Skip to main content

Investigations

An international instrument has been adopted. Does it work yet?

Adoption, entry into force, application and national implementation are four different facts, and four instruments read for this section sit at four different points. One states in its own text that its cooperation articles require Parties to legislate first.

Fact-checkedSafety review clearedLast updated Last reviewed

In short

An instrument existing is not the same as an instrument working. Between the two sit several distinct events — a text agreed, a State bound, the instrument in force, its provisions applicable, and a national legislature having done what the instrument told it to do — and each can be true while the next is not.

Why it exists

AnalysisThe failure this distinction prevents is specific and common: reading that an instrument creates a mechanism, and concluding that the mechanism is available. Almost every cooperation instrument is written as an obligation on States to build something, and the gap between the obligation and the thing is where the practical answer lives.

How it works

The Convention on Cybercrime states the point about itself. Article 25(2) provides that "Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35" — which is to say that its own international-cooperation articles are obligations to legislate rather than rules that operate of their own force.

The Second Additional Protocol shows an earlier stage. The official treaty database of the Government of the Netherlands, on a page stating that its information is valid on 5 September 2026, records a single lifecycle entry for the Protocol — its conclusion, dated 12 May 2022 — and leaves the entry-into-force column empty. Every article of the text carries a marker meaning "text without entry-into-force date".

The European Union instruments show two further stages, and they differ from each other by design. Article 34(2) of Regulation (EU) 2023/1543 provides: "It shall apply from 18 August 2026." A Regulation is directly applicable, so once that date arrives the Regulation applies in the Member States bound by it without any national measure being required to make it apply.

A Directive is different. Article 7(1) of Directive (EU) 2023/1544 provides that "Member States shall bring into force the laws, regulations and administrative provisions necessary to comply with this Directive by 18 February 2026" — an obligation on each Member State to legislate, with a deadline. The deadline passing is a fact about the deadline, not about any Member State.

One instrument can carry more than one date
Article 34(2) of the Regulation states the application date and then, in the same paragraph, a separate and later trigger: the obligation to use the decentralised IT system established in Article 19 applies "from one year after the adoption of the implementing acts referred to in Article 25". An instrument can be applicable while an obligation inside it is not.
Whether that later date has arrived is not established here
Whether the Article 25 implementing acts have been adopted was not researched, so this section states no date for the Article 19 obligation and does not describe it as operative.
The stages are not a sequence every instrument completes
A text can be concluded and never enter into force; an instrument can be in force for some Parties and not others; and an instrument in force can still require every Party to legislate before anything works. The four instruments here illustrate four different positions on 5 September 2026.

Common misconceptions

Widely held beliefs that do not match how the system actually operates.

  • Common belief: An instrument that has been adopted is in force.

    In practice: The register consulted for this section records the Second Additional Protocol as concluded on 12 May 2022 and leaves its entry-into-force column empty, on a page stating its information is valid on 5 September 2026.

  • Common belief: Signing an instrument makes a state bound by it.

    In practice: The instruments read here treat signature and the deposit of an instrument of ratification, acceptance or approval as different events — the Second Additional Protocol’s Articles 7(2)(b) and 9(1)(b) allow a Party to make declarations "at the time of signature … or when depositing its instrument of ratification, acceptance or approval", which are stated as alternatives.

  • Common belief: A treaty in force creates the mechanisms it describes.

    In practice: Article 25(2) of the Convention on Cybercrime requires each Party to adopt such legislative and other measures as may be necessary to carry out the obligations in Articles 27 to 35. Every operative article of the Second Additional Protocol opens with the same formula.

  • Common belief: An EU Regulation and an EU Directive work the same way.

    In practice: The Regulation states its own application date and is directly applicable from it. The Directive obliges Member States to bring transposing measures into force by a deadline, which is an obligation on each of them.

  • Common belief: Once a transposition deadline has passed, the Directive is implemented.

    In practice: The deadline is a date in the Directive. Whether any Member State has transposed Directive (EU) 2023/1544 was not researched for any Member State, and nothing here asserts that any has.

  • Common belief: If a Regulation applies, everything in it applies.

    In practice: Article 34(2) of Regulation (EU) 2023/1543 makes the Regulation applicable from 18 August 2026 and, in the same paragraph, makes the Article 19 decentralised IT system obligation applicable one year after implementing acts adopted under Article 25.

How this varies between jurisdictions

A required section on every guide. Arrangements differ between countries, and we say how.

Four instruments, four positions as at 5 September 2026.

  • In force, and stating in its own text that its cooperation articles require Parties to legislate — Convention on Cybercrime, Art. 25(2).
  • Concluded 12 May 2022, with no entry-into-force date recorded in the register consulted, and every operative article requiring Parties to legislate — Second Additional Protocol.
  • Directly applicable, and applying since 18 August 2026 — Regulation (EU) 2023/1543, Art. 34(2).
  • Carrying a further obligation inside it that applies one year after implementing acts whose adoption was not researched — Regulation Art. 34(2), second sentence, with Art. 19 and Art. 25.
  • Requiring national transposition by 18 February 2026, with completion in any Member State not researched — Directive (EU) 2023/1544, Art. 7(1).

Rights and accountability

AnalysisThe reason this matters beyond bookkeeping is that a mechanism which does not yet operate is not a route anyone can use — and a mechanism believed to operate when it does not produces requests that fail, or worse, requests answered under a power nobody has. The stages are how a legal system keeps the difference visible.

What we could not establish

  • Every status on this page is stated as at 5 September 2026, the date the instruments were read. Legal status changes, and a reader consulting this later should check the position again.
  • Party lists, signature dates and ratification counts for the two Council of Europe instruments were NOT RESEARCHED. The Council of Europe Treaty Office returned HTTP 403 to three separate URL forms, and secondary summaries giving a count were deliberately not used.
  • No national implementing legislation and no national transposition measure was read for any country. Nothing here establishes what any State has enacted.

Where to go next

Related: international rights and domestic law, direct cooperation with foreign providers, and European production and preservation orders.

Sources

  1. Convention on Cybercrime (Council of Europe, ETS No. 185, Budapest, 23 November 2001), Articles 14–21 and Chapter III (Articles 23–35)

    Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0001839) · International organisation · 2001-11-23 · link verified 2026-09-05

    WAVE 22 ADDITION. ACCESS NOTE: rm.coe.int and coe.int returned HTTP 403 to automated requests in this session, so the Convention was read from the official Dutch government treaty database, which publishes the authentic English text alongside the Dutch translation. The English text quoted below is the authentic one; English and French are the authentic languages. Supports Art. 14(1)–(2), that the procedural powers are established “for the purpose of specific criminal investigations or proceedings” and are applied to the offences established under Arts. 2–11, to other criminal offences committed by means of a computer system, and to “the collection of evidence in electronic form of a criminal offence”. Supports Art. 14(3)(a), that a Party restricting the Art. 20 power to specified offences must not restrict it more narrowly than the range to which it applies Art. 21. Supports Art. 15(1), that the powers are subject to conditions and safeguards under domestic law providing adequate protection of human rights, including rights under the 1950 European Convention and the 1966 Covenant, “and which shall incorporate the principle of proportionality”. Supports Art. 15(2), that such conditions and safeguards shall, as appropriate, “include judicial or other independent supervision, grounds justifying application, and limitation of the scope and the duration of such power or procedure”. Supports Art. 16(1)–(3): expedited preservation of specified stored computer data “including traffic data”, in particular where it is particularly vulnerable to loss or modification; where effected by order to a person, an obligation to preserve and maintain integrity “for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure”, renewable; and an obligation on the custodian to keep the undertaking of the procedure confidential. Supports Art. 17, expedited preservation and PARTIAL disclosure of traffic data sufficient to identify the service providers and the path through which the communication was transmitted. Supports Art. 18(1)(a)–(b), the production order: a person in the territory to submit specified stored computer data in that person’s possession or control, and a service provider offering services in the territory to submit subscriber information. Supports Art. 18(3), which defines “subscriber information” as information held by a service provider relating to subscribers of its services “OTHER THAN TRAFFIC OR CONTENT DATA” and by which the type of service, the subscriber’s identity, postal or geographic address, telephone and other access number, billing and payment information, and information on the site of installation of communication equipment can be established. Supports Art. 19(1)–(4): the power to search or similarly access a computer system or a computer-data storage medium; the power under 19(2) to EXTEND the search expeditiously to another system in the territory where the data sought is “lawfully accessible from or available to the initial system”; the power under 19(3) to seize or similarly secure, comprising the separate powers to “seize or similarly secure a computer system or part of it or a computer-data storage medium”, to “make and retain a copy of those computer data”, to “maintain the integrity of the relevant stored computer data”, and to “render inaccessible or remove those computer data in the accessed computer system”; and the power under 19(4) to order any person with knowledge about the functioning of the system to provide, as is reasonable, the necessary information. Supports Art. 20, real-time collection of TRAFFIC data, and Art. 21, interception of CONTENT data, the latter available only “in relation to a range of serious offences to be determined by domestic law”; both articles oblige a service provider to keep the execution confidential. Cited for the structural propositions that preservation is a distinct act from production, that traffic data and content data are distinct powers, that subscriber information is defined by exclusion from both, and that seizing, copying and accessing are separately enumerated. LIMITATIONS, and they are load-bearing: this is a TREATY. It obliges Parties to establish powers in domestic law; it is NOT evidence of what any particular Party has enacted, and no country claim on this platform rests on it. It describes no technique. STATUS: in force; the Convention has two additional protocols, of which the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was located but NOT read for this wave. WAVE 23 ADDITION. That Protocol has now been read and is held separately as `coe-cybercrime-second-protocol`. Chapter III of the Convention, on international co-operation, was read from the same authentic English text, and it is a different subject from the domestic powers above. Supports Art. 23, that Parties co-operate “in accordance with the provisions of this chapter, and through the application of relevant international instruments on international co-operation in criminal matters, arrangements agreed on the basis of uniform or reciprocal legislation, and domestic laws”. Supports Art. 25(1)-(4), and in particular Art. 25(2), that “Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35” -- the Convention’s own statement that its co-operation articles are not self-executing -- and Art. 25(4), that except as specifically provided “mutual assistance shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation”. Supports Art. 27(1), that the Article applies only “where there is no mutual assistance treaty or arrangement on the basis of uniform or reciprocal legislation in force between the requesting and requested Parties”, and Art. 27(2)(a)-(d), that each Party designates a central authority “responsible for sending and answering requests for mutual assistance, the execution of such requests or their transmission to the authorities competent for their execution”, that central authorities communicate directly with each other, and that the Secretary General keeps a register of them. Supports Art. 29(1)-(4): a Party may request another to preserve data “located within the territory of that other Party and in respect of which the requesting Party intends to submit a request for mutual assistance”; the request must state that intention (29(2)(f)); “For the purposes of responding to a request, dual criminality shall not be required as a condition to providing such preservation” (29(3)); and a Party that requires dual criminality for disclosure may reserve the right to refuse preservation where it has reasons to believe the condition cannot be fulfilled at the time of disclosure (29(4)). Supports Art. 30(1)-(2), expedited disclosure of a sufficient amount of preserved traffic data to identify a service provider in another State and the path through which the communication was transmitted, withholdable only for a political offence or where execution is likely to prejudice sovereignty, security, ordre public or other essential interests. Supports Art. 31(1)-(3), mutual assistance to search, seize and disclose stored data “including data that has been preserved pursuant to Article 29”, responded to on an expedited basis where data is particularly vulnerable to loss. Supports Art. 32 IN FULL, and its narrowness is the point: “A Party may, without the authorisation of another Party: a) access publicly available (open source) stored computer data, regardless of where the data is located geographically; or b) access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data to the Party through that computer system.” There is no third limb and no unilateral remote-access provision. Supports Art. 33(1)-(2), mutual assistance in the real-time collection of traffic data, governed by the conditions and procedures of domestic law and available at least for offences for which such collection would be available in a similar domestic case; and Art. 34, mutual assistance regarding the interception of content data “to the extent permitted under their applicable treaties and domestic laws”. Supports Art. 35(1)-(2), that each Party designates a point of contact available twenty-four hours a day, seven days a week, to ensure immediate assistance -- facilitating or, if permitted by its domestic law and practice, directly carrying out technical advice, preservation under Arts. 29 and 30, and the collection of evidence, provision of legal information and locating of suspects -- and that where the point of contact is not part of the Party’s authority responsible for international mutual assistance, it must ensure co-ordination with that authority. LIMITATION ON CHAPTER III, restated because it is easy to lose: these are obligations on Parties to legislate and to co-operate. They are NOT evidence of what any Party has enacted. The Party list, signature dates and ratification counts were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403 to three separate URL forms.

  2. Second Additional Protocol to the Convention on Cybercrime on enhanced co-operation and disclosure of electronic evidence (Council of Europe, CETS No. 224, Strasbourg, 12 May 2022), Articles 6-9

    Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0006966) · International organisation · 2022-05-12 · link verified 2026-09-05

    WAVE 23 ADDITION. ACCESS NOTE: coe.int and rm.coe.int returned HTTP 403 to automated requests on three separate URL forms, so the Protocol was read from the official Dutch government treaty database, which publishes the authentic English text. English and French are the authentic languages. TEMPORAL STATUS, and it is the most load-bearing fact on this record: the database records exactly ONE lifecycle row for this instrument -- “Nieuwe-regeling · Trb. 2022, 66 · 12-05-2022 · Totstandkoming” -- and its “Inwerkingtreding / Voorlopige toepassing” (entry into force / provisional application) column is EMPTY, on a page stating “Informatie geldend op 05-09-2026”. Every article of the Protocol additionally carries the marker “[Tekst zonder datum inwerkingtreding]” -- text without entry-into-force date. Supports the four distinct co-operation channels the Protocol creates, and their DIFFERENT REACH, which is the point. Supports Art. 6(1)-(2): a Party empowers its competent authorities, for specific criminal investigations or proceedings, to issue a REQUEST to an entity providing domain name registration services in another Party’s territory for information to identify or contact the registrant of a domain name, and permits an entity in its own territory to disclose such information “subject to reasonable conditions provided by domestic law”. Supports Art. 7(1): a Party empowers its competent authorities “to issue an order to be submitted directly to a service provider in the territory of another Party, in order to obtain the disclosure of specified, stored subscriber information in that service provider’s possession or control, where the subscriber information is needed for the issuing Party’s specific criminal investigations or proceedings” -- SUBSCRIBER INFORMATION ONLY. Supports Art. 7(2)(a) and, importantly, Art. 7(2)(b): a Party may, at signature or when depositing its instrument, DECLARE that “The order under Article 7, paragraph 1, must be issued by, or under the supervision of, a prosecutor or other judicial authority, or otherwise be issued under independent supervision” -- a declaration, not a default. Supports Art. 7(3)-(4), the order’s required contents and supplemental information. Supports Art. 8(1): an order “to be submitted as part of a request to another Party” compelling a service provider in the REQUESTED Party’s territory to produce specified and stored (a) subscriber information AND (b) traffic data. Supports Art. 9(1)(a): in an emergency, the Art. 35 Convention 24/7 point of contact may transmit and receive requests seeking immediate assistance in obtaining expedited disclosure of specified stored computer data from a provider in another Party’s territory “without a request for mutual assistance”; and Art. 9(1)(b), that a Party may declare it will not execute such requests seeking only subscriber information. LIMITATIONS: this is a TREATY and it obliges Parties to legislate; it is NOT evidence of what any Party has enacted, and no country claim rests on it. Articles 5, 10, 11, 12, 13 and 14 were NOT read. The number of ratifications and the list of Parties were NOT RESEARCHED, because the Council of Europe Treaty Office was unreachable; secondary summaries stating a count were found and are deliberately NOT used. It describes no technique.

  3. Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings, Articles 3, 4, 8, 13, 17, 18 and 34

    Publications Office of the European Union (EUR-Lex) · International organisation · 2023-07-12 · link verified 2026-09-05

    WAVE 23 ADDITION. The Regulation read directly on EUR-Lex. TEMPORAL STATUS, verified from the instrument itself: Art. 34(1) provides that it enters into force on the twentieth day following publication in the Official Journal, and Art. 34(2) provides in terms “It shall apply from 18 August 2026.” Against the research date of 5 September 2026 the Regulation is therefore APPLICABLE, and had been for eighteen days. The SAME paragraph carries a separate and later trigger: “the obligation for competent authorities and service providers to use the decentralised IT system established in Article 19 for written communication under this Regulation shall apply from one year after the adoption of the implementing acts referred to in Article 25” -- whether those implementing acts have been adopted was NOT RESEARCHED, so that trigger date is NOT ESTABLISHED. Supports Art. 3(1), that a “European Production Order” is a decision ordering the production of electronic evidence, issued or validated by a judicial authority of a Member State, and “addressed to a designated establishment or to a legal representative of a service provider offering services in the Union, where that designated establishment or legal representative is located in another Member State bound by this Regulation”. Supports Art. 3(2), that a “European Preservation Order” orders preservation “for the purposes of a subsequent request for production”. Supports the four data definitions in Art. 3(9)-(12): subscriber data; “data requested for the sole purpose of identifying the user” as a DISTINCT category; traffic data; and content data, defined as any data in digital format “other than subscriber data or traffic data”. Supports Art. 4(1)-(3), the authorisation ladder: a production order for subscriber data or identification data may be issued by a judge, court, investigating judge OR PUBLIC PROSECUTOR, or by another competent investigating authority whose order is then validated by one of those; a production order for traffic data (other than identification data) or content data may be issued only by a judge, court or investigating judge -- NOT a public prosecutor -- or validated by one of those; and a PRESERVATION order for data of ANY category may be issued by a judge, court, investigating judge or public prosecutor. Supports Art. 8(1)-(4): where a production order seeks traffic data (other than identification data) or content data, the issuing authority shall notify the enforcing authority by transmitting the EPOC to it at the same time as to the addressee; that duty does not apply where the issuing authority has reasonable grounds to believe both that the offence was, is being or is likely to be committed in the issuing State and that the person whose data are requested resides there; and the notification “shall have a suspensive effect on the obligations of the addressee” except in emergency cases. Supports Art. 13(1)-(3): the issuing authority shall without undue delay inform the person whose data are being requested, may delay, restrict or omit that under the conditions of Art. 13(3) of Directive (EU) 2016/680 while recording reasons, and when informing shall include information about available remedies. Supports Art. 17(1)-(2), the reasoned-objection procedure where an addressee considers compliance would conflict with the law of a third country, and that the objection may not rest merely on the absence of similar provisions in that law. Supports Art. 18(1)-(2), that any person whose data were requested has the right to effective remedies, exercised “before a court in the issuing State” and including a challenge to legality, necessity and proportionality. Supports recital 8, which states why the instrument exists alongside the European Investigation Order: Directive 2014/41/EU and the Convention on Mutual Assistance in Criminal Matters provide for requesting evidence from another Member State, but “the procedures and timelines” they provide “might not be appropriate for electronic evidence, which is more volatile and could more easily and quickly be deleted”. LIMITATIONS: this is EU law binding the Member States bound by it. It is NOT evidence of the law of any non-EU country and NOT evidence that any particular Member State has any particular arrangement in place. Whether any Member State has designated addressees under Directive (EU) 2023/1544 was NOT RESEARCHED. Articles 5, 6, 7, 9, 10, 11, 12, 14, 15, 16 and 19-33 were not read in full.

  4. Directive (EU) 2023/1544 laying down harmonised rules on the designation of designated establishments and the appointment of legal representatives for the purpose of gathering electronic evidence in criminal proceedings, Articles 3 and 7

    Publications Office of the European Union (EUR-Lex) · International organisation · 2023-07-12 · link verified 2026-09-05

    WAVE 23 ADDITION. The Directive read directly on EUR-Lex, and cited alongside Regulation (EU) 2023/1543 because the two do different jobs: the Regulation addresses orders to a designated establishment or legal representative, and this Directive is what obliges providers to have one. TEMPORAL STATUS: Art. 7(1) provides that “Member States shall bring into force the laws, regulations and administrative provisions necessary to comply with this Directive by 18 February 2026”. Against the research date of 5 September 2026 that deadline is PAST -- but whether any Member State has actually transposed the Directive was NOT RESEARCHED for any Member State, and a passed deadline is not a completed transposition. Art. 8 requires the Commission to evaluate the Directive by 18 August 2029. Supports Art. 3(1)(a)-(c): Member States shall ensure that service providers offering services in the Union designate or appoint at least one addressee for the receipt of, compliance with and enforcement of decisions and orders within the scope of Art. 1(2) -- with providers established in the Union with legal personality designating a “designated establishment” in the Member State of establishment; providers NOT established in the Union appointing a “legal representative” in Member States taking part in the instruments; and providers established in Member States not taking part appointing a legal representative likewise. LIMITATIONS: this is a DIRECTIVE. It binds Member States as to the result to be achieved and requires national transposition; it is not directly applicable in the way the Regulation is, and it is NOT evidence that any provider has in fact designated anyone. Articles 1, 2, 4, 5, 6 and 9 were not read in full.