Understanding EPOC EPOC-PR request types is essential for operators subject to the EU e-evidence regulation. The EU e-Evidence Regulation (Regulation 2023/1543) represents one of the most significant developments in cross-border digital evidence gathering within the European Union. At its core, the regulation introduces two new legal instruments — the European Production Order Certificate (EPOC) and the European Preservation Order Certificate (EPOC-PR) — that enable judicial authorities in one EU member state to request digital evidence directly from service providers established in another member state. For telecommunications operators and other service providers, understanding the distinction between these two instruments is essential for building compliant response processes.
This article provides a detailed examination of EPOC and EPOC-PR, explaining what each instrument does, who can issue them, what they require from service providers, how they differ from each other, and how they relate to existing lawful interception obligations.
Understanding EPOC EPOC-PR Requests
The EPOC is an order requiring a service provider to produce specific electronic evidence to the issuing authority. It is the more consequential of the two instruments, as it compels the actual disclosure of data. EPOCs can be issued for subscriber data, access data, transactional data, and content data, with different authorisation requirements depending on the category of data requested.
For subscriber data and access data — which include basic registration information, IP addresses, and connection logs — an EPOC can be issued by a judge, a court, an investigating judge, or a prosecutor. For transactional data and content data — which include communication metadata and the actual content of communications — an EPOC must be issued or validated by a judge or court, reflecting the higher privacy impact of these data categories.
When a service provider receives an EPOC, it must produce the requested data within ten days, or within eight hours in emergency cases. The provider must direct any objections — such as questions about the validity of the order, the scope of the request, or potential conflicts with the law of the provider’s country — through a defined process involving the enforcing authority in the provider’s member state. However, the provider cannot simply refuse to comply; the regulation establishes a presumption of compliance, with limited grounds for refusal.
The EPOC represents a significant departure from traditional Mutual Legal Assistance (MLA) procedures, which require requests to be routed through central authorities and can take months or even years to process. By allowing judicial authorities to address orders directly to service providers, the e-Evidence Regulation dramatically reduces the time required to obtain cross-border digital evidence. For service providers, this means they must be prepared to receive, validate, and respond to EPOCs within tight timescales.
The European Preservation Order Certificate (EPOC-PR)
The EPOC-PR is a less intrusive instrument that requires a service provider to preserve specific electronic evidence pending a subsequent production request. Unlike the EPOC, the EPOC-PR does not require the provider to disclose any data — it simply requires the provider to ensure that the specified data is not deleted, altered, or otherwise made unavailable. The EPOC-PR serves as a holding measure that prevents the loss of evidence while the issuing authority prepares a production order or other legal process to obtain the data.
An EPOC-PR can be issued by a broader range of authorities than an EPOC, including prosecutors, as well as judges and courts. This broader issuing authority reflects the lower privacy impact of preservation (the data is retained but not disclosed) compared to production (the data is actually disclosed to the requesting authority).
When a service provider receives an EPOC-PR, it must take immediate steps to preserve the specified data. The preservation obligation continues for 60 days, which can be extended by 30 days if the issuing authority confirms that a production request has been initiated. If no production request is received within the preservation period, the provider may release the preserved data in accordance with its normal retention policies.
The EPOC-PR is particularly useful in situations where evidence may be at risk of deletion — for example, when a suspect is aware of an investigation and may attempt to destroy evidence, or when the data is subject to automatic deletion under the service provider’s retention policies. By securing the preservation of data quickly, the EPOC-PR prevents the loss of evidence while allowing time for the more rigorous authorisation process required for a production order.
Key Differences Between EPOC and EPOC-PR
The differences between EPOC and EPOC-PR are fundamental and span several dimensions. Purpose is the most basic distinction: an EPOC compels the production (disclosure) of data, while an EPOC-PR compels only the preservation (retention) of data. The privacy impact of an EPOC is significantly higher than that of an EPOC-PR, which is reflected in the different authorisation requirements and procedural safeguards.
Issuing authority requirements differ between the two instruments. EPOCs for transactional and content data must be issued or validated by a judge or court, while EPOC-PRs can be issued by prosecutors without judicial validation. This difference reflects the proportionality principle — the more invasive the measure, the higher the level of judicial oversight required.
Response timescales also differ. EPOCs require production within ten days (or eight hours in emergencies), while EPOC-PRs require immediate preservation with the obligation lasting 60 days (extendable to 90 days). The EPOC-PR is designed to be a rapid, temporary measure, while the EPOC is a definitive order requiring substantive compliance.
The grounds for refusal differ between the two instruments. For EPOCs, service providers have limited but defined grounds for raising objections, including questions about the immunity or privileges that may apply to the requested data, the potential impact on fundamental rights, and conflicts with the law of the provider’s member state. For EPOC-PRs, the grounds for objection are more limited, reflecting the less invasive nature of preservation compared to production.
Implications for Telecommunications Operators
Telecommunications operators are among the most likely recipients of both EPOCs and EPOC-PRs, given the volume of subscriber data, traffic data, and content data they hold. Operators must build processes and systems to handle both types of orders, including the ability to receive and validate incoming orders, identify the relevant data in their systems, preserve data in response to EPOC-PRs, produce data in response to EPOCs, track the status and timelines of each order, and maintain documentation and audit trails for regulatory compliance.
The ten-day response time for EPOCs (and eight hours for emergencies) is particularly demanding. Operators must have processes in place that enable rapid identification and extraction of the requested data, review by qualified legal and compliance personnel, and secure delivery to the requesting authority. Manual processes that rely on individual action may not be sufficient to meet these timescales consistently, and operators should consider investing in automated or semi-automated systems for handling e-Evidence requests.
Relationship to Lawful Interception
It is important to distinguish e-Evidence orders from lawful interception. Lawful interception involves the real-time capture and delivery of communications as they occur. E-Evidence orders, by contrast, relate to stored data — data that has already been generated and is retained by the service provider. An EPOC may request historical traffic data, subscriber records, or stored content, but it does not authorise real-time interception.
However, the two frameworks are complementary. Law enforcement may use e-Evidence orders to obtain historical data about a target’s communications patterns and then use lawful interception to monitor the target’s ongoing communications. Operators must be capable of supporting both frameworks, with appropriate systems and processes for each. The data retention policies of the operator are also relevant, as the availability of historical data depends on how long the operator retains different data categories.
Preparing for e-Evidence Compliance
Operators should begin preparing for e-Evidence compliance by designating a legal representative in the EU (if not already established in an EU member state) to receive and handle e-Evidence orders. They should review their data retention policies to ensure that the data categories covered by e-Evidence are available for the required retention periods. They should also develop internal procedures for receiving, validating, and responding to both EPOCs and EPOC-PRs, train relevant staff on the requirements and timescales, and implement technical systems to support the rapid identification, preservation, and extraction of requested data.
Conclusion
The EPOC and EPOC-PR are the two pillars of the EU e-Evidence framework, each serving a distinct purpose in the cross-border evidence-gathering process. The EPOC compels the production of specified data, while the EPOC-PR requires its preservation. Together, they provide law enforcement with a faster, more direct mechanism for obtaining digital evidence across EU borders, replacing the slow and cumbersome MLA process. For telecommunications operators, compliance with both instruments requires investment in processes, systems, and trained personnel — but the rewards of early preparation include smoother compliance, reduced regulatory risk, and a constructive relationship with the law enforcement authorities that rely on operator cooperation.
The e-Evidence Regulation also introduces requirements for the establishment of a decentralised IT system to facilitate the transmission of e-Evidence orders between member states and service providers. Operators should monitor the development and deployment of this system and prepare to integrate with it as it becomes operational. The IT system is intended to provide a secure, standardised channel for the exchange of orders and responses, replacing the ad hoc communication methods that have been used to date. Early engagement with the implementation process will help operators avoid last-minute compliance challenges when the system goes live and will ensure that their internal processes are aligned with the technical requirements of the new infrastructure.
As the EU e-evidence regulation takes effect, the volume of EPOC EPOC-PR requests will increase significantly. Operators must ensure their processes can handle EPOC EPOC-PR requests within the mandated timelines.
Related Articles
For further reading on related topics, explore these articles:
- How e-Evidence and Lawful Interception Differ — and Where They Overlap
- EU E-Evidence Regulation: What Service Providers Need to Know Before August 2026
- Legal Holds in Telecom: What Operators Must Preserve and for How Long
External Resources
The following external resources provide additional context and official documentation:



