On 18 August 2026, the way European police and prosecutors obtain digital evidence changed more than at any point since the Budapest Convention. Regulation (EU) 2023/1543 — the e-Evidence Regulation — became directly applicable across all 27 member states, letting a judicial authority in Lithuania order a cloud provider represented in Ireland to hand over user data, or a prosecutor in Portugal compel a messaging app headquartered in Germany, without routing the request through a central government office first. Under the European Commission's own description, a European Production Order must be answered within 10 days — or 8 hours in an emergency.
The Case for Speed
The strongest argument for this regime is straightforward, and worth taking seriously before critiquing it. Digital evidence is volatile: IP logs rotate, chat metadata gets purged on retention schedules, and a suspect can delete an account faster than a magistrate can sign a letter rogatory. The system the Regulation replaces — mutual legal assistance, or MLAT — was built for a world of paper files and physical borders, not one where a WhatsApp thread relevant to a Berlin fraud case sits on servers a provider designates as Dublin-based. According to figures cited in industry analysis of the framework, MLAT requests have historically averaged around 10 months to resolve, with some letters rogatory taking over a year. A decade-old kidnapping or trafficking investigation cannot wait ten months for a subscriber record. On that narrow point, the Commission has a real case: crime that moves at the speed of the internet needs an evidentiary process that doesn't move at the speed of 1990s diplomacy.
What Actually Changed
The mechanics are more sweeping than the "faster MLAT" framing suggests. Under the EUR-Lex summary of the Regulation, any EU judicial authority can now compel production directly from a provider's designated EU establishment or legal representative — bypassing not just MLAT but, for many categories of data, the receiving state's own courts. Content and traffic data still require judicial sign-off, but subscriber and IP-address data can move on a prosecutor's order alone. The scope is broad by design: per Reed Smith's analysis of the compliance obligations, it covers not just telecoms and email providers but domain registrars, IP allocators, cloud storage, social platforms, and online marketplaces — essentially any "information society service" where data storage is a defining feature. Non-compliant providers face penalties of up to 2% of global annual turnover, a Digital Markets Act-style enforcement lever grafted onto a criminal-procedure statute.
The Readiness Gap
Here is where the pro-innovation case for caution becomes hard to ignore. The companion Directive (EU) 2023/1544, which requires member states to designate the authorities and systems that actually process these orders, had a transposition deadline of 18 February 2026. It largely blew past it: on 27 March 2026, the Commission opened infringement proceedings against 22 of the EU's 27 member states for failing to communicate complete transposition. That is not a rounding error — it is four-fifths of the bloc going live on a binding 10-day, 8-hour-emergency data-disclosure regime without having finished building the domestic legal scaffolding the Regulation assumes exists.
That gap matters because the safeguards in this framework — judicial review for content data, notification to the state where a provider is established, a right to challenge manifestly unlawful orders — depend on national authorities actually being staffed, systems being built, and courts knowing which orders to flag. A regulation engineered around 8-hour emergency compliance has essentially no margin for a member state that hasn't finished appointing its central review authority. Service providers, meanwhile, must have designated an EU establishment or legal representative by the same 18 August deadline, per the Commission's own guidance — leaving a narrow window between knowing the rules and having to obey them under threat of turnover-based fines.
The Pro-Innovation Verdict
This is a case where the underlying goal — collapsing a 10-month bottleneck into 10 days for genuinely urgent criminal investigations — is defensible and even overdue. Cross-border platforms have spent a decade complaining, fairly, that MLAT was too slow to be useful and too opaque to audit. A harmonised, faster mechanism with defined deadlines is a real improvement over 27 bilateral patchworks. But speed without uniform judicial capacity on the receiving end isn't proportionality — it's a bet that oversight will catch up before the first wrongly-issued order does damage. The Commission should treat the infringement backlog as an operational emergency, not a paperwork footnote, and providers should be pushing loudly — now, while the fine schedule is still new — for published compliance statistics on order volumes and rejection rates. A regime this fast needs transparency at the same speed, or the 10-day deadline becomes the only part of the law anyone actually enforces.