Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What can a preservation request not achieve?

It cannot by itself disclose evidence, freeze an account, stop ongoing harm, guarantee completeness or prove who used the service. Each of those outcomes requires separate evidence, authority or action.

Retention is not access or containment

The investigator normally still needs the proper process to obtain preserved material. Meanwhile, an account may remain active, sessions may continue and a user may send messages or delete material visible to them. Safeguarding, financial-loss prevention and incident containment therefore need their own decisions rather than waiting on preservation.

The provider can retain only data it held, had not already deleted and can identify from the request. Different systems may store content, subscriber, billing, login and audit records for different periods. A request may cover only some categories and may expire if follow-on action is late.

A preserved record still needs evaluation

Provider data can be incomplete, technically inferred or linked to shared accounts and devices. Preservation does not authenticate its content or attribute activity to a person. Local devices, screenshots, organisational logs and witness accounts may provide the context required to interpret it.

Record the exact scope, reference, time range, categories, expiry and stated limitations. Describe the records as preserved only to that extent; do not label the account “secured” or the future evidence guaranteed.

Key takeaway

Treat provider preservation as a limited retention measure, keeping disclosure, containment, completeness and personal attribution as separate questions that still require action and proof.

Reference: FRP-161First Response & Preservation