Your email provider has ten days to hand you over
Since 18 August 2026, your email data can be handed over within ten days to an authority in any member state, without a judge in your country.
On 18 August 2026, a rule came into force across almost all of the European Union, and nobody said a word about it to the general public. It doesn’t change what your emails contain. It changes who can come and get them, how fast, and through which door.
The text is called e-Evidence: a European regulation (2023/1543) and its twin directive (2023/1544). The name is about as thrilling as a residents’ association meeting. What it does is a good deal less so. Since 18 August, a judicial authority in any member state can demand your data directly from your host or your email provider, within ten days, without going through a judge in your country, without a mutual assistance procedure, without you moving off your sofa.
Your email provider now has ten days to hand over what it holds on you. What’s left to work out is exactly what it can hand over, and what will always stay out of its reach.
Before e-Evidence, how it worked
Until now, when a prosecutor in one European country wanted data from a service hosted in another, they had to ask permission. In practice, that meant mutual legal assistance: an official request passed to the authorities of the country where the provider sits, reviewed by a local judge, executed under local law. Slow, heavy, full of national safeguards. Months, often a great deal more.
e-Evidence removes that step.
What changed on 18 August
Since that date, in every member state except Denmark, an authority in one country can send its order straight to a provider located or represented in another. No intermediate judge in the provider’s country. No mutual assistance. A certificate, a deadline, an obligation.
Two instruments worth remembering:
- The production order (EPOC): the provider must hand over the requested data within ten days. In an emergency (imminent threat to life or safety), the deadline drops to eight hours.
- The preservation order (EPOC-PR): it freezes the data to stop it being deleted while a formal request is prepared. Freeze period: sixty days, extendable by thirty.
The scope is broad, and that’s where it catches people out. Don’t think only about your inbox. The text covers communication services, messaging apps, the cloud, hosts, platforms, and even domain name registrars. Your domain name is an access point too. Nobody ever thinks of that.
And it doesn’t stop at the Union’s borders. A provider established outside the EU, in the United States for example, falls within scope as soon as it offers services in the Union with what the text calls a substantial connection: a significant number of European users, an offer in the local language, pricing in the country’s currency, local advertising. No need for an office or servers in Europe. It makes no difference where the data is stored.
To make all this enforceable, the directive requires every provider concerned to designate an establishment or a legal representative in the Union, empowered to receive and execute orders. Refusing to play along is expensive: penalties can reach 2% of annual worldwide turnover.
The change isn’t “they can access your data”. They already could. The change is the speed and the door: direct, fast, with your country out of the loop.
Also read: Chat Control 2.0: The EU wants to read your messages before you send them and NIS2 forces companies to encrypt. CSAR prevents them from really doing it.
Four categories of data, and the three everyone forgets
The regulation doesn’t treat all your data the same way. It distinguishes four families:
- Subscriber data: who you are in the service’s eyes, the information you provided when you signed up.
- Identification data: your IP address in particular, the one that links an activity to a connection.
- Traffic data: who communicates with whom, when, for how long, by what means.
- Content data: the text of your messages, your files, what you actually wrote or stored.
The last two, traffic and content, are the most sensitive, and the text gives them reinforced safeguards (more on that shortly). But there’s a trap in this list, and it’s a big one.
Everyone focuses on content. “My messages are encrypted, I’m fine.” Except content is only one of the four families. The other three describe the envelope: who, when, with whom, from where.
Encryption hides the letter. It doesn’t hide the envelope.
Who you write to, at what time, from which IP, how often: these metadata often say more than the message itself. A regular, anonymous exchange with a specialist lawyer tells a story, even without reading a single line of it. And no content encryption erases those metadata. They travel, in Europe and elsewhere, and an EPOC can go and fetch them.
What it can hand over, what it can’t
e-Evidence doesn’t require any provider to decrypt your data, or to break or weaken its own encryption. That point is solid. And it has a direct consequence.
Two worlds need separating. On one side, providers that hold the keys to your data: server-side encryption, the case for most consumer webmail. Those can technically decrypt your content, so they have to produce it on order.
On the other, providers whose architecture rests on client-side end-to-end encryption, where the keys are generated on your device and never leave your hands. Those don’t hold the keys. They can’t produce your content in the clear, even if they wanted to.
And the text says so plainly: the data requested must be handed over whether it is encrypted or not. So an E2E provider doesn’t hand over nothing, it hands over a block nobody can open, itself included. It isn’t cheating, it’s stating a mathematical fact.
There’s the real shield. Not the country, the architecture. Content encrypted end-to-end on the client side is beyond the reach of a production order, European or otherwise. Content encrypted “in transit” or “at rest” but whose keys the provider keeps stays producible on a simple order.
That’s exactly the argument Mac Souverain has been making since its first comparisons. The rest is shop-window encryption.
Also read: Apple Mail vs Gmail vs Proton Mail, the honest comparison, Switching from Gmail to ProtonMail on Mac and Why your mail client is a sieve, and how to fix it.
The safeguards, and their limits
e-Evidence isn’t a blank cheque, on paper at least. For traffic and content data, when the person targeted or the offence sits outside the issuing country, an authority in the executing country (where the provider is established or represented) is notified.
That notification suspends the obligation to hand over for ten days, a window in which a legality and proportionality review can operate. In an emergency, that drops to ninety-six hours.
Several grounds allow an order to be refused or not recognised: immunities and privileges under the executing country’s law, a manifest breach of fundamental rights, the principle of not being tried twice for the same facts, or the absence of dual criminality. On top of that come protections for particular categories: professional secrecy, journalists and their sources, diplomats.
It sounds reassuring. One caveat: the provider itself doesn’t have to review the general legality of the order. It mainly checks there’s no manifest impossibility within its own sphere. And part of the legal community considers these safeguards too soft, not least because the burden of challenge falls on an executing authority that isn’t always brought in, particularly for subscriber and identification data.
Translation: to find out who you are and where you connect from, the net is looser than it is for the content of your messages.
So what about Switzerland?
That’s the question every sovereignty-minded reader asks. Proton, Infomaniak, Swiss hosts are outside the Union. “I’m hosted in Switzerland, so e-Evidence doesn’t touch me.”
e-Evidence doesn’t bite a purely Swiss provider. A service hosted in Switzerland, with no establishment in the Union and not actively targeting the European market, stays outside the regulation’s direct scope. To get its data, the Union has to go back to the old road: international mutual legal assistance, passed to the Swiss authorities, reviewed by a Swiss judge, executed under Swiss law. Count several months, against ten days for an intra-EU EPOC. A Swiss provider adds friction and time. That’s a real brake, not an illusion.
An honest grey area remains: Proton and Infomaniak clearly have users and an audience in the Union. Whether they fall within the regulation’s scope on the “substantial connection” test, and whether they have had to designate a European representative, is an open question. I’m not going to settle it on their behalf.
But Switzerland has rules of its own. The country applies a law on the surveillance of correspondence (the LSCPT), enforced by a dedicated federal service. In practice: metadata is retained for around six months, your IP address can be logged and then handed over on the order of a Swiss authority, and cooperation targets serious offences, under judicial supervision. Content stays protected if it is end-to-end encrypted.
A proposed revision of its implementing ordinances has been under debate for a while, with head-on opposition from the industry. Its fate isn’t settled, so we draw no conclusion from it here.
The best example is a real one. In 2021, on a binding order from the Swiss authorities (triggered by a request from France), Proton was compelled to log and then hand over the IP address of an activist.
Proton couldn’t hand over the content of their emails: encryption stopped it. Proton says so in black and white, and its transparency reports document that it executes Swiss orders while contesting some of them, without ever handing data directly to a foreign government. Everything goes through the Swiss authorities.
Read the lesson of that case properly. Swiss jurisdiction didn’t save the activist’s IP. Encryption saved the content.
Switzerland is a speed bump, not a wall. It protects your metadata less well than people think, and your content only if the architecture is right. The flag adds time and a judge. It doesn’t add immunity.
What changes, what doesn’t
What changes. Your email provider can be served by a judicial authority in any member state, and it has ten days to hand over, without your country and without an intermediate judge. Speed is the new weapon.
What doesn’t change. Mathematics. Content encrypted end-to-end on the client side, with keys your provider doesn’t hold, stays unreadable to anyone, order or no order.
What that means in practice, in three moves:
- Put your sensitive content under client-side end-to-end encryption. It’s the only level where your provider can’t betray you, because it doesn’t hold the key. For email, that means a service whose architecture guarantees it, Proton Mail first among them. A classic webmail, even a “secure” one, keeps the keys: it can produce.
- Treat your metadata as data, not as decoration. Encryption protects the letter, not the envelope. Cut down what you expose: who, when, with whom, from which IP. That’s the ground where no flag covers you.
- Choose your jurisdiction for the right reasons. Sitting outside the EU adds time and a local judicial review, which counts. But never confuse “slower to reach” with “out of reach”. Jurisdiction governs speed. Architecture governs access.
The real question has never been which country your email is hosted in. It’s what your provider can hand over the day someone asks, and what it will never be able to hand over because it doesn’t hold it. e-Evidence invented nothing on that front. It just reminded us, very fast and very loudly, where the one lock nobody can force actually is.
The one you alone hold the key to.
Sources
The text
- EUR-Lex, Regulation (EU) 2023/1543 on European Production and Preservation Orders for electronic evidence, the official text, applicable since 18 August 2026.
- EUR-Lex, Directive (EU) 2023/1544, the obligation for providers to designate an establishment or a legal representative in the Union.
The analysis
- eucrim, E-evidence Regulation and Directive Published, the deadlines, the grounds for refusal and the penalties.
- BfDI, the German federal data protection authority, E-Evidence Regulation, the notification mechanism and the deliberately limited role of the provider.
Switzerland
- Proton, Important clarifications regarding arrest of climate activist, the 2021 case: IP address handed over on a Swiss order, email content out of reach.