When should a preservation request be considered?¶
A preservation request should be considered when relevant records may be volatile, routinely deleted or likely to expire before the necessary lawful process can be completed.
The purpose is to prevent foreseeable loss while the investigation progresses.
Avoid the dangerous assumption¶
The dangerous assumption is that logs will remain available until investigators are ready to obtain them.
Many will not.
Short-retention authentication, network, cloud, messaging and security records may disappear within days or weeks. High-volume local logs may overwrite even sooner.
Investigators should first identify the specific records, provider or organisation, relevant account or system, and the time period needed. A preservation request should be focused and proportionate rather than a vague demand to retain everything.
Use the lawful and organisational process that applies. A preservation request does not itself create authority to disclose the material. Preservation and acquisition are separate steps.
Record the date, recipient, scope, identifiers, time zone and confirmation. Ask what the provider can preserve, how long preservation lasts and whether renewal or further legal process is required.
Consider related records, not just the obvious source. An account event may depend on identity, session, device, network or audit records held in different systems.
Do not delay urgent risk management while waiting for preservation. Equally, do not assume preservation guarantees completeness; data already expired or never logged cannot be recreated.
Operational takeaway¶
A preservation request should be considered early where relevant logs may expire or overwrite, using a specific, proportionate scope and recognising that preservation protects availability but does not itself authorise disclosure.