DENOG18

A Prosecutor in Another Country Wants Your Data in 8 Hours — Now What?

Since 18 August 2026, a prosecutor in another EU country can demand your users' data directly from you — ten days to comply, eight hours if they're in a hurry. No mutual legal assistance, no local court in between: just an order in your inbox and a clock. This talk is the E-Evidence Regulation for the people who actually run the infrastructure: which data you can be forced to produce, how fast, and whether the systems you already operate could even answer in time. A few months in, we'll look at what's working, what's on fire, and what you should have built before the first order arrives.


Most coverage of the EU E-Evidence Regulation is written for lawyers. This one isn't. If you operate an ISP, a hosting platform, a cloud, or a registrar, you are the addressee of these orders — and the obligations are technical and time-boxed long before they're legal.

We'll start with the 90-second operator edition: European Production Orders (EPOC) and European Preservation Orders (EPOC-PR), who can issue them, which data categories are in play (subscriber, traffic, content), and the deadlines that turn this into an on-call problem rather than a policy memo. Then we get to the parts nobody warns you about: that you must designate an establishment or legal representative, that liability is joint and several with fines reaching into a percentage of global turnover, and that there's an actual machine interface behind all this — a decentralised IT system, a transport spec, a hard size limit, and a rollout that may not be finished when the orders start arriving.

The practical core is simpler than the crypto-heavy forensics literature suggests. Evidence just needs to be trustworthy: the right data, demonstrably unchanged, anchored in time, and traceable back to where it came from. You don't need a forensics lab for that — you need to know whether the logs and exports you already produce would survive someone asking "how do you know this is genuine?" We'll cover the idea at a level you can act on, then look at how it usually falls apart in practice: data that's already been rotated away, mutable logs, a screenshot instead of a record, no idea who pulled what or when.

We close with a field report from the first months of the regime — readiness across the EU, what early orders actually look like, and a pragmatic checklist so that when (not if) one lands in your inbox, you can produce the right data, in a defensible form, within the deadline — without it turning into a fire drill every time.

This session is for ISP, hosting, cloud, and registrar engineers, DevOps, abuse/LI-interface teams, and anyone who owns logging or will be the one woken up at 2 a.m. by an 8-hour emergency order. No legal background required; bring your healthy disrespect for bureaucracy.

The speaker's profile picture
Mathias Handsche

Mathias Handsche is an expert in IT security and network infrastructure, focused on NIS2, KRITIS, and ISO/IEC 27001 in the telecommunications and internet-service sector. As Managing Director of nGENn GmbH, he helps telecom operators, ISPs, and data centres build sustainable ISMS structures and turn regulatory requirements into lean processes that fit day-to-day operations rather than fighting them.

He is an active ISO/IEC 27001:2022 and ISO 22301:2019 lead auditor working in critical-infrastructure and telecommunications environments, and contributes to the German national standards committee (DIN), bringing field experience into the national standard mapping NIS2 to ISO/IEC 27001. His current work also extends to evidentiary integrity and the handling of digital evidence under the EU E-Evidence framework.