing on appointing a representative, determining whether they're in scope to have to register to be able to receive these requests in any member state, updating their policies potentially. And those things, in my mind, all matter. But I think one of the things that teams are missing when it comes to getting ready for day one is the technical systems and workflow and operating procedures. So the most important thing to me is what happens when you actually receive a request. Let's say it's in the middle of the night, on the weekend. What are the systems and processes that you have in place to be able to deal with that? If you dig into this a little bit deeper, that request comes in. Can you triage it in the right way? Can you determine whether it's an emergency? Do you have systems and tools to be able to notify an accountable person that's on call to be able to receive that request and deal with it right away? These eight-hour windows are tight. It's really different from what we've seen in the past, especially across the EU, where there is actually an enforceable deadline, an SLA, that's expected to respond to. And so being able to triage that, being able to validate the request, have the systems in place to check the signature of the request, and then as much as possible to automate all the things that can be done upfront so that if somebody's getting a page in the middle of the night, they already have a place to look at the request, to see whether they have responsive data to it, whether it's legally appropriate, whether there's enforcing state approval required, and to have all of that upfront work ready so that you can respond within that tight window. And to me, running through those scenarios, we're actually starting with our customers this week to test that specific scenario. Where you receive it, what do you do? What are the tools that are supported? Who does the request get assigned to? To me, that's the most important thing to have ready for day one.

John Weeke 05:42 Agree there, Jesse. I can see we're getting a lot of questions about the Kodex platform specifically, which we love. We're gonna get into it, but first a couple more general questions about EU e-Evidence. One that we get often is, are we in scope, especially from our US-based companies. Even if we have no entity today in the EU, do we have to do anything? Mike.

Mike Flores 06:18 Yeah. And I'll give the big disclaimer. Everybody should be working with their internal general counsel and any outside legal guidance on the specifics, because there are a lot of instances. But based off of what we know, if you have customers in the EU, you have business operations in the EU, the regulation would apply to you. And frankly, any company that's already receiving MLAT requests or has some sort of international law enforcement presence, or in the EU specifically, it is something that you should expect to need to register. But again, working with your internal legal team and really going through the regulation in depth is always gonna be our guidance. We are the tech provider. And for the companies that have already raised their hands saying that yes, this applies to me, and we need a way of being able to triage these and delineate them from other requests, we were working very closely.

John Weeke 07:25 So another big question. In theory, not only does this change the process for service providers, it changes the process for requesters, and could make it a lot easier for law enforcement to make requests in the first place. We don't have a crystal ball, but I think we can make some assumptions as far as what impacts this could have on the demand side. James, what do you think? Are we going to expect higher request volumes on the 18th?

James Clark 08:05 I mean, I'm always happy to make outlandish statements. Just from prep for this, one of the things that Jesse pointed out is that organically, most of our clients see annual increases of 15 to 30% without EU e-Evidence in existence. From the project groups that we've been involved with and the SIRIUS project, when we've been chatting to the teams there, it really varies. People are expecting somewhere between a 30% and a 300% increase in volume. No one's talking about a reduction in volume. And I think if I think about human nature, law enforcement have known that this is coming for a long time, and law enforcement know that they will now have a regulation where if they raise the request, they will get the data back. It's no longer about voluntary disclosure and a privacy team making that decision. So I can't see how there isn't something close to a tsunami level event of all of these agencies and law enforcement platforms that are waiting to be able to issue these orders and get this data back, having been frustrated basically since 2018 when GDPR came in.

John Weeke 09:17 Agree. And Jesse, you just shared a stat that we're seeing an increase year over year in the number of requests already in the EU. Is that right?

Jesse Goodman 09:31 Yeah. So we've run aggregated data analysis across our customer base, which is hundreds of thousands of requests over the past two years, and as James mentioned, we have seen on average about a 15 to 30% increase in requests to our customers across the EU. And that is pretty diverse. We see requests from most EU member states. Now whether or not, and this is where James and I and others have some interesting debate, there is enough resources and administrative support on the government side across these countries to be able to open the floodgates of requests. I think that's a great topic to discuss. As well, there are now mechanisms to alleviate sort of optional response or MLAT processes. We're not sure what the level of increase will be on top of what we've already seen.

John Weeke 10:38 In addition to potential increases in volume, the number that keeps on getting thrown out is 2%. A 2% potential fine for non-compliance. Is this a real thing? This is of total revenue, so we could be talking a heck of a lot of money. Mike or Avery, what do you think?

Avery Oracheff 11:07 I do think that this is something that's listed in the regulation and is a figure that's meant to encourage service providers to respond to these requests within the deadlines. That being said, this is a common figure that's in many different regulations across the EU, so we don't know for sure that this is going to be enforced on day one. But I'll let James go, I know you also have some context here.

James Clark 11:30 Well, I think just the meetings that we've been involved with, with various national entities and the service providers that we're working with, there's this hope that there is a sensible introduction phase and they aren't coming out with fines on day one. Obviously there's some challenges in member states meeting the regulatory deadline in terms of getting architecture in place to issue this, and so there's a hope that there is a kind of sensible integration process to give service providers the chance to get up to speed. Obviously, we have seen fines in other regulatory regimes across GDPR, OSA, DSA, so it's definitely there. But we see this level of fine regularly included within a regulatory regime, so I don't think it's anything particularly special that anyone needs to think about differently.

John Weeke 12:20 Let's get to the final general question before we dig into the Q&A, of which there are many, and they're great. Thank you for submitting. We're gonna get to as many of these as we can. Generally, what are our technical options when it comes to dealing with this? Ike, we haven't heard from you yet, and I know you're deep into it, so I'm gonna throw this to you.

Ike Anude 12:46 Yeah. So the technical options for handling e-Evidence requests, or European production orders, is gonna be mainly the API that is supposed to be provided by the Commission, and their platform. They call it the reference implementation, the RI platform. Both of these platforms connect directly to eCODEX within your member state and are able to handle communication between member states. So eCODEX is kind of the infrastructure that already handles some of that interstate communication, but the main addition is going to be both the API and the reference implementation that allows service providers to handle requests directly from member states outside of their enforcing authority.

John Weeke 13:32 Avery or Jesse, is there anything you'd like to add in terms of these technical options?

Jesse Goodman 13:39 Yeah, I can start with that. What Ike referenced is definitely a big part of it that we've been preparing with our customers. We have built an API to the ETSI standard, which I suggest everybody take a look at if you haven't already. It is very detailed in terms of the technical architecture and how to set that up. I think that is the ideal solution down the road, when it is available, though we're seeing delays across pretty much every member state in opening that up for testing and implementation. We are also pursuing alternative paths. So Kodex, email, fax, regular portals that exist today are still applicable for member states that may be in scope for requests for you as a service provider, that do not have reference infrastructure in place or their systems in place to be able to serve and receive responses to requests. And that's where these alternative means, through Kodex or through other channels, are still available for the deadline, day one, especially if the bills for the legislation are passed within the member states that are in scope for you. That's definitely one method. We are also seeing a third channel where there might be a reference system in place for a member state, but no API and potentially no desire to use alternative channels. And so there are three different approaches that are definitely surfacing that I think will evolve over time. We're trying to understand those different scenarios and monitor each one of them. And from a Kodex perspective, we're prepared to receive requests manually just like we do today, through verified agents, through a centralized system, or through API. And even in the scenario where there's a member state that issues requests through their own system, there are still channels to be able to intake that manually and still use whatever case management system you have as a system of record. So there might be a bit of a hybrid approach to start, and ideally all of this then gets centralized and streamlined through API over time.

Ike Anude 16:20 If I could go, I could take Monty's latest question. What he asked was, what are the latest timelines on the API implementation? When realistically do we believe the decentralized system will roll out? So I wanna separate two things. First off, the decentralized system, they call it the DIS. This is already preexisting. This is eCODEX. To call it a messaging platform might be a bit of a big word for what it is, but it's a decentralized network and messaging protocol to allow governments within the EU to communicate with each other. The API implementation will depend on the member state in terms of timeline. The API implementation is currently being developed by the European Commission. They have a testing group. There's a couple of companies and service providers that are testing with them currently. However, that API package needs to be sent to all the member states, who will then implement it under their own infrastructure. And that transition process should have happened a while ago. However, there's been all kinds of delays, all kinds of issues, and it is really hard to say for certain that they will be ready by X date. Some authorities are saying Q1 of next year, some are saying Q4 of next year. I think it's really hard to put an exact number on when that'll be done. But it is required by the regulation, so at the end of the day, they have to do it if they have transposed the regulation.

John Weeke 17:56 Related question here from Luke. Can you confirm if Kodex are setting up APIs directly with member states, or just the European Commission as the decentralized IT system? You kind of touched on it. Anything that you'd wanna add?

Ike Anude 18:13 Yeah. I touched on it a little bit, but again, the distinction is that the eCODEX system is something that the API connects to. Anything that the Commission is developing now connects to the eCODEX system. It's kind of the underlying infrastructure that connects all of these member states together.

Jesse Goodman 18:34 I'll add to that, John. As far as the API connection, we are working through our customers as a technical implementation partner, which is specified in the regulation and standard, to be able to support them in connecting the Kodex API that we build according to the ETSI standard with a specific member state portal. And so as soon as those are available and ready for testing, we are ready and supporting our customers and making sure that they have the most scalable compliant solution. For any of the member states that are a little ahead of the game, like Ireland or Germany, some others, they are starting with sort of a phase one that includes some of the larger tech providers like Meta, Google, those that you would expect. And we are actually in discussion with those large tech providers to be able to share knowledge and best practice so that when they get to the next phase, we're able to learn from anything that happened previously and apply that to support our customers as their technical implementation resource.

John Weeke 19:48 Great. So speaking of being the technical implementation resource, this is another question we've gotten a lot. What if a member state pushes back on working with Kodex as a third party? Obviously we want to be your solution for everything here, but we've seen some early signals that, can we even be in the room?

Jesse Goodman 20:17 So the answer is, we have been in the room, and have been working with our customers who are in working groups with different member states and the EU Commission. And they have brought us as kind of a plus one to those sessions to be able to support them as their implementation partner. Through the registration process, we've also sent out guides, which we can share after the session, on how to register. And within that registration process, there are options to be able to select how you wanna receive requests for that specific member state. API is one of those options where you can select that, and we provide an endpoint URL on behalf of our service providers so that they can reference our standard API implementation as one of the options to receive requests when that technical capability is ready.

John Weeke 21:19 So at the end of the day, it is your relationship with the member state. You're setting it up, you're creating your entity if you're creating it from scratch, and you can designate Kodex as the way of handling these requests. So we're all figuring it out together, but the conversation at the end of the day shouldn't be too tricky.

Jesse Goodman 21:46 And I'll just... because we're in the spirit of challenging each other a little bit, John, I would say these words matter. The service provider is the legal entity that is signing up to receive requests, so those are our customers in this scenario. We are the technical implementation partner for service providers. And so I understand, we provide a service, and often that's a common term to use. In this case, I think that's where some of the confusion happens, because those terms are important and they have to tie back to the standard and the regulation.

John Weeke 22:25 Agreed. And these are actual terms in the regulation itself, correct?

Jesse Goodman 22:31 Yeah, exactly. So we'll learn, just like every company has its own acronyms and everything. There's a whole language here, and I think we're all learning that so that we're speaking the same language.

John Weeke 22:43 So I think a related question here from Paula, maybe already asked and answered, but have you received assurances from the EC and/or EU member states that they will accept providers integrating with Kodex's solution as compliant? Answer in relation to both the short-term solution and the longer term eCODEX API integration we are offering. Is there a difference between the short term versus the long term?

Ike Anude 23:12 I can take that one. Just to add to what Jesse said, 100%, words matter. We're not service providers, but the best way to think of us is as transparent to the member states. So for the most part, they are going to interact with our customers and see them as service providers. We're just handling, shuttling the requests back and forth and handling some of the operational business workflows. But in terms of assurances from the EC and the EU member states that they'll accept Kodex's solution as compliant, they will be developing according to a very specific standard that we had a hand in creating. So we've influenced some of the different endpoints and the business workflows within this particular spec. And as long as we are compliant with that spec and they are compliant with that spec, we should be compliant overall.

James Clark 24:12 I was gonna say there's a good question that came in from Steve, which I am also keen to answer, just about how the requests that come in would be treated. Are they gonna appear as any other request? Are they delineated separately with different tabs? Ike and Avery are probably best placed, but I have seen this from a demonstration perspective. And from a user experience perspective, the clients that are already using Kodex and are used to that intake process, and how the analyst teams will be responding to intake, it's gonna look and feel exactly the same. It will be flagged as an EU e-Evidence regulatory intake. So from a user experience perspective, we don't expect any need for significant retraining of the team that are used to working in the platform. But it will be clear that the regulation applies to a specific ticket, and therefore you need to treat it with the timelines that are associated to it. Ten days, eight hours, et cetera.

Mike Flores 25:12 Something that I would add to that, James. We haven't really talked a lot about the turnaround times. I know we talked about the penalties, but for some companies, 10 days to turn around a request is a pretty high hill to climb. And working a lot with companies that hadn't used Kodex before and they're transitioning from email or a Google form or maybe a self-built portal, I could see a major risk if one of those requests then gets blended in with all the other requests from their timeline or from their inbox. And then ultimately, if you already have a three to four-week delay, or I have some companies that have had like a two to three-month backlog on requests, that's a huge risk. And so I think having a way to triage those automatically, have them being set aside, having the ticklers on them and the reminders of, hey, this is how many days you have to respond. Which, if you are using Kodex as the backend, that's gonna be very clear. But even if some companies need to think about a dual path here, where okay, we need a separate solution or a separate instance for these EPOCs to come in. Just because we don't know what the volume's gonna be, we don't know what the impact's gonna be, I think it's a smart move, and we have many ways that we could explore doing that without a ton of lift. But it is important, certainly within Kodex, to have that delineation between, all right, I'm on the clock for these and there's a lot at stake, versus the ones that are just maybe your normal production orders.

Jesse Goodman 27:05 John, if it's okay, I'd like to take a question from Mariel here. "Will the regulation also apply retroactively," referring to tickets presented before August 18th? Thank you. So again, I would suggest that you run this through counsel that you have supporting you. But the answer from my perspective is no. The regulation should not retroactively convert requests received before the deadline into EPOCs, or subject them to new response deadlines. That is an interpretation of Article 34 from the regulation. So as far as I'm concerned, the regulation does not allow for any of those requests to apply retroactively.

John Weeke 28:02 Good to know. One more. Mike was talking about consequences. I have a fun question here regarding consequences. If we do not register, what happens?

James Clark 28:15 We don't know. Who's gonna be the first to roll the dice and find out? Who wants to find out? Unclear. I don't think anyone can answer that at the moment. There'll certainly be repercussions.

Ike Anude 28:34 Additionally, I wanna say it's better safe than sorry, because when you do register, depending on your member state, it's very common for people to fill out the forms wrong, the notification form incorrectly. And because of that, and unclear instructions on how to fill out the notification form, a lot of these member states are having trouble automatically approving people. So if you do make your best effort to register and document the entire process, this is obviously not legal advice, but it should give you a little bit of assurance in, okay, at least we tried, we made a good faith attempt, and if there's any challenge or any issues, we have documented every step of the way.

John Weeke 29:31 If our member state of registration were to tell us they were ready to integrate tomorrow, are we ready to go immediately? And how long do you anticipate it would take to integrate once we get clear instructions?

Jesse Goodman 29:49 The answer to ready to go is yes. We are ready to start testing, to look at the data going back and forth to make sure that's appropriate. The timeline shouldn't be more than a few weeks. But obviously we want the proof to be in the pudding once we have the opportunity to start testing. We have even gone so far as to vibe code a member state system. So we've tried to create and simulate a scenario that would involve integrating and testing with the system if and when they are ready. And so that's obviously something that's giving us more confidence to be able to apply that whenever we can, in quick order. So we're running the drills, we're doing the homework, and really building the muscle so that if and when the member states are ready, we're right there with them.

John Weeke 30:54 Anything that you can share on readiness on the individual member states? I think that's been a hot topic as well. We've talked about Ireland and Germany. Any other signals, any specifics as far as status of those, if that's where our folks on the call are thinking about registering?

Ike Anude 31:16 Yeah, I can speak to the Netherlands a little bit. The Netherlands wanted to originally build their own API. Now they're finding out that this is a little bit more difficult than they thought, so they are tentatively pushing it out to Q1 of next year. Now, I can't say, like I said earlier, I'm not sure if this is something that they're going to hold themselves to. And for the most part, from what we've heard from some of the bigger service providers, testing is a bit spotty on the Commission side. So I can't really give a very specific timeline for all the member states. We've only really heard about Ireland, Germany, and the Netherlands.

John Weeke 32:00 Got it. Thank you. So we have another question from Monty. I don't think this has come up in any conversations internally before, so this could be a pass, but let's give it a try. Your perspective on future legislative tension between SCA and rejected Article 17 pushback. Do you have any EU perspective on the thousands of requests that could be tied up in courts weekly? Jesse, I see you're thinking hard on this one. Any thoughts?

Jesse Goodman 32:34 I think for this one we have to pass on it. It's probably a whole other webinar in itself, and I think it's a super interesting question and an important one to address. But I would say it's a little nuanced to be able to get into a conversation today.

John Weeke 32:53 We'll take this back to the lab, though. And maybe, who knows? I think Jesse just signed up for a whole other webinar.

Jesse Goodman 33:01 Yeah, there we go. I'm always looking for another webinar excuse.

John Weeke 33:06 All right, let's see what else we have. The deadline itself, and this is categorically similar to a question we've heard before and talked about internally. How hard is this deadline? How hard is the 2%? How hard is the 10-day, or the eight hour even? Obviously the blanket answer here is we don't know. But I'm curious, James, your thoughts on this, being geographically the closest to the EU. What's your guess?

James Clark 33:44 I think it's gonna vary, and it's gonna vary on the provider, the case nature, and the severity to some degree. What we see typically when a regulation goes live is the implementation of the regulation deadline slips, but the expectation on the service providers to be able to comply with it often doesn't, and I think we've seen that repeatedly over multiple regulations going live across Europe. I suspect we're in a similar position again. So there are some things that mean the regulation isn't going to be delivered as expected on the 18th, but all of the conversations that we've seen is that the member states are making provisions so that even though their technical architecture isn't in place to support the API, they are going to be in a position to start to use this regulation to request the data that they want. Are they then going to enforce the 10-day deadline? I think perhaps to some degree at this stage it possibly depends on the relationship and the case nature. If they believe that you are working hard to try and address it, and that basically you are a kind of good corporate citizen in that response, maybe it buys you some flexibility. But from a legal perspective, I don't think that would stand up in court. There is a regulation that goes live. You have a compliance objective that you must meet, and then it's a question about how the enforcing agency would choose to see your behavior. Are we gonna see big fines early? Does Europe want to start making an example of service providers? It's like I'm answering questions with questions, but I would be taking every step I possibly could to be able to respond to this regulation as soon as it goes live, despite the technical limitations in member states being ready to use the API.

Jesse Goodman 35:36 I'll add to that, John, and reference back to actually the first question of the webinar, which is, the deadline's here, what do I do? Or how do I prepare for that now, from today, for the next two weeks? And I think the answer is, if you're in scope and you've registered, and a member state has a means to be able to serve an EPOC or EPOC-PR, and the legislation has been passed within that member state, I think it's on service providers to be ready to respond to that request within the timelines defined for the regulation. And so preparing for that, and having the systems and clarity around how you receive those requests and how you respond, to me is the most important thing. Now, there are some gray areas that are really interesting that we've been discussing with our customers for a long time, that the EU Commission itself has even mentioned in their last webinar like this with service providers, and that is, when does the clock start? And I think the simple answer is, as soon as you receive it through whatever inbox has been defined by that member state and that you've registered for, that is when the clock starts. So that could be through a web interface for a country. That could be through API at some point in time. That could be through Kodex, through email. And as soon as you receive that, you are required to process and respond to that request within the SLA. Now there are some other gray questions, like if the issuing authority requires approval from the enforcing authority, are there stops in the clock along the way if you're waiting for that? And we've had some interesting discussions with our customers to say, well, if a specific EPOC does require enforcing authority approval, or may potentially require that approval, then we will wait five, six, seven days to determine whether we're able to respond, and then that last two or three days of the clock will be when everything is formally submitted. So there are different approaches to it. There's wait and see, but I think having the playbooks for those different situations operationally is the most important thing, so that you can try to meet those SLAs.

John Weeke 38:17 Follow-up newbie question here. Can you define issuing versus enforcing authority? And who is responsible at the end of the day for judging whether you've met the 10-day deadline?

Jesse Goodman 38:41 Sometimes I think of things in very simple ways. From my perspective, the issuing authority is the one that, in today's world outside of e-Evidence, is performing the investigation. There is an incident, or a situation that has occurred that's created the need for this data. And it's obviously the issuing authority's duty to go through the administrative process to get legal approval within their state to be able to receive the clearance through an EPOC to submit a data request. And so the issuing authority is essentially the one that is needing the data, and responding to some sort of investigative need. Now, that issuing authority may be requesting data outside of their jurisdiction, or a certain type of data that triggers an additional approval for situations like content data, for example, and that's where an enforcing authority may come in. And this translates pre e-Evidence, right? It's related to other types of GDPR interpretations and so on around cross-border data requests, and the legality for those requests. And so I think of the enforcing authority as the one that may need to approve the specific circumstance for certain types of data requests. And that enforcing authority may also be the primary location for which you have established your legal entity, or one of your legal entities, within the EU. And so that's kind of like your home base, I guess I would put it, is the enforcing authority, and they may need to provide additional approval if there's a request from an issuing authority outside of that jurisdiction. So for a lot of our customers, Ireland, for example, is their enforcing authority member state, where they're expecting to receive all of their requests from any country across the EU. And so there are these mechanisms in place to ensure the legality of those requests.

John Weeke 41:05 Thank you. And that actually transitions to Monty's follow-up question. Ireland has been the number one topic in terms of our customers at Kodex thinking about whether it makes sense to register there. They're also farthest ahead in the implementation process. We've got actually some news this week. So Ike, can you reiterate your latest info on Ireland readiness, and any other detail you think might be useful?

Ike Anude 41:34 So in terms of Irish readiness, they do appear to want us to be in a contingency period at the August 18th deadline. And this is still being more or less ironed out, there's still a bit of negotiation going on between large service providers and the Irish DOJ. But there will be multiple paths. Specifically the reference implementation, which is the web portal that's provided by the EU, plus any other kind of alternative methods, such as Kodex's portal or, for a large service provider, Meta's portal, to be able to handle requests. So that's why we said earlier that there's gonna be a lot of hybrid. There's gonna be a hybrid solution where there's not gonna be one specific channel where requests will be submitted and handled. However, this all will depend on what happens at go live, whether the Irish... And we're still pushing for the Irish to have this in writing, but based on the last working session, they said we'll be in the contingency period and there's gonna be multiple different avenues in which you can receive requests. I think maybe Avery could expand on that a little bit more, because she was also on the call.

Avery Oracheff 42:55 Yeah, Ike, I think you did a great job summarizing that. I would just add that one of the biggest open questions that we had to the Irish DOJ is for a formal list of all member states that will, one, have transposed the regulation, and two, also be starting outside the DIS, so that service providers know what to expect on the 18th. But as Ike mentioned, today there's no commitment from member states that they'll share that with service providers, but we're really pushing to make sure that is clear so that everyone knows what's going on on the 18th. And then I may just jump into Paula's question about Sweden. We did hear, again informally, that they're likely going to start outside the DIS, but that would trigger the fallback plan. But in that sense, we don't have confirmation from Sweden that is the case.

Ike Anude 43:43 To add to that, a lot of these countries, Germany and Ireland specifically, are waiting for everyone else to also be using the API, or to be integrated with the DIS. There's kind of this network effect issue where they want everyone to be using this API connected to DIS before they onboard. So it's kind of a weird catch-22, right? Where everyone is kinda waiting for everyone else to use the API before they use the API. So are they going to use the API? It's required. They have to. However, the timelines are just gonna get pushed out in the near term because of this kind of weird cat and mouse game.

John Weeke 44:27 Last question, or second to last question. The EU-US CLOUD Act. Is it coming? How does it impact us?

Jesse Goodman 44:38 I can take this one. Some of these questions are definitely important to have with legal counsel, so caveat that. This is a really important nuance for sure, and I would say that I would avoid saying Article 17 becomes entirely moot, but it should become substantially less relevant for conflicts based on US law. The anticipated EU-US agreement is specifically intended to remove these legal barriers that currently sit between US providers and qualifying European orders. However, as of today, official US and EU sources still describe the negotiations as ongoing, and no agreement has entered into force. So it's an interesting one, for sure, and I feel like those discussions are ongoing.

John Weeke 45:56 Thank you. All right, one more from Paula here. Follow-up to the question of the DIS APIs. Avery, will we support outside the DIS?

Avery Oracheff 46:10 Ike, actually I may lean on you for that question. I feel like you're the best person to answer that.

Ike Anude 46:15 Yeah, I would like a bit of clarification here. What APIs are we referring to that are outside the DIS? The DIS is kind of the underlying infrastructure. The RI implementations connect to the DIS. I'm not sure which APIs we'd be able to integrate that wouldn't be part of the DIS, or at least connected in some way to the DIS.

John Weeke 46:44 Paula, if you have any thoughts on that, feel free to follow up in chat or reply to the question. Jesse, anything you wanted to add there?

Jesse Goodman 46:51 This is something I can say sort of not even specific to EU e-Evidence. If you were able to catch the last Kodex keynote, I talked about this a little bit in terms of how we think about overall infrastructure for the exchange of public-private data requests, or even in general system-to-system interactions. And so while we have built an API according to the ETSI standard for EU e-Evidence, we have also built essentially the infrastructure, we call it Intake Bridge, to be able to translate requests from any country or any system, and be able to interpret that and do the data mapping in order to ingest that request into Kodex as a centralized response source. And so outside of EU e-Evidence, we have been working around CLOUD Act, with Australia, with the UK for COPO, with India, as we see this trend across the board of governments moving to having platforms for issuing process and being able to exchange data for this type of business process and legal process. And so for us, while we're here obviously talking about this deadline and what is imminent and most top of mind, we're also preparing for that bigger picture, which is the full infrastructure regarding any API, and having the technical capability to do that translation and respond to any requests and have it feel close to the same. There's always gonna be nuances and specific legal requirements, but for us, the technical infrastructure we're hoping to standardize for any of these scenarios across the industry.

John Weeke 49:03 Just to follow up, and I think you answered the question, Jesse. That's a follow-up to the Sweden-specific API implementation. But it sounds like Kodex is building the universal rails for any type of legal request, which by definition means that we will be able to support any type of API, any type of digital request. So I assume that means yes.

Jesse Goodman 49:29 Yeah. And I think, ideally within the industry we align on best practices for authentication, for encryption, and that becomes a model that can be applied to any of these API specs.

John Weeke 49:48 Hopefully that helps, Paula. Thank you. Ike, anything else?

Ike Anude 49:52 Yeah. I just wanted to add that within the near term, if it complies with the ETSI specifications, we'll be able to handle it. And I think the intake bridge is our main... Like, as Jesse said, the intake bridge will handle any type of government to service provider translation from anywhere in the world. It is meant to be the kind of rails that all legal requests ride on.

John Weeke 50:16 Everything into your own single portal. And going back to the question from 20 minutes ago, yes, you'll be able to see where it came from, as it's coming into your unified portal, handle things quickly, efficiently. All right, thank you Paula.

James Clark 50:45 John, while you're doing that, I can just answer Steve's question. He asked early on, and I don't wanna not address Steve's important question, which was tell us about the opening rap song. I happen to know that Steve is a bit of a music producer in his spare time. I feel like Steve has just offered to help us with a more cynical European version of the introductory rap song for any future webinar that we might be hosting. So we'd definitely like to take you up on that, Steve. And thank you for the kind offer.

John Weeke 51:16 Absolutely. You might join this webinar and think that Kodex is just wonky technical folks. Not true. We have style, we have talent. And so Steve, would love to chat later. And yes, if you stick around to the end, you're gonna be able to hear the song again as the outro. So I just had one other question. I feel like the folks on the call, they're deep into it, so this may or may not relate to you, but one of the questions we have gotten is, "If I'm a smaller provider, if I only receive a handful of requests today from the EU, do I need a solution at all? Should I just go ahead and register and monitor the inbox?" What do you suggest, Mike?

Mike Flores 52:11 EU e-Evidence aside, I think there's a lot of companies that are on some side of the spectrum of how many requests they get on a daily basis, weekly basis perhaps. And I would say that just as far as best practice, we do have some walk-up usable version of Kodex that is for this exact purpose of receiving low volumes of EPOCs, making sure that they are covered from an audit trail perspective. And again, what I said earlier of having maybe a system that is set aside for these requests just to kind of cover your bases, I think would be wise. Especially if you do... I've worked with a lot of companies that are rapidly expanding internationally and have parts of their business that could be useful in an investigation. Think of it as insurance. Think of it as just thinking ahead, and you never wanna try to implement something too late. And we are interested if somebody is connecting and says, "I may get one of these in the next year. I may get 100." We are happy to talk through some options for anybody that just needs to have something in place, and we are being very flexible on anybody that needs to have an instance and somewhere to point these requests to. So my team would be happy to talk to anybody and just kind of walk through it.

John Weeke 53:49 I think that, not to put words in your mouth, Mike, but I believe that we might have a... And most folks on the call are of course already Kodex customers, so this wouldn't apply to you, but as you were saying, Mike, anybody who's in that category of trying to figure something out, we've got a pretty special promo when it comes to helping you guys get set up, in the door easily.

James Clark 54:15 John, I would just add something to that. Obviously the US team are often dealing with the very largest providers who already receive huge volumes of intake, and for them it's as much a capacity problem and a workflow problem about how they triage and manage that workflow. A lot of the European clients that I work with are at the other end of the spectrum. They are smaller in nature. They receive fewer number of intake requests. Typically, what that means is they don't have a dedicated team or a dedicated business function looking at this, and that falls to an analyst team or a team that is multifunctional across different areas. And one of the things that we've seen is that those teams are often the teams that need the most support. They need a dedicated platform. They need support with verification. And the platforms know that they've got what can often be a junior team making critical decisions about sharing data. So I think the smaller platforms that don't receive huge volumes, I would say it's as important to get best practice architecture, establish your standard operating procedures, and it can be difficult to do that reading through a regulation. If you take Kodex as a reference architecture, it helps to focus the mind in terms of what do we need to do? What decisions do we need to make? Who needs to be in the decision process? So we see a lot of the smaller clients with lower volumes still getting significant value from the platform.

John Weeke 55:37 Everything much more manageable with Kodex, especially to your point, for smaller teams. All right, so that wraps it up, everybody. We are at time. So any last words of advice or anything like that? Anybody? All right, great. So you can find us on social media. All the folks here, tag them, follow up to questions. We are of course going to share this recording after the fact, and we learned some things here, so we're gonna update the EU e-Evidence handbook that you can see linked in the top right corner of the screen. If you don't already have that, please get your copy. And yeah, we are less than two weeks out, so good luck everyone, and we're here for you if you need anything. See y'all.