What can a preservation request not achieve?¶
A preservation request can help retain identified provider-held records, but it cannot solve every evidential or operational problem.
Avoid this assumption: Preservation freezes an account, stops the user and guarantees later access to everything connected with it.
A preservation request does not normally disclose the material to the investigator. A separate lawful process may still be required.
It does not automatically disable the account, terminate sessions, stop messages, prevent further offending or protect a victim from immediate harm.
It cannot preserve records the provider never held, has already deleted or cannot identify from the information supplied.
It may not cover every category of data associated with an account. Content, subscriber details, login records, billing, deleted data and audit events may be held differently and for different periods.
A request also does not prove that preserved records are complete, accurate or attributable to a particular person.
Preservation may be time-limited. If the follow-on process is not completed, the protection may expire.
Before relying on preservation, record the exact scope, provider reference, categories, date range, expiry and any stated limitation.
Consider what must still be done locally. Devices, screenshots, account state, organisational logs and witness evidence may need separate preservation.
Where safeguarding, containment or urgent financial loss is involved, address that risk through an appropriate separate decision.
Do not describe an account as “secured” merely because a preservation request has been made.
Operational takeaway¶
Use preservation to reduce routine provider-side data loss, but do not mistake it for disclosure, containment, victim protection, completeness or proof of attribution.