GlossaryCompliance operations

DLP

Short answer

DLP (Data Loss Prevention) is the set of policies and tools that detect and block sensitive data leaving the organisation without authorisation, whether by email, cloud uploads, USB drives, messaging apps or AI tools. It covers both accidental leaks and deliberate theft.

Where DLP works

Endpoint DLP monitors what happens on laptops, such as copying files to USB drives or pasting data into a website. Network and email DLP inspects outgoing traffic and messages. Cloud DLP applies rules inside SaaS platforms like Microsoft 365 and Google Workspace, for example blocking public sharing of files that contain customer data.

Classification comes first

DLP can only protect what it can recognise. That requires knowing what sensitive data the company holds and labelling it, for instance personal data, financial information or source code. Rules then decide what happens: warn the user, block the action or alert the security team. Starting in monitoring mode avoids blocking legitimate work.

New leak channels

Employees pasting confidential information into AI assistants and personal cloud accounts, often as part of shadow IT, are now one of the most common leak paths. Policies, approved tools and awareness matter as much as technology here.

Where it shows up in compliance

Data leakage prevention became a control in ISO 27001:2022 (Annex A 8.12). Under the GDPR, an unauthorised disclosure of personal data is a data breach, so DLP also reduces regulatory exposure. Encryption complements it by protecting data that does leave.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub