How long might a cloud provider retain records?¶
There is no single answer to how long a cloud provider retains records.
Retention may range from hours or days to months or years, depending on the record type, service and configuration.
What this means in practice¶
An organisation may be able to extend or shorten retention through its subscription or settings. A personal account may have fewer options.
Investigators should identify the exact service, account type, tenant, product level and record required.
What this may show¶
Login events may have one retention period. Audit logs, deleted files, backups, billing records and support records may have others.
Account deletion can also affect availability. Some data may enter a recovery period, while other records may be removed or anonymised.
Where the event is recent and the records may be important, preserve them quickly. Delay can turn a viable line of enquiry into an unavailable one.
What this does not show on its own¶
The dangerous assumption is that a familiar provider keeps all records for a standard period.
Do not rely only on online summaries, previous cases or assumptions based on another provider. Policies and products change.
A retention statement still does not guarantee completeness. Logging may have been disabled, reduced or unavailable for that account.
Where provider retention is central to the enquiry, preserve the source of the retention information and the date it was confirmed. A later policy page may not describe the product or subscription that applied when the event occurred.
What to do next¶
Ask the provider or customer organisation about the relevant period and whether the record is currently available.
Key takeaway
Provider retention depends on the precise record, service and configuration, so verify current availability and preserve potentially short-lived records without delay.