DLP is the set of controls that stop sensitive data leaving your organisation, whether someone is doing it deliberately or by accident.
The short answer
Data loss prevention identifies sensitive data, watches the paths it could take out of the organisation, and blocks or flags movement that breaks policy. It covers accidental exposure as much as malicious exfiltration, and most real incidents are the accidental kind.
Encryption protects data from an outsider who obtains the storage. DLP addresses the other direction: an insider who already has legitimate access moving data somewhere it should not go.
On this page
How data actually leaves
How DLP works
Three steps, and the first is where most deployments succeed or fail. A policy that cannot tell customer data from a lunch menu will either block everything or nothing.
| Step | What happens |
|---|---|
| Classify | Identify what is sensitive, by pattern, by location, or by label applied at creation |
| Monitor | Watch the paths data can take: file access, uploads, removable media, sharing |
| Enforce | Allow, warn the user, log for review, or block the action outright |
Start in monitor mode
Blocking from day one generates support tickets and workarounds, and workarounds are worse than the original risk. Run in monitor mode first, learn what normal movement looks like, then enforce on the paths that matter.
Where frameworks require it
| Framework | What it expects |
|---|---|
| ISO 27001:2022 | Annex A 8.12 data leakage prevention, added in the 2022 edition. |
| DPDP Act, 2023 | Reasonable security safeguards against unauthorised disclosure of personal data. |
| SOC 2 | Confidentiality criteria, where the scope includes confidential customer information. |
| Buyer questionnaires | Whether staff can copy customer data to personal accounts or removable media. |
How Osto handles DLP
Osto provides file access data loss prevention, governing who can reach which files and recording what they do with them, alongside endpoint and device control that covers removable media and content filtering on the device itself. Because the same platform holds identity, endpoint and cloud activity, a file access event can be read next to the sign-in that preceded it, which is what separates an unusual download from an incident.
Free security assessment
See where your data actually goes
File access DLP plus endpoint and device control, with the identity and cloud context needed to tell an unusual download from an incident.
Get a free security assessment Book a platform walkthroughFile access governance · Device control · One platform, everything
Frequently asked questions
What does DLP stand for?
Data loss prevention. It refers to controls that identify sensitive data, monitor how it moves, and block or flag movement that breaks policy.
Is DLP only about malicious insiders?
No. Most incidents are accidental: a file attached to the wrong thread, a folder synced to a personal account, an export saved to a laptop before a trip. DLP catches carelessness far more often than theft.
How is DLP different from access control?
Access control decides who can open the data. DLP decides what they can do with it afterwards. Someone with legitimate access can still move data somewhere it should not go, which is the gap DLP covers.
Does encryption remove the need for DLP?
No. Encryption protects data from someone who obtains the storage. It offers nothing against an authorised user who opens a file and forwards it, because to that user the data is already decrypted.

