Key data
| Regulation | Corrigendum to Council Decision (EU) 2026/1347, of 4 June 2026, on the ratification of the United Nations Convention on Cybercrime |
|---|---|
| Publication | 7 October 2026 |
| Entry into force | 19 June 2026 |
| Affected parties | EU Member States, technology companies and digital service operators |
| Category | European Regulation |
| Year | 2026 |
| CELEX Reference | 32026D1347R(01) |
If your company operates in digital environments, provides cloud services, manages communications or stores user data, this regulation concerns you directly. Council Decision (EU) 2026/1347 converts into binding European law the United Nations Convention on Cybercrime, an international treaty that establishes the rules for prosecuting crimes committed through ICT systems and for cross-border exchange of electronic evidence in cases of serious crimes.
The corrigendum published on 7 October 2026 corrects material errors in the text of the original decision, but does not modify its substantive content. The ratification remains fully valid from 19 June 2026.
What does this regulation establish?
The UN Convention on Cybercrime—ratified by the EU through Decision 2026/1347—creates an international legal framework with three main pillars:
- Prosecution of ICT crimes: establishes common criminal offences for crimes committed through information and communication systems, facilitating States' cooperation in their prosecution.
- Cross-border exchange of electronic evidence: regulates how States can request and share digital evidence in investigations of serious crimes, including data stored by private companies.
- Adaptation of national regulatory frameworks: EU Member States must review and, where necessary, modify their internal legislation on cybersecurity, data retention and judicial cooperation to align with the convention.
The correction published on 7 October 2026 (CELEX reference: 32026D1347R(01)) remedies material errors detected in the text of the original Council Decision, published in the EU Official Journal on 19 June 2026 (OJ L, 2026/1347). It does not alter the substance or obligations arising from the ratification.
Economic and operational impact
For companies, the impact is not immediate and does not translate into a penalty figure published in this regulation. The effect will occur gradually, as Member States adapt their national legislation. However, there are operational consequences worth anticipating:
- New data retention obligations: it is foreseeable that national transpositions will expand or clarify the periods and conditions under which companies must retain user data to make it available to authorities in criminal investigations.
- Requirements for cooperation with authorities: digital service operators may receive formal requests to deliver electronic evidence as part of international investigations, with regulated timelines and formats.
- Review of internal cybersecurity policies: alignment with the convention may require updating internal protocols, designating officials responsible for responding to judicial requests and reviewing contracts with infrastructure providers.
- Costs of legal and technical adaptation: although no specific figures are published in this regulation, companies with operations in multiple EU countries will need to monitor national transpositions to avoid non-compliance.
Who does it affect?
- Technology companies that develop or distribute software, platforms or digital services in the EU.
- Digital service operators: cloud providers, hosting, telecommunications, messaging and social media providers.
- Companies that store user data in ICT systems, regardless of their main sector.
- EU Member States, which must adapt their national regulatory frameworks on cybersecurity and judicial cooperation.
- Legal advisors and DPOs who manage regulatory compliance for companies with digital presence.
- CFOs and executives of companies operating in digital environments who must anticipate adaptation costs.
Practical example
Imagine a Spanish SaaS company that provides document management services to clients in several EU countries. Currently, its data retention policy follows GDPR timelines. Following the ratification of the UN Convention on Cybercrime and subsequent transposition in Spain, this company could receive a formal request from authorities to deliver activity logs of a user being investigated for a serious crime committed through its systems.
In that scenario, the company would need: (1) to have identified an internal official to handle judicial requests, (2) to have documented procedures for delivering electronic evidence in the format required by the authority, and (3) to have reviewed its contracts with infrastructure providers to ensure it can comply with legal timelines without interrupting service to other clients.
Without that prior preparation, the risk is not just legal: it is operational and reputational.
What should companies do now?
- Identify whether you are a digital service operator or technology company within the meaning of the convention: if you store user data, manage communications or provide ICT infrastructure, you are within the scope of application.
- Monitor national transpositions in each EU country where you operate. Decision 2026/1347 requires Member States to adapt their internal legislation: specific timelines and obligations will be defined in those transpositions.
- Review your data retention policies to anticipate possible new requirements regarding retention of digital evidence for criminal investigations.
- Designate or confirm an internal official for managing international judicial requests related to electronic evidence.
- Update contracts with infrastructure providers (cloud, hosting, telecommunications) to ensure they can support data delivery requests within legal timelines.
- Consult with your legal advisor or DPO on the specific impact on your business model, especially if you operate in sensitive sectors (health, finance, communications).
Frequently asked questions
What is the UN Convention on Cybercrime and why does it affect my company?
It is an international treaty that establishes a legal framework for prosecuting crimes committed through ICT systems and regulating cross-border exchange of electronic evidence in cases of serious crimes. The EU has ratified it through Council Decision 2026/1347, of 4 June 2026, which requires Member States to adapt their national legislation. If your company operates in digital environments, stores user data or provides ICT services, you could be subject to new obligations to cooperate with authorities in international criminal investigations.
What does the corrigendum published on 7 October 2026 change?
The corrigendum (CELEX reference: 32026D1347R(01)) remedies only material errors in the text of the original Council Decision. It does not alter the substance of the decision or the obligations arising from the ratification of the convention. The ratification remains valid from 19 June 2026.
When do the concrete obligations for companies come into force?
Council Decision (EU) 2026/1347 entered into force on 19 June 2026. However, the concrete obligations for companies will depend on the transpositions carried out by each Member State in its national legislation on cybersecurity, data retention and judicial cooperation. It is essential to monitor regulatory developments at the national level in each country where you operate.
What type of data or evidence can authorities request from my company?
The convention regulates the cross-border exchange of electronic evidence in investigations of serious crimes committed through ICT systems. This may include activity logs, communications, user data or any digital evidence stored in the company's systems. The specific procedures and timelines will be defined in national transpositions.
What happens if my company is not prepared to respond to international judicial requests?
Non-compliance with judicial cooperation requirements, once the regulation is transposed at the national level, can result in legal, operational and reputational consequences. Although this regulation does not publish specific penalty figures, the lack of internal procedures can lead to legal liabilities and loss of customer trust. It is recommended to review internal protocols and contracts with providers before national transpositions are completed.
Official source
Consult the complete regulation on the official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=CELEX:32026D1347R(01)