Until 18 August 2026, obtaining from Meta, Apple or Google the name behind an account, the contents of a mailbox or a connection history meant persuading a foreign State, and those States refused. Since that date, a judge may address the company holding the data directly, wherever it stores them: ten days to respond, eight hours in an emergency, up to 2 % of worldwide turnover for a refusal. Company receiving the order, victim of anonymous content, person whose accounts are targeted: the question is no longer what the law allows, but who acts first.
- What the e-Evidence Regulation changes
- What the Regulation opens up, depending on the position in the proceedings
- Responding to an order received by a company
- Identifying the author of an anonymous account
- What the courts can obtain from the accounts of a person under investigation
- Why identification failed before 18 August 2026
- Frequently asked questions
What the e-Evidence Regulation changes
Regulation (EU) 2023/1543 of 12 July 2023 applies from 18 August 2026 in twenty-six Member States. Denmark does not take part; Ireland does, whereas it had stayed outside the European Investigation Order. The State that hosts the European headquarters of Meta, Apple and Google thus enters a binding system it had so far escaped. Directive (EU) 2023/1544 supplies its architecture. Four rules define its reach for the reader; the full regime, categories of data, grounds for refusal and legal remedies, is set out on our page on the European Production Order (EPOC).
The addressee is no longer a State but a company. Every service provider already offering services in the Union on 18 February 2026 had to designate in writing, by 18 August 2026 at the latest, an establishment responsible for receiving and executing orders, and to notify it to the authority of the State where it is located; providers that entered the market since then have six months. The order is addressed to that establishment directly, without any State intermediary. The Directive requires these designations to be published on a dedicated page of the European Judicial Network in criminal matters, but that publication is not yet effective. A State’s refusal no longer has any place in the procedure: there is no longer a requested State, only a company under obligation.
The location of the data becomes legally irrelevant. The obligation applies regardless of where the data are located, and the Regulation expressly prohibits basing an objection on the mere fact that they are stored in a third country. A conflict with an obligation under the law of a third country may, by contrast, give rise to a reasoned objection, raised within ten days and having suspensive effect.
The deadline falls from several months to ten days. The duty to preserve arises upon receipt of the certificate. Transmission takes place within ten days, or within eight hours in emergency cases, a notion strictly defined as an imminent threat to the life, physical integrity or safety of a person, or to critical infrastructure. On the scale of digital evidence, the gap with the one hundred and twenty days of the European Investigation Order is not a procedural improvement: it is a change in kind.
Refusal becomes costly. Member States must provide for pecuniary penalties of up to 2 % of the service provider’s total worldwide annual turnover for the preceding financial year. The designated addressee and the service provider may be held jointly and severally liable for the breach; in return, a provider that complies in good faith is not liable for any harm that may result to its users or to third parties.
One reservation must be made, and it matters. France has published no text giving effect to this system, so that the national penalty regime does not yet exist. On 27 March 2026, the European Commission sent a letter of formal notice to twenty-two Member States, France among them, for incomplete transposition of the Directive accompanying the Regulation. The situation is transitional. It relieves the addressee of none of the obligations that the Regulation, which is directly applicable, imposes on it when an order is issued by an authority of another Member State.
What the Regulation opens up, depending on the position in the proceedings
The table below does not set out the regime: it indicates what the new situation opens up, what it leaves unresolved and what matters most, according to the place one occupies in the proceedings.
| Position in the proceedings | What the Regulation opens up | What it does not resolve | What matters most |
|---|---|---|---|
| The company receiving an order | Nothing: it bears a new, immediate and sanctioned obligation | The internal allocation of roles within the group, which cannot be raised against the issuing authority | The first hours: the duty to preserve is immediate, and a badly framed objection is lost |
| The victim seeking to identify an author | Identification becomes possible without mutual legal assistance and without any seriousness threshold, including for an offence punishable by a fine | Access to the content of messages, which remains subject to a threshold and to a judge | Time: the data are retained for only a few weeks, and nothing obliges anyone to keep them longer |
| The person under investigation | A remedy before the courts of the issuing State, covering necessity and proportionality | Prior information: it may be delayed, restricted or omitted | The category of data targeted, which alone determines who was entitled to issue the measure |
Responding to an order received by a company
The scope goes well beyond the major platforms: online marketplaces enabling users to communicate, hosting and cloud computing services, online gaming and gambling platforms all fall within it, provided there is a substantial connection with the Member State concerned. The designated addressee cannot hide behind the absence of internal procedures with the service provider, nor behind the fact that it is not authorised to release the data.
The first hours decide almost everything: the duty to preserve is immediate, and a badly framed objection is lost. Two grounds are expressly ruled out, the place where the data are stored and the absence of an equivalent provision in the law of a third country. What remains open must be raised within the deadline, through the right channel and on the right basis, failing which the company either complies or exposes itself.
The firm assists addressee companies from the moment the certificate is received: assessment of the measure and of the authority that issued it, framing of objections within the deadline, and organisation of the internal receipt process. Contact the firm →
Identifying the author of an anonymous account
Subscriber data and data requested for the sole purpose of identifying the user are subject to no seriousness threshold: any criminal offence suffices, including those punishable by a mere fine. No notification to the enforcing State is required for these categories, and a public prosecutor may issue the order. The obstacle that produced the finding of no case to answer in February 2026 therefore no longer exists for identification purposes.
The difficulty has shifted. It is no longer legal but chronological: the Regulation creates no general retention obligation and covers only data stored at the time the certificate is received. A perfectly lawful order, issued too late, will run into an earlier, lawful deletion. The first request to make is therefore not production but preservation: the European Preservation Order freezes the data for sixty days, extendable by thirty, and may be issued for any criminal offence. In a French judicial investigation, the civil party applies for it by a written and reasoned request for an investigative act, to which the investigating judge, if unwilling to grant it, must respond by a reasoned order within one month. The file is prepared accordingly: time-stamped screenshots, the addresses of the content, account identifiers, so that the request designates precisely the data whose preservation and then production are sought.
The firm acts for civil parties in identification cases and cases involving unlawful online content: drafting the complaint, requests for investigative acts seeking a preservation order and then a production order, and monitoring their execution. Contact the firm →
What the courts can obtain from the accounts of a person under investigation
The answer depends less on the extent of the magistrate’s powers than on the regime applicable to the category of data sought, and on the technical configuration of the service used. Identification data remain accessible without any seriousness threshold; content requires a judge and a threshold of three years’ imprisonment, or one of the offences the Regulation lists by reference to four directives, essentially those committed by means of an information system.
The service provider must produce encrypted data, but bears no obligation to decrypt them. The information owed to the person concerned, where provided for, may be delayed, restricted or omitted for as long as the conditions laid down by data protection law are met. The Regulation also opens a route for the defence: the suspect, the accused person or their lawyer may request that an order be issued, which makes it possible to have exculpatory data frozen before they disappear.
The firm acts for the defence in proceedings based on cross-border digital evidence: review of the issuing authority against the category of data, remedies before the courts of the issuing State, and requests for orders in the defendant’s favour. Contact the firm →
Why identification failed before 18 August 2026
The data sought are almost always held by a company established outside France, most often in Ireland, and sometimes stored in the United States. To obtain them, the magistrate had to ask another State, through international mutual legal assistance or the European Investigation Order. The latter gives the executing State thirty days to decide on recognition, then ninety days to execute the measure; the former is more likely to run to some ten months. All this for evidence whose retention period is often counted in weeks. The European Investigation Order was, moreover, ineffective as regards Ireland, which is not bound by the Directive establishing it, and neither is Denmark.
Above all, the requested State could refuse, and it did. The case decided on 10 February 2026 shows the scale of it: a television channel spent five years seeking the name of the author of twenty-nine messages posted on a social network, and the proceedings closed with a finding of no case to answer, the investigating chamber having held that requests for mutual legal assistance would meet with a refusal from the American and Irish authorities. The American authorities raised the First Amendment to their Constitution against requests concerning press offences; the Irish authorities, the absence of any criminal offence of defamation in their law and the lack of jurisdiction of their courts over data stored in the United States. No sanction attached to these refusals. French law, for its part, was not the obstacle: since 2023, the Criminal Chamber has repeated that Article 60-1-2 of the Code of Criminal Procedure does not prevent operators and hosting providers from being required to produce data relating to the civil identity of the user, including at the request of the victim of public defamation, an offence punishable by a mere fine. The formula first appears on 14 March 2023 (nos 22-90.018 and 22-90.019), is repeated on 30 April 2024 (no 23-85.683) and again on 10 February 2026, in three decisions delivered by a restricted bench and not published in the Bulletin. The law authorised the request; what was missing was the means of enforcing it.
The Criminal Chamber upholds the finding of no case to answer, made for want of identification of the author of statements posted on a social network, holding that the investigating chamber had made a sovereign assessment that requests for mutual legal assistance would have met with a refusal of execution by the American and Irish authorities, “irrespective of the obligation to retain those data incumbent on the hosting provider under Article L. 34-1 of the Postal and Electronic Communications Code”. The duty to retain remained; the retained data remained out of reach.
Read the decision →An older judgment, published in the Bulletin, sets out its basis. In it, the Criminal Chamber accepts that investigators may gather information outside their district, including by addressing a request directly to a person domiciled abroad, but only on condition that the person remains free not to answer. The direct request was tolerated only because it carried no force: the freedom not to answer was the counterpart of the direct route. It is this freedom that the Regulation removes. The same judgment set the second limit of the former regime, by excluding the content of correspondence from what a production request could reach; the Regulation brings that content within scope, subject to a threshold and to a judge’s decision.
While judicial police officers in principle have jurisdiction only within the territorial limits in which they habitually perform their duties, “they are not prohibited from gathering information, notably by means of electronic communication, outside their district, even by addressing a request directly to a person domiciled abroad, that person remaining, in that case, free not to answer”. The handing over of documents within the meaning of Article 77-1-1 of the Code of Criminal Procedure means documents held by the operator of a messaging service, “excluding, as in the present case, the content of the correspondence exchanged”.
Read on Légifrance →Frequently asked questions
My investigation stalled because the author could not be identified: can I revive it?
Identification data may now be requested directly from the service provider, without going through mutual legal assistance, for any criminal offence and without any seriousness threshold, including offences punishable only by a fine. The obstacle that produced findings of no case to answer for want of identification has disappeared for this category of data. The difficulty has shifted to timing: the data sought are often retained for only a few weeks.
Must one wait for French transposition before acting?
No. An EU regulation applies without any national text; what is missing in France is the penalty regime for a defaulting provider and the internal organisation of the issuing process, which the accompanying Directive leaves to the Member States. The practical conditions under which a French magistrate issues a certificate today have not yet been clarified by practice. That is a reason to make the request now, in writing and with reasons: a request dismissed without sufficient grounds opens a remedy, and a request never made opens none.
How can I find out whether my data were obtained through this route?
The issuing authority must inform the person whose data were requested and indicate the available remedies. It may, however, delay, restrict or omit that information for as long as the conditions laid down by data protection law are met, the reasons being placed on the case file. Verification will therefore have to take place when the case file is accessed, since the measure is not always identifiable as such on its face.
My company has received a request from a judge in another Member State: is it obliged to comply?
Yes, if it is the service provider’s designated addressee. The duty to preserve the data arises upon receipt of the certificate; transmission takes place within ten days, or within eight hours in emergency cases. A breach exposes the company to a pecuniary penalty of up to 2 % of its total worldwide annual turnover. Objections exist, but they are confined to short deadlines, and two grounds are expressly ruled out: the place where the data are stored and the absence of an equivalent provision in the law of a third country.
Does the Regulation concern my company if it is not a platform?
The scope goes well beyond social networks. It covers electronic communications services, but also online marketplaces enabling users to communicate with one another, hosting and cloud computing services, and online gaming and gambling platforms, provided that storage is a defining component of the service and that there is a substantial connection with the Member State concerned. The mere accessibility of a website is not enough.
Can I challenge a European Production Order, and before which court?
The remedy lies before a court of the issuing State and covers the legality of the measure, including its necessity and proportionality; for a French order, before the French courts. The Regulation further requires the issuing State, like any other Member State to which the evidence has been transmitted, to ensure that the rights of the defence and the fairness of the proceedings are respected when that evidence is assessed.
How long do I have to act before the data are erased?
The Regulation creates no general retention obligation: it covers only data stored at the time the certificate is received. A perfectly lawful order, issued too late, will run into an earlier, lawful deletion. The European Preservation Order makes it possible to freeze the data for sixty days, extendable by thirty, and may be issued for any criminal offence, without any seriousness threshold. In practice, it is the first request to make.
The Regulation does not abolish the European Investigation Order, which it complements: the two routes coexist, and the choice of instrument has consequences for the applicable regime of challenge. Nor does it settle the question of the probative value of data produced by a foreign service provider, on which no French decision has yet been handed down, for a simple reason: no French court has yet had to rule on evidence obtained through this route. That is the system’s main uncertainty. The shift it brings about is settled in law; its reach in practice will be measured by the first challenges. In the three situations described, the decisive element is the same: the data still exist, or they no longer do, and the law does not repair the second case.
The author
Maître Mehdy Kadri is a member of the Paris Bar. He practises within Cabinet Kadri Avocat (Paris 8th) in general and serious crime, business crime, tax crime, cybercrime and crypto-assets, media law and human rights. He publishes regularly in AJ Pénal (Dalloz) and the Encyclopédie Doctrine.
This analysis forms part of the firm’s practice in cybercrime and digital criminal law and in online reputation and media law. It does not constitute legal advice and is no substitute for personalised counsel.
