Skip to content
FRP-159 Fraud & Financial Crime

What is a provider preservation request?

A provider preservation request asks an organisation or service provider to retain specified existing records so they are not deleted through ordinary processes.

Avoid this assumption: Preservation automatically obtains the records or freezes an entire account. It usually protects identified data from routine deletion for a limited purpose and period, subject to the provider’s process and applicable authority.

The request should identify the correct account, service, object, time range and categories of data as precisely as possible.

Relevant identifiers may include usernames, email addresses, phone numbers, account IDs, URLs, tenant names, device IDs, session IDs, transaction references and file or message identifiers.

Record what evidence creates the urgency, such as short retention, account deletion, disappearing content or active compromise.

Use the correct organisational, legal, communications-data or provider channel.

Do not rely on a general customer-service message where a formal preservation route exists.

Preservation should be proportionate and connected to a defined investigative purpose.

Record who authorised the request, who submitted it, the time, method, scope and provider reference.

Retain any confirmation, stated expiry, limitation or refusal.

A request may preserve provider-held records that are not visible through the account, but it does not prove their content, completeness or attribution.

It also does not prevent a user from continuing to act unless separate containment steps are taken.

Preserve the provider’s stated retention terms.

Operational takeaway

Use a provider preservation request to retain precisely identified existing records at risk of routine loss, while keeping preservation separate from disclosure, containment and proof.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.