Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What is a provider preservation request?

A provider preservation request asks an organisation to retain specified records it already holds so ordinary deletion or retention expiry does not remove them while the proper acquisition process is pursued.

Preservation holds records; it does not disclose them

The request usually identifies data by account, service, object, category and time range. Useful identifiers may include account IDs, usernames, email addresses, phone numbers, URLs, tenant names, device or session IDs, transaction references and message or file identifiers. Precision helps the provider locate the intended records and limits unrelated retention.

Preservation is distinct from obtaining the material. Disclosure or production normally requires the appropriate separate authority and channel. It is also distinct from containment: retaining provider records does not necessarily stop an account holder acting or prevent further harm.

The request creates its own audit trail

Record the risk of loss, investigative purpose, authority, sender, time, method, scope and provider reference. Retain the acknowledgement and any stated categories, date range, expiry, limitation or refusal. Use the relevant organisational, legal, communications-data or formal provider route rather than assuming general customer support can act.

A confirmation describes what the provider says it has retained; it does not establish completeness, content or attribution. Local device, account-state and witness evidence may still require separate preservation.

Key takeaway

A preservation request protects precisely identified provider-held records from routine loss while lawful acquisition is arranged; it is neither disclosure nor account containment.

Reference: FRP-159First Response & Preservation