sota.io
Join the waitlist
2026-08-04·11 min read·sota.io team

The EU e-Evidence Regulation Goes Live August 18: What Cloud and PaaS Providers Must Do, and Why Most of the EU Isn't Ready Either

The EU e-Evidence Regulation Goes Live August 18: What Cloud and PaaS Providers Must Do, and Why Most of the EU Isn't Ready Either

On August 18, 2026, Regulation (EU) 2023/1543 — the EU's "e-Evidence" Regulation on European Production Orders and European Preservation Orders — becomes directly applicable law in every EU member state except Denmark. If you run a cloud, hosting, communications, or "information society" service that EU users can sign up for, this law can reach you even if your company has never opened an EU office, never signed an EU government contract, and has no idea the deadline exists.

Two things make this different from the usual EU-compliance-deadline post. First, the obligation is genuinely new and genuinely broad: it is not GDPR, not the CLOUD Act, and it applies regardless of where your servers physically sit. Second — and this is the part almost nobody covers — the EU's own member states are largely not ready for it either. Twenty-two of them are currently under formal infringement proceedings from the European Commission for failing to transpose the companion Directive on time. The obligation on providers still starts August 18 regardless.

What the Regulation actually requires, in plain terms

Regulation (EU) 2023/1543 lets a judicial authority in one EU member state issue a European Production Order (EPO) or European Preservation Order (EPO-PR) directly to a service provider, without going through the slow mutual-legal-assistance channel that cross-border law enforcement has relied on for decades. The order arrives as a European Production Order Certificate (EPOC) or preservation certificate (EPOC-PR), and it can compel you to hand over subscriber data, traffic data, or content data.

The deadlines, verified directly against the regulation's Article 10 ("Execution of an EPOC"):

Who's covered — this is Article 3(3), and it's deliberately wide. "Service provider" means any entity offering:

  1. electronic communications services (as defined in Directive (EU) 2018/1972 — think VoIP, messaging, email);
  2. internet domain name and IP numbering services (registries, registrars, proxy/privacy services); or
  3. other "information society services" that either let users communicate with each other, or let users store or process data, where storage is a defining feature of the service.

Category 3 is the one that pulls in PaaS, IaaS, and generic cloud hosting. If your product lets a customer store data or run a backend that stores data, you are very plausibly in scope — regardless of whether you think of yourself as a "cloud company" or a "SaaS tool."

The part most coverage skips: this isn't the Regulation's job

Here's a nuance that matters if you're trying to figure out who to actually appoint and by when: the obligation to designate an EU establishment or appoint a legal representative is not in Regulation 2023/1543 at all. It's in the companion instrument, Directive (EU) 2023/1544. Citing only the Regulation for the representative duty is citing the wrong legal basis — the two instruments were adopted together (both dated July 12, 2023, both published in the same Official Journal issue) and have to be read together.

Directive 2023/1544, Article 3, verified directly:

Denmark is out — verified, not assumed

Regulation (EU) 2023/1543, Recital 101: "In accordance with Articles 1 and 2 of Protocol No 22 on the position of Denmark annexed to the TEU and to the TFEU, Denmark is not taking part in the adoption of this Regulation and is not bound by it or subject to its application." Denmark's long-standing opt-out from EU justice-and-home-affairs measures applies here as it does elsewhere in this area of law. If your only EU establishment or representative sits in Denmark, you are not covered by this specific instrument — though you should not treat that as a general shield, since Denmark can and does adopt parallel national measures.

The awkward part: the EU isn't ready for its own law

Directive 2023/1544 gave member states until February 18, 2026 to transpose it into national law (Art. 7). On March 27, 2026, the European Commission sent formal letters of notice — the first step of an infringement procedure — to 22 member states for failing to fully communicate transposition: Belgium, Bulgaria, Czechia, Estonia, Ireland, Greece, Spain, France, Cyprus, Latvia, Lithuania, Luxembourg, Hungary, Malta, the Netherlands, Austria, Poland, Portugal, Romania, Slovenia, Finland, and Sweden. That's a large majority of the bloc, roughly five months before the Regulation's own application date.

There's a second readiness gap underneath the legal one. The Regulation establishes a "decentralised IT system" (Art. 19) for the formal written exchange of orders and certificates between authorities and providers — but Art. 34(2) explicitly defers the obligation to actually use that system until one year after the relevant implementing acts (Art. 25) are adopted, and those implementing acts were not finalized as of this writing. In practice, that means the digital plumbing EU authorities are supposed to use to send you an EPOC won't be uniformly in place on day one, even though your 10-day (or 8-hour) clock starts regardless of which channel the order arrives through.

None of this changes your deadline. It changes what you should expect on the ground: uneven enforcement readiness, inconsistent penalty regimes depending on which member state your representative sits in, and very likely some early orders sent through improvised channels rather than the eventual standardized IT system. Waiting for the EU to finish its own homework is not a compliance strategy — the obligation on you starts August 18 whether or not the counterpart infrastructure does.

What this means if you run infrastructure on a US-headquartered PaaS

This Regulation is a different mechanism from the US CLOUD Act, and the two can now both apply to the same data at the same time. The CLOUD Act lets a US court compel a US-incorporated provider (and its foreign subsidiaries) to produce data regardless of where it's stored. The e-Evidence Regulation lets an EU judicial authority compel any provider offering services in the EU — including that same US-incorporated provider, via its EU-based designated establishment or representative — to produce data on a much tighter clock than mutual legal assistance ever allowed. A US PaaS provider serving EU developers now sits at the intersection of both regimes, with two different legal systems that can each independently order data disclosure, on different timelines, potentially with different confidentiality (gag-order) rules attached.

If your production data — your customers' data — lives on infrastructure incorporated outside the EU, the practical question isn't "is my provider GDPR-compliant" (most large US providers can point to EU data-processing addenda and Standard Contractual Clauses). It's "which government's compulsion process reaches this data fastest, and under what secrecy obligations." Running on EU-incorporated infrastructure doesn't make you exempt from European Production Orders — an EU-based provider is squarely in scope of Regulation 2023/1543 too — but it does remove the second, US-side channel that only applies because of where the parent company is incorporated. That's the actual, narrower claim worth making here, distinct from marketing claims about "sovereignty" that this Regulation does not itself grant.

What to actually do before August 18

  1. Confirm whether your product falls under Art. 3(3) of the Regulation — specifically, whether you enable user communication or store/process data as a defining feature. Most PaaS, hosting, and backend-as-a-service products clear this bar.
  2. Check your provider's designated establishment or legal representative status under Directive 2023/1544, Art. 3 — ask directly, don't assume; many providers have not publicized this yet given the transposition gaps described above.
  3. Don't assume a specific fine percentage without checking the implementing law of the specific member state involved — the Directive leaves this to national legislators, and figures circulating online vary by source.
  4. Separate this from your CLOUD Act exposure assessment. They're not the same order, the same authority, or the same clock, and mitigating one does not mitigate the other.

Regulation (EU) 2023/1543 and Directive (EU) 2023/1544 were both published in the Official Journal on July 28, 2023, both adopted July 12, 2023, and the Regulation's Article 34(2) sets August 18, 2026 as the application date — 14 days from this post. Whether the infrastructure and national laws that are supposed to support that date are actually ready is, per the Commission's own March 27, 2026 infringement letters, a separate and currently unresolved question.

Sources: Regulation (EU) 2023/1543, EUR-Lex CELEX:32023R1543 · Directive (EU) 2023/1544, EUR-Lex CELEX:32023L1544 · eucrim.eu — E-Evidence Regulation and Directive Published · ComplexDiscovery — The EU's E-Evidence Framework Goes Live in August and Most of Europe Isn't Ready · Bird & Bird — e-Evidence Implementation Tracker

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.