Summary

  • RIPE-865, issued on 27 July 2026 and approved by the Executive Board, places two notification states in one procedure. The general rule retains member notice unless it is expressly prohibited; the eEvidence branch says the RIPE NCC cannot notify members of orders received through that section.
  • The absence of member notice does not remove the controls stated in the procedure. Every order is assessed on its merits. An order that does not meet the eEvidence Regulation is not complied with and is challenged under that Regulation; an order issued in accordance with it must be complied with.
  • RIPE-854 supplies a useful example of aggregate LEA reporting, but its 2025 figures predate RIPE-865 and are not eEvidence counts, a forecast of later use or evidence that the new channel has handled an order.
  • Because ordinary case-level member notice is unavailable in the published eEvidence branch, the burden of public observability shifts towards carefully designed aggregate reporting. Any channel-and-outcome record would still require competent legal review of its fields, granularity, suppression rules and publication timing.

The accountability issue in RIPE-865 begins with a documentary contrast, not with an alleged case. The procedure, Handling Requests for Information, Orders and Investigations from Law Enforcement Authorities, concerns public and confidential member information held by the RIPE NCC in its RIR role. It updates RIPE-836, RIPE-675 and RIPE-588. Its significance here lies in the routes it identifies for demands involving non-public information or specific action, and in the notice conditions attached to those routes.

The general policy requires a court order or another binding and enforceable instrument under Dutch law before confidential or private information is disclosed or specific action is taken. Members are informed of requests or orders concerning their data unless notice is expressly prohibited. That creates a recognisable accountability path: the RIPE NCC evaluates the instrument and, where notice is not barred, the affected member is told.

RIPE-865 then separates the available channels. Dutch LEAs may proceed with binding Dutch orders. EU LEAs or judicial authorities may use the eEvidence Regulation where that framework applies. Non-EU authorities, and EU authorities acting outside the eEvidence Regulation, use applicable MLAT procedures. An EU origin alone therefore does not put every request into the eEvidence branch; authority, instrument and legal channel remain different facts.

The eEvidence section describes orders for preservation or production of electronic evidence in a criminal investigation or prosecution. It also says confidentiality rules apply and the RIPE NCC cannot notify members of any orders received under that section. This is more specific than the general possibility that notice may be prohibited in an individual matter. The published branch itself carries a no-notice state.

That changes the accountability mechanism. Under the general rule, member notice can create an external case-level trace. Under the eEvidence branch, the member cannot be a routine observer of the event. This conclusion says nothing about whether an event has occurred. It identifies what would be observable, and by whom, if the branch were used.

The procedure retains a different control. Every order is evaluated on its merits. If an order does not meet the eEvidence Regulation, the RIPE NCC will not comply with it and will challenge it under the Regulation. Orders issued in accordance with the Regulation must be complied with. Confidentiality therefore does not remove merits review or the stated challenge path; it limits who can observe a case directly.

These states must remain separate. Notice concerns whether a member is informed. Review concerns assessment of the instrument. Challenge concerns the response to an order found not to meet the Regulation. Compliance concerns the treatment of an order issued in accordance with it. Evidence about one state is not evidence about the others.

The prior procedure locates the documentary change. RIPE-836 exposed the Dutch-order and MLAT route and retained the general notice policy. The checked text did not contain the explicit eEvidence route now present in RIPE-865. That establishes a change in the published procedure, not receipt or use of any order, and not a basis for reclassifying earlier requests.

RIPE-854 provides a second boundary. Published on 31 March 2026, it reports 99 LEA requests in 2025. Its verified categories include eight binding Dutch requests that were complied with; two non-binding non-Dutch requests for non-public information, for which only public information was provided; four procedural enquiries; 81 user-identification requests for information the RIPE NCC says it does not have; and one unsupported non-Dutch request to modify records.

The report shows that the RIPE NCC has published aggregates distinguishing some authority, instrument, information and outcome categories. It does not populate the new branch. RIPE-854 predates RIPE-865. Its Dutch figures cannot be relabelled as eEvidence data, and its non-Dutch categories cannot stand in for later orders under the eEvidence Regulation. It is a reporting precedent, not a baseline for inferred channel use.

The dates prevent a broader claim. A 2025 report describes what RIPE-854 classified for that year. A procedure issued on 27 July 2026 describes how defined requests and orders are to be handled. No checked source reports receipt, challenge, preservation, production, compliance or refusal under an eEvidence order. Nor does any checked source identify which aggregates may lawfully be published, or with what delay, suppression or review.

The resulting opacity is specific. The eEvidence channel is publicly described, as are its review and challenge rules. What is unavailable is ordinary case-level notice to the member. One potential external witness is removed from the accountability chain, increasing the importance of other records: internal classification, legal review, governance oversight, stable methodology and later aggregate transparency. The sources do not disclose those records; they establish why their public design matters.

Aggregate reporting cannot recreate member notice. Its narrower purpose would be institutional observability: whether the published channel has been used during a defined period; whether instruments were found in scope; whether challenges occurred; and how outcomes were categorised. It must not expose a member, investigation, authority or evidence, directly or by inference.

Even that record is not automatically lawful. Low counts, rare action classes and short periods can permit reconstruction. A preservation or production split may be sensitive. A challenge outcome may reveal timing or procedural posture. Publication may require suppression, broader aggregation, redaction or delay. The checked sources decide none of those questions. Competent legal review would have to approve the fields, granularity and timing.

A minimum test record should therefore consist of separable fields rather than case detail. The matrix below is an accountability design test, not a claim that every field may be published.

Aggregate field What it would make observable Required boundary
Reporting period The interval covered Use a defined, consistently applied period
Legal channel Dutch, eEvidence Regulation or MLAT routing Do not treat every EU-origin matter as eEvidence
Request/order class Enquiry, request, binding order or other defined instrument Keep informal requests and binding orders distinct
Received count Items entering the stated channel Receipt alone says nothing about validity or outcome
Count found in scope Items meeting channel and scope definitions Do not equate scope with compliance
Challenged count Activation of the stated challenge control Do not equate challenge with refusal, success or failure
Challenge outcome Aggregate disposition, if publishable Use legally reviewed categories and timing
Complied/not-complied counts Recorded operational outcome Keep outcome separate from challenge and scope
Preservation/production split The two eEvidence order classes Suppress or combine where granularity creates exposure
Specific-action split Any legally approved action category Do not disclose sensitive action detail
Notice state Case-level member notice unavailable in the published branch Do not present an aggregate as delayed notice
Suppression or redaction basis Why a cell is withheld, combined or delayed Apply an approved rule rather than ad hoc omission
Publication authority and legal review Who authorised release and on what basis Do not imply permission without competent review
Method and version note Definitions and procedure version Preserve comparability when classifications change
Correction history Revisions to earlier aggregates Date and explain corrections without exposing a case

The value lies in separation. A received order may be found outside scope. An in-scope order may be challenged. A challenge outcome differs from the eventual compliance state. Preservation and production are different order classes. Member notice and aggregate publication are different accountability mechanisms. A single total can conceal each transition.

Channel visibility matters for the same reason. RIPE-865 distinguishes Dutch binding orders, the eEvidence Regulation and MLAT procedures. Grouping all LEA contacts would preserve a total while hiding the route that determines notice, review and challenge conditions. Excessive granularity, however, could create low-count exposure. The sources do not predetermine the lawful balance.

Definitions matter as much as numbers. RIPE-854 illustrates why: a user-identification request for information the RIPE NCC says it does not have is not a binding Dutch request; a procedural enquiry is not an order; and providing only public information is not compliance with a demand for confidential data. Compressing those classes would destroy forensic value.

A method note should identify the reporting period, procedure version and category definitions. If the procedure or taxonomy changes, the start date should be visible. A correction history should distinguish a data error from a classification change. Otherwise, readers may mistake a change in method for a change in authority activity.

Suppression also needs a stated meaning. A blank cell could mean zero, unavailable data, legal prohibition, low-count suppression or a category not collected. An approved notation can preserve that distinction without disclosing the protected fact. The point is not to prescribe a threshold or delay, which the sources do not authorise, but to prevent silence from being misread as evidence of no orders.

RIPE-865 has therefore made the no-notice state visible while retaining merits review and challenge. RIPE-836 did not expose the same branch in the checked text. RIPE-854 shows an existing form of aggregate LEA reporting but supplies no eEvidence facts. Until a later source reports the channel explicitly, the responsible conclusion is not that it has been used, but that any use would be unavailable to members at case level and would require another lawful mechanism for public observability.

Sources