Europol: Electronic evidence becomes a critical bottleneck for European law enforcement

August 27, 2026

Messages, e-mails, IP addresses and data held by cryptocurrency exchanges have become indispensable to modern criminal investigations. Yet obtaining such evidence across borders remains legally complex, technically demanding and, above all, time-critical. Europol and Eurojust’s latest SIRIUS Electronic Evidence Situation Report shows that the volume of data requests has risen to 3.5 times its 2018 level. With the EU’s new e-Evidence framework now entering its operational phase, Europe faces a decisive test: whether its investigators, judicial authorities and private service providers can secure digital evidence before it disappears.

Electronic evidence is becoming one of the central resources of European law enforcement. Communications data, e-mails, messages exchanged through apps, connection records and account information can help identify suspects, reconstruct criminal networks and trace financial flows. But the architecture of the digital economy creates a fundamental problem for investigators: the evidence is often located outside the jurisdiction in which the crime is being investigated. Servers may be distributed across several countries, the physical location of data may be unknown and the company controlling access to it may be established in yet another jurisdiction.

The scale of the issue is highlighted by the SIRIUS Electronic Evidence Situation Report 2025, published by Europol and Eurojust on 27 August. More than half of criminal investigations now involve a request for cross-border access to electronic evidence. The volume of data requests is 3.5 times higher than in 2018, while the number of emergency requests is also increasing. For police and prosecutors, the question is therefore no longer whether relevant digital traces exist, but whether they can be identified, preserved and obtained quickly enough to remain useful.

More requests meet fragmented procedures

This growing demand is colliding with a legal and procedural environment that remains fragmented. Investigators and judicial authorities must navigate different national rules, cooperation mechanisms and service-provider procedures. There are still no fully harmonised rules governing how long relevant information must be preserved or how quickly providers must respond to lawful requests.

The consequences can be serious. According to the SIRIUS report, judicial cooperation mechanisms are frequently regarded by judicial authorities as slow and procedurally complex. In some cases, the delay can result in potentially critical electronic evidence being lost before investigators are able to obtain it.

This is particularly significant because digital evidence is often far more volatile than its physical equivalent. Accounts can be deleted, communications removed and service providers may retain different categories of data for different periods. Once information has disappeared, a later judicial order cannot recover what is no longer available.

The lack of an EU-wide data retention framework therefore remains one of the report’s central concerns. Differences between national regimes and company practices can create gaps in investigations precisely when authorities need to move quickly.

Cryptocurrency exchanges move into the investigative mainstream

One of the report’s most striking findings concerns the types of companies receiving requests from law enforcement. Cryptocurrency exchanges are now among the three categories of service providers from which investigators most frequently request data.

This reflects a wider transformation in criminal investigations. Digital assets are no longer relevant only to specialist cybercrime units. Cryptocurrency can appear in cases involving fraud, ransomware, money laundering, illegal online markets and other forms of organised crime. Investigators consequently need not only communications and subscriber information but increasingly data capable of connecting digital financial transactions to individual users and criminal networks.

The development also illustrates how quickly the electronic-evidence landscape is changing. Police forces and prosecutors that only a few years ago primarily dealt with telecommunications providers and major online platforms must now understand the structures of cryptocurrency exchanges, cloud providers and an expanding range of digital services.

SIRIUS has developed into an important European support structure for precisely this reason. The project, jointly implemented by Europol and Eurojust, provides law enforcement and judicial authorities with operational guidance, training and contact information for more than 1,000 service providers, including cryptocurrency exchanges.

The EU’s e-Evidence rules enter the operational phase

The European Union is attempting to address some of these problems through its new e-Evidence framework. At its centre is Regulation (EU) 2023/1543, which has applied since 18 August 2026 and introduces European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings.

The underlying change is significant. Under specified conditions, an authority in one Member State can require a service provider established or legally represented in another Member State to produce or preserve electronic evidence without relying solely on the traditional mechanisms of international judicial cooperation.

Crucially, the framework is designed to operate irrespective of where the relevant data is physically stored. That addresses one of the fundamental mismatches between conventional legal structures and cloud computing. A criminal investigation may be conducted in one country, the service provider may be headquartered in another and the relevant information may move dynamically between data centres in several jurisdictions. In such an environment, the physical location of a server is an increasingly impractical basis for determining how investigators should obtain evidence.

The new framework is intended to make procedures more predictable and legally robust for service providers as well. Regulation 2023/1543 is accompanied by Directive (EU) 2023/1544, which sets out requirements concerning designated establishments and legal representatives through which providers can receive and comply with orders.

The objective is therefore broader than speed alone. Europe is attempting to create a more standardised infrastructure for cooperation between public authorities and private technology companies while retaining procedural safeguards and fundamental-rights protections.

New powers are of limited value without training

The existence of a new legal instrument, however, does not guarantee effective use. One of the more concerning findings in the SIRIUS report is the continuing lack of awareness among law enforcement authorities about the new EU e-Evidence legislation.

Europol and Eurojust therefore identify training as an urgent requirement. Investigators, prosecutors and judges need to understand which tools are available, which categories of information can be requested, which procedural thresholds apply and how requests should be directed to providers.

This is particularly important because the electronic-evidence environment evolves much faster than traditional investigative procedures. New communications services, business models and financial platforms can become operationally relevant within a short period. Legal knowledge and technical competence must therefore develop together.

The application of Europe’s new rules should consequently be regarded less as the end of a legislative process than as the beginning of an operational test. If the authorities expected to use the instruments are unfamiliar with them, the efficiency gains promised by the legislation may be lost in practice.

Service providers are becoming part of the security infrastructure

The pressure is not confined to public authorities. Technology companies are receiving growing numbers of requests from police and judicial bodies, with emergency requests creating particular strain on specialised Law Enforcement Response Teams.

At the same time, compliance with the new European framework requires significant modifications to internal processes and IT systems. Providers must be capable of receiving legally valid requests, identifying the relevant account or dataset, preserving information, assessing legal requirements and responding within the applicable procedures.

This means that access to electronic evidence is increasingly dependent on a functioning public-private security architecture. Much of the information required for modern criminal investigations is no longer held by the state. It is stored by telecommunications companies, social networks, cloud platforms, internet services and cryptocurrency exchanges.

The effectiveness of law enforcement therefore increasingly depends on the technical and organisational interfaces between those companies and the authorities requesting information from them.

SIRIUS encourages providers to engage proactively with the project and prepare for the changing legal environment. For large technology companies with established compliance departments, this represents a significant but manageable adjustment. Smaller providers may face a much more difficult task, particularly as emergency requests and cross-border obligations increase.

The race for the digital trace

The findings point to a broader transformation of criminal justice in Europe. As communications, financial transactions and commercial activity become digital, the evidence needed to investigate crime increasingly follows the same path. Yet those digital traces can be distributed across jurisdictions and controlled by private companies whose retention periods, technical architectures and legal obligations differ.

The strategic challenge for Europe is therefore not simply to give investigators additional powers. It is to create an environment in which relevant evidence can be recognised, legally secured and transmitted quickly enough to remain operationally useful.

The e-Evidence framework is intended to close part of this gap, but legislation alone cannot achieve that objective. Police and judicial authorities require specialised training, service providers need reliable compliance processes, and both sides need secure and interoperable technical systems. At the same time, the absence of a common EU data-retention framework continues to leave a potential weakness in investigations.

With the volume of law-enforcement data requests now three and a half times higher than in 2018, electronic evidence can no longer be treated as a specialist issue at the margins of criminal investigation. It has become part of the core infrastructure of European law enforcement.

The new benchmark for successful digital investigations is therefore not merely whether authorities know which information they need. It is whether they can secure that information before the digital trace disappears.

Related Articles

Cross-border security cooperation offers lessons for Europe

The German states of Hesse and Rhineland-Palatinate are expanding cooperation between police, emergency services, civil protection authorities, intelligence agencies and cybersecurity bodies. While many of the individual projects are rooted in Germany’s federal...

Editor’s Note: A jacket is not a privacy strategy

Facial recognition is moving out of the control room and into everyday life. If cameras, artificial intelligence and biometric identification converge in devices that look like ordinary glasses, the change will not simply be technological. It will alter the balance...

Share This