Data Retention Notices Under the Investigatory Powers Act: What ISPs Actually Have to Log, and for How Long
Ask a UK ISP what they log about your internet use, and the honest ones will tell you something unsatisfying: they can't say, in public, in full. Not because they're hiding something shady, but because the specific instrument that tells them what to retain, a retention notice issued under section 87 of the Investigatory Powers Act 2016, is not published. It's a written notice served on a named operator or class of operators, and its contents are treated as confidential between the Home Office and whoever received it. What follows is everything that is public: the statutory ceiling on what a notice can demand, the categories of data involved, and the safeguards that are supposed to stop the power being abused. What any specific ISP has actually been told to keep is, by design, not something you or I get to read.
The basic mechanism
Part 4 of the IPA gives the Secretary of State power to serve a "retention notice" on a telecommunications operator, requiring them to retain communications data they wouldn't otherwise keep for business purposes. A notice has to specify the operator (or description of operators), the data to be retained, the retention period, and the level of contribution the government will make towards the operator's costs. It can be given to a single named company or to a whole category of them, and it can require "all data or any description of data" the operator generates or processes, subject to the limits below.
Notices aren't handed out on a minister's say-so alone. The Secretary of State has to consider the notice necessary and proportionate for one of a defined set of purposes: national security, preventing or detecting an applicable form of crime, the UK's economic well-being where linked to national security, public safety, preventing death or injury, or investigating a miscarriage of justice. A Judicial Commissioner has to approve the decision before it takes effect, and under changes made by the Investigatory Powers (Amendment) Act 2024, notices now lapse automatically after two years unless renewed or varied.
Twelve months, but the clock starts in different places
The headline figure everyone quotes is 12 months, and that's correct as a ceiling: no retention notice can require data to be kept for longer. What's less often mentioned is that the 12 months doesn't start from a single fixed point. Section 87(9) sets three different starting lines depending on what kind of data is in play:
- For data tied to a specific communication, the clock starts on the day of that communication.
- For entity data that isn't tied to a single communication (think: an account or device record), it starts when the entity stops being associated with the service, or when the data is changed, whichever comes first.
- For anything else, it starts on the day the operator first holds the data.
In practice this means a notice covering, say, records of who was assigned which IP address at a given time behaves differently in terms of when the countdown begins compared with a notice covering the timestamp of an individual connection event. It's a fiddly distinction, but it matters if you're ever trying to work out whether a given record should still exist.
Entity data and events data aren't the same power
The Act draws a line that's easy to gloss over but does real work: entity data versus events data, both defined in section 261. Entity data is data about an entity, or an association between a service and an entity, roughly the "who has this account, what's linked to it" layer. Events data is data describing something that happened, one or more entities engaging in a specific activity at a specific time, the "who connected to what, when" layer. This distinction isn't academic, because the purposes for which each can be retained aren't the same. Under section 87(10A), events data can only be retained for the "applicable crime purpose" of preventing or detecting serious crime, defined by reference to section 86 and section 263 as an offence carrying a maximum sentence of 12 months' imprisonment or more (with a few specific exceptions written in). Entity data has a lower bar and can be retained for preventing crime generally or preventing disorder, not just serious crime.
That split isn't how the Act was originally drafted. It was inserted by the Data Retention and Acquisition Regulations 2018, in direct response to a High Court ruling. In 2018, in R (Liberty) v Secretary of State for the Home Department, the Divisional Court held that Part 4 of the IPA was, in part, incompatible with EU law, specifically because it allowed retention notices for ordinary crime rather than just serious crime, and because access to retained data wasn't subject to prior independent review. The government's fix was to tier the purposes by data type and to build independent authorisation into the acquisition side of the regime. It's a good example of a surveillance power actually being narrowed by litigation rather than just debated and left alone.
Internet connection records: narrower than people assume
Internet Connection Records get disproportionate attention, understandably, since they were the genuinely new capability the IPA introduced in 2016. An ICR is communications data that identifies which telecommunications service a device connected to, generated as a by-product of the operator supplying that service. Concretely, that's closer to "this device connected to this app or platform, at this time, for this duration" than it is to a browsing history. The Act does not extend to page-level detail such as a full URL path or the content exchanged; an ICR tells you which service was used, not what was said or which page within it was visited. Access to ICRs is also more tightly gated than access to other communications data, under section 62. Local authorities can't obtain them at all. Other public authorities need to fit one of a small number of conditions, roughly: identifying which person used a known service at a known time, identifying which of several services a known person used, or detecting certain offences involving unlawful access to or distribution of material online. The 2024 Act added two further conditions for the security services and the National Crime Agency, but the general shape, ICRs as a narrowly-conditioned power rather than an open browsing log, hasn't changed.
What operators can push back on
A retention notice isn't take-it-or-leave-it. Under section 90, an operator served with a notice can refer it back to the Secretary of State for review, triggering a formal process: the Technical Advisory Board assesses whether the notice is technically feasible and what it would cost the operator to comply, while a Judicial Commissioner separately assesses proportionality. Both report back, the operator gets a chance to make representations, and the Secretary of State then decides whether to confirm, vary or withdraw the notice. This is the main lever a smaller ISP has if a notice asks for something disproportionate to their size or infrastructure, cost contribution disputes and technical infeasibility are exactly the sort of thing this mechanism exists to resolve, and it's a large part of why cost-sharing terms are baked into every notice from the outset.
Oversight of the whole regime sits with the Investigatory Powers Commissioner's Office, which audits how notices are used and reports annually, though its reports understandably discuss the regime in aggregate rather than confirming which operators hold which notices.
None of this tells you exactly what your own ISP logs, because that answer genuinely isn't public. But it does tell you the boundaries within which any notice they've received has to sit: a hard 12-month cap with data-type-dependent start dates, a two-tier purpose test that's stricter for events data than entity data, ICRs that are considerably narrower than "browsing history," and at least two independent checks, a Judicial Commissioner and, on referral, the Technical Advisory Board, standing between a minister's signature and an operator's server room.