Back to overview
Podcast
Ins and Outs of the e-Evidence Regulation and Directive

Episode 1: e-Evidence and the GDPR: simplification of the digital rulebook?

The EU e-Evidence framework was designed to make access to electronic evidence across borders faster. But faster access also means that service providers and authorities need to make decisions quickly about data that is often sensitive, while still complying with existing data protection rules.

In the first episode of ICCT’s The Ins and Outs of the e-Evidence Regulation and Directive, Isabella Pirlogea speaks with data protection expert Danny van Roijen about how the new framework interacts with the GDPR and what this means in practice for service providers, authorities and data subjects.

One of the first issues is the relationship between the data controller and the data processor. Under the GDPR, the controller decides why and how personal data is processed, while the processor acts on the controller’s behalf. In practice, however, this relationship is not always obvious to an authority sending an e-Evidence order. An order may reach a processor rather than the controller, and existing data processing agreements do not always explain in enough detail what should happen in this situation. This matters because the e-Evidence framework works with strict deadlines. A provider will normally have ten days to respond to a production order, while in emergency cases the deadline can be as short as eight hours. Where responsibilities are unclear, even basic questions — who receives the order, who assesses it, and who decides whether the data can be disclosed — can become difficult to resolve within the available time.

This is where operational preparedness becomes important. Providers need to know where their data is held, what type of data they are dealing with, and who is responsible for responding when an order arrives. Internal escalation procedures also need to be clear, especially in emergency cases.

The discussion also raises questions about the position of the data subject. Under the GDPR, transparency is an important principle. Yet in practice, a person may not know that their data has been disclosed to an authority, particularly where an investigation requires confidentiality. Privacy notices often state in general terms that data may be shared with public authorities, but they are not necessarily written with the e-Evidence framework in mind.

Data retention adds another difficulty. Rules on retention are still not fully harmonised across the EU and differ depending on the type of data involved. This leaves both providers and authorities working in a fragmented environment. The European Preservation Order provides some structure by allowing data to be preserved for a limited period while a production order is prepared, but it does not solve the broader differences between national approaches to retention.

For service providers, one practical starting point is therefore to revisit existing data processing agreements and clarify how e-Evidence orders should be handled between controllers and processors. Providers also need clear internal procedures, a good overview of their data flows, and staff who understand the new deadlines and obligations.

Member States also have an important role. Delays in the transposition of the e-Evidence Directive and differences in national implementation can create further uncertainty for providers operating across several jurisdictions. In practice, the new framework will therefore have to coexist, at least for some time, with other instruments and established forms of cooperation.

The broader challenge is that the e-Evidence framework does not operate in isolation. It enters an already complex EU digital and data protection landscape. The question is therefore not only whether providers and authorities can comply with the new rules, but whether the different legal frameworks can work together in a way that is clear and workable in practice. If the system is expected to work quickly, responsibilities need to be clear before an order arrives, not after.

 

Isabella Pirlogea is a Marie Salomea Skłodowska Curie PhD candidate at Leiden University and a Research Fellow at the International Centre for Counter-Terrorism (ICCT) in The Hague. Her research focuses on the practical implementation of the EU e-Evidence Regulation and Directive, with particular attention to their implications for cross-border electronic evidence cooperation and transatlantic counter-terrorism.

Danny Van Roijen is a public affairs and compliance professional with 20 years of experience in European policies and regulations across various technology sectors. He has worked on a broad range of EU digital and data policies, with in-depth knowledge and expertise on topics such as artificial intelligence, cybersecurity and data protection, and the interaction between these domains. He is a certified Data Protection Officer and a former member of the European Commission's expert groups on eHealth and on cyber security certification.

 

About this series

Extra body

The Ins and Outs of the e-Evidence Regulation and Directive is a mini-series designed to take the law out of the books and examine what the EU e-Evidence framework means in practice.

Rather than focusing only on the legal text, the series brings together practitioners, policymakers, service providers and other experts involved in the collection, production and transfer of electronic evidence across borders. Through focused conversations, it explores how the new framework is expected to operate in real cases, where implementation challenges may arise, and what the Regulation and Directive will mean for the authorities and companies responsible for making the system work.

Each episode approaches the e-Evidence framework from the particular perspective and expertise of its guest, focusing on a specific dimension of implementation, from data protection and fundamental rights to the practical application of the Regulation in Member States such as Ireland.

The series aims to create a space for informed and practical discussion at a critical moment for European electronic evidence cooperation. By bringing different perspectives into the same conversation, it seeks to identify not only how the new rules are designed to work, but also what will be required to make them work effectively, consistently and with the necessary safeguards in practice.

Related podcasts