As of 18 August 2026, the new European framework on the cross-border gathering of electronic evidence in criminal matters applies, comprising Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings and for the execution of custodial sentences following criminal proceedings (the “Regulation”) and Directive (EU) 2023/1544 laying down harmonised rules on the designation of designated establishments and the appointment of legal representatives for the purpose of gathering electronic evidence in criminal proceedings (the “Directive”).
The new legal framework seeks to facilitate cross-border access to electronic evidence in criminal proceedings by allowing competent authorities of a Member State, under the conditions laid down by the Regulation, to directly address the designated establishment or legal representative of a service provider from another Member State, regardless of where the data are stored.
For the service providers concerned, the new legal framework entails the need to establish appropriate internal mechanisms for receiving, verifying and executing orders, while complying with strict compliance deadlines.
The Regulation introduces two main instruments, as follows:
- European Production Order – represents a decision issued or validated by a judicial authority of a Member State, ordering the production of electronic evidence stored by, or on behalf of, the service provider, and which is addressed to the designated establishment or legal representative of the service provider in another Member State. The order is transmitted through the European Production Order Certificate (“EPOC”);
- European Preservation Order – represents a decision issued or validated by a judicial authority of a Member State, ordering the preservation of electronic evidence for the purposes of a subsequent request for production, and which is addressed to the designated establishment or legal representative of the service provider in another Member State. The order is transmitted through the European Preservation Order Certificate (“EPOC-PR”).
I. Which service providers are covered?
The Regulation applies to service providers offering services in the European Union (“EU”) that fall within one of the following categories:
- service providers of electronic communications services (such as voice-over-IP services, instant messaging and email services);
- service providers of internet domain name and IP numbering services (such as IP address assignment services, domain name registry services, domain name registrar services and domain name-related privacy and proxy services);
- service providers of certain information society services that enable their users to communicate with each other or that enable the storage or other processing of data on behalf of users, where the storage of data is a defining component of the service (this category has a broad scope and may include, among others, services such as online marketplaces and other hosting services, including where the service is provided via cloud computing technology, as well as online gaming platforms).
II. Territorial applicability of the Regulation and the Directive
The existence of an establishment in the EU is not a condition for the application of the Regulation. It is sufficient for the provider to offer services in the EU and to have a “substantial connection” with at least one Member State. A “substantial connection” may result from the existence of an establishment, a significant number of users or from the targeting of activities towards one or more Member States.
In this context, for providers established outside the EU, the mere accessibility of a website in a Member State is not, in itself, sufficient to demonstrate the existence of a “substantial connection”. Instead, factors indicating that the provider actively targets its activities towards the market of the relevant Member State are relevant.
As regards the Directive, it applies to the above-mentioned service providers that offer their services in the EU. The Directive does not apply to service providers established on the territory of a single Member State that offer services exclusively on the territory of that Member State.
III. The designated establishment and the legal representative
The Directive requires the service providers concerned to designate an establishment or appoint a legal representative in the EU, responsible for the receipt of, compliance with and enforcement of orders issued by competent authorities. The designated establishment or legal representative must be established or reside in a Member State where the provider offers services and which takes part in the EU instruments applicable to the gathering of electronic evidence in criminal proceedings.
In principle:
- service providers with legal personality established in the EU must designate at least one designated establishment in writing;
- service providers with legal personality not established in the EU, but offering services on that territory, must appoint at least one legal representative in a Member State where they offer services.
The designated establishment or legal representative must have the necessary powers and resources to handle the orders. The absence of adequate internal procedures between the provider and the designated entity cannot justify non-compliance, and the Directive provides, under the conditions laid down therein, for the joint and several liability of the provider and the designated establishment or legal representative.
IV. Deadline for the designated establishment and legal representative
Service providers that were already offering services in the EU on 18 February 2026 must fulfil the designation or appointment obligation by 18 August 2026. Service providers that start offering services in the EU after 18 February 2026 benefit from a period of six months from the date on which they start offering services in the EU.
Registration must be carried out through the European Commission’s decentralised IT system, namely the European Commission portal for the registration of service providers.[1]
V. Transmission of Production and Preservation Orders
Orders issued by competent authorities are addressed directly to the designated establishment or legal representative of the service provider concerned. Exceptionally, in emergency cases, where the designated establishment or legal representative does not react to the EPOC or EPOC-PR within the applicable deadline, the certificate may be addressed to any other establishment or legal representative of the same service provider in the EU.
VI. What do Production and Preservation Orders entail?
1. The European Production Order (EPOC)
By means of an EPOC, a service provider may be requested to produce electronic evidence existing at the time the certificate is received, namely:
- subscriber data;
- data requested for the sole purpose of identifying the user;
- traffic data;
- content data.
Conditions applicable to the issuing of the order
The conditions for issuing the order differ depending on the category of data, as follows:
- subscriber data and data requested for the sole purpose of identifying the user may be requested for any criminal offence, under the conditions laid down in the Regulation.
- for traffic data, other than data requested for the sole purpose of identifying the user, and for content data, the conditions are stricter. In principle, the order may be issued for criminal offences punishable in the issuing State by a custodial sentence of a maximum of at least three years, as well as, irrespective of that threshold, for the offences listed in Article 5(4)(b) and (c) of the Regulation, such as fraud and counterfeiting in relation to non-cash means of payment, sexual abuse and sexual exploitation of children, attacks against information systems and terrorist offences.
Production deadline
- Standard deadline - no later than 10 days following receipt of the EPOC. Where notification of the enforcing authority is required, production must also take into account the notification procedure and the authority’s ability to raise grounds for refusal.
- Emergency case – data must be produced without undue delay and at the latest within 8 hours of receipt of the EPOC. The Regulation restrictively defines such situations, primarily by reference to the existence of an imminent threat to the life, physical integrity or safety of a person or, under certain conditions, to the safety of a critical infrastructure.
2. The European Preservation Order (EPOC-PR)
An EPOC-PR does not involve the immediate transmission of data to the authority, but instead seeks to prevent the deletion, removal or alteration of data pending a possible subsequent request for production.
Applicable deadlines
- Preservation period and cessation of the preservation obligation - the data must be preserved without undue delay. As a rule, the obligation ceases after 60 days, unless the issuing authority confirms that a subsequent request for production has been issued.
- Extension of the preservation obligation - the authority may extend the preservation obligation by an additional 30 days, where necessary to allow for the issuing of the subsequent request. If the issuing of such a request is confirmed, the data will continue to be preserved for as long as necessary to enable it to be produced.
VII. What should the service provider do upon receiving an order?
The direct nature of the mechanism and the short deadlines make it necessary to have a well-defined internal process in place before receipt of an EPOC or EPOC-PR.
Immediately upon receiving an EPOC, the addressee must act promptly to preserve the requested data. From a practical standpoint, an adequate internal workflow should enable at least the following:
- rapid identification of the certificate and its transmission to the responsible persons;
- identification of the user, account and data concerned;
- preventing the deletion or alteration of the relevant data;
- verifying the applicable deadline and whether the case is an emergency case;
- verifying the information and formal requirements necessary for execution;
- ensuring the confidentiality, secrecy and integrity of the certificate and of the data.
The Regulation also governs situations in which the order cannot be executed as received. The addressee may flag, using the form set out in Annex III to the Regulation, among other things, that the EPOC or EPOC-PR is incomplete, contains manifest errors or insufficient information, that the data are not available, that the service does not fall within the scope of the Regulation, or that other impediments provided for therein exist.
Informing the person whose data were requested is, under the conditions of the Regulation, the responsibility of the issuing authority, while the provider is subject to confidentiality obligations regarding the certificate and the data produced or preserved.
VIII. Penalties applicable under the Regulation
The Regulation requires Member States to lay down effective, proportionate and dissuasive pecuniary penalties for infringements of certain obligations relating to the execution of EPOCs and EPOC-PRs and to the confidentiality and integrity of the certificates and data. Accordingly, the Regulation sets pecuniary penalties of up to 2% of the total worldwide annual turnover recorded in the preceding financial year.
Service providers are not liable for damage caused to users or third parties resulting exclusively from good-faith compliance with a certificate.
IX. Implementation in Romania
In Romania, the European framework is expected to be supplemented, subject to the adoption and entry into force of the relevant legislation, by the Draft Law establishing measures for the implementation of the Regulation, adopted by the Senate on 8 June 2026 under reference no. L272/2026 and subsequently registered with the Chamber of Deputies under reference no. PL-x 467/2026 (the “Draft Law”)[2]. In the version adopted by the Senate, the Draft Law sets out, among other things, the mechanism applicable where the addressee of a European order fails to comply with it within the prescribed time limit. The Draft Law is currently pending before the Chamber of Deputies.
In the event of non-execution of the order within the applicable deadline, the issuing authority may request the Romanian enforcing authority to proceed with its enforcement. Under the form of the Draft Law adopted by the Senate, the addressee has 48 hours from receipt of the request either to comply or to raise objections, within the limits of the grounds provided for by the Regulation.
At the same time, the Draft Law provides that unjustified non-compliance with the relevant obligations laid down by the Regulation may be sanctioned by the Romanian enforcing authority with a judicial fine ranging between RON 100,000 (approx. EUR 19,073) and 2% of the total worldwide annual turnover recorded by the service provider in the preceding financial year.
———————
[1] The notification form for service providers made available by the European Commission can be accessed at the following address: Notification Form for Service Provider
[2] Draft Law establishing measures for the implementation of Regulation (EU) 2023/1543 of the European Parliament and of the Council of 12 July 2023 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings and for the execution of custodial sentences following criminal proceedings, adopted by the Senate of Romania under reference no. L272/2026 and registered with the Chamber of Deputies of Romania under reference no. PL-x 467/2026, available at: https://www.cdep.ro/ords/pls/proiecte/upl_pck2015.proiect?cam=2&idp=23338.