Skip to content
Skip to main content
Cloud Services Operational Explainer

What should I check if cloud data appears to have been deleted?

Treat “deleted” as a change in availability, not immediate proof that every copy and every record has gone.

Cloud services may retain recycle-bin items, previous versions, audit events, synchronised copies, backups or copies held by other users.

The practical rule
Follow the object by stable identifier, versions and copies before deciding what has actually disappeared.

Fix the exact object first

Record whatever stable identifiers the service provides:

Example deleted-resource record
Resource ID: DOC-7742Name: forecast-q4.xlsxParent folder: FIN-22Deleted: 2026-09-20 11:14 UTCRecovery state: recoverable

A filename or path can change. A stable resource ID is usually a better anchor for finding audit, sharing and version records.

Look for the object in every likely state

Check, where relevant:

  • recycle bin or deleted-item store;
  • version history;
  • retention or legal-hold area;
  • organisational archive;
  • backup;
  • synchronised devices;
  • offline folders;
  • shared copies;
  • recipient downloads; and
  • exports or attachments in other systems.

A move or rename can also look like deletion if the search relies only on the old path.

Work out what caused the change

A deletion event may have been caused by:

  • a user;
  • a synchronisation client;
  • an automated retention rule;
  • an administrator;
  • a connected application; or
  • another service acting through delegated access.

Link the event to the relevant account, session, application or policy.

ObjectWhich resource changed?Use ID, version and parent relationship.
EventWhat did the provider record?Delete, move, purge, overwrite or retention action.
CopiesWhere else might it remain?Versions, bins, sync devices, backups and recipients.
CauseWho or what triggered it?User, app, policy or administrator.

Do not restore casually

Restoration can create new audit events, change metadata, reapply permissions or notify users.

If restoration is necessary, record the authority, account, method, time and resulting changes.

The practical point is: “deleted” is only the first observation. Identify the object, recovery state, copies and event source before concluding what was lost.

Reference: CLD-168Cloud Services