The EU e-Evidence Regulation: What UK Businesses Need to Know Before 18 August
12th August 2026
On 18 August 2026, Regulation (EU) 2023/1543, the EU’s e-Evidence Regulation, becomes applicable across every member state except Denmark. It allows a judicial authority in one member state to issue a European Production Order directly to a service provider in another, bypassing the slow mutual legal assistance process. The PROVIDER has ten days to comply, or eight hours in an emergency, and non-compliance can attract penalties of up to 2% of total worldwide annual turnover.
What is a PROVIDER?
A producer under Regulation (EU) 2023/1543 is a service provider or other person who creates, stores, processes or otherwise handles electronic data that may be requested by competent authorities as electronic evidence.
An example of a producer would be Microsoft, where it stores customer email or cloud data that may be requested as electronic evidence.
This is a criminal justice instrument, not a data protection one, and it does not change your UK GDPR obligations. But it is worth understanding, because it undermines an assumption many organisations have built their procurement decisions on.
The ‘European provider’ assumption
Plenty of organisations have responded to the US CLOUD Act by moving to a European supplier and treating the matter as closed.
What Is the CLOUD Act?
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a U.S. federal law passed in 2018. It allows U.S. law enforcement to compel American companies to provide access to data stored abroad, even if that data belongs to non-U.S. persons and resides in data centers located in the UK or European Union.
That includes:
- “Sovereign” Cloud providers like Microsoft, Google and Amazon
- Communication tools like Teams or Slack
Any U.S.-owned platform storing data globally.
If the data sits outside American jurisdiction, the thinking goes, it is beyond American legal process. That is broadly true, and it misses the point: the EU has now built its own fast, direct mechanism for compelling disclosure, and your European provider sits squarely within it.Put simply, the question was never only ‘where is the data’, but ‘who can be compelled to produce it, and how quickly’. A provider that can read your data can be ordered to disclose it, whether it sits in Virginia, Frankfurt or Dublin.
Does the EU Regulation apply to UK organisations?
For most organisations, not directly. The Regulation places obligations on service providers: cloud and hosting companies, communications and messaging services, online marketplaces and similar. If you are a customer rather than a provider, you have no obligation under the Regulation itself. The companion Directive requires in-scope providers to designate an establishment or legal representative in the EU to receive orders.
There is an important exception. The Regulation applies to any provider offering services in the EU, wherever it is based. A UK software, SaaS or platform business with EU users is in scope, Brexit notwithstanding, and should be taking advice on designating a legal representative and on the operational steps required before August.
What this means in practice
For everyone else, the value is in what this tells you about your supply chain. Three things follow.
First, know your processors. If you cannot list which providers hold your personal data and where, you cannot assess this or anything like it. That is a record of processing activities (RoPA) question before it is anything else.
Second, look at your contracts. Reputable providers commit to notifying customers of law enforcement requests where legally permitted, and to challenging overbroad orders. Some do not. That clause is worth finding before you need it, alongside the work many organisations are already revisiting on the international transfer regime.
Third, be realistic about encryption. Where a provider holds no key capable of reading your content, an order served on it yields far less. That is a genuine risk reduction, but not a universal answer: it constrains functionality, shifts key management onto you, and does nothing for the metadata a provider must hold to run the service.
A note on proportion
The package exists because cross-border investigations were genuinely hampered by a process that could take the better part of a year, and it is more calibrated than the headlines suggest. Subscriber data can be sought for any criminal offence, but traffic and content data require an offence carrying a maximum penalty of at least three years, and a request for content data must be validated by a judge. Where traffic or content data is sought, the authorities in the provider’s own member state are notified and have ten days to raise grounds for refusal. This is not a surveillance regime. Equally, those safeguards rest on a Directive most member states have not yet transposed, a fair criticism the Commission has itself pursued through infringement proceedings.
How Griffin House Consultancy Can Help
The practical lesson is an old one: know your data, know your suppliers, and read the contract. We help organisations map their processing, review processor arrangements and contractual terms, and build the records that make questions like this answerable in an afternoon rather than a fortnight. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.