RSSAmplifier

decoded.legal's blog - RSS Feed · Aug 12, 2026

The EU eEvidence framework and UK Internet and telecoms service providers

0
Sign in to vote or save

decoded.legal

Published on: by Neil Brown

I have seen very little - in fact, nothing - written about the imminent EU “eEvidence” framework from the perspective of UK telecoms operators and Internet service providers.

I accept that, even by my blogging standards, this one is a bit niche, but nevertheless, it might be of interest to someone.

What is this about?

The eEvidence regulation is an EU framework, to deal with the challenges of obtaining electronic evidence - including data from communications providers - across borders.

In essence, it is a new framework under which public authorities in one EU country can demand a service provider in another EU country - and, potentially, countries outside the EU, which is my focus here - to assist them directly.

The regulation purports to have extra-territorial effect although, as I discuss, exactly how this will work in practice is unclear.

The eEvidence regulation, and the obligations set out below, apply from 18 August 2026.

The types of products and services which are in scope

The regulation applies to a broad range of communications-related services. It includes:

  • services provided over electronic communications networks, including internet access services, leased lines and inter-site connectivity, and transit links
  • services which enable two or more people to communicate (whether by using phone numbers or not)
  • IoT and M2M communications transmission systems
  • internet domain name and IP numbering services, such as IP address assignment, domain name registry, domain name registrar and domain name-related privacy and proxy services
  • hosting and data processing services (even if the storage facility is outside the EU)

What brings a provider in scope, in terms of where/how it sells its services, and where they are established

A service provider is in scope if it offers services in the European Union. This means that it:

  • enables people (including companies) in an EU country to use their in-scope products and services; and
  • has a “substantial connection” to that country, such as by:
    • being established there (e.g. has an office or branch, and possibly even just having staff, there);
    • having a significant number of users there or in other EU countries; or
    • targeting activities towards EU countries.

The language of the regulation is hard to parse, as it switches between talking about one specific country, and countries in the EU more generally. It is not the same as the language around establishment in the EU GDPR (although in practice it might be interpreted in the same way).

It is questionable whether offering EU roaming, for instance, brings the home operator within scope of the regulation. This is not explicit, and, practically, if it did, this interpretation would bring every cellular provider in the world (which permitted EU roaming) into scope, without the regulation saying anywhere explicitly that this is the case.

There is a requirement within the framework for an in-scope service provider to ensure that it can use the EU’s eEvidence decentralised IT system for receiving and responding to requests. The service provider is required to do this at its own cost. Even though we are just a few days away from the framework coming into effect, it is not yet clear how this will work in practice for an organisation outside the EU. For instance, whether a service provider will only be permitted to connect to it from within the EU (perhaps via a representative), or whether the service provider will be allowed direct access from outside the EU.

My feeling - and it is just that, a personal feeling - is that insufficient thought has been given to service providers outside the EU, which could well lead to a bit of a mess if an EU public authority attempted to apply the framework to, or enforce it against, such a provider.

I am hopeful that, for most service providers in the UK, a lack of engagement about this means that the chances of receiving a request is very low.

High level obligations

Production order

A production order is an order to produce – i.e. supply - subscriber data / data to identify a user, traffic data, or content data, as set out in the specific order.

A production order must issued by a court or validated by a court.

There is an exception for this for an emergency case, when a competent authority can request subscriber data / information to identify a subscriber without prior approval by a court.

An emergency case is

a situation in which there is an imminent threat to the life, physical integrity or safety of a person, or to a critical infrastructure, … where the disruption or destruction of such critical infrastructure would result in an imminent threat to the life, physical integrity or safety of a person, including through serious harm to the provision of basic supplies to the population or to the exercise of the core functions of the State.

A production order must be notified to the service provider by means of an “EPOC”: a European Production Order Certificate. A service provider can specify that the EPOC must be made available to it in English or be translated into English.

Following receipt of an EPOC, the service provider has 10 days to provide the required data, other than in emergency cases, when it has eight hours to provide the required data.

An EPOC can only require the service provider to produce data which it held on or before the time of receipt of the EPOC. To my mind, this precludes it being used for interception other than access to existing stored communications.

A service provider cannot be compelled to decrypt data under an EPOC. I wonder how this is going to pan out in practice, as it seems surprising to me that a service provider which could decrypt data is not obliged to do so.

Compliance with an EPOC is a legal obligation under EU law (but not law in any part of the UK), with the possibility of a fine for non-compliance - but this only applies to service providers who are in scope. Since there may well be circumstances where there is genuine doubt as to whether a provider outside the EU is in scope or not, it will be interesting to see the approach taken to engagement / enforcement.

There are limited grounds to object, including where the EPOC is incomplete, contains manifest errors, or does not contain sufficient information, or if it is impossible for the service provider to comply.

A service provider may be able to recover its costs, but this appears to be on a country-by-country basis. It is not clear to me what this means in practice, and whether there will be funding for a 24/7 team, to handle requests whenever they come in, or whether the expectation is that they will pay only for each request, meaning that an in-scope service provider potentially needs to stand up a 24/7 team (to allow for either hour responses for emergency cases out of hours) which gets very few requests, and thus very little funding. Again, rather a mess, and perhaps indicating that not much thought has been given to service providers outside the EU.

Preservation order

A preservation order is an order to preserve – i.e. retain – information, for supply under a subsequent production order.

A preservation order must be notified to the service provider by means of an “EPOC-PR”: a European Preservation Order Certificate. The service provider can specify that the EPOC-PR must be made available to the service provider in English or be translated into English.

Following receipt of an EPOC-PR, the service provider must preserve the requested data “without undue delay”. The service provider must preserve the requested data for 60 days, with the possibility of a further 30 days.

It applies only to data which the service provider stores at the point of receipt of the EPOC-PR.

Compliance with an EPOC-PR is a legal obligation, with the possibility of a fine for non-compliance.

There are limited grounds to object, including where the EPOC-PR is incomplete, contains manifest errors, or does not contain sufficient information, or if it is impossible for the service provider to comply.

As above, a service provider may be able to recover its costs, but this appears to be on a country-by-country basis.

Data protection implications

Compliance with an EPOC/EPOC-PR is a legal obligation under Union law.

However, because the UK GDPR does not treat EU laws / laws of a member state as establishing a legal obligation, a service provider cannot rely on this as the lawful basis of processing for the purposes of the UK GDPR.

Instead, a service provider would need need to find another lawful basis - perhaps “task in the public interest” or “(recognised) legitimate interests” (or, in emergency cases, “vital interests”).

This is something to take into account when considering the potential risks from a data protection compliance point of view / doing a privacy risk impact assessment.

What next?

As above, if a service provider in the UK has not yet had any contact from public authorities in the EU about this, then I would hope that the likelihood of receiving a request is very low.

It might still be sensible to identify:

  • whether the service provider is established in one or more EU countries, or has a legal representative in one or more EU countries
  • whether any of its products and services bring it in scope, or might bring it in scope
  • what position the service provider would take if it were to receive a request

It might also be worthwhile briefing staff who are most likely to receive such a request (e.g. those who receive requests from UK law enforcement, or who monitor publicly-available contact addresses / channels) to alert them to the possibility of such requests, so that they know how to recognise them, and to whom they should be flagging them.

Read the original on decoded.legal

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.