Signal Scanner · REGULATION, STANDARDS & POLICY CHANGE · 31 August 2026

Deputised: EU Criminal Production Orders Now Land Directly on Service Providers

The e-Evidence Regulation became applicable on 18 August 2026: authorities in any participating EU state can order firms to produce user data within 10 days, 8 hours in emergencies, under fines of up to 2% of worldwide turnover. Exposed: cloud, telecoms, platforms, registries, fintech, legal and trust-and-safety functions.

The consensus on European regulation in 2026 is retreat: omnibus simplification, delayed AI obligations, lighter reporting. On 18 August something moved the other way. Regulation (EU) 2023/1543, the e-Evidence Regulation, became fully applicable, and a prosecutor in one member state can now serve a production order directly on a company's designated EU addressee in another, ten days to comply, eight hours in an emergency, with the host state's courts mostly out of the loop (Reed Smith, 11/08/2026). The regime moves enforcement work inside corporate legal departments. For the next two years the cost and the legal risk of that transfer sit with firms, while the connecting infrastructure is still being assembled.

Signal Identification

A regulatory pivot. While the EU cuts substantive reporting burden, its enforcement layer is being rebuilt through compelled intermediaries: registration duties, response clocks and turnover-linked fines make providers the operational endpoint of twenty-six national criminal-justice systems, Denmark excepted. The readiness gap at go-live, most member states untransposed and the shared IT system unfinished, puts the regime's early costs on firms.

Time horizon: 0-3 years (duties live 18 August 2026; decentralised IT system phases in 2027-2028; first fines and case law 2027-2029)
duties live; system phases in2026202720282029
Plausibility band: High
LowMediumHigh
Geographic / Jurisdictional Scope: Primary: EU-26 (Denmark does not participate), with Germany and Ireland as operational hubs. Spillover: US, UK and other third-country providers offering services in the EU.
PrimaryEU-26 (not DK)GermanyIreland
SpilloverUS providersUK providersOther third-country
Sectors exposed:
Cloud and hostingTelecoms, email and messagingPlatforms and marketplacesDomain and IP registriesFintech and gamingLegal, privacy and trust-and-safety functions

What's Changing

The clocks are the headline. A European Production Order must be met within 10 days, or eight hours in emergency cases; the Commission contrasts that with up to 120 days for a European Investigation Order and an average of 10 months for mutual legal assistance (European Commission, accessed 31/08/2026). Non-compliance carries penalties of up to 2% of worldwide annual turnover, and providers already offering services in the EU on 18 February had to designate their EU addressee by 18 August (Reed Smith, 11/08/2026).

Germany shows what the machinery looks like when it is built. The EBewMG, promulgated on 12/03/2026 (Bundesgesetzblatt, 12/03/2026), makes the Bundesamt für Justiz the central authority validating registrations and connecting providers to JUDEX (Bundesamt für Justiz, accessed 31/08/2026), with fines of up to €500,000 or 2% of worldwide turnover (Heuking, 19/08/2026). Registration tells the other story: by 18 August the BfJ held 193 notifications against a government estimate of roughly 9,000 covered providers (Heuking, 19/08/2026).

Most of the union is behind. Besides Germany only eleven member states have adopted implementing legislation, and the justice ministry expects Germany to be initially the only state able both to send and to receive orders through the secure decentralised IT system (Heuking, 19/08/2026); Ireland, hosting the European operations of the large US platforms, can be sent orders but cannot yet issue them. EuroISPA's June position paper: providers need at least 18 months from confirmed technical specifications, “and those specifications have not been delivered anywhere in the EU” (EuroISPA, 29/06/2026).

The response clock collapses: 10 months to 8 hours

Each row magnifies the orange slice of the row above Mutual legal assistance 10 months European Investigation Order up to 120 days e-Evidence production order 10 days emergency: 8 hours Indigo: full deadline at each stage. Orange: the next, shorter clock.

Response times under the successive cross-border evidence channels. Source: European Commission.

Disruption Pathway

Two phases, then a hinge. Until the shared IT system binds, roughly a year after the Commission adopts its implementing acts (European Commission, accessed 31/08/2026), orders will move over interim channels to whichever addressees are registered; the operative constraint is each state's build-out, not the regulation: Germany can issue today, most others cannot (Heuking, 19/08/2026). As transpositions and connections land through 2027 and 2028, volume shifts from bilateral police cooperation into the standing order channel. The hinge is enforcement posture: the first BfJ fines, and whether the Commission concedes the readiness-tied grace period industry has asked for (EuroISPA, 29/06/2026).

Stress concentrates on three seams: mid-sized cloud, hosting and gaming firms facing eight-hour clocks with no law-enforcement-response function; multinationals whose purely domestic subsidiaries sit outside the directive's scope, which turns corporate structure into an enforcement variable (Heuking, 19/08/2026); and remedies, where German scholarship notes that for content data, the most rights-intensive category, review comes only after disclosure has already happened (KriPoZ, 01/06/2026). Two adaptations follow. Law-enforcement response becomes a staffed, 24/7 corporate function with escalation paths and data-category mapping (Reed Smith, 11/08/2026). And providers begin engineering registration, retention and subsidiary structure around the regime's edges.

Why This Matters Now

The constituency is general counsel, privacy officers and infrastructure boards of any firm that stores or moves EU user data, wherever it is headquartered. The assumption needing revision is that criminal-evidence demands arrive occasionally, via national police, filtered by local courts. Since 18 August they can arrive from any participating jurisdiction, on the clock, addressed to a function most firms have not built; Germany's 193 registrations against roughly 9,000 expected providers say the median in-scope firm is already late (Heuking, 19/08/2026). Registration, an order-validation playbook and an out-of-hours escalation path are this quarter's work, not next year's.

Decision-action posture for this signal: Decide — the designation duty and fine exposure are already live and the registration gap is measurable, so boards should authorise the EU addressee and a 24/7 response process this cycle, whatever pace enforcement sets.

Counter-Argument

The strongest objection is that this is another EU delivery gap. The IT system is unfinished, specifications undelivered, most member states untransposed, and EuroISPA argues that “Enforcing the law before the conditions to comply with it exist would be disproportionate” (EuroISPA, 29/06/2026). On that reading the regime starts as paper, order volumes stay low, and firms that wait lose little.

Waiting misreads where the risk sits. The duties bind the firm, not the infrastructure: the designation deadline has passed (Reed Smith, 11/08/2026), German fines of up to €500,000 or 2% of turnover are in force (Heuking, 19/08/2026), and orders can already be issued by the one state that is ready, into every registered addressee. An unready regime is more dangerous for an unready firm, because early orders arrive over improvised channels against untested processes. The gap argues for building now, at leisure, rather than during a first eight-hour deadline.

Implications

This is durable. The regulation is in force, the German machinery exists (Bundesgesetzblatt, 12/03/2026), and the design, direct duties on providers backed by turnover-linked fines, matches the EU's wider pattern of direct duties for online content, data retention and lawful access. On this report's reading, e-Evidence is the first operational piece of a rebuilt European lawful-access layer, and its compliance costs land on firms before its investigative benefits reach states. Scale providers with standing law-enforcement-response teams absorb it; mid-sized European hosts and third-country firms discovering the regime late carry the transition risk. The window to build before volumes arrive runs roughly to the end of 2027.

Early Indicators to Monitor

Disconfirming Signals

Strategic Questions

Keywords

e-Evidence Regulation; European Production Order; EPOC; e-Evidence Directive; legal representative; designated establishment; EBewMG; Bundesamt für Justiz; decentralised IT system; e-CODEX; cross-border data access; lawful access

Bibliography

Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.


Prepared by Shaping Tomorrow: 31 August 2026