Skip to content
FRP-162 Fraud & Financial Crime

When should provider preservation be considered?

Provider preservation should be considered when relevant records may be lost before the proper disclosure or production process can be completed.

Avoid this assumption: Preservation is needed only after an account is deleted. Provider records may have short or uncertain retention periods even while the account remains active.

Consider preservation where messages disappear, account activity changes quickly, logs are routinely overwritten or deleted items are time-limited.

It may also be appropriate where an account is about to close, an employee is leaving, a service is being migrated or an incident is still developing.

Start with the investigative question. Identify which records matter, which provider holds them and what event creates the risk of loss.

Preserve exact identifiers before contact, including account IDs, usernames, email addresses, phone numbers, URLs, tenant names, object IDs, session IDs and relevant timestamps.

Use the correct organisational, legal, communications-data or provider route.

Do not make a broad request merely because the account may be relevant. Define the categories and time period proportionately.

Record what local evidence has already been preserved and what remains at risk.

Where the provider is outside the jurisdiction, the account is shared or the service structure is unclear, seek specialist advice quickly.

Do not delay urgent safeguarding or containment solely because preservation is being considered.

Record who authorised the request, when it was sent, the scope and any provider response.

Operational takeaway

Consider provider preservation whenever identified records face a credible risk of routine loss before lawful acquisition, and make the request precise, proportionate and properly documented.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.