Where DLP works
Endpoint DLP monitors what happens on laptops, such as copying files to USB drives or pasting data into a website. Network and email DLP inspects outgoing traffic and messages. Cloud DLP applies rules inside SaaS platforms like Microsoft 365 and Google Workspace, for example blocking public sharing of files that contain customer data.
Classification comes first
DLP can only protect what it can recognise. That requires knowing what sensitive data the company holds and labelling it, for instance personal data, financial information or source code. Rules then decide what happens: warn the user, block the action or alert the security team. Starting in monitoring mode avoids blocking legitimate work.
New leak channels
Employees pasting confidential information into AI assistants and personal cloud accounts, often as part of shadow IT, are now one of the most common leak paths. Policies, approved tools and awareness matter as much as technology here.
Where it shows up in compliance
Data leakage prevention became a control in ISO 27001:2022 (Annex A 8.12). Under the GDPR, an unauthorised disclosure of personal data is a data breach, so DLP also reduces regulatory exposure. Encryption complements it by protecting data that does leave.




