e-Evidence compliance is a provider’s ability to receive, assess and answer cross-border orders for electronic evidence under Regulation (EU) 2023/1543 and Directive (EU) 2023/1544. It combines an EU contact point, a secure exchange channel, data extraction and documented decisions. ICS delivers turnkey e-Evidence compliance for communication service providers, cloud platforms and digital service providers.

What does the e-Evidence Regulation require?

According to the European Commission, more than 85 % of criminal investigations rely on electronic evidence. Much of that data sits with providers in another Member State or outside the EU. Traditional mutual legal assistance often took too long.

The e-Evidence Regulation lets a judicial authority in one Member State address a provider in another Member State directly. The provider must preserve or produce the requested data within fixed deadlines. The accompanying Directive requires every provider to name an addressee for these orders.

In Germany, the implementing act (EBewMG) was published in the Federal Law Gazette on 12 March 2026. It enters into force in stages. For a plain-language introduction, see our guide What is e-Evidence?

Who is in scope of e-Evidence compliance?

The rules apply to providers that offer the following services in the EU:

  • Electronic communication services, such as telephony, messaging and internet access
  • Internet domain name and IP numbering services, such as IP address assignment and domain name services
  • Other information society services that let users communicate or store data, such as social networks, online marketplaces and cloud services

The Regulation also covers companies established outside the EU if they offer services in the Union. Location of the data or the company headquarters does not change that.

Which orders and data categories apply?

Issuing authorities use two certificates. The European Production Order Certificate (EPOC) requests data. The European Preservation Order Certificate (EPOC-PR) requests that data is kept for a later production request.

EPOC (production)EPOC-PR (preservation)
PurposeHand over existing dataPreserve data for a later request
Standard deadline10 daysPreserve for 60 days
Emergency or extension8 hours in emergenciesExtendable by 30 days
Data categoriesSubscriber, identification, traffic and content dataSubscriber, identification, traffic and content data
Penalty for breachesUp to 2 % of worldwide annual turnoverUp to 2 % of worldwide annual turnover

The Regulation distinguishes four data categories:

  • Subscriber data, such as name, address and contract details
  • Data requested solely to identify the user, such as IP addresses and related identifiers
  • Traffic data, such as time, duration and endpoints of a communication
  • Content data, such as messages, files and other stored content

Who is the contact point for e-Evidence orders?

Providers established in the EU name a designated establishment. Providers without an EU establishment appoint a legal representative in a participating Member State. Both must be notified to the competent authority, in Germany the Bundesamt für Justiz.

The addressee must be able to receive and act on orders at any time. ICS can act as legal representative for non-EU providers and supports EU providers in running their designated establishment. Legal representative and designated establishment service

How ICS delivers e-Evidence compliance

01

Automated order processing

Incoming EPOC and EPOC-PR orders are registered, checked and routed automatically. Deadlines are tracked from the moment of receipt. Learn more

02

Legal representative support

ICS acts as legal representative for non-EU providers and helps EU providers set up their designated establishment. Learn more

03

Secure exchange

Orders and responses are exchanged via the decentralized IT system based on e-CODEX and, where applicable, other secure national channels.

04

Full audit trail and reporting

Every step, decision and data transfer is logged. Reports support internal oversight, authority questions and transparency duties.

05

Shared LI and retention architecture

The platform shares its architecture with the ICS lawful interception and data retention stack. Data sources and security controls are reused. Learn more

06

Managed operations

ICS can run e-Evidence operations around the clock as an extension of its Managed LI Operations.

Which challenges does e-Evidence compliance solve?

e-Evidence turns occasional legal requests into a time-critical operational process. ICS addresses four recurring challenges:

  • Near-real-time workflows: an 8-hour emergency deadline leaves no room for manual hand-offs.
  • 24/7 readiness: orders can arrive at night, on weekends and on public holidays.
  • Secure integration: extraction must reach CRM, logs and storage systems without opening new attack paths.
  • GDPR balance: providers must disclose exactly what an order requires and document why. Data minimization stays part of every response.
Scales of justice representing e-Evidence compliance under Regulation (EU) 2023/1543

How are e-Evidence orders processed?

1

Receive

The order arrives via the decentralized IT system or a national channel and is registered with its deadline.

2

Validate

Formal requirements, issuing authority and jurisdiction are checked.

3

Assess

Complex cases are routed to your legal or compliance team for a decision.

4

Extract

The requested data categories are collected from the relevant systems.

5

Deliver

The response is reviewed and returned through the secure channel.

6

Document

Every step is stored in the audit trail for later review.

e-Evidence solutions for your organization

01

Telecom operators

Built on your existing LI architecture, with automated extraction from network and billing systems. e-Evidence for telcos

02

Enterprises and large platforms

API-first workflows, role-based approvals and high-volume processing for large order numbers. e-Evidence for enterprises

03

Non-EU providers

An EU contact point that receives and validates orders on your behalf. Legal representative service

04

Platform buyers

A ready platform for order management, extraction and audit. e-Evidence Compliance Platform

Why ICS

01

More than 20 years of experience

ICS has handled lawful interception and data disclosure for operators and authorities for more than two decades.

02

Proven in regulated environments

ICS holds multiple BNetzA acceptances for interception solutions. Our staff is security-cleared by the German Federal Ministry of the Interior.

03

One stack for all disclosure duties

Lawful interception, data retention and e-Evidence run on a shared architecture. That means one set of integrations and one audit approach.

04

Based in the EU

ICS is based in Cologne, Germany, inside a participating Member State. That makes it a practical EU contact point for non-EU providers.

Frequently Asked Questions

When does the e-Evidence Regulation apply?

Regulation (EU) 2023/1543 has applied since 18 August 2026. It was adopted on 12 July 2023 together with Directive (EU) 2023/1544. Member States had to transpose the Directive by 18 February 2026. In Germany, the implementing act (EBewMG) was published in the Federal Law Gazette on 12 March 2026 and enters into force in stages. Providers in scope must be able to handle orders now.

Which companies need e-Evidence compliance?

Providers of electronic communication services, domain name and IP numbering services, and other information society services that enable communication or storage are in scope. Examples include telecom operators, social networks, online marketplaces and cloud providers. Companies outside the EU are covered if they offer services in the Union. The German Federal Ministry of Justice estimates around 9,000 affected companies in Germany.

How fast must a provider respond to an EPOC?

A provider must hand over the requested data within 10 days of receiving a European Production Order Certificate. In emergencies, the deadline is 8 hours. For a European Preservation Order Certificate, the provider must keep the data for 60 days. The issuing authority can extend that period by 30 days. These deadlines require 24/7 readiness and a documented workflow.

What are the penalties for non-compliance?

Member States set the penalties for breaches of the Regulation. Under Art. 15, pecuniary penalties can reach up to 2 % of the provider’s total worldwide annual turnover in the preceding financial year. Penalties must be effective, proportionate and dissuasive. A documented, auditable process is therefore important. It shows authorities how each order was received, assessed and answered.

What is the difference between a designated establishment and a legal representative?

Both are addressees for e-Evidence orders. A provider established in the EU names one of its establishments as designated establishment. A provider without an EU establishment appoints a legal representative in a participating Member State. In both cases, the contact point must be notified to the competent authority. In Germany, that authority is the Bundesamt für Justiz.

How are e-Evidence orders transmitted?

Orders and responses are exchanged via a decentralized IT system based on e-CODEX. It connects competent authorities and providers through interoperable access points. Where applicable, other secure national channels can also be used. The ICS e-Evidence Compliance Platform supports both routes. It registers every incoming order, tracks its deadline and logs each response in the audit trail.

Scroll to Top
ICS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.