Skip to main content

Investigations

Can an authority in one country order a service provider in another country directly?

Under the Second Additional Protocol, for one category of data. Its direct route reaches specified, stored subscriber information only; traffic data requires going through the other Party, and content data is in neither.

Fact-checkedSafety review clearedLast updated Last reviewed

In short

The Second Additional Protocol to the Convention on Cybercrime creates routes that do not run through a foreign government. The most discussed of them lets an authority in one Party send an order straight to a company in another. What that route reaches is much narrower than its reputation.

Why it exists

AnalysisMutual assistance requires a second government to evaluate a request under its own law, which is the right answer when what is sought is intrusive and the wrong answer when it is an account name. The Protocol’s premise is that the weight of the process should track the weight of what is being obtained.

How it works

Article 7(1) is the direct route. Each Party is to empower its competent authorities "to issue an order to be submitted directly to a service provider in the territory of another Party, in order to obtain the disclosure of specified, stored subscriber information in that service provider’s possession or control, where the subscriber information is needed for the issuing Party’s specific criminal investigations or proceedings". Article 7(2)(a) obliges each Party to make providers in its own territory able to disclose in response.

Nor does the Protocol impose a single authorisation rule for that route. Article 7(2)(b) provides that a Party may, at signature or when depositing its instrument of ratification, acceptance or approval, declare that — for orders issued to providers in its territory — "The order under Article 7, paragraph 1, must be issued by, or under the supervision of, a prosecutor or other judicial authority, or otherwise be issued under independent supervision". That is a declaration a Party may make, not a default the Protocol sets.

Article 8 is the route for more than subscriber information, and it is not direct. Each Party is to empower its authorities "to issue an order to be submitted as part of a request to another Party" for the purpose of compelling a service provider in the requested Party’s territory to produce specified and stored "(a) subscriber information, and (b) traffic data". The order reaches the provider through the other Party, and reaches a category Article 7 does not.

A request, not an order, for domain registration information
Article 6(1) empowers authorities, for specific criminal investigations or proceedings, to issue a request to an entity providing domain name registration services in another Party’s territory, for information in its possession or control "for identifying or contacting the registrant of a domain name". Article 6(2) requires each Party to permit an entity in its territory to disclose such information "subject to reasonable conditions provided by domestic law".
An emergency channel between designated contacts
Article 9(1)(a) provides for the Convention’s Article 35 24/7 point of contact to transmit and receive requests seeking immediate assistance in obtaining, from a provider in another Party’s territory, the expedited disclosure of specified, stored computer data "without a request for mutual assistance". Article 9(1)(b) lets a Party declare that it will not execute such requests seeking only subscriber information.
And every route depends on Parties legislating
Each of Articles 6, 7, 8 and 9 opens with the same formula — each Party "shall adopt such legislative and other measures as may be necessary". The Protocol creates obligations to build these routes, not the routes themselves.

Common misconceptions

Widely held beliefs that do not match how the system actually operates.

  • Common belief: The Protocol lets police directly obtain any data from any foreign provider.

    In practice: Article 7 reaches specified, stored subscriber information, for a specific investigation, from a provider in another Party. Traffic data requires Article 8, which runs through the requested Party. Content data is in neither and remains with Convention mutual assistance.

  • Common belief: A direct order to a provider means no judicial or independent involvement.

    In practice: Article 7(2)(b) allows a Party to declare that orders to providers in its territory must be issued by, or under the supervision of, a prosecutor or other judicial authority, or otherwise under independent supervision.

    It is a declaration a Party may make, so the answer differs between Parties and was not researched for any of them.

  • Common belief: Article 6 lets authorities order a registration entity to hand over information.

    In practice: Article 6(1) provides for a request, and Article 6(2) requires Parties to permit disclosure "subject to reasonable conditions provided by domestic law". The instrument distinguishes a request from an order, and uses each in a different article.

  • Common belief: The emergency channel is a faster way to make an ordinary request.

    In practice: Article 9(1)(a) operates in an emergency, between the Convention’s 24/7 points of contact, for the expedited disclosure of specified stored data. Article 9(1)(b) additionally lets a Party declare it will not execute such requests seeking only subscriber information.

  • Common belief: Because the Protocol has been adopted, these routes are available.

    In practice: Every one of Articles 6 to 9 requires each Party to adopt legislative and other measures. And the register consulted for this wave records the Protocol as concluded on 12 May 2022 with no entry-into-force date.

  • Common belief: Direct provider cooperation replaces mutual legal assistance.

    In practice: It supplements it for one category. The Protocol’s own Article 8 keeps traffic data running through the requested Party, and content data stays with the Convention.

How this varies between jurisdictions

A required section on every guide. Arrangements differ between countries, and we say how.

Four channels, four different reaches — which is the Protocol’s architecture.

  • Authority → domain name registration entity in another Party, by request, for registrant identification or contact information — Art. 6(1)–(2).
  • Authority → service provider in another Party, by order, for specified stored subscriber information only — Art. 7(1), with the Art. 7(2)(b) supervision declaration available to a Party.
  • Authority → another Party → provider in that Party, by order in a request, for specified stored subscriber information and traffic data — Art. 8(1).
  • Point of contact → point of contact, in an emergency, for expedited disclosure of specified stored computer data without a mutual assistance request — Art. 9(1)(a), with the Art. 9(1)(b) declaration available.
  • Content data — in none of them; it remains with Convention mutual assistance, Arts. 31 and 34.

Rights and accountability

AnalysisWhat the graduation protects is the proportion between the process and the material. A route that reaches an account name without engaging a second government is defensible in a way that the same route reaching the content of communications would not be — and the Protocol keeps the heavier categories on the heavier routes rather than trusting that the lighter one will be used sparingly.

What we could not establish

  • Articles 6, 7, 8 and 9 of the Protocol were read. Articles 5, 10, 11, 12, 13 and 14 — including its conditions, safeguards and personal-data provisions — were not, and nothing is asserted about them.
  • The Protocol’s entry into force is NOT ESTABLISHED. The official Dutch treaty database, on a page stating information valid on 5 September 2026, records its conclusion on 12 May 2022 and leaves the entry-into-force column empty. Its ratification count and Party list were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403.
  • No provider is named here and nothing compares how any provider or jurisdiction responds. No national implementing legislation was read for any Party.

Where to go next

Related: asking a state and ordering a provider, mutual legal assistance, and when a cooperation instrument starts to operate.

  • Is a cross-border request made to a country or to a company?

    Both exist and they are different instruments. Mutual assistance and the European Investigation Order run state to state; a European Production Order is addressed to a provider’s establishment in another Member State; and the Second Additional Protocol contains one of each.

  • An international instrument has been adopted. Does it work yet?

    Adoption, entry into force, application and national implementation are four different facts, and four instruments read for this section sit at four different points. One states in its own text that its cooperation articles require Parties to legislate first.

  • Does "subscriber data" mean the same thing in every instrument?

    No. The Convention draws three categories and the European Union Regulation draws four, and the extra one is not a sub-case — it carries its own authorisation rule and its own exemption from the duty to notify the other Member State.

  • How does one state ask another for evidence?

    Through a channel each Party designates and a body of law that mostly is not the treaty being invoked. The Convention’s own procedure applies only where no assistance treaty is in force between the two Parties, and its cooperation articles require each Party to legislate first.

Sources

  1. Second Additional Protocol to the Convention on Cybercrime on enhanced co-operation and disclosure of electronic evidence (Council of Europe, CETS No. 224, Strasbourg, 12 May 2022), Articles 6-9

    Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0006966) · International organisation · 2022-05-12 · link verified 2026-09-05

    WAVE 23 ADDITION. ACCESS NOTE: coe.int and rm.coe.int returned HTTP 403 to automated requests on three separate URL forms, so the Protocol was read from the official Dutch government treaty database, which publishes the authentic English text. English and French are the authentic languages. TEMPORAL STATUS, and it is the most load-bearing fact on this record: the database records exactly ONE lifecycle row for this instrument -- “Nieuwe-regeling · Trb. 2022, 66 · 12-05-2022 · Totstandkoming” -- and its “Inwerkingtreding / Voorlopige toepassing” (entry into force / provisional application) column is EMPTY, on a page stating “Informatie geldend op 05-09-2026”. Every article of the Protocol additionally carries the marker “[Tekst zonder datum inwerkingtreding]” -- text without entry-into-force date. Supports the four distinct co-operation channels the Protocol creates, and their DIFFERENT REACH, which is the point. Supports Art. 6(1)-(2): a Party empowers its competent authorities, for specific criminal investigations or proceedings, to issue a REQUEST to an entity providing domain name registration services in another Party’s territory for information to identify or contact the registrant of a domain name, and permits an entity in its own territory to disclose such information “subject to reasonable conditions provided by domestic law”. Supports Art. 7(1): a Party empowers its competent authorities “to issue an order to be submitted directly to a service provider in the territory of another Party, in order to obtain the disclosure of specified, stored subscriber information in that service provider’s possession or control, where the subscriber information is needed for the issuing Party’s specific criminal investigations or proceedings” -- SUBSCRIBER INFORMATION ONLY. Supports Art. 7(2)(a) and, importantly, Art. 7(2)(b): a Party may, at signature or when depositing its instrument, DECLARE that “The order under Article 7, paragraph 1, must be issued by, or under the supervision of, a prosecutor or other judicial authority, or otherwise be issued under independent supervision” -- a declaration, not a default. Supports Art. 7(3)-(4), the order’s required contents and supplemental information. Supports Art. 8(1): an order “to be submitted as part of a request to another Party” compelling a service provider in the REQUESTED Party’s territory to produce specified and stored (a) subscriber information AND (b) traffic data. Supports Art. 9(1)(a): in an emergency, the Art. 35 Convention 24/7 point of contact may transmit and receive requests seeking immediate assistance in obtaining expedited disclosure of specified stored computer data from a provider in another Party’s territory “without a request for mutual assistance”; and Art. 9(1)(b), that a Party may declare it will not execute such requests seeking only subscriber information. LIMITATIONS: this is a TREATY and it obliges Parties to legislate; it is NOT evidence of what any Party has enacted, and no country claim rests on it. Articles 5, 10, 11, 12, 13 and 14 were NOT read. The number of ratifications and the list of Parties were NOT RESEARCHED, because the Council of Europe Treaty Office was unreachable; secondary summaries stating a count were found and are deliberately NOT used. It describes no technique.

  2. Convention on Cybercrime (Council of Europe, ETS No. 185, Budapest, 23 November 2001), Articles 14–21 and Chapter III (Articles 23–35)

    Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0001839) · International organisation · 2001-11-23 · link verified 2026-09-05

    WAVE 22 ADDITION. ACCESS NOTE: rm.coe.int and coe.int returned HTTP 403 to automated requests in this session, so the Convention was read from the official Dutch government treaty database, which publishes the authentic English text alongside the Dutch translation. The English text quoted below is the authentic one; English and French are the authentic languages. Supports Art. 14(1)–(2), that the procedural powers are established “for the purpose of specific criminal investigations or proceedings” and are applied to the offences established under Arts. 2–11, to other criminal offences committed by means of a computer system, and to “the collection of evidence in electronic form of a criminal offence”. Supports Art. 14(3)(a), that a Party restricting the Art. 20 power to specified offences must not restrict it more narrowly than the range to which it applies Art. 21. Supports Art. 15(1), that the powers are subject to conditions and safeguards under domestic law providing adequate protection of human rights, including rights under the 1950 European Convention and the 1966 Covenant, “and which shall incorporate the principle of proportionality”. Supports Art. 15(2), that such conditions and safeguards shall, as appropriate, “include judicial or other independent supervision, grounds justifying application, and limitation of the scope and the duration of such power or procedure”. Supports Art. 16(1)–(3): expedited preservation of specified stored computer data “including traffic data”, in particular where it is particularly vulnerable to loss or modification; where effected by order to a person, an obligation to preserve and maintain integrity “for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure”, renewable; and an obligation on the custodian to keep the undertaking of the procedure confidential. Supports Art. 17, expedited preservation and PARTIAL disclosure of traffic data sufficient to identify the service providers and the path through which the communication was transmitted. Supports Art. 18(1)(a)–(b), the production order: a person in the territory to submit specified stored computer data in that person’s possession or control, and a service provider offering services in the territory to submit subscriber information. Supports Art. 18(3), which defines “subscriber information” as information held by a service provider relating to subscribers of its services “OTHER THAN TRAFFIC OR CONTENT DATA” and by which the type of service, the subscriber’s identity, postal or geographic address, telephone and other access number, billing and payment information, and information on the site of installation of communication equipment can be established. Supports Art. 19(1)–(4): the power to search or similarly access a computer system or a computer-data storage medium; the power under 19(2) to EXTEND the search expeditiously to another system in the territory where the data sought is “lawfully accessible from or available to the initial system”; the power under 19(3) to seize or similarly secure, comprising the separate powers to “seize or similarly secure a computer system or part of it or a computer-data storage medium”, to “make and retain a copy of those computer data”, to “maintain the integrity of the relevant stored computer data”, and to “render inaccessible or remove those computer data in the accessed computer system”; and the power under 19(4) to order any person with knowledge about the functioning of the system to provide, as is reasonable, the necessary information. Supports Art. 20, real-time collection of TRAFFIC data, and Art. 21, interception of CONTENT data, the latter available only “in relation to a range of serious offences to be determined by domestic law”; both articles oblige a service provider to keep the execution confidential. Cited for the structural propositions that preservation is a distinct act from production, that traffic data and content data are distinct powers, that subscriber information is defined by exclusion from both, and that seizing, copying and accessing are separately enumerated. LIMITATIONS, and they are load-bearing: this is a TREATY. It obliges Parties to establish powers in domestic law; it is NOT evidence of what any particular Party has enacted, and no country claim on this platform rests on it. It describes no technique. STATUS: in force; the Convention has two additional protocols, of which the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was located but NOT read for this wave. WAVE 23 ADDITION. That Protocol has now been read and is held separately as `coe-cybercrime-second-protocol`. Chapter III of the Convention, on international co-operation, was read from the same authentic English text, and it is a different subject from the domestic powers above. Supports Art. 23, that Parties co-operate “in accordance with the provisions of this chapter, and through the application of relevant international instruments on international co-operation in criminal matters, arrangements agreed on the basis of uniform or reciprocal legislation, and domestic laws”. Supports Art. 25(1)-(4), and in particular Art. 25(2), that “Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35” -- the Convention’s own statement that its co-operation articles are not self-executing -- and Art. 25(4), that except as specifically provided “mutual assistance shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation”. Supports Art. 27(1), that the Article applies only “where there is no mutual assistance treaty or arrangement on the basis of uniform or reciprocal legislation in force between the requesting and requested Parties”, and Art. 27(2)(a)-(d), that each Party designates a central authority “responsible for sending and answering requests for mutual assistance, the execution of such requests or their transmission to the authorities competent for their execution”, that central authorities communicate directly with each other, and that the Secretary General keeps a register of them. Supports Art. 29(1)-(4): a Party may request another to preserve data “located within the territory of that other Party and in respect of which the requesting Party intends to submit a request for mutual assistance”; the request must state that intention (29(2)(f)); “For the purposes of responding to a request, dual criminality shall not be required as a condition to providing such preservation” (29(3)); and a Party that requires dual criminality for disclosure may reserve the right to refuse preservation where it has reasons to believe the condition cannot be fulfilled at the time of disclosure (29(4)). Supports Art. 30(1)-(2), expedited disclosure of a sufficient amount of preserved traffic data to identify a service provider in another State and the path through which the communication was transmitted, withholdable only for a political offence or where execution is likely to prejudice sovereignty, security, ordre public or other essential interests. Supports Art. 31(1)-(3), mutual assistance to search, seize and disclose stored data “including data that has been preserved pursuant to Article 29”, responded to on an expedited basis where data is particularly vulnerable to loss. Supports Art. 32 IN FULL, and its narrowness is the point: “A Party may, without the authorisation of another Party: a) access publicly available (open source) stored computer data, regardless of where the data is located geographically; or b) access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data to the Party through that computer system.” There is no third limb and no unilateral remote-access provision. Supports Art. 33(1)-(2), mutual assistance in the real-time collection of traffic data, governed by the conditions and procedures of domestic law and available at least for offences for which such collection would be available in a similar domestic case; and Art. 34, mutual assistance regarding the interception of content data “to the extent permitted under their applicable treaties and domestic laws”. Supports Art. 35(1)-(2), that each Party designates a point of contact available twenty-four hours a day, seven days a week, to ensure immediate assistance -- facilitating or, if permitted by its domestic law and practice, directly carrying out technical advice, preservation under Arts. 29 and 30, and the collection of evidence, provision of legal information and locating of suspects -- and that where the point of contact is not part of the Party’s authority responsible for international mutual assistance, it must ensure co-ordination with that authority. LIMITATION ON CHAPTER III, restated because it is easy to lose: these are obligations on Parties to legislate and to co-operate. They are NOT evidence of what any Party has enacted. The Party list, signature dates and ratification counts were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403 to three separate URL forms.