Data loss prevention (DLP) is a set of technologies and policies that detect and block the unauthorised transfer of sensitive data outside an organisation.
How DLP works
A DLP system first has to know what is sensitive. It identifies data using:
- pattern matching – regular expressions for card numbers, passport or social security numbers, IBANs;
- fingerprinting – hashes of specific documents or database records;
- classification labels applied by users or automatically;
- machine learning models for contracts, source code or medical records.
It then monitors the channels where data can leave: email, web uploads, cloud storage, messengers, USB drives, printing and copy-paste. Depending on policy, DLP logs the event, warns the user, encrypts the file or blocks the transfer. Deployments are usually split into endpoint DLP (agents on computers), network DLP (gateways and proxies) and cloud DLP (integrated with Microsoft 365, Google Workspace and other SaaS services).
Why DLP matters
Data leaks are caused not only by hackers but by insider threats: employees taking customer databases to a new job, sending files to personal email or uploading confidential text to public AI chatbots. Regulations such as GDPR, HIPAA and PCI DSS require companies to protect personal and payment data, and a leak can mean large fines. DLP also helps detect data exfiltration by external attackers during an intrusion, especially when its events feed a SIEM.
Best practices
- Start by discovering and classifying where sensitive data actually lives.
- Roll out policies in monitoring mode first to tune false positives.
- Combine DLP with encryption, least-privilege access and awareness training against social engineering.
- Explain the rules to employees – overly strict blocking pushes people to workarounds.