DLP Explained: How Data Loss Prevention Works

DLP explained: how data loss prevention works

DLP is the set of controls that stop sensitive data leaving your organisation, whether someone is doing it deliberately or by accident.

  • Glossary
  • Data protection

The short answer

Data loss prevention identifies sensitive data, watches the paths it could take out of the organisation, and blocks or flags movement that breaks policy. It covers accidental exposure as much as malicious exfiltration, and most real incidents are the accidental kind.

Encryption protects data from an outsider who obtains the storage. DLP addresses the other direction: an insider who already has legitimate access moving data somewhere it should not go.

How data actually leaves

Sensitive data files, records, exports Email attachment Personal cloud sync USB or external drive Upload to a website Chat or AI tool paste Policy check Who, what data, going where Allow Warn or log Block Most incidents come from the top two paths, and most are careless rather than malicious.

How DLP works

Three steps, and the first is where most deployments succeed or fail. A policy that cannot tell customer data from a lunch menu will either block everything or nothing.

StepWhat happens
ClassifyIdentify what is sensitive, by pattern, by location, or by label applied at creation
MonitorWatch the paths data can take: file access, uploads, removable media, sharing
EnforceAllow, warn the user, log for review, or block the action outright

Start in monitor mode

Blocking from day one generates support tickets and workarounds, and workarounds are worse than the original risk. Run in monitor mode first, learn what normal movement looks like, then enforce on the paths that matter.

Where frameworks require it

FrameworkWhat it expects
ISO 27001:2022Annex A 8.12 data leakage prevention, added in the 2022 edition.
DPDP Act, 2023Reasonable security safeguards against unauthorised disclosure of personal data.
SOC 2Confidentiality criteria, where the scope includes confidential customer information.
Buyer questionnairesWhether staff can copy customer data to personal accounts or removable media.

How Osto handles DLP

Osto provides file access data loss prevention, governing who can reach which files and recording what they do with them, alongside endpoint and device control that covers removable media and content filtering on the device itself. Because the same platform holds identity, endpoint and cloud activity, a file access event can be read next to the sign-in that preceded it, which is what separates an unusual download from an incident.

Free security assessment

See where your data actually goes

File access DLP plus endpoint and device control, with the identity and cloud context needed to tell an unusual download from an incident.

Get a free security assessment Book a platform walkthrough

File access governance · Device control · One platform, everything

Frequently asked questions

What does DLP stand for?

Data loss prevention. It refers to controls that identify sensitive data, monitor how it moves, and block or flag movement that breaks policy.

Is DLP only about malicious insiders?

No. Most incidents are accidental: a file attached to the wrong thread, a folder synced to a personal account, an export saved to a laptop before a trip. DLP catches carelessness far more often than theft.

How is DLP different from access control?

Access control decides who can open the data. DLP decides what they can do with it afterwards. Someone with legitimate access can still move data somewhere it should not go, which is the gap DLP covers.

Does encryption remove the need for DLP?

No. Encryption protects data from someone who obtains the storage. It offers nothing against an authorised user who opens a file and forwards it, because to that user the data is already decrypted.