On Monday 18 August 2026, Regulation (EU) 2023/1543 โ the e-Evidence Regulation โ starts applying across the EU. From that day, a prosecutor in one member state can order a hosting provider in another to hand over data directly, without going through the provider’s own government first. If you run a website, this is a law about you. Here is what it actually says, what it does not say, and what it changes about the question this site exists to answer: does it matter who owns your host?
What starts on 18 August
The Regulation creates two instruments. A European Production Order tells a service provider to hand data over; a European Preservation Order tells it to keep data from being deleted while a production order is prepared. Both are issued by a judicial authority in one member state and served on a provider โ or the contact it has designated โ in another. The old route, a mutual legal assistance request from government to government that could take months, is bypassed.
The deadlines are short: ten days to comply with a production order, and eight hours in an emergency. The orders cover four kinds of data โ subscriber data (who holds the account), data needed to identify a user such as IP addresses with source ports and timestamps, traffic data (who communicated with whom, when), and content. Subscriber and identification data can be ordered for any criminal offence. Traffic and content data require an offence carrying at least three years’ maximum imprisonment, or one of a list of specific crimes.
It is not a blank cheque. When an order seeks traffic or content data about someone who does not live in the issuing state, the authorities where the provider sits are notified and can block execution โ within ten days, or 96 hours in emergencies โ on grounds that include fundamental-rights violations and immunities. Those safeguards were fought into the text over five years of negotiation; the first drafts, leaked in 2018, had almost none of them. EFF warned about those drafts at the time, and civil-society groups like EDRi still consider the final version a step down for procedural rights. Read their criticism; it is not wrong. But the law that applies from Monday is the negotiated one, safeguards included.
What it is not: the CLOUD Act, with a treaty
The comparison everyone reaches for is the US CLOUD Act of 2018, and the two laws are genuinely similar in mechanism: both let an authority compel a provider directly, across a border, wherever the data sits. The differences are the ones that matter to a European customer:
- Whose law, whose courts. An e-Evidence order is issued under EU law, by a judicial authority, reviewable by European courts, with the Charter of Fundamental Rights and the GDPR applying end to end. A CLOUD Act demand is issued under US law, reviewable โ if at all โ in US courts, by a government you did not elect and cannot petition.
- Who is reachable. e-Evidence reaches every provider offering services in the EU โ European ones, American ones, all of them, including us. The CLOUD Act reaches providers subject to US jurisdiction: US companies and their subsidiaries, wherever the data is stored.
- The overlap. Host with a US-owned provider and from 18 August you are reachable under both regimes: European orders because they serve Europe, American ones because of who owns them. Host with a European provider and you are reachable under one โ the one your own courts control.
That asymmetry is the entire argument of this company, stated by a European legislator instead of by us. Sovereignty was never “beyond the law’s reach” โ nobody lawful is selling that, and you should distrust anyone who implies it. It is: which law, and whether the courts that check it are yours.
What this means for our customers โ including the honest part
The honest part first: this law applies to us. A hosting provider offering services in the EU is exactly what Article 3 has in mind, and a valid European Production Order served on us after 18 August is an order we comply with, on the deadlines above. A host that told you otherwise would be lying to you, and we would rather lose a sale than compete on that.
What we can honestly promise is the posture around it. We verify before we comply: an order has to be what the Regulation says it is โ issued by a judicial authority, in the form the law prescribes โ and one that is not gets challenged through the mechanisms the law provides, not waved through. We hold little: no tenant passwords, backups encrypted before they leave the server, and an access log we deliberately summarise rather than hoard, because data we do not keep is data nobody can order. And we say what happened: unless a court forbids it, a customer whose data is produced hears it from us.
None of that is heroism. It is the ordinary duty of a provider under a law with actual safeguards โ which is precisely the point of choosing one governed by that law alone.
Sources: Regulation (EU) 2023/1543 and Directive (EU) 2023/1544 (in force 17 August 2023; the Regulation applies from 18 August 2026); eucrim’s summary of the deadlines, thresholds and notification mechanism; EDRi on the civil-liberties objections. This is our reading as a hosting provider, not legal advice โ for your own obligations, ask a lawyer, not a host.