Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

When should a preservation request be considered?

Consider preservation as soon as relevant records may expire, rotate or otherwise disappear before lawful acquisition can be completed. It protects availability; it does not itself authorise disclosure.

Volatility determines urgency

Authentication, cloud, network and security data can expire within days or weeks, while high-volume device logs may overwrite sooner. Identify the particular provider, tenant, account, system, record types and time range rather than asking vaguely for “all logs”. Related identity, session, device and audit records may need separate scopes.

Record a focused preservation trail

Use the applicable lawful and organisational process and record recipient, date, identifiers, time zone, scope and confirmation. Establish what can be preserved, for how long, whether renewal is needed and what acquisition process remains.

Preservation cannot recover data already expired or never logged, and should not delay urgent risk action. Its value is preventing foreseeable loss while authority and collection arrangements progress.

The point to remember

Preserve volatile records early with a specific, proportionate scope while keeping preservation and disclosure authority distinct.

Reference: LOG-132Logs, Records & Provider Evidence