EU forces platforms to hand over data within 8 hours from Monday
On 18 August 2026, social platforms across the EU must be ready to produce user data within 8 hours in emergencies, under a regulation most social media professionals have never heard of.
EU investigative authorities will be able to request electronic evidence directly from service providers in other EU member states, bypassing the previous mutual legal assistance procedure that could take months. European Production Orders require transmission of requested data within 10 days, or 8 hours in emergency situations.
The regulation applies to social media platforms, online marketplaces, and cloud services. That includes every major platform your team manages, and the regulation extends to providers based outside the EU, as long as they offer services to users within the Union.
What constitutes an emergency? Situations involving an imminent threat to life, physical integrity, or critical infrastructure. When an order lands, the clock is already running.
What most social teams don't know
On 27 March 2026, the European Commission sent formal notices to 22 member states for failing to communicate full transposition of the E-Evidence Directive. The infrastructure is behind schedule. The application date is not.
Service providers must designate a permanent point of contact within the EU by 18 August 2026, to receive and execute orders. A US company with EU users is in scope. A provider with no establishment in the EU must appoint a legal representative there.
This is not a platform policy update your Legal team will brief you on. It is a criminal procedure regulation most social teams will encounter for the first time when the platform they manage receives its first order.
The data authorities can request
The regulation distinguishes between four categories of data, each with different thresholds.
The data covered by the order falls into four categories: subscriber data, IP address data, traffic data, and content data.
Subscriber data (name, contact details, account creation date) and access data can be requested for any criminal offence. For traffic and content data, which are the most sensitive, an EPOC can only be issued for offences punishable by a maximum custodial sentence of at least three years, or for specific cyber and terrorism offences.
Content means messages, posts, images, and any other data a user has shared or stored on the platform. If a French prosecutor is investigating fraud and believes evidence sits in a user's Instagram DMs or their Facebook business page, they can now request it directly from Meta's EU representative, not through a lengthy diplomatic channel.
Who handles this on your team
The regulation creates an operational problem most social teams are not structured to solve. When an 8-hour emergency order arrives, who opens it? Who verifies it? Who extracts the data? Who confirms it meets evidentiary standards?
The 10-day clock starts when the provider receives the order, not when someone on the legal team opens it, not when the data team begins searching for records.
Your community managers are not trained to handle law enforcement requests. Your legal team may not monitor the designated inbox in real time. The platform itself may have the data stored in a format that cannot be produced within the deadline.
Who reviews an order, who pulls the data, who answers, and who is on call for the eight-hour emergency window. Legal, compliance, trust and safety, and product all own a piece.
Most brands running social accounts have no process for this. Agencies managing client accounts have even less clarity about where liability sits.
The 10-day clock starts when the provider receives the order, not when someone on the legal team opens it.
TrueScreen implementation guideThe cost of getting it wrong
Member States must lay down pecuniary penalties if service providers infringe the rules on the execution of European Production and Preservation Orders. It must be ensured that pecuniary penalties of up to 2% of the service provider's total worldwide annual turnover can be imposed.
For platforms, that is a significant financial exposure. For brands and agencies managing accounts on those platforms, the risk is reputational and operational. If you manage a high-profile brand account and an emergency order requests subscriber or traffic data for a user who has interacted with that account, the platform must respond. You will not be consulted. The user will not be notified in advance.
This is not a data protection issue in the GDPR sense. This is criminal procedure. The regulation only covers e-Evidence already stored when an order is received; it does not create obligations to retain data without a reason. But if the data exists, and an order is valid, it must be produced.
What social teams should do now
The regulation goes live in six days. If your organisation operates social accounts with EU users, or if you manage accounts on behalf of clients who do, three questions need answers before Monday.
Do you know where your organisation's EU legal representative is registered? Service providers must designate a permanent point of contact within the EU by 18 August 2026. If you manage accounts for a US or UK-headquartered brand, this representative has likely been appointed by the platform, not by your organisation. But if your organisation is itself the service provider (for example, running a membership platform, a private community, or a branded app with social features), you are directly in scope.
Do you have a process for emergency requests? Most companies lack the internal workflows, designated roles, and technical infrastructure to meet these timelines. If your Legal, Compliance, or Trust and Safety teams are unaware of the 8-hour emergency deadline, the first order will be a crisis, not a procedure.
Do you know what user data your platforms hold? Traffic data, subscriber data, and content data all carry different legal thresholds, but all can be requested. If you run a branded community, a members-only group, or any platform where users communicate or share content, you hold data that could be subject to an order.
For most social teams, the immediate action is escalation. Flag this to Legal and Compliance now, not after the first order arrives. Ask whether your organisation has registered its EU addressee, and whether anyone has tested the process for receiving and responding to orders.
What this means for the industry
The e-Evidence Regulation changes the speed at which user data moves from platforms to authorities, but it also changes who needs to understand criminal procedure.
Social media compliance has historically focused on advertising standards, content moderation, and data protection. This regulation introduces a new compliance layer that sits outside those frameworks. It is not about what you post. It is about what data you hold, and how fast you can produce it when an authority in another country demands it.
Approximately 9,000 companies in Germany alone are affected. Multiply that across 27 member states, and the compliance population is vast.
Agencies, platforms, and in-house teams all need to know where this obligation sits in their operating structure. The regulation applies from 18 August 2026. There is no grace period.
If you manage social accounts with EU users and you have not yet mapped who handles emergency data requests, Monday is already too late to start building the process. But it is not too late to escalate.

