Updated on 19 September 2026
⏱ 11 min read

The certificate arrives on a Friday at the end of the day, signed by a judge in another Member State, with the emergency box completed: eight hours to transmit the data of an account, and an obligation to preserve them that is already running. Nothing in the e-Evidence Regulation leaves the company time to wonder whether it is concerned: the obligation arises on receipt, the room for discussion is narrow and bound by forms, and the costly mistake is not the refusal, it is the answer given beside the point. This page describes what the addressee company does, in the order in which it does it, from hour zero to the closing of the file.

Hour zero: read the certificate and freeze the data

The company does not receive the foreign judge’s decision, but the standardised certificate that carries it: the EPOC for a European Production Order, the EPOC-PR for a European Preservation Order. The regime of those instruments, the categories of data and the competent authorities are set out in our page on the European Production Order (EPOC); this page does not repeat them. The first reading bears on three items: the acronym, which distinguishes a request to hand over from a request to freeze; the emergency indication, which cuts the ten-day deadline to eight hours; the time of receipt, the starting point of every deadline, to be recorded at once.

The obligation to preserve the requested data arises at that moment. It depends on no internal validation and on no assessment of the regularity of the certificate. Where the company requests clarification of a defective certificate, its execution obligations are suspended until the answer, but the data remain preserved to the extent possible, and the form by which it requests clarification must state whether preservation was possible. Preservation is thus the one obligation the Regulation keeps alive through every challenge described below.

Reference
Regulation (EU) 2023/1543, Article 10(1)

“Upon receipt of an EPOC, the addressee shall act expeditiously to preserve the data requested.” Paragraph 9 of the same Article adds that the data are preserved, to the extent possible, until they are produced or until the order is withdrawn, and Article 11 sets at sixty days, extendable by thirty, the preservation ordered by an EPOC-PR.

Full text on EUR-Lex →

The technical consequence is immediate: automatic purges, programmed retention periods and routine deletions are neutralised on the perimeter concerned, even before that perimeter is precisely delineated. Data deleted after receipt through the mere operation of a setting are not data lawfully deleted before receipt, and that distinction governs the benefit of the presumption of impossibility. The Regulation covers only data stored at the time of receipt: the inventory drawn up at that hour fixes the extent of the obligation and the proof of what no longer existed. Who received the certificate, at what time, which perimeter was frozen and on which systems: that is the first document in the file.

Where the certificate is an EPOC-PR, no data are to be transmitted. Confusion between the two certificates can occur in both directions, handing over data that were not requested or remaining inactive in the face of a production order, and it is resolved by reading the acronym.

The first hours: three checks on the certificate

These checks are carried out alongside preservation, never in its place. They do not bear on the expediency of the measure, which is beyond the addressee, but on what the certificate itself shows.

The status of the authority, matched against the category of data. For subscriber data and for data requested for the sole purpose of identifying the user, the certificate may be issued or validated by a judge, a court, an investigating judge or a prosecutor. For traffic data and content data, only a judge, a court or an investigating judge may issue or validate it: a certificate concerning the content of messages or communication metadata, issued by a prosecutor’s office without validation by a judge, does not meet the condition laid down by the Regulation itself. IP addresses call for a careful reading of the stated purpose: requested for the sole purpose of identifying the user, they fall under the lighter regime; requested for any other purpose, they are traffic data.

The seriousness threshold. For subscriber and identification data, any criminal offence suffices. For traffic and content data, the offence must be punishable in the issuing State by a custodial sentence of a maximum of at least three years, or fall within the offences the Regulation designates by reference to four directives (fraud involving means of payment, sexual abuse of children and attacks against information systems, on condition that they are committed by means of an information system, and terrorism). The certificate states the applicable provisions of the criminal law of the issuing State: that is what the check bears on.

Completeness. The certificate contains, among other things, the issuing authority and, where applicable, the validating authority, the addressee, the user or identifier concerned, the category of data, the period covered, the applicable criminal provisions and, in emergency cases, the duly justified reasons for the emergency. It contains neither the grounds of necessity and proportionality nor the description of the case, which appear only in the order and, where notification is required, in the copy notified to the authority of the enforcing State. The company therefore need not be surprised not to know the case; it checks that what must be there is there, and that an emergency indication is reasoned rather than merely ticked. It also checks the language: the certificate is, where necessary, translated into an official language of the Union that the service provider declared it accepts when it was designated or, failing such a declaration, into an official language of the State of its designated establishment. The Regulation does not say what becomes of a certificate received in another language; the prudent course is a request for clarification through the form, preservation being required in the meantime.

The firm reviews the regularity of an EPOC and the competence of the issuing authority within the deadline given to the addressee. Contact the firm →

Day one: decide, and route everything through the form

Once the checks are done, the company finds itself in one of four situations, and a single rule governs them: anything that is not plain execution is expressed by means of the form set out in Annex III to the Regulation, addressed to the issuing authority and, where it has been notified, to the authority of the enforcing State. A free-form reply, an explanatory email or silence produce none of the effects the Regulation attaches to the form.

The certificate is incomplete, contains manifest errors or is insufficient to be executed. The company requests clarification through the form, stating whether identification and preservation of the data were possible. The issuing authority must react within five days; the execution obligations are suspended until the answer, the data remaining preserved to the extent possible. Used without serious grounds, this channel exposes the company to seeing its inaction requalified as a refusal; used properly and documented, it is the route by which an addressee acting in good faith obtains what it needs to identify the data and delineate the perimeter.

Execution is impossible in fact. Impossibility owing to circumstances not attributable to the company releases it. The recitals of the Regulation presume it in three cases: the person concerned is not a customer of the service provider, that person cannot be identified as such even after a request for additional information to the issuing authority, or the data were lawfully deleted before receipt. It is explained through the form, and the inventory drawn up at hour zero is what proves it.

Execution would conflict with the law of a third country. The company files a reasoned objection, through the form, within ten days of receipt. The objection sets out the foreign law, its applicability to the case and the nature of the conflicting obligation. The issuing authority then reviews the order and, if it intends to uphold it, refers the matter to the competent court of its State; execution is suspended until that review is completed. Two grounds are excluded in advance.

Reference
Regulation (EU) 2023/1543, Article 17(2)

“The reasoned objection shall not be based on: (a) the fact that similar provisions concerning the conditions, formalities and procedures for issuing an order for production do not exist in the applicable law of the third country; or (b) the sole fact that the data are stored in a third country. The reasoned objection shall be filed no later than 10 days after the date on which the addressee received the EPOC.”

Full text on EUR-Lex →

The company that has built its objection on one of those grounds will not have filed an objection of uncertain outcome: it will have used up its deadline and allowed a situation to arise that can be characterised as a refusal to execute. A useful objection identifies a precise obligation, drawn from a specific foreign provision, the execution of which would breach it.

The certificate appears to touch on an immunity, a privilege or the protection of the press. Where the company considers so, on the sole basis of the information contained in the certificate, it informs the issuing authority and the authority of the enforcing State, through the form: the text makes this an obligation, not an option. It does not refuse on that account: the decision to withdraw, adapt or maintain the order lies with the issuing authority, and the corresponding ground for refusal lies with the authority of the enforcing State. But it has done what the text requires of it, and the record is kept.

What the form does not open must be stated just as plainly. The necessity and proportionality of the measure, the legal characterisation adopted and the merits of the investigation are not questions put to the addressee: that dispute belongs to the person concerned, before a court of the issuing State. The location of the data outside the Union, the absence of an equivalent provision in French law, the absence of internal procedures between the service provider and its designated establishment and confidentiality undertakings given to users are no more grounds. And where the company does not transmit, does not transmit everything or does not transmit in time for any other reason, it must still inform the issuing authority, through the form and within the deadline: that authority reviews the order and, where appropriate, sets a new deadline.

An ill-founded objection costs the time it consumes. The firm assesses the admissibility of an objection before it is filed and drafts the Annex III form. Contact the firm →

Day two to day ten: transmit, or wait

The moment of transmission depends on one element the certificate indicates: whether or not the authority of the State where the company is located has been notified.

For subscriber or identification data, no notification is required: the company transmits directly to the issuing authority or to the service it designates, by the tenth day at the latest. For traffic or content data, the issuing authority in principle notifies the authority of the enforcing State, and that notification suspends the obligation to transmit: the company waits for the ten days to expire and transmits if no ground for refusal has been raised, or earlier if that authority confirms it will raise none. If a ground for refusal is raised, it ceases execution and transfers nothing.

The notification is subject to a broad exemption: it is not required where the issuing authority has reasonable grounds to believe that the offence has been, is being or is likely to be committed in its own State and that the person concerned resides there. A case that appears internal to the issuing State thus escapes any control by the State where the company is located, even though the data are hosted there. The company therefore does not wait for an authority of its own country to step in: in cases that appear internal to the issuing State, none will be seised, and the tenth day is its own.

In an emergency, transmission takes place without undue delay and within eight hours at the latest, whether or not notification is required: notification is then not suspensive. The authority of the enforcing State has ninety-six hours to object to the use of the data or to set conditions on it, and it then falls to the issuing authority to erase or restrict what it has received. The company, for its part, must be able to show what it transmitted, to whom and at what time.

Confidentiality is settled at the same time. The Regulation does not task the company with informing the user whose data are requested: that information is for the issuing authority, which may delay, restrict or omit it under the conditions of data protection law. It does, however, require the addressee and the service provider to ensure the confidentiality, secrecy and integrity of the certificate and of the data, and that obligation is among those whose breach is subject to the financial penalty. Internal circulation of the certificate is limited to those who need it to execute it.

Once the data have been transmitted, the service provider that complied in good faith is not liable for damage resulting exclusively from that compliance for its users or third parties. That immunity protects the company that executed, not the one that abstained, and it presupposes that good faith can be shown: the register kept since hour zero, receipt, freeze, checks, forms and answers, transmission, is the proof. The data are preserved, to the extent possible, until they are produced or the order is withdrawn, and the issuing authority informs the addressee when their production and preservation are no longer necessary.

If the company has not responded: the enforcement procedure

The penalty is not automatic. Where the addressee has not complied with a certificate within the deadline without providing reasons accepted by the issuing authority, that authority may ask the authority of the State where the company is located to enforce the order, transferring to it the order and the form completed by the addressee. That authority recognises the order within five working days, unless one of the grounds listed in the Regulation applies: the issuing authority’s lack of competence for the category of data, the absence of the seriousness threshold, impossibility in fact, manifest error, data not stored at the time of receipt, a service outside the scope of the Regulation, among others.

It then formally orders the addressee to comply, informing it that it may object on those same grounds, of the applicable penalties and of the time limit for compliance or objection. This is the last moment at which the checks of the first hours can be raised, and the Annex III form, completed on day one, carries the record of them. If the confirmed order remains unexecuted, the financial penalty is imposed, up to 2 % of the service provider’s total worldwide annual turnover, subject to an effective judicial remedy; the designated establishment and the service provider may be held jointly and severally liable.

For an establishment designated in France, the enforcing authority is French. Yet France has published, as at the date this page was written, no text giving effect to the Regulation, and the national penalty regime it requires of Member States does not exist; on 27 March 2026 the European Commission sent letters of formal notice to twenty-two Member States, including France, for incomplete transposition of the accompanying Directive. That situation is transitional. It suspends neither the applicability of the Regulation, nor the preservation and transmission obligations, nor the issuing authority’s power to review the order and set a new deadline; and it has no bearing on a group whose designated establishment is in a Member State that has legislated, whose law governs enforcement. A company that organised its abstention around the absence of any fine currently incurred in France would expose itself, once the French text is published, to a file of refusal already built.

Before the first order: the organisation

Everything above presupposes an organisation that does not arise on its own, and the eight-hour deadline alone dictates it.

The starting point is designation. Any service provider offering services in the Union on 18 February 2026 had to designate, by 18 August 2026 at the latest, an establishment in the Union, or a legal representative if it is not established there, responsible for receiving and executing orders, and to notify it in writing to the central authority of the State concerned, specifying the accepted languages; a provider that entered the market after that date has six months. The Directive requires that establishment to be given the necessary powers and resources and prohibits reliance on the absence of internal procedures between the provider and it. The allocation of roles within the group is therefore settled beforehand, in writing; it is not a defence to raise afterwards.

The organisation comes down to four elements: a receipt point monitored continuously, weekends and public holidays included; a single person authorised to answer the issuing authority, identified in advance, to avoid parallel replies; the ability to identify immediately the technical perimeter covered by an account identifier, so that the freeze takes place within the hour; a legal escalation path that can be activated within that same time, since the decision to execute, to request clarification or to object cannot wait until Monday. In an emergency, if the designated addressee does not react within the deadlines, the certificate may be addressed to any other establishment or legal representative of the service provider in the Union: a failure of the receipt point does not suspend the system, it moves it to a counterpart that is not prepared for it.

There remains the preliminary question of applicability, for the company that is not a messaging service. Online marketplaces enabling users to communicate with one another, hosting and cloud computing services, online gaming and gambling platforms fall within the scope, under the conditions set out in our technical page. The answer, for a given company, is built on a precise description of its services and of its users in the Union, before the first order.

The firm assists with the designation of the establishment and the setting up of the receipt process, the register and the escalation procedure of addressee companies. Contact the firm →

Frequently asked questions

Who, within a group, is bound to answer the certificate?

The designated establishment or the legal representative that the service provider notified for that purpose. The order is addressed to it directly; it may rely neither on the absence of internal procedures with the service provider nor, according to the recitals of the Directive, on the fact that it would not be authorised to provide the data, and the provider and it may be held jointly and severally liable for non-compliance.

The certificate is written in a foreign language: must the company execute it?

The Regulation provides that the certificate is, where necessary, translated into an official language of the Union accepted by the service provider in its notification or, failing that, into an official language of the Member State of the designated establishment. It does not settle the fate of a certificate received in another language: the prudent course is a request for clarification through the Annex III form, preservation of the data being required from receipt.

Must the company inform the user whose data are requested?

No: that information is for the issuing authority, which may delay, restrict or omit it under the conditions of data protection law. The company is bound, for its part, to ensure the confidentiality of the certificate and of the data, an obligation whose breach is subject to the financial penalty. Only a processor producing data on behalf of a controller informs the latter, unless the issuing authority has requested otherwise in the certificate.

An EPOC-PR has been received: must the data be transmitted?

No. A preservation order only requires the data to be frozen, for sixty days extendable by thirty; transmission presupposes a subsequent request for production, the issuing of which the issuing authority confirms by a dedicated form. A rule specific to the EPOC-PR: if the certificate is incomplete and the issuing authority does not answer the request for clarification within five days, the service provider is exempted from the obligation to preserve.

Can the company be reimbursed for the cost of execution?

It may claim reimbursement of its costs from the issuing State if the national law of that State provides for it for domestic orders in similar situations; Member States communicate their rules to the Commission, which publishes them.

What happens if the company does not respond within ten days?

The issuing authority may seise the authority of the State where the company is located, which recognises the order within five working days unless a ground listed in the Regulation applies, formally orders the company to comply while opening a time limit to object, and then, if the confirmed order remains unexecuted, imposes the financial penalty, up to 2 % of the service provider’s worldwide annual turnover, subject to judicial remedy.

The Regulation shifts the point at which the obligation attaches from a requested State to a private company, and the connecting factor from the location of the server to that of the establishment. Our analysis of digital evidence and the end of the Irish safe haven sets out that shift and what it opens up depending on the position occupied in the proceedings. For the addressee company, the essential is decided in the first hours: the data were frozen or they were not, the form was sent within the deadline or it was not, and the Regulation repairs neither omission.

The author

Maître Mehdy Kadri is a member of the Paris Bar. He practises within Cabinet Kadri Avocat (Paris 8th) in general and serious crime, business crime, tax crime, cybercrime and crypto-assets, media law and human rights. He publishes regularly in AJ Pénal (Dalloz) and the Encyclopédie Doctrine.

Contact the firm →

This analysis forms part of the firm’s practice in cybercrime and digital criminal law. It does not constitute legal advice and is no substitute for personalised counsel.