Today, the European Union's e-Evidence rules—a new framework for law enforcement to access data across borders—take effect. As discussed in our recently released report, Digital Evidence in Europe: Persistent Challenges, Practical Solutions, the e-Evidence framework promises to dramatically transform the way law enforcement can access data for criminal investigations and prosecutions across borders.

Among other changes, the e-Evidence rules enable law enforcement authorities in one Member State to issue production and preservation order certificates directly to private-sector service providers located in other EU countries—without having to go through the cumbersome and time-consuming mutual legal assistance process, which requires a formal government-to-government request for data.  

The deadlines for responses are short: 10 days for an initial response in most cases and eight hours for emergency responses. The new framework also has broad reach, applying to all service providers that “offer services” in the EU, including U.S.-based service providers that are not physically located in the EU. The rules include minimal procedural and substantive standards, procedures for challenging data requests, and adjudication standards.

Once fully implemented, these changes will standardize and streamline law enforcement requests for data and facilitate law enforcement access to data needed to investigate and prosecute serious crime.

But there is significant work ahead:

  •  As of this writing, fewer than half of the EU Member States have implemented the national legislation needed to transpose the e-Evidence rules into local law—and thus make them effective. One notable development: On July 15, Ireland adopted the requisite national legislation to transpose the Directive into Irish law. This is significant given that a large number of service providers—including several large U.S.-based service providers—are expected to designate in Ireland. But far too many EU Member States do not have the key national laws in place, without which they will not be able to meaningfully participate in the new framework.
  • There are ongoing challenges with the new technical system, pursuant to which requests for data will be made and received—and the need for strong cybersecurity measures to protect the information sent and received. In recognition that the technical system is not yet fully operational, the European Commission in July published informal guidance on the contingency operations that should apply, suggesting alternative transmission through secure email, secure cloud solutions, and secure platforms operated by the service provider. As Member States make the eventual transition to the decentralized IT system, it will be essential to prioritize the cybersecurity of the system, no matter what mechanisms are used. This should include regular testing, audits, governance controls, and strong access and authentication controls—drawing on the expertise of the European Union Agency for Cybersecurity and other technical experts. This is critical to protecting sensitive data and trust in the system as a whole.
  • Effective implementation will require meaningful and ongoing training and support for all stakeholders involved. The transition to e-Evidence involves a shift in the standards, processes, and technology used to request and receive electronic data.  It even shifts which government entities are given primary responsibility for requesting digital evidence. There will be an inevitable learning curve. Effective training, at both the national and regional levels, is critical to supporting law enforcement, judicial authorities, and private sector entities as they transition to a new technical system and legal framework
  •  Given the reach of e-Evidence, U.S.-based service providers risk being caught in a conflict of laws subject to both e-Evidence production demands and the restrictions imposed by the U.S. Electronic Communications Privacy Act that prohibits the disclosure of communications content data to foreign government entities, absent an applicable exception. To provide clarity in such cases, the EU and the United States should pursue a Data Sharing Agreement under the U.S. CLOUD Act. Such an agreement could minimize conflicts of law, clarify expectations for U.S.-based providers, and ensure sufficient protection for Americans’ data.

Getting this right is important. Digital evidence is critical to the investigation and prosecution of serious crime; often critical evidence is located across physical borders. In our survey of European law enforcement earlier this year (described in the Digital Evidence Report), more than 85% of respondents indicated that they sought digital evidence from entities in other countries in almost all or some of their cases. Our survey further found that approximately 60% of cross-border requests involve other EU Member States.

Now that the effective date for e-Evidence implementation has arrived, the hard work needs to begin. This will require all Member States to transpose the rules into their national laws, along with continued investments in training, technology, cybersecurity, and governance structures to ensure success.

Read our full report, “Digital Evidence in Europe: Persistent Challenges, Practical Solutions,” here.

Read Next

European Commission Publishes Final Cyber Resilience Act Implementation Guidance, Addresses Concerns Raised by Cybersecurity Coalition

The Cybersecurity Coalition welcomes final guidance on the Cyber Resilience Act that provides covered entities with clearer guidance on the landmark product security regulation.

Building Texas Cyber Resilience: From Awareness to Action

Texas is building a new model for cyber resilience. A recent convening of state, local, academic, and private sector leaders identified practical steps to strengthen coordination, expand shared capabilities, and improve cybersecurity readiness.

An Important Win for Vulnerability Disclosure in the Post-Quantum Cryptography Executive Order

President Trump's recent Executive Order highlights the need for federal contractors to have access to clear channels to report vulnerabilities.