A Faster Lane for Cross-Border Evidence
On August 18, 2026, Regulation (EU) 2023/1543 — the e-Evidence Regulation — became directly applicable across the EU, with Denmark alone exempt under its justice opt-out (EUR-Lex summary). The regulation lets a prosecutor in any of the 26 participating member states issue a European Production Order straight to a service provider, requiring data — emails, messages, subscriber records — within 10 calendar days, or eight hours in an emergency (Regulation text, Art. 56; EUR-Lex summary). Non-compliance can draw fines of up to 2% of a provider's global turnover (EUR-Lex summary). Providers "offering services in the Union" — a jurisdictional hook, not an establishment test — fall in scope regardless of where their servers sit, and those without an EU establishment must appoint a legal representative to receive orders (Regulation text, Art. 18).
The Case for It
The old system — mutual legal assistance treaties routed through central justice ministries — genuinely was too slow for digital evidence. Chat logs and IP session data can be gone in days; a request that takes months to clear diplomatic channels routinely arrives after the data has been deleted. Eurojust's own case-management data has driven the push for a harmonized, fast-track mechanism precisely because 27 different national procedures were producing 27 different delays for the same category of evidence (Eurojust e-Evidence page). A single EU-wide production order, with defined deadlines and refusal grounds, is a defensible fix to a real coordination failure — in principle.
Where Switzerland Sits — Nowhere
The catch is that Switzerland is not a party to any of this. The Swiss Federal Council only opened exploratory talks with the EU on electronic evidence cooperation on April 9, 2025, and as of this writing no agreement, treaty, or even a negotiating mandate has been finalized — the Federal Office of Justice's own page describes the file as still under evaluation (bj.admin.ch). A 2023 Federal Office of Justice assessment of the then-draft EU package recommended against any unilateral Swiss move and urged Bern to revise domestic law before seeking a negotiated arrangement — exactly the deliberate, judicially-supervised process the regulation's direct-order mechanism now sidesteps for any Swiss company with EU users (eucrim summary of the FOJ report).
That matters because the regulation doesn't require Switzerland's consent to bind Swiss companies — it requires only that they "offer services in the Union." Proton, domiciled in Geneva and long marketed on Swiss privacy law as a selling point, already maintains an EU representative entity, Proton Europe sàrl in Luxembourg, for Digital Services Act purposes. Whether that same entity — or a separate one required under Directive (EU) 2023/1544 — now becomes the recipient of ten-day production orders is precisely the compliance question the industry is racing to close before enforcement starts (Bird & Bird, "e-Evidence day one").
The Policy Bind This Creates for Proton
Proton's own published law-enforcement policy states plainly: "in no case will Proton AG provide you with data directly following contact... it will always be transmitted through the Swiss authorities," with requests routed through MLATs (Proton, Information for Law Enforcement). That is the Swiss MLA process the e-Evidence Regulation is explicitly designed to bypass. The company's transparency track record shows why the distinction matters in practice: in the first half of 2026, Proton reported receiving 47 legally binding requests for VPN user data, all from Swiss authorities, and rejected all of them because its no-logs architecture left nothing to hand over (CyberInsider). A ten-day EU production order changes the clock, not the underlying data minimization — but it does change who gets to ask, and whether a Swiss court ever reviews the request first.
A Proportionate Fix, an Improvised Rollout
We don't dispute the underlying premise: harmonized, time-bound production orders are a sensible modernization of a genuinely slow system, and providers operating in the EU market should expect EU-grade process obligations. But applying that regime to a non-member state's companies through a market-access trigger, ahead of any negotiated Swiss-EU framework, inverts the sequencing that both Brussels and Bern's own 2023 assessment endorsed. Speed for law enforcement shouldn't come at the cost of the judicial-authorization safeguards Swiss law currently provides before data leaves the country. The fix isn't to weaken the regulation — it's to finish the exploratory talks Bern started in April 2025 into an actual bilateral instrument, modeled on the EU-US CLOUD Act executive agreements, so Swiss courts retain a defined role rather than being written out by default. Until then, Swiss providers serving European users are complying with a regime their own government never got to negotiate.