Skip to main content

Investigations

Does "subscriber data" mean the same thing in every instrument?

No. The Convention draws three categories and the European Union Regulation draws four, and the extra one is not a sub-case — it carries its own authorisation rule and its own exemption from the duty to notify the other Member State.

Fact-checkedSafety review clearedLast updated Last reviewed

In short

Cross-border mechanisms are written in terms of data categories: this route reaches subscriber information, that one reaches traffic data, another reaches content. The categories look like a shared vocabulary. They are not — each instrument defines them for itself, and one of them counts differently from the others.

Why it exists

AnalysisThe categories carry the weight of the whole design. Which route may be used, who may authorise it, whether another State must be told, and whether the mechanism reaches at all — every one of those turns on which category the material falls into. A term that shifted meaning between instruments would shift all of those with it.

How it works

The Convention on Cybercrime defines its third category by excluding the other two. Article 18(3) provides that "subscriber information" means information held by a service provider relating to subscribers of its services other than traffic or content data, by which the type of service and period, the subscriber’s identity and contact and billing details, and information on the site of installation of communication equipment can be established.

Regulation (EU) 2023/1543 defines four. Article 3(9) defines subscriber data as data relating to the subscription — identity, address, billing and payment data, contact details, service type and duration and related technical data — while expressly excluding "passwords or other authentication means used instead of a password that are provided by a user, or created at the request of a user". Article 3(11) defines traffic data by enumeration, including source and destination, the location of the device, date, time, duration, size, route, format and protocol, and session log-in and log-off data. Article 3(12) defines content data as any data in digital format "other than subscriber data or traffic data".

And Article 3(10) defines a category the Convention has no counterpart for: "data requested for the sole purpose of identifying the user".

The exclusions differ, and they are not decorative
The Convention’s subscriber information is defined negatively — anything held about a subscriber that is not traffic or content data. The Regulation’s subscriber data is defined positively by enumeration and then narrowed by an express carve-out for passwords and other authentication means. An item can therefore sit inside one instrument’s subscriber category and outside the other’s.
Location appears inside traffic data in the Regulation
Article 3(11) lists "the location of the device" among the elements of traffic data, alongside source and destination, timing and session data. Where a system treats location separately, that treatment does not come from this definition.
The Protocol uses the categories to divide its routes
Article 7 of the Second Additional Protocol reaches specified, stored subscriber information and nothing else; Article 8 reaches specified and stored subscriber information and traffic data. Content data appears in neither. The categories are what separate a direct route from one that runs through the other Party.

Common misconceptions

Widely held beliefs that do not match how the system actually operates.

  • Common belief: Subscriber data, traffic data and content mean the same thing in every instrument.

    In practice: The Convention defines subscriber information by excluding traffic and content data. The Regulation defines subscriber data by enumeration with an express carve-out for passwords and other authentication means, and adds a fourth category the Convention does not have.

  • Common belief: There are three categories of communications data.

    In practice: Regulation (EU) 2023/1543 defines four. Article 3(10) creates "data requested for the sole purpose of identifying the user" as a distinct category, and Articles 4(1), 4(2) and 8(1) each treat it differently from traffic data.

  • Common belief: A category label tells you which route may be used.

    In practice: It tells you which route may be used under that instrument, and no further. Article 7 of the Second Additional Protocol reaches subscriber information as the Protocol uses the term; the Regulation’s categories govern the European orders; and the Convention’s govern its own articles.

  • Common belief: Identification data is simply a kind of subscriber data.

    In practice: The Regulation treats it separately. Article 4(2) defines the stricter authorisation rule as applying to traffic data "except for data requested for the sole purpose of identifying the user", and Article 8(1) excludes it from the notification duty on the same terms.

  • Common belief: Because content is the most protected category, everything else is lightly protected.

    In practice: The Regulation’s subscriber-data definition expressly excludes passwords and other authentication means, so material that might look like account information is outside the lightest category by definition.

  • Common belief: These definitions tell you what the categories mean in national law.

    In practice: They define the terms for their own instruments. Whether any national law adopts them, or defines the categories differently again, was not researched for any country.

How this varies between jurisdictions

A required section on every guide. Arrangements differ between countries, and we say how.

Three instruments, two different category models.

  • Three categories, the third defined by excluding the other two — Convention on Cybercrime, Art. 18(3).
  • Four categories, enumerated, with content defined as everything that is not the other two named ones — Regulation (EU) 2023/1543, Arts. 3(9)–(12).
  • A fourth category that changes the authoriser — Reg. Art. 4(1)–(2) — and the notification duty — Art. 8(1).
  • Subscriber data expressly excluding passwords and other authentication means — Reg. Art. 3(9)(b).
  • Device location inside traffic data — Reg. Art. 3(11).
  • Categories used to divide the routes themselves — Second Additional Protocol, Art. 7 against Art. 8, with content in neither.

Rights and accountability

AnalysisA category boundary is a safeguard boundary. Because the route, the authoriser and the duty to tell another State all follow the category, a disagreement about which category material falls into is a disagreement about how much protection it gets — which is why the instruments define the terms rather than leaving them to the requesting authority.

What we could not establish

  • Three instruments were read. Whether any national law adopts any of these definitions, or defines the categories differently again, was NOT RESEARCHED for any country.
  • The Convention’s definitions of traffic data and content data outside Article 18(3), and the Protocol’s Article 14 on personal data, were not read for this wave.
  • Nothing here describes what any particular provider holds, or how any category of data is generated, stored or obtained.

Where to go next

Related: content and communications data, European production and preservation orders, and direct cooperation with foreign providers.

Sources

  1. Convention on Cybercrime (Council of Europe, ETS No. 185, Budapest, 23 November 2001), Articles 14–21 and Chapter III (Articles 23–35)

    Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0001839) · International organisation · 2001-11-23 · link verified 2026-09-05

    WAVE 22 ADDITION. ACCESS NOTE: rm.coe.int and coe.int returned HTTP 403 to automated requests in this session, so the Convention was read from the official Dutch government treaty database, which publishes the authentic English text alongside the Dutch translation. The English text quoted below is the authentic one; English and French are the authentic languages. Supports Art. 14(1)–(2), that the procedural powers are established “for the purpose of specific criminal investigations or proceedings” and are applied to the offences established under Arts. 2–11, to other criminal offences committed by means of a computer system, and to “the collection of evidence in electronic form of a criminal offence”. Supports Art. 14(3)(a), that a Party restricting the Art. 20 power to specified offences must not restrict it more narrowly than the range to which it applies Art. 21. Supports Art. 15(1), that the powers are subject to conditions and safeguards under domestic law providing adequate protection of human rights, including rights under the 1950 European Convention and the 1966 Covenant, “and which shall incorporate the principle of proportionality”. Supports Art. 15(2), that such conditions and safeguards shall, as appropriate, “include judicial or other independent supervision, grounds justifying application, and limitation of the scope and the duration of such power or procedure”. Supports Art. 16(1)–(3): expedited preservation of specified stored computer data “including traffic data”, in particular where it is particularly vulnerable to loss or modification; where effected by order to a person, an obligation to preserve and maintain integrity “for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure”, renewable; and an obligation on the custodian to keep the undertaking of the procedure confidential. Supports Art. 17, expedited preservation and PARTIAL disclosure of traffic data sufficient to identify the service providers and the path through which the communication was transmitted. Supports Art. 18(1)(a)–(b), the production order: a person in the territory to submit specified stored computer data in that person’s possession or control, and a service provider offering services in the territory to submit subscriber information. Supports Art. 18(3), which defines “subscriber information” as information held by a service provider relating to subscribers of its services “OTHER THAN TRAFFIC OR CONTENT DATA” and by which the type of service, the subscriber’s identity, postal or geographic address, telephone and other access number, billing and payment information, and information on the site of installation of communication equipment can be established. Supports Art. 19(1)–(4): the power to search or similarly access a computer system or a computer-data storage medium; the power under 19(2) to EXTEND the search expeditiously to another system in the territory where the data sought is “lawfully accessible from or available to the initial system”; the power under 19(3) to seize or similarly secure, comprising the separate powers to “seize or similarly secure a computer system or part of it or a computer-data storage medium”, to “make and retain a copy of those computer data”, to “maintain the integrity of the relevant stored computer data”, and to “render inaccessible or remove those computer data in the accessed computer system”; and the power under 19(4) to order any person with knowledge about the functioning of the system to provide, as is reasonable, the necessary information. Supports Art. 20, real-time collection of TRAFFIC data, and Art. 21, interception of CONTENT data, the latter available only “in relation to a range of serious offences to be determined by domestic law”; both articles oblige a service provider to keep the execution confidential. Cited for the structural propositions that preservation is a distinct act from production, that traffic data and content data are distinct powers, that subscriber information is defined by exclusion from both, and that seizing, copying and accessing are separately enumerated. LIMITATIONS, and they are load-bearing: this is a TREATY. It obliges Parties to establish powers in domestic law; it is NOT evidence of what any particular Party has enacted, and no country claim on this platform rests on it. It describes no technique. STATUS: in force; the Convention has two additional protocols, of which the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was located but NOT read for this wave. WAVE 23 ADDITION. That Protocol has now been read and is held separately as `coe-cybercrime-second-protocol`. Chapter III of the Convention, on international co-operation, was read from the same authentic English text, and it is a different subject from the domestic powers above. Supports Art. 23, that Parties co-operate “in accordance with the provisions of this chapter, and through the application of relevant international instruments on international co-operation in criminal matters, arrangements agreed on the basis of uniform or reciprocal legislation, and domestic laws”. Supports Art. 25(1)-(4), and in particular Art. 25(2), that “Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35” -- the Convention’s own statement that its co-operation articles are not self-executing -- and Art. 25(4), that except as specifically provided “mutual assistance shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation”. Supports Art. 27(1), that the Article applies only “where there is no mutual assistance treaty or arrangement on the basis of uniform or reciprocal legislation in force between the requesting and requested Parties”, and Art. 27(2)(a)-(d), that each Party designates a central authority “responsible for sending and answering requests for mutual assistance, the execution of such requests or their transmission to the authorities competent for their execution”, that central authorities communicate directly with each other, and that the Secretary General keeps a register of them. Supports Art. 29(1)-(4): a Party may request another to preserve data “located within the territory of that other Party and in respect of which the requesting Party intends to submit a request for mutual assistance”; the request must state that intention (29(2)(f)); “For the purposes of responding to a request, dual criminality shall not be required as a condition to providing such preservation” (29(3)); and a Party that requires dual criminality for disclosure may reserve the right to refuse preservation where it has reasons to believe the condition cannot be fulfilled at the time of disclosure (29(4)). Supports Art. 30(1)-(2), expedited disclosure of a sufficient amount of preserved traffic data to identify a service provider in another State and the path through which the communication was transmitted, withholdable only for a political offence or where execution is likely to prejudice sovereignty, security, ordre public or other essential interests. Supports Art. 31(1)-(3), mutual assistance to search, seize and disclose stored data “including data that has been preserved pursuant to Article 29”, responded to on an expedited basis where data is particularly vulnerable to loss. Supports Art. 32 IN FULL, and its narrowness is the point: “A Party may, without the authorisation of another Party: a) access publicly available (open source) stored computer data, regardless of where the data is located geographically; or b) access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data to the Party through that computer system.” There is no third limb and no unilateral remote-access provision. Supports Art. 33(1)-(2), mutual assistance in the real-time collection of traffic data, governed by the conditions and procedures of domestic law and available at least for offences for which such collection would be available in a similar domestic case; and Art. 34, mutual assistance regarding the interception of content data “to the extent permitted under their applicable treaties and domestic laws”. Supports Art. 35(1)-(2), that each Party designates a point of contact available twenty-four hours a day, seven days a week, to ensure immediate assistance -- facilitating or, if permitted by its domestic law and practice, directly carrying out technical advice, preservation under Arts. 29 and 30, and the collection of evidence, provision of legal information and locating of suspects -- and that where the point of contact is not part of the Party’s authority responsible for international mutual assistance, it must ensure co-ordination with that authority. LIMITATION ON CHAPTER III, restated because it is easy to lose: these are obligations on Parties to legislate and to co-operate. They are NOT evidence of what any Party has enacted. The Party list, signature dates and ratification counts were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403 to three separate URL forms.

  2. Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings, Articles 3, 4, 8, 13, 17, 18 and 34

    Publications Office of the European Union (EUR-Lex) · International organisation · 2023-07-12 · link verified 2026-09-05

    WAVE 23 ADDITION. The Regulation read directly on EUR-Lex. TEMPORAL STATUS, verified from the instrument itself: Art. 34(1) provides that it enters into force on the twentieth day following publication in the Official Journal, and Art. 34(2) provides in terms “It shall apply from 18 August 2026.” Against the research date of 5 September 2026 the Regulation is therefore APPLICABLE, and had been for eighteen days. The SAME paragraph carries a separate and later trigger: “the obligation for competent authorities and service providers to use the decentralised IT system established in Article 19 for written communication under this Regulation shall apply from one year after the adoption of the implementing acts referred to in Article 25” -- whether those implementing acts have been adopted was NOT RESEARCHED, so that trigger date is NOT ESTABLISHED. Supports Art. 3(1), that a “European Production Order” is a decision ordering the production of electronic evidence, issued or validated by a judicial authority of a Member State, and “addressed to a designated establishment or to a legal representative of a service provider offering services in the Union, where that designated establishment or legal representative is located in another Member State bound by this Regulation”. Supports Art. 3(2), that a “European Preservation Order” orders preservation “for the purposes of a subsequent request for production”. Supports the four data definitions in Art. 3(9)-(12): subscriber data; “data requested for the sole purpose of identifying the user” as a DISTINCT category; traffic data; and content data, defined as any data in digital format “other than subscriber data or traffic data”. Supports Art. 4(1)-(3), the authorisation ladder: a production order for subscriber data or identification data may be issued by a judge, court, investigating judge OR PUBLIC PROSECUTOR, or by another competent investigating authority whose order is then validated by one of those; a production order for traffic data (other than identification data) or content data may be issued only by a judge, court or investigating judge -- NOT a public prosecutor -- or validated by one of those; and a PRESERVATION order for data of ANY category may be issued by a judge, court, investigating judge or public prosecutor. Supports Art. 8(1)-(4): where a production order seeks traffic data (other than identification data) or content data, the issuing authority shall notify the enforcing authority by transmitting the EPOC to it at the same time as to the addressee; that duty does not apply where the issuing authority has reasonable grounds to believe both that the offence was, is being or is likely to be committed in the issuing State and that the person whose data are requested resides there; and the notification “shall have a suspensive effect on the obligations of the addressee” except in emergency cases. Supports Art. 13(1)-(3): the issuing authority shall without undue delay inform the person whose data are being requested, may delay, restrict or omit that under the conditions of Art. 13(3) of Directive (EU) 2016/680 while recording reasons, and when informing shall include information about available remedies. Supports Art. 17(1)-(2), the reasoned-objection procedure where an addressee considers compliance would conflict with the law of a third country, and that the objection may not rest merely on the absence of similar provisions in that law. Supports Art. 18(1)-(2), that any person whose data were requested has the right to effective remedies, exercised “before a court in the issuing State” and including a challenge to legality, necessity and proportionality. Supports recital 8, which states why the instrument exists alongside the European Investigation Order: Directive 2014/41/EU and the Convention on Mutual Assistance in Criminal Matters provide for requesting evidence from another Member State, but “the procedures and timelines” they provide “might not be appropriate for electronic evidence, which is more volatile and could more easily and quickly be deleted”. LIMITATIONS: this is EU law binding the Member States bound by it. It is NOT evidence of the law of any non-EU country and NOT evidence that any particular Member State has any particular arrangement in place. Whether any Member State has designated addressees under Directive (EU) 2023/1544 was NOT RESEARCHED. Articles 5, 6, 7, 9, 10, 11, 12, 14, 15, 16 and 19-33 were not read in full.

  3. Second Additional Protocol to the Convention on Cybercrime on enhanced co-operation and disclosure of electronic evidence (Council of Europe, CETS No. 224, Strasbourg, 12 May 2022), Articles 6-9

    Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0006966) · International organisation · 2022-05-12 · link verified 2026-09-05

    WAVE 23 ADDITION. ACCESS NOTE: coe.int and rm.coe.int returned HTTP 403 to automated requests on three separate URL forms, so the Protocol was read from the official Dutch government treaty database, which publishes the authentic English text. English and French are the authentic languages. TEMPORAL STATUS, and it is the most load-bearing fact on this record: the database records exactly ONE lifecycle row for this instrument -- “Nieuwe-regeling · Trb. 2022, 66 · 12-05-2022 · Totstandkoming” -- and its “Inwerkingtreding / Voorlopige toepassing” (entry into force / provisional application) column is EMPTY, on a page stating “Informatie geldend op 05-09-2026”. Every article of the Protocol additionally carries the marker “[Tekst zonder datum inwerkingtreding]” -- text without entry-into-force date. Supports the four distinct co-operation channels the Protocol creates, and their DIFFERENT REACH, which is the point. Supports Art. 6(1)-(2): a Party empowers its competent authorities, for specific criminal investigations or proceedings, to issue a REQUEST to an entity providing domain name registration services in another Party’s territory for information to identify or contact the registrant of a domain name, and permits an entity in its own territory to disclose such information “subject to reasonable conditions provided by domestic law”. Supports Art. 7(1): a Party empowers its competent authorities “to issue an order to be submitted directly to a service provider in the territory of another Party, in order to obtain the disclosure of specified, stored subscriber information in that service provider’s possession or control, where the subscriber information is needed for the issuing Party’s specific criminal investigations or proceedings” -- SUBSCRIBER INFORMATION ONLY. Supports Art. 7(2)(a) and, importantly, Art. 7(2)(b): a Party may, at signature or when depositing its instrument, DECLARE that “The order under Article 7, paragraph 1, must be issued by, or under the supervision of, a prosecutor or other judicial authority, or otherwise be issued under independent supervision” -- a declaration, not a default. Supports Art. 7(3)-(4), the order’s required contents and supplemental information. Supports Art. 8(1): an order “to be submitted as part of a request to another Party” compelling a service provider in the REQUESTED Party’s territory to produce specified and stored (a) subscriber information AND (b) traffic data. Supports Art. 9(1)(a): in an emergency, the Art. 35 Convention 24/7 point of contact may transmit and receive requests seeking immediate assistance in obtaining expedited disclosure of specified stored computer data from a provider in another Party’s territory “without a request for mutual assistance”; and Art. 9(1)(b), that a Party may declare it will not execute such requests seeking only subscriber information. LIMITATIONS: this is a TREATY and it obliges Parties to legislate; it is NOT evidence of what any Party has enacted, and no country claim rests on it. Articles 5, 10, 11, 12, 13 and 14 were NOT read. The number of ratifications and the list of Parties were NOT RESEARCHED, because the Council of Europe Treaty Office was unreachable; secondary summaries stating a count were found and are deliberately NOT used. It describes no technique.