A message, a cloud file, or the records linking an IP address to an account may be technically held in another country and controlled by a provider established outside the European Union. The EU e-Evidence package does not give authorities general access to accounts. It creates a defined cross-border procedure through which a competent authority in one participating Member State sends a certified order to a service provider's designated addressee in another participating Member State.

The central distinction is between a European Production Order and a European Preservation Order. The former requires the disclosure of specified data. The latter temporarily secures specified data against removal, deletion, or alteration, but does not by itself authorise disclosure. The rules apply from 18 August 2026 and combine short deadlines with conditions on judicial control, notification, refusal, professional privilege, data protection, and effective remedies.

Regulation (EU) 2023/1543 establishes European Production Orders and European Preservation Orders, the EPOC and EPOC-PR certificates, enforcement procedures, and rights for affected persons. It entered into force on 17 August 2023 and applies directly from 18 August 2026. Greece and Ireland are bound by it; Denmark does not participate.

Directive (EU) 2023/1544 requires Member States to ensure that service providers designate an establishment or legal representative in the Union for receiving and complying with orders. The transposition deadline was 18 February 2026. Providers already offering services in the EU on that date had to designate an addressee by 18 August 2026; providers entering the market later have six months.

Implementing Regulation (EU) 2025/1550 lays down the technical specifications for the decentralised communication system and entered into force on 18 August 2025. A corrigendum published on 13 July 2026 is legally significant: it removed wording that could have suggested an emergency bypass merely because no designated establishment or legal representative existed. Alternative service is available after an existing designated addressee fails to act within the deadline, not simply because no addressee was designated in the first place.

2. Proceedings, providers, and data within scope

The mechanism is for criminal proceedings. It is not a private discovery tool for civil litigation, commercial disputes, or general administrative inquiries. It also covers the narrow enforcement situation specified by the Regulation for a custodial sentence or detention order of at least four months, imposed following criminal proceedings, where the convicted person has absconded and the other statutory conditions are met.

Covered providers include electronic communications services; domain name and IP numbering services; registries, registrars, and privacy or proxy services; and information society services for which communication between users or the storage or processing of data is a defining component. Mere accessibility of a website from the EU is insufficient. A substantial connection is required, such as an establishment, a significant number of users, or activities targeted at the Union.

The Regulation distinguishes subscriber data, data requested for the sole purpose of identifying a user, traffic data, and content data. An order reaches data already stored by, or on behalf of, the provider when the certificate is received. It does not create a power to intercept communications in real time or collect future data.

3. Who may issue or validate an order

For an EPO seeking subscriber data or data requested for the sole purpose of identifying a user, the issuing authority may be a judge, court, investigating judge, or public prosecutor. Another authority competent under national law may issue it only with the validation required from a judicial or prosecutorial authority.

Traffic data other than data requested for the sole purpose of identifying a user, and content data, receive stricter control. The order must be issued or validated by a judge, court, or investigating judge; a public prosecutor acting alone is not sufficient for those categories. A preservation order may be issued by a judge, court, investigating judge, or public prosecutor, or by another competent authority subject to validation.

Every order must be necessary and proportionate, must be available in a comparable domestic case, and must respect the rights of the suspected or accused person. A suspect or defence lawyer may request that an order be sought where national defence rights allow it, but neither can privately send an EPOC to a provider.

4. What an EPO requires and what the EPOC certifies

The European Production Order is the judicial or validated decision. The EPOC is the standard certificate transmitted to the provider's designated addressee. It contains the information needed for execution without unnecessarily disclosing the underlying case. The addressee must preserve confidentiality and produce only the data specified in the order.

Subscriber data and data requested for the sole purpose of identifying a user may be sought for any criminal offence. Traffic and content data normally require an offence punishable in the issuing State by a maximum custodial sentence of at least three years. That threshold operates differently for the specifically listed EU offences, including terrorism, child sexual abuse, attacks against information systems, and fraud involving non-cash means of payment, where the Regulation's particular conditions are fulfilled.

The fact that the relevant server is located in a third country does not automatically exclude an order. The decisive questions include whether the provider offers services in the Union, whether a lawful cross-border addressee exists, and whether the substantive and procedural safeguards are satisfied.

5. What the EPO-PR and EPOC-PR do

A European Preservation Order prevents the removal, deletion, or alteration of specified data while a later production request is prepared. The EPOC-PR is the certificate received by the provider. Its command is to preserve the identified data immediately and narrowly, not to disclose them to the issuing authority.

The initial preservation period is 60 days. During that period, the issuing authority may extend it once for a further 30 days where the extension is necessary to allow a subsequent request for production to be issued. Preservation may continue beyond those time limits only if the authority confirms in time that the subsequent European Production Order, European Investigation Order, or mutual legal assistance request has already been issued. The data must then be preserved for as long as necessary so that they can be produced once the request is received. When preservation is no longer necessary, the authority must notify the addressee without undue delay.

This distinction matters to both defence counsel and providers. Compliance with an EPOC-PR does not prove that disclosure has been authorised and cannot cure defects in a later EPO. Preservation and production are separate legal steps, each with its own purpose and legal basis.

6. The 10-day and 8-hour deadlines

In the ordinary procedure, the addressee must act without undue delay and no later than 10 days after receiving the EPOC. In a valid emergency, the deadline is 8 hours. Emergency is narrowly defined: there must be an imminent threat to a person's life, physical integrity, or safety, including a corresponding threat arising from serious disruption to or destruction of critical infrastructure.

In a specified emergency, an EPO for subscriber data or data requested for the sole purpose of identifying a user, and an EPO-PR, may be issued without prior validation where validation cannot be obtained in time and equivalent domestic authority exists. Validation must then be sought within 48 hours. If it is refused, the order must be withdrawn and data already transmitted must be deleted or their use restricted as the Regulation requires.

The Commission's non-binding deadline guidance explains that the day of receipt is excluded when a period is expressed in days. Saturdays, Sundays, and public holidays count, but a period expressed in days that ends on a non-working day moves to the next working day in the enforcing State. For the 8-hour period, counting begins with the next full hour and there is no weekend or holiday extension. The guidance expressly states that only the Court of Justice of the European Union can give an authoritative interpretation.

7. Notification of the enforcing State and refusal

When an EPO seeks traffic data not limited to identification, or content data, the issuing authority must transmit the EPOC simultaneously to the enforcing authority. Notification may be omitted only where there are reasonable grounds to believe both that the offence was, is being, or is likely to be committed in the issuing State and that the person whose data are sought resides there. Notification normally suspends disclosure, except in a valid emergency.

The enforcing authority has 10 days to raise a ground for refusal, or 96 hours in an emergency. Article 12 provides four categories: immunities, privileges, or rules protecting freedom of the press and expression in other media; specific and objective grounds indicating a manifest breach of a relevant fundamental right; ne bis in idem; and lack of double criminality, subject to the Annex IV exception where the offence is punishable in the issuing State by a maximum custodial sentence of at least three years.

The authorities must consult before refusal. Part of an order may be rejected, or conditions may be imposed on use. If data have already been transmitted in an emergency and a valid ground is raised, the issuing authority must delete them, restrict their use, or comply with the conditions set by the enforcing authority.

8. What a provider may flag and how enforcement works

The designated addressee does not become the court reviewing the order. It may nevertheless use the Annex III form to report that execution is factually impossible, the certificate contains manifest errors, the data were not in the provider's possession or control when received, the service falls outside scope, or immunities, privileges, or media freedom may be affected.

If the addressee does not comply, the order may be transferred to the enforcing authority for enforcement. At that stage the Regulation provides closed grounds for non-enforcement, including lack of proper issue or validation, failure to satisfy substantive thresholds, factual impossibility, privilege, and a manifest breach of a fundamental right. National penalties must be effective, proportionate, and dissuasive.

9. Legal professional privilege, immunities, and media protection

The issuing authority must not issue an EPO for traffic or content data where it determines that the data are protected by an immunity or privilege under the law of the enforcing State, or by rules protecting freedom of the press and expression in other media. If the position is uncertain, it may seek clarification from the other authority directly or through Eurojust or the European Judicial Network.

Article 5(9) gives specific protection where professionally privileged data are stored or otherwise processed in infrastructure supplied to a lawyer or another protected professional for professional activity. An EPO for traffic or content data is permitted only if the professional resides in the issuing State, directly approaching that professional could be detrimental to the proceedings, or the privilege has been waived under the applicable law.

Legal professional privilege is not an undefined exception for every item connected with a lawyer. The communication, professional capacity, applicable national law, and any lawful waiver must be identified. The provider flags a risk on the basis of the certificate; the competent authorities make the legal determination.

10. Data protection, notice, and remedies

The GDPR continues to apply to providers, while Directive (EU) 2016/680 governs processing by competent law-enforcement authorities, together with the relevant ePrivacy rules. An order must be targeted, necessary, and proportionate. The addressee must use up-to-date technical and organisational measures to protect the confidentiality, secrecy, and integrity of certificates and data.

The issuing authority must inform the person whose data were produced without undue delay and explain the available remedies. Notice may be delayed, restricted, or omitted only while the conditions of Directive 2016/680 are fulfilled. The reasons must be documented in the case file and a concise justification recorded in the EPOC.

Any person whose data were sought by an EPO has a right to an effective remedy before a court in the issuing State. Review includes legality, necessity, and proportionality. If compliance conflicts with the law of a third country, a specific judicial procedure applies and execution is suspended while the conflict is assessed.

11. What changes for a Greek citizen, lawyer, and provider

For a citizen: the cross-border route is faster and no longer depends only on lengthy mutual legal assistance. That does not mean every police authority can directly enter a cloud account. A lawful order, the appropriate judicial or prosecutorial control, a defined data category, and access to a judicial remedy remain necessary.

For a lawyer: review should cover the data category, offence threshold, authority to issue or validate, any exception from notification, the reality of the claimed emergency, professional privilege, notice to the affected person, and domestic remedy deadlines. The label "e-Evidence" alone does not establish legality.

For a provider: practical compliance requires a clearly designated legal addressee, authenticity checks, limitation to the data ordered, secure preservation and transmission, an audit trail, and immediate escalation for privilege or error. The 8-hour deadline makes continuously available triage operationally prudent, although the Regulation does not prescribe one particular staffing model.

12. Greece's operational readiness on 30 August 2026

The Regulation applies directly in Greece from 18 August 2026. Direct applicability, however, does not by itself prove that every national institutional, administrative, and technical arrangement for issuing, receiving, notifying, enforcing, sanctioning, and communicating securely has been completed.

When checked on 30 August 2026, the EUR-Lex national-transposition page displayed "Number of measures: 0" for Greece under Directive 2023/1544. This establishes that no Greek measure was displayed as notified in that particular register at the time of checking. It does not by itself establish that no relevant national text exists or that every possible domestic act is ineffective.

The Commission readiness list updated on 27 August 2026 named only Germany, Ireland, Italy, and Sweden, with different issuing or receiving capabilities; Greece was not listed. The supportable conclusion is therefore that full Greek legal and technical operational readiness was not confirmed by the public official sources reviewed. It would go beyond those sources to claim that application was universally impossible.

The Commission's non-binding contingency Q&A states that, where no establishment or representative has been designated because the Directive was not transposed, an EPOC or EPOC-PR cannot simply be sent directly to the provider. Alternative secure channels under Article 19(5) address technical unavailability where the lawful actors and addressee exist; they do not cure missing competence or a missing legal addressee. European Investigation Orders and mutual legal assistance remain available.

13. Common misconceptions and official sources

  • An EPOC-PR preserves data; it does not by itself let an authority read them.
  • The 8-hour rule concerns the Regulation's narrow emergency definition, not every matter labelled urgent.
  • Server location does not automatically invalidate an order, but it does not remove substantive safeguards.
  • A provider may flag a problem; it does not issue a final judgment on fundamental rights.
  • The package does not impose general retention, live surveillance, or a general duty to decrypt.
  • It does not abolish European Investigation Orders, mutual legal assistance, or the separate Council of Europe framework.

Legal note: Official sources were checked on 30 August 2026. Binding EU legislation is distinguished from non-binding Commission guidance and from the cautious inference concerning operational readiness. This article does not determine the legality of a particular order and is not individual legal advice.