Home
Web Hosting
Domains FAQ
Resources
About Contact Client Portal
Guides ยท ยท 15 min read

The EU e-Evidence Regulation: What It Means for Hosting Customers

ยท 15 min read

On 18 August 2026 the EU e-Evidence Regulation becomes applicable, and cross-border access to hosting data changes more than it has in twenty years. A prosecutor in one member state will be able to order a hosting provider in another to produce customer data within ten days, or eight hours in an emergency, without going through the courts of the country where the provider sits.

Most coverage of this is written for corporate compliance teams. This page is written for the person deciding where to put a server. It covers what the orders are, what can be demanded and on what grounds, what a provider is actually able to refuse, what you can do yourself, and what happens if your host is outside the EU.

What the EU e-Evidence Regulation actually is

The package is two instruments. Regulation (EU) 2023/1543 sets the substantive rules and applies directly, without national implementation. Directive (EU) 2023/1544 obliges service providers to have someone in the EU who can receive and execute orders, and had to be transposed into national law by 18 February 2026.

Both apply in every EU member state except Denmark, which under Protocol 22 did not take part in adoption and is not bound. Ireland, which has a case-by-case opt-in for justice and home affairs measures, notified its wish to take part and is covered. Norway, Iceland, the United Kingdom and Switzerland are not member states and are not bound by the Regulation.

Until now, a prosecutor in Spain who wanted data from a provider in Finland had to use mutual legal assistance or a European Investigation Order, which involves the authorities of the receiving country and routinely takes months. The Regulation creates two instruments that go straight to the provider instead:

  • The European Production Order requires the provider to hand over specified data.
  • The European Preservation Order requires the provider to freeze specified data so that it cannot be deleted while a production request is prepared.

Both are transmitted on standard certificates and, critically, apply regardless of where the data is physically stored. Choosing a data centre in one country does not put the data beyond an order addressed to a provider covered by the Regulation.

What can be demanded, and on what grounds

The thresholds are not uniform. They rise with the sensitivity of the data, and this distinction matters more to a hosting customer than any other part of the Regulation.

Data category Threshold Who can issue
Subscriber data, and data requested solely to identify a user Any criminal offence, or the execution of a custodial sentence of at least four months A public prosecutor, as well as a judge or court
Traffic data and content data Offences punishable in the issuing state by a maximum custodial sentence of at least three years, or a listed set covering terrorism, child sexual abuse material, non-cash payment fraud and certain cybercrime A judge or court, or an order validated by one

For a hosting account, subscriber data is the registration record and whatever identifies the account holder. Traffic data covers connection and access records. Content data is the material itself, which for a VPS means the disk.

The practical reading is that the low bar applies to identity. Any criminal offence in any participating member state is enough to trigger a request for who holds the account. The three year threshold protects the contents of the server, not the name on it.

The deadlines, and what was left out of them

A production order must generally be executed within ten days. In emergency cases involving an imminent threat to life, physical integrity or critical infrastructure, the deadline is eight hours. A preservation order requires the provider to freeze the data without delay for 60 days, extendable by a further 30 if production is being sought.

Compare that to mutual legal assistance, which routinely runs to months and sometimes longer. But speed is only half of the story. The grounds on which an order can be resisted are enumerated and short. They cover immunities and privileges, rules protecting press freedom and freedom of expression, certificates that are incomplete or contain manifest errors, and manifest breaches of fundamental rights. They do not extend to dual criminality, to double jeopardy, or to any assessment of whether the order is necessary and proportionate.

Who is caught by the rules

Hosting providers, cloud operators, domain registrars and registries are explicitly in scope, alongside communications services and online marketplaces. This is not limited to large platforms.

Every provider offering services in the Union must, by 18 August 2026, either designate an establishment in a member state or appoint a legal representative there. That entity has to have the authority and the resources to actually execute orders, not simply exist on paper, and under the Directive the provider and its representative carry joint and several liability. Financial penalties reach up to 2 percent of worldwide annual turnover, national implementing laws may set higher caps, and criminal penalties are possible where national law provides for them.

Read that requirement carefully, because it is where the common assumption about jurisdiction breaks down. It applies to providers incorporated outside the EU when they offer services within it. A provider based in a third country that sells to customers in member states is expected to appoint a representative in the EU, and once it has one, it can receive orders. There is one carve-out: a provider established in a single member state and serving only that same state is outside the Directive's representative requirement.

The notification mechanism, and why Finland objected

During negotiations the main fight was over how much say the country where the provider sits should retain. The compromise is a notification mechanism that applies in defined situations, chiefly where content data is sought and the person under investigation does not reside in the issuing state.

Where it applies, notification suspends execution. The provider may not hand over the data until the enforcing authority either confirms that it will not object or lets the ten day window expire, reduced to 96 hours in urgent cases. If a ground for refusal is invoked, the provider must not comply.

The mechanism is narrow. It does not apply across all data categories, and the grounds are enumerated rather than open. Finland voted against final adoption in Council and filed a statement that the notification mechanism and its refusal grounds were insufficient. Several national parliaments and data protection bodies made similar objections during the process. Whatever your view of the outcome, the disagreement was real and it is worth knowing that it happened.

What your provider can and cannot refuse

This is the question actually worth asking a hosting company, and the answer is narrower than most people assume.

A provider that receives an order has to respond. It can tell the issuing authority that compliance is impossible, that the certificate is incomplete or contains manifest errors, or that the data cannot be produced within the deadline. It can raise a short list of substantive objections: that compliance would interfere with immunities or privileges under the enforcing state's law, or with rules on press freedom and freedom of expression that limit criminal liability. If compliance would conflict with the law of a third country, a separate review procedure exists for that.

What a provider cannot do is refuse because the order looks abusive or disproportionate. Earlier versions of the text gave service providers exactly that ability, allowing them to challenge an order they considered manifestly abusive or in manifest violation of the Charter of Fundamental Rights. That ground did not survive into the adopted Regulation. Some providers argued during the process that they should at least be able to raise fundamental rights problems apparent on the face of an order. The final text did not take up that position.

This is the ceiling on what any hosting company can do for you once a valid order arrives, and it is worth being clear-eyed about it. A provider that promises to fight every request on your behalf is describing something the law does not give it room to do. What a provider genuinely controls is how much data it collected in the first place, how long it keeps it, and whether it responds to informal requests that carry no legal force at all.

What you can do yourself

Your position is separate from your provider's, and it is better in one respect and worse in another. The Regulation provides that a person whose data has been obtained through a European Production Order has a right to effective remedies against it. Those remedies are exercised in the issuing state, under that state's law, and they do not depend on your provider raising anything at all.

The practical difficulty is obvious. If your host is in Finland and the order came from a prosecutor in another member state, the challenge is a proceeding in that other country, in its language and its courts. It also depends on knowing that an order existed, and notification can be deferred while an investigation is ongoing. A right that arrives after the data has been produced is worth having, but it is not a shield.

Most of Europe is not ready

The transposition record is poor. As of February 2026, only four member states bound by the package had adopted implementing legislation, being Croatia, Italy, Lithuania and Slovakia, with others still holding drafts or bills in progress. On 27 March 2026 the European Commission sent letters of formal notice to 22 member states for failing to communicate complete transposition, opening infringement proceedings less than five months before the application date.

The Regulation applies on 18 August regardless. What varies country by country is which national authorities are designated, how penalties are enforced, and how smoothly the receiving side functions. Expect an uneven first year rather than a clean switch, and expect the practical picture to differ noticeably between member states.

What it means if your host is in the EU

If your server is with an EU provider, the honest summary is that the identity of your national jurisdiction now matters less than it did. Your provider can be reached directly by authorities in any other participating state, on that state's thresholds, with your own country's authorities involved only in the limited notification cases.

This does not erase national differences. Data retention duties, confidentiality obligations, copyright procedure and intelligence powers all remain national, and they still determine how much data exists and what else can be done with it. Our guide to Finnish hosting law works through one example in detail. But the specific question of who can order production of what has largely been standardised, and comparing EU jurisdictions on that basis alone is now much weaker analysis than it was in July.

What it means if your host is outside the EU

Switzerland is the case most relevant to our own customers, so here is the accurate version rather than the marketing version.

Switzerland is not an EU member state and is not bound by the Regulation. Swiss authorities are not part of the system, and a Swiss court cannot be handed an EU production order to enforce. Access to data held in Switzerland by foreign authorities runs through Swiss mutual legal assistance and Swiss criminal procedure, which is slower, involves Swiss judicial review, and carries a dual criminality requirement that direct EU orders do not.

Two qualifications matter, and both cut against the simple story.

  • Offering services in the EU is what triggers the obligations, not where the servers are. A provider outside the EU that sells to customers in member states is expected to appoint a legal representative there, and orders can be addressed through it. The rule that orders apply regardless of the location of the data cuts straight through server geography for any provider that is in scope. What it cannot do is reach a provider that is out of scope entirely, which is why the real question is the provider's connection to the EU rather than the address of the rack.
  • A parallel route exists internationally, though it is not yet operational. The Second Additional Protocol to the Budapest Convention would allow authorities in one party to request subscriber information directly from providers in another. It was opened for signature in May 2022 and has not entered into force, with four ratifications as of April 2026. This is the direction of travel rather than a permanent gap.

So the real Swiss advantage after 18 August is narrower and more specific than "outside the EU". It is that Switzerland retains an independent judicial process with its own substantive standards, and that process cannot be replaced by a certificate sent directly from a prosecutor abroad. Our page on Swiss data protection law for hosting covers what that process involves, and the hosting jurisdiction index scores the wider field.

What the EU e-Evidence Regulation does not change

An order can only reach data that exists. No procedural reform alters that, and it is the part of the picture a customer actually controls.

Preservation orders are worth understanding on their own terms, because they change the timing of that calculation. A preservation order does not hand anything over. It freezes what is there, for 60 days, extendable by 30, while a production request is prepared or a mutual assistance route is opened. Anyone whose plan is to delete a server once trouble appears should understand that the freeze is designed to arrive before the request does, and that the decision about how much data existed was made months earlier, at signup and in the log retention policy.

What that decision consists of, in practice, is what the signup form collected, what the payment method recorded, how long access logs are kept, and whether the contents of the disk are readable to the operator. We worked through the real limits of each of those, including the ones that do not hold up, in anonymous VPS: what it actually hides.

Frequently asked questions

What is the EU e-Evidence Regulation?

Regulation (EU) 2023/1543, applicable from 18 August 2026, which lets a judicial authority in one EU member state send a European Production Order or European Preservation Order directly to a service provider in another member state. It works alongside Directive (EU) 2023/1544, which requires providers offering services in the EU to designate an establishment or legal representative to receive those orders.

Does the EU e-Evidence Regulation apply to my VPS?

It applies to your provider, not to you directly. Hosting and cloud services are explicitly in scope. If your provider offers services in the EU, orders can be addressed to it regardless of where the data is stored, so the answer is not determined by the location of the server alone.

Can my hosting provider refuse an order?

Only on narrow grounds. A provider can report that compliance is impossible, that the certificate is incomplete or contains manifest errors, or that the request conflicts with immunities, privileges or rules protecting press freedom, and a separate procedure covers conflicts with third-country law. It cannot refuse on the basis that the order appears abusive or disproportionate. That ground existed in earlier versions of the text and is not in the adopted Regulation.

Can I challenge an order myself?

Yes, in principle. The Regulation gives the person whose data was obtained a right to effective remedies, but they are exercised in the courts of the state that issued the order, under its law. In practice that means a foreign proceeding, and it depends on learning that the order existed, which can be deferred while an investigation is ongoing.

How fast does a provider have to respond?

Ten days for a standard production order, eight hours in emergency cases involving an imminent threat to life, physical integrity or critical infrastructure. A preservation order freezes the data for 60 days, extendable by 30.

Does it apply in Switzerland?

No. Switzerland is not an EU member state and is not bound by the Regulation, so foreign requests for data held there run through Swiss mutual legal assistance and Swiss judicial process instead. The qualification is that a provider selling into the EU is still expected to have a legal representative there, so the analysis depends on the provider as much as on the country.

Which countries does it cover?

All EU member states except Denmark, which did not take part in adoption under Protocol 22. Ireland opted in and is covered. Non-member states including Switzerland, Norway, Iceland and the United Kingdom are not bound.

Will I be told if an order is served on my host?

Not necessarily, and not immediately. The Regulation contains provisions on informing the person whose data is sought, but the issuing authority can require confidentiality where disclosure would obstruct the investigation. Assume that notification is possible rather than guaranteed.

Does this replace mutual legal assistance entirely?

No. The framework is additional rather than exclusive. Authorities can still use the European Investigation Order or traditional mutual legal assistance, and must do so for anything outside the Regulation's scope, including requests directed at non-participating countries.

Swiss and Finnish VPS hosting, no KYC, Monero accepted.

KVM virtualisation, full root access, dedicated IPv4 and DDoS protection in both locations. Signup requires an email address and a password, with no identity documents at any stage, which is the part of this that actually stays under your control. View Switzerland Cloud VPS plans or Finland Cloud VPS plans.

This article is general information about EU and Swiss law, current as of August 2026, and is not legal advice. National implementation of the e-Evidence package is still incomplete in most member states, so the practical picture will change over the coming months.

Need Reliable Hosting?

Privacy-focused, anonymous, and built for people who value their data.