Investigations
If data has been "preserved", has anyone read it?
No. Preservation freezes material so that it still exists later; production hands it over. The Convention caps preservation at ninety days precisely because its purpose is to enable authorities to seek disclosure afterwards, by a separate power.
In short
Preserving data and obtaining it are two steps, and a system that has taken the first has not taken the second. Preservation stops something being deleted. Production hands it over. Between them, nobody investigating has read anything.
Why it exists
AnalysisThe problem preservation answers is timing. Data that matters to an investigation may be deleted — routinely, automatically, or deliberately — long before the process required to obtain it can be completed. If the only available step were the full one, the material would often be gone by the time it was authorised.
AnalysisA separate, lighter step solves that without solving it too generously. Freezing material is a smaller intrusion than reading it: the holder keeps it, the investigators do not get it, and the question whether they may have it is answered afterwards on its own terms.
How it works
Article 16 of the Convention on Cybercrime states the mechanism and its purpose in the same sentence. Parties must empower their authorities to order or similarly obtain the expeditious preservation of specified computer data, including traffic data, "in particular where there are grounds to believe that the computer data is particularly vulnerable to loss or modification". Where this is done by an order to a person, that person must preserve and maintain the integrity of the data "for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure". The order may be renewed.
That different act is Article 18. It obliges Parties to empower their authorities to order a person in the territory to submit specified computer data in that person’s possession or control, and to order a service provider offering services in the territory to submit subscriber information relating to those services. Article 17 adds a narrow intermediate step for traffic data: where data has been preserved under Article 16, enough traffic data must be disclosed to enable the Party to identify the service providers and the path through which the communication was transmitted.
Preservation also carries a confidentiality duty running the other way from the investigation. Article 16(3) obliges Parties to require the custodian or other person preserving the data to keep the undertaking of the procedure confidential for the period provided by domestic law.
United States law shows what the production side looks like when a national statute grades it. Section 2703 of Title 18 provides different routes according to what is sought and whether notice is given: a warrant without required notice; a subpoena or a § 2703(d) court order with prior notice to the subscriber or customer, with delayed notice available under § 2705; and, for the six enumerated basic items, a subpoena with no notice requirement at all under § 2703(c)(3).
Common misconceptions
Widely held beliefs that do not match how the system actually operates.
Common belief: If data has been preserved, investigators have it.
In practice: Article 16(2) of the Convention requires preservation for up to ninety days "to enable the competent authorities to seek its disclosure". Seeking disclosure is Article 18, a separate power with its own conditions.
Common belief: A preservation order is a lighter version of a production order.
In practice: They do different things. Preservation obliges the holder to keep material and maintain its integrity; production obliges someone to hand material over. One can be complied with entirely without the other ever being made.
Common belief: Preservation lasts as long as the investigation needs.
In practice: Article 16(2) caps it at a maximum of ninety days where it is effected by order to a person, though it permits a Party to provide for renewal.
Common belief: A preservation order and a data-retention obligation are the same thing.
In practice: A preservation order concerns specified data already held, in a particular case. A retention mandate is a general obligation to keep data about everyone for a period, whether or not any investigation exists. Retention regimes were not researched for this wave and nothing here describes one.
Common belief: The person whose data was preserved will be told.
In practice: Article 16(3) requires the opposite of the custodian: Parties must oblige the person preserving the data to keep the undertaking of the procedure confidential for the period their domestic law provides. Whether the subject is ever notified is a separate question answered by each system’s own rules.
Common belief: Because these steps are separated, data is lost while the process runs.
In practice: Separating them is what prevents that. Preservation exists precisely because the fuller process takes time, and Article 16 directs it at data "particularly vulnerable to loss or modification".
How this varies between jurisdictions
A required section on every guide. Arrangements differ between countries, and we say how.
Four distinct mechanisms, and the Convention keeps them in four articles.
- Expedited preservation of specified stored data, up to ninety days, renewable, with a confidentiality duty on the custodian — Convention Art. 16.
- Expedited preservation with partial disclosure of enough traffic data to identify the providers and the path — Convention Art. 17.
- A production order: specified stored computer data from a person, or subscriber information from a service provider — Convention Art. 18.
- Graded national production routes differing by what is sought and whether notice is given — United States, 18 U.S.C. § 2703(b)–(c), with delayed notice under § 2705.
- A general retention mandate — a different instrument entirely, NOT researched for this wave and not described here.
Rights and accountability
Preservation is the step at which the integrity question and the authority question separate cleanly. Article 16(2) requires the person ordered to preserve to "preserve and maintain the integrity" of the data — an obligation about the material’s condition, owed while the question of who may have it is still open.
What we could not establish
- This page rests mainly on one treaty. National preservation regimes were not researched in any of the four systems this wave examined, and nothing is asserted about them.
- A general retention mandate — an obligation on providers to keep data about everyone for a period — is a third and different instrument. Retention regimes were not researched and this page makes no claim about any of them.
- Nothing here describes how data is stored, preserved, transferred or obtained.
Where to go next
Related: content and communications data, scope, duration and notification, and evidence integrity and admissibility. The same two steps across a border, where dual criminality enters at one and not the other, are cross-border preservation and disclosure.
Related topics
- Is who a person contacted treated the same as what they said?
No. Two instruments define the line in their own text — the Convention defines subscriber information as data "other than traffic or content data", and United States law excludes contents from the pen-register and subscriber-record definitions — and the three categories carry different conditions.
- Who decides that an investigator may take a digital investigative step?
Not always a judge, and not always the same judge. One German power needs a single court, another a three-judge panel with a higher court taking over after six months; United States law allocates three different instruments to three categories; and the Convention requires "judicial or other independent supervision".
- Once a measure is authorised, what bounds it — and is the person ever told?
German law requires the order to state the measure’s type, extent, duration and end-point, then names measure by measure who must be notified afterwards and gives them two weeks to ask a court whether it was lawful and properly executed.
- If the chain of custody is broken, is the evidence thrown out?
Not automatically, and the assumption hides two different questions. Integrity asks whether the item is what it is said to be; admissibility asks whether the law lets a court receive it. A system can answer one yes and the other no.
Sources
Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0001839) · International organisation · 2001-11-23 · link verified 2026-09-05
WAVE 22 ADDITION. ACCESS NOTE: rm.coe.int and coe.int returned HTTP 403 to automated requests in this session, so the Convention was read from the official Dutch government treaty database, which publishes the authentic English text alongside the Dutch translation. The English text quoted below is the authentic one; English and French are the authentic languages. Supports Art. 14(1)–(2), that the procedural powers are established “for the purpose of specific criminal investigations or proceedings” and are applied to the offences established under Arts. 2–11, to other criminal offences committed by means of a computer system, and to “the collection of evidence in electronic form of a criminal offence”. Supports Art. 14(3)(a), that a Party restricting the Art. 20 power to specified offences must not restrict it more narrowly than the range to which it applies Art. 21. Supports Art. 15(1), that the powers are subject to conditions and safeguards under domestic law providing adequate protection of human rights, including rights under the 1950 European Convention and the 1966 Covenant, “and which shall incorporate the principle of proportionality”. Supports Art. 15(2), that such conditions and safeguards shall, as appropriate, “include judicial or other independent supervision, grounds justifying application, and limitation of the scope and the duration of such power or procedure”. Supports Art. 16(1)–(3): expedited preservation of specified stored computer data “including traffic data”, in particular where it is particularly vulnerable to loss or modification; where effected by order to a person, an obligation to preserve and maintain integrity “for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure”, renewable; and an obligation on the custodian to keep the undertaking of the procedure confidential. Supports Art. 17, expedited preservation and PARTIAL disclosure of traffic data sufficient to identify the service providers and the path through which the communication was transmitted. Supports Art. 18(1)(a)–(b), the production order: a person in the territory to submit specified stored computer data in that person’s possession or control, and a service provider offering services in the territory to submit subscriber information. Supports Art. 18(3), which defines “subscriber information” as information held by a service provider relating to subscribers of its services “OTHER THAN TRAFFIC OR CONTENT DATA” and by which the type of service, the subscriber’s identity, postal or geographic address, telephone and other access number, billing and payment information, and information on the site of installation of communication equipment can be established. Supports Art. 19(1)–(4): the power to search or similarly access a computer system or a computer-data storage medium; the power under 19(2) to EXTEND the search expeditiously to another system in the territory where the data sought is “lawfully accessible from or available to the initial system”; the power under 19(3) to seize or similarly secure, comprising the separate powers to “seize or similarly secure a computer system or part of it or a computer-data storage medium”, to “make and retain a copy of those computer data”, to “maintain the integrity of the relevant stored computer data”, and to “render inaccessible or remove those computer data in the accessed computer system”; and the power under 19(4) to order any person with knowledge about the functioning of the system to provide, as is reasonable, the necessary information. Supports Art. 20, real-time collection of TRAFFIC data, and Art. 21, interception of CONTENT data, the latter available only “in relation to a range of serious offences to be determined by domestic law”; both articles oblige a service provider to keep the execution confidential. Cited for the structural propositions that preservation is a distinct act from production, that traffic data and content data are distinct powers, that subscriber information is defined by exclusion from both, and that seizing, copying and accessing are separately enumerated. LIMITATIONS, and they are load-bearing: this is a TREATY. It obliges Parties to establish powers in domestic law; it is NOT evidence of what any particular Party has enacted, and no country claim on this platform rests on it. It describes no technique. STATUS: in force; the Convention has two additional protocols, of which the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was located but NOT read for this wave. WAVE 23 ADDITION. That Protocol has now been read and is held separately as `coe-cybercrime-second-protocol`. Chapter III of the Convention, on international co-operation, was read from the same authentic English text, and it is a different subject from the domestic powers above. Supports Art. 23, that Parties co-operate “in accordance with the provisions of this chapter, and through the application of relevant international instruments on international co-operation in criminal matters, arrangements agreed on the basis of uniform or reciprocal legislation, and domestic laws”. Supports Art. 25(1)-(4), and in particular Art. 25(2), that “Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35” -- the Convention’s own statement that its co-operation articles are not self-executing -- and Art. 25(4), that except as specifically provided “mutual assistance shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation”. Supports Art. 27(1), that the Article applies only “where there is no mutual assistance treaty or arrangement on the basis of uniform or reciprocal legislation in force between the requesting and requested Parties”, and Art. 27(2)(a)-(d), that each Party designates a central authority “responsible for sending and answering requests for mutual assistance, the execution of such requests or their transmission to the authorities competent for their execution”, that central authorities communicate directly with each other, and that the Secretary General keeps a register of them. Supports Art. 29(1)-(4): a Party may request another to preserve data “located within the territory of that other Party and in respect of which the requesting Party intends to submit a request for mutual assistance”; the request must state that intention (29(2)(f)); “For the purposes of responding to a request, dual criminality shall not be required as a condition to providing such preservation” (29(3)); and a Party that requires dual criminality for disclosure may reserve the right to refuse preservation where it has reasons to believe the condition cannot be fulfilled at the time of disclosure (29(4)). Supports Art. 30(1)-(2), expedited disclosure of a sufficient amount of preserved traffic data to identify a service provider in another State and the path through which the communication was transmitted, withholdable only for a political offence or where execution is likely to prejudice sovereignty, security, ordre public or other essential interests. Supports Art. 31(1)-(3), mutual assistance to search, seize and disclose stored data “including data that has been preserved pursuant to Article 29”, responded to on an expedited basis where data is particularly vulnerable to loss. Supports Art. 32 IN FULL, and its narrowness is the point: “A Party may, without the authorisation of another Party: a) access publicly available (open source) stored computer data, regardless of where the data is located geographically; or b) access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data to the Party through that computer system.” There is no third limb and no unilateral remote-access provision. Supports Art. 33(1)-(2), mutual assistance in the real-time collection of traffic data, governed by the conditions and procedures of domestic law and available at least for offences for which such collection would be available in a similar domestic case; and Art. 34, mutual assistance regarding the interception of content data “to the extent permitted under their applicable treaties and domestic laws”. Supports Art. 35(1)-(2), that each Party designates a point of contact available twenty-four hours a day, seven days a week, to ensure immediate assistance -- facilitating or, if permitted by its domestic law and practice, directly carrying out technical advice, preservation under Arts. 29 and 30, and the collection of evidence, provision of legal information and locating of suspects -- and that where the point of contact is not part of the Party’s authority responsible for international mutual assistance, it must ensure co-ordination with that authority. LIMITATION ON CHAPTER III, restated because it is easy to lose: these are obligations on Parties to legislate and to co-operate. They are NOT evidence of what any Party has enacted. The Party list, signature dates and ratification counts were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403 to three separate URL forms.
Legal Information Institute, Cornell Law School (reproducing the United States Code) · Legislation · link verified 2026-09-05
WAVE 22 ADDITION. ACCESS NOTE, stated because it affects the tier of this record: the official hosts were attempted first and were unreachable in this session — uscode.house.gov timed out without response and govinfo.gov returned HTTP 502 — so the text was read from the Legal Information Institute, which reproduces the United States Code verbatim rather than summarising it. It is cited for statutory wording only, and every proposition below is a quotation or a close paraphrase of one. Supports § 2703(a): a governmental entity may require disclosure of the CONTENTS of a wire or electronic communication in electronic storage for one hundred and eighty days or less “only pursuant to a warrant”; contents held more than one hundred and eighty days may be required by the means available under subsection (b). Supports § 2703(b)(1): contents held by a remote computing service may be required WITHOUT required notice to the subscriber or customer on a warrant, or WITH prior notice where the entity uses an administrative, grand jury or trial subpoena or obtains a § 2703(d) court order, with delayed notice available under § 2705. Supports § 2703(c)(1), that a governmental entity may require disclosure of “a record or other information pertaining to a subscriber to or customer of such service (NOT INCLUDING THE CONTENTS OF COMMUNICATIONS)” only by warrant, § 2703(d) order, subscriber consent, a narrow written request confined to telemarketing-fraud investigations, or under paragraph (2). Supports § 2703(c)(2), which lists the six items a provider shall disclose on an administrative, grand jury or trial subpoena: name; address; local and long distance telephone connection records, or records of session times and durations; length of service including start date and types of service utilised; telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and means and source of payment. Supports § 2703(c)(3), that a governmental entity receiving records under subsection (c) “is not required to provide notice to a subscriber or customer”. Supports § 2703(d), that a court order shall issue “only if the governmental entity offers specific and articulable facts showing that there are reasonable grounds to believe” the material sought is “relevant and material to an ongoing criminal investigation”, and that a court may quash or modify on a provider’s prompt motion where the records are unusually voluminous or compliance would cause an undue burden. Cited for the proposition that one statute can allocate three different authorising instruments to three different categories of digital material. LIMITATIONS: this record supports the wording of § 2703 and nothing else. It establishes no United States constitutional doctrine, no case law, and nothing about the Wiretap Act, which was not read. STATUS: current codified text as reproduced at the verification date. WAVE 23 ADDITION. Section 2703(h) was read from the same source under the same access note. Supports § 2703(h)(1)(A), defining a “qualifying foreign government” as one “with which the United States has an executive agreement that has entered into force under section 2523” and whose laws provide electronic communication service providers and remote computing service providers “substantive and procedural opportunities similar to those provided under paragraphs (2) and (5)”. Supports § 2703(h)(2)(A), that a provider -- “including a foreign electronic communication service or remote computing service” -- being required to disclose the contents of a communication may file a motion to modify or quash the legal process where it reasonably believes (i) that the customer or subscriber “is not a United States person and does not reside in the United States” and (ii) that the required disclosure “would create a material risk that the provider would violate the laws of a qualifying foreign government”, such a motion to be filed not later than 14 days after service. Cited for the proposition that the same body of legislation which removes the data’s location as an answer also provides a route for a provider to raise a conflict of legal obligations. LIMITATION: which governments qualify turns on executive agreements under § 2523, and that coverage was NOT RESEARCHED. No list of qualifying foreign governments is stated anywhere on this platform.