What should I check if cloud data appears to have been deleted?¶
Treat “deleted” as a change in availability, not immediate proof that every copy and every record has gone.
Cloud services may retain recycle-bin items, previous versions, audit events, synchronised copies, backups or copies held by other users.
Fix the exact object first¶
Record whatever stable identifiers the service provides:
DOC-7742Name: forecast-q4.xlsxParent folder: FIN-22Deleted: 2026-09-20 11:14 UTCRecovery state: recoverableA filename or path can change. A stable resource ID is usually a better anchor for finding audit, sharing and version records.
Look for the object in every likely state¶
Check, where relevant:
- recycle bin or deleted-item store;
- version history;
- retention or legal-hold area;
- organisational archive;
- backup;
- synchronised devices;
- offline folders;
- shared copies;
- recipient downloads; and
- exports or attachments in other systems.
A move or rename can also look like deletion if the search relies only on the old path.
Work out what caused the change¶
A deletion event may have been caused by:
- a user;
- a synchronisation client;
- an automated retention rule;
- an administrator;
- a connected application; or
- another service acting through delegated access.
Link the event to the relevant account, session, application or policy.
Do not restore casually¶
Restoration can create new audit events, change metadata, reapply permissions or notify users.
If restoration is necessary, record the authority, account, method, time and resulting changes.
The practical point is: “deleted” is only the first observation. Identify the object, recovery state, copies and event source before concluding what was lost.