John Weeke 00:00 :
We are live, everybody. Welcome to the first EU e-Evidence Prep Talk. I am John Weeke, your moderator today, and we have collected five of the foremost experts at Kodex when it comes to everything EU e-Evidence. Wanted to get together today to have a little conversation, share our knowledge, ask some questions, and find out what we should collectively be doing, and individually as companies be doing, to prepare for this big date coming up in less than two weeks. Ten days, I believe. So to introduce our panel, we've got three folks from the Kodex product team led by Jesse Goodman, Ike, and Avery, on the product and technical side. They've been going deep not only on Kodex's solution, but also talking to officials, talking to different companies, trying to figure out what the heck is going on. And then on the customer and growth side, we've got Mike and James. Mike, who leads our revenue function, and James, who if you are located in the EU or spend any time on LinkedIn, you've probably seen plenty. He has been having tons of conversations with folks out there. The format we're thinking today, we've got no slides, and we want this to be more of a quick rapid fire conversation and Q&A. Full disclosure, even on this panel, we're not all gonna necessarily agree with each other on what the right take should be. Maybe that's a good thing. We're trying to figure this out together. So EU e-Evidence goes live on August 18th. We're trying to figure out what this new world looks like. Let's say you've registered, it is 2:00 AM on a Sunday, and you've just received an emergency request from Bulgaria into the system. It is up to you to respond. How does this work in this new world, Jesse?
Jesse Goodman 03:05
Thanks, John. Hey, everybody. Good to see you today. Appreciate you joining. So in this new world, what does this look like? We've obviously been working with all of our customers, with the member states, with ETSI, to understand the regulation and build systems and tools to be able to support this. A lot of our customers have been focusing on appointing a representative, determining whether they're in scope to have to register to be able to receive these requests in any member state, updating their policies potentially. And those things, in my mind, all matter. But I think one of the things that teams are missing when it comes to getting ready for day one is the technical systems and workflow and operating procedures. So the most important thing to me is what happens when you actually receive a request. Let's say it's in the middle of the night, on the weekend. What are the systems and processes that you have in place to be able to deal with that? If you dig into this a little bit deeper, that request comes in. Can you triage it in the right way? Can you determine whether it's an emergency? Do you have systems and tools to be able to notify an accountable person that's on call to be able to receive that request and deal with it right away? These eight-hour windows are tight. It's really different from what we've seen in the past, especially across the EU, where there is actually an enforceable deadline, an SLA, that's expected to respond to. And so being able to triage that, being able to validate the request, have the systems in place to check the signature of the request, and then as much as possible to automate all the things that can be done upfront so that if somebody's getting a page in the middle of the night, they already have a place to look at the request, to see whether they have responsive data to it, whether it's legally appropriate, whether there's enforcing state approval required, and to have all of that upfront work ready so that you can respond within that tight window. And to me, running through those scenarios, we're actually starting with our customers this week to test that specific scenario. Where you receive it, what do you do? What are the tools that are supported? Who does the request get assigned to? To me, that's the most important thing to have ready for day one.
John Weeke 05:42
Agree there, Jesse. I can see we're getting a lot of questions about the Kodex platform specifically, which we love. We're gonna get into it, but first a couple more general questions about EU e-Evidence. One that we get often is, are we in scope, especially from our US-based companies. Even if we have no entity today in the EU, do we have to do anything? Mike.
Mike Flores 06:18
Yeah. And I'll give the big disclaimer. Everybody should be working with their internal general counsel and any outside legal guidance on the specifics, because there are a lot of instances. But based off of what we know, if you have customers in the EU, you have business operations in the EU, the regulation would apply to you. And frankly, any company that's already receiving MLAT requests or has some sort of international law enforcement presence, or in the EU specifically, it is something that you should expect to need to register. But again, working with your internal legal team and really going through the regulation in depth is always gonna be our guidance. We are the tech provider. And for the companies that have already raised their hands saying that yes, this applies to me, and we need a way of being able to triage these and delineate them from other requests, we were working very closely.
John Weeke 07:25
So another big question. In theory, not only does this change the process for service providers, it changes the process for requesters, and could make it a lot easier for law enforcement to make requests in the first place. We don't have a crystal ball, but I think we can make some assumptions as far as what impacts this could have on the demand side. James, what do you think? Are we going to expect higher request volumes on the 18th?
James Clark 08:05
I mean, I'm always happy to make outlandish statements. Just from prep for this, one of the things that Jesse pointed out is that organically, most of our clients see annual increases of 15 to 30% without EU e-Evidence in existence. From the project groups that we've been involved with and the SIRIUS project, when we've been chatting to the teams there, it really varies. People are expecting somewhere between a 30% and a 300% increase in volume. No one's talking about a reduction in volume. And I think if I think about human nature, law enforcement have known that this is coming for a long time, and law enforcement know that they will now have a regulation where if they raise the request, they will get the data back. It's no longer about voluntary disclosure and a privacy team making that decision. So I can't see how there isn't something close to a tsunami level event of all of these agencies and law enforcement platforms that are waiting to be able to issue these orders and get this data back, having been frustrated basically since 2018 when GDPR came in.
John Weeke 09:17
Agree. And Jesse, you just shared a stat that we're seeing an increase year over year in the number of requests already in the EU. Is that right?
Jesse Goodman 09:31
Yeah. So we've run aggregated data analysis across our customer base, which is hundreds of thousands of requests over the past two years, and as James mentioned, we have seen on average about a 15 to 30% increase in requests to our customers across the EU. And that is pretty diverse. We see requests from most EU member states. Now whether or not, and this is where James and I and others have some interesting debate, there is enough resources and administrative support on the government side across these countries to be able to open the floodgates of requests. I think that's a great topic to discuss. As well, there are now mechanisms to alleviate sort of optional response or MLAT processes. We're not sure what the level of increase will be on top of what we've already seen.
John Weeke 10:38
In addition to potential increases in volume, the number that keeps on getting thrown out is 2%. A 2% potential fine for non-compliance. Is this a real thing? This is of total revenue, so we could be talking a heck of a lot of money. Mike or Avery, what do you think?
Avery Oracheff 11:07
I do think that this is something that's listed in the regulation and is a figure that's meant to encourage service providers to respond to these requests within the deadlines. That being said, this is a common figure that's in many different regulations across the EU, so we don't know for sure that this is going to be enforced on day one. But I'll let James go, I know you also have some context here.
James Clark 11:30
Well, I think just the meetings that we've been involved with, with various national entities and the service providers that we're working with, there's this hope that there is a sensible introduction phase and they aren't coming out with fines on day one. Obviously there's some challenges in member states meeting the regulatory deadline in terms of getting architecture in place to issue this, and so there's a hope that there is a kind of sensible integration process to give service providers the chance to get up to speed. Obviously, we have seen fines in other regulatory regimes across GDPR, OSA, DSA, so it's definitely there. But we see this level of fine regularly included within a regulatory regime, so I don't think it's anything particularly special that anyone needs to think about differently.
John Weeke 12:20
Let's get to the final general question before we dig into the Q&A, of which there are many, and they're great. Thank you for submitting. We're gonna get to as many of these as we can. Generally, what are our technical options when it comes to dealing with this? Ike, we haven't heard from you yet, and I know you're deep into it, so I'm gonna throw this to you.
Ike Anude 12:46
Yeah. So the technical options for handling e-Evidence requests, or European production orders, is gonna be mainly the API that is supposed to be provided by the Commission, and their platform. They call it the reference implementation, the RI platform. Both of these platforms connect directly to eCODEX within your member state and are able to handle communication between member states. So eCODEX is kind of the infrastructure that already handles some of that interstate communication, but the main addition is going to be both the API and the reference implementation that allows service providers to handle requests directly from member states outside of their enforcing authority.
John Weeke 13:32
Avery or Jesse, is there anything you'd like to add in terms of these technical options?
Jesse Goodman 13:39
Yeah, I can start with that. What Ike referenced is definitely a big part of it that we've been preparing with our customers. We have built an API to the ETSI standard, which I suggest everybody take a look at if you haven't already. It is very detailed in terms of the technical architecture and how to set that up. I think that is the ideal solution down the road, when it is available, though we're seeing delays across pretty much every member state in opening that up for testing and implementation. We are also pursuing alternative paths. So Kodex, email, fax, regular portals that exist today are still applicable for member states that may be in scope for requests for you as a service provider, that do not have reference infrastructure in place or their systems in place to be able to serve and receive responses to requests. And that's where these alternative means, through Kodex or through other channels, are still available for the deadline, day one, especially if the bills for the legislation are passed within the member states that are in scope for you. That's definitely one method. We are also seeing a third channel where there might be a reference system in place for a member state, but no API and potentially no desire to use alternative channels. And so there are three different approaches that are definitely surfacing that I think will evolve over time. We're trying to understand those different scenarios and monitor each one of them. And from a Kodex perspective, we're prepared to receive requests manually just like we do today, through verified agents, through a centralized system, or through API. And even in the scenario where there's a member state that issues requests through their own system, there are still channels to be able to intake that manually and still use whatever case management system you have as a system of record. So there might be a bit of a hybrid approach to start, and ideally all of this then gets centralized and streamlined through API over time.
Ike Anude 16:20
If I could go, I could take Monty's latest question. What he asked was, what are the latest timelines on the API implementation? When realistically do we believe the decentralized system will roll out? So I wanna separate two things. First off, the decentralized system, they call it the DIS. This is already preexisting. This is eCODEX. To call it a messaging platform might be a bit of a big word for what it is, but it's a decentralized network and messaging protocol to allow governments within the EU to communicate with each other. The API implementation will depend on the member state in terms of timeline. The API implementation is currently being developed by the European Commission. They have a testing group. There's a couple of companies and service providers that are testing with them currently. However, that API package needs to be sent to all the member states, who will then implement it under their own infrastructure. And that transition process should have happened a while ago. However, there's been all kinds of delays, all kinds of issues, and it is really hard to say for certain that they will be ready by X date. Some authorities are saying Q1 of next year, some are saying Q4 of next year. I think it's really hard to put an exact number on when that'll be done. But it is required by the regulation, so at the end of the day, they have to do it if they have transposed the regulation.
John Weeke 17:56
Related question here from Luke. Can you confirm if Kodex are setting up APIs directly with member states, or just the European Commission as the decentralized IT system? You kind of touched on it. Anything that you'd wanna add?
Ike Anude 18:13
Yeah. I touched on it a little bit, but again, the distinction is that the eCODEX system is something that the API connects to. Anything that the Commission is developing now connects to the eCODEX system. It's kind of the underlying infrastructure that connects all of these member states together.
Jesse Goodman 18:34
I'll add to that, John. As far as the API connection, we are working through our customers as a technical implementation partner, which is specified in the regulation and standard, to be able to support them in connecting the Kodex API that we build according to the ETSI standard with a specific member state portal. And so as soon as those are available and ready for testing, we are ready and supporting our customers and making sure that they have the most scalable compliant solution. For any of the member states that are a little ahead of the game, like Ireland or Germany, some others, they are starting with sort of a phase one that includes some of the larger tech providers like Meta, Google, those that you would expect. And we are actually in discussion with those large tech providers to be able to share knowledge and best practice so that when they get to the next phase, we're able to learn from anything that happened previously and apply that to support our customers as their technical implementation resource.
John Weeke 19:48
Great. So speaking of being the technical implementation resource, this is another question we've gotten a lot. What if a member state pushes back on working with Kodex as a third party? Obviously we want to be your solution for everything here, but we've seen some early signals that, can we even be in the room?
Jesse Goodman 20:17
So the answer is, we have been in the room, and have been working with our customers who are in working groups with different member states and the EU Commission. And they have brought us as kind of a plus one to those sessions to be able to support them as their implementation partner. Through the registration process, we've also sent out guides, which we can share after the session, on how to register. And within that registration process, there are options to be able to select how you wanna receive requests for that specific member state. API is one of those options where you can select that, and we provide an endpoint URL on behalf of our service providers so that they can reference our standard API implementation as one of the options to receive requests when that technical capability is ready.
John Weeke 21:19
So at the end of the day, it is your relationship with the member state. You're setting it up, you're creating your entity if you're creating it from scratch, and you can designate Kodex as the way of handling these requests. So we're all figuring it out together, but the conversation at the end of the day shouldn't be too tricky.
Jesse Goodman 21:46
And I'll just... because we're in the spirit of challenging each other a little bit, John, I would say these words matter. The service provider is the legal entity that is signing up to receive requests, so those are our customers in this scenario. We are the technical implementation partner for service providers. And so I understand, we provide a service, and often that's a common term to use. In this case, I think that's where some of the confusion happens, because those terms are important and they have to tie back to the standard and the regulation.
John Weeke 22:25
Agreed. And these are actual terms in the regulation itself, correct?
Jesse Goodman 22:31
Yeah, exactly. So we'll learn, just like every company has its own acronyms and everything. There's a whole language here, and I think we're all learning that so that we're speaking the same language.
John Weeke 22:43
So I think a related question here from Paula, maybe already asked and answered, but have you received assurances from the EC and/or EU member states that they will accept providers integrating with Kodex's solution as compliant? Answer in relation to both the short-term solution and the longer term eCODEX API integration we are offering. Is there a difference between the short term versus the long term?
Ike Anude 23:12
I can take that one. Just to add to what Jesse said, 100%, words matter. We're not service providers, but the best way to think of us is as transparent to the member states. So for the most part, they are going to interact with our customers and see them as service providers. We're just handling, shuttling the requests back and forth and handling some of the operational business workflows. But in terms of assurances from the EC and the EU member states that they'll accept Kodex's solution as compliant, they will be developing according to a very specific standard that we had a hand in creating. So we've influenced some of the different endpoints and the business workflows within this particular spec. And as long as we are compliant with that spec and they are compliant with that spec, we should be compliant overall.