Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Cyber Security & Compliance

Data Loss Prevention (DLP): What It Is and How to Build a Programme That Stops Data Leaks

What is data loss prevention and where do company data leaks really happen? A seven-step plan from data classification to monitoring and blocking.

9 min read  · Digital Bridge Engineering Team
Data Loss Prevention (DLP): What It Is and How to Build a Programme That Stops Data Leaks

Data loss prevention (DLP) is the set of policies, processes and tools that detects sensitive data leaving an organisation without authorisation and, where needed, stops it. After classifying sensitive data, you apply rules to exit channels such as email, file sharing, USB, cloud apps and AI tools, so a policy breach triggers a warning, an approval step or a block.

Most data leaks are not attacks

When people hear "data leak", they picture an outside attacker. In practice, many of the cases we see happen inside ordinary workflows. A sales rep forwards the customer list to a personal inbox, someone in payroll sends a salary file to the wrong recipient, an engineer copies drawings to a USB stick to "look at them at home". Nobody means harm, but the data is now outside the company's control.

Generative AI has added a new channel. An employee pastes a proposal into a chatbot, opened with a personal account, to get a quick summary. We cover that scenario and the usage policy it needs in our guide to ChatGPT and company data security. DLP answers a broader question: whichever channel the data takes, how do you recognise what is sensitive and keep it where it belongs?

Why leaks are so common, and what is at stake

People sit at the centre of most breaches. According to the Verizon 2026 Data Breach Investigations Report, the human element was present in 62% of breaches. The same report found that 45% of employees are now regular AI users on corporate devices, up from 15% a year earlier, and that 67% of users reach these services through non-corporate accounts. Data is flowing into accounts the organisation cannot see.

In Verizon's 2026 DBIR, source code was the most common data type submitted to unauthorised generative AI tools, and 3.2% of DLP policy violations involved research and technical documentation being uploaded to them. (Verizon 2026 Data Breach Investigations Report)

For companies operating in Türkiye there is a regulatory side too. KVKK, the Personal Data Protection Law No. 6698, requires data controllers under Article 12 to take the technical and administrative measures needed to prevent unauthorised access to personal data, much as the GDPR's security principle does in Europe.

The Turkish Data Protection Authority's 2025 Annual Report shows that 2,838 complaints (22%) in 2025 concerned the unlawful sharing of personal data with third parties, the second-largest category. Where suppliers process data on your behalf, a data processing agreement sets the ground rules. Once a leak occurs, the KVKK breach notification process begins.

Basic safeguards are often missing as well. According to IBM's 2026 Cost of a Data Breach press release, only 37% of breached organisations said they encrypt sensitive data both at rest and in transit. The point of DLP is to make these gaps visible before they turn into incidents.

What data loss prevention protects: the three states of data

A DLP programme looks at data in three states. Each carries different risks and needs different controls, and no single product covers all three equally well.

State of dataWhere it livesTypical leakExample control
In motionEmail, web uploads, messagingWrong recipient, forwarding to a personal addressOutbound email rules, send approval, domain restrictions
In useLaptops and desktop appsCopying to USB, screenshots, pasting into AI toolsEndpoint agent, USB policy, clipboard rules
At restFile servers, cloud storage, databasesOpen shared folders, old backups, leavers' accessData discovery, permission matrix, encryption, retention periods

One thing stands out in that table: DLP does not start with buying a separate tool. Most problems with data at rest are solved by permissions, which we explain in our guide to file sharing permissions. Encryption is a separate layer for data in motion and is covered in business email encryption; DLP asks a different question, namely "should this data go to this recipient at all?"

Seven steps to a working DLP programme

For small and mid-sized firms, the approach that works is to start with the most critical data and the busiest channel rather than a sprawling rule set. The sequence below builds on our SME cyber security checklist.

  1. Build a data inventory. Customer lists, pricing and proposals, payroll, technical drawings, source code, health data: where does each sit, and who can reach it? If you already have a KVKK processing inventory, start there; if not, pair this work with the KVKK compliance steps.
  2. Agree a classification scheme. Three or four levels are enough: public, internal, confidential, special category. Complex schemes are ignored; staff should know the right label at a glance.
  3. Map the exit channels. Corporate email, personal webmail, cloud share links, USB, printers, messaging apps, AI tools. For each, decide whether data is allowed, needs approval or is blocked.
  4. Run in monitor-only mode first. For the first few weeks, rules only log. You see where the real risk lies without breaking legitimate work, and you do not move to blocking until false positives fall.
  5. Escalate enforcement gradually. A warning to the user for low risk, manager approval for medium risk, a block for high risk. A warning that explains why teaches far more than a silent block.
  6. Tie it to identity and the joiner-mover-leaver cycle. When someone changes department or leaves, access should close the same day; the quietest leaks happen here. Our guide to offboarding email access covers this step in detail, and a zero trust security model, which re-verifies every access request, is its architectural counterpart.
  7. Review incidents and train. Look at DLP logs monthly, turn recurring mistakes into training and adjust rules. Deleting data whose retention period has expired also shrinks the leak surface; see our data retention and disposal policy guide.

Channel-by-channel checklist

ChannelQuestion to askFirst action
Corporate emailCan sensitive attachments reach outside recipients unchecked?Send approval on critical mailboxes, external-recipient warning
Personal webmailCan staff move company files to personal accounts?Webmail access policy, endpoint rule
File sharingDo share links live forever?Time-limited links, department-based permissions
USB and external drivesIs write access open on every machine?Off by default, documented exceptions
AI toolsAre non-corporate accounts in use?Approved tools list, AI acceptable use policy
LeaversAre accounts and shares closed on the last day?Single point for revoking access

Common DLP mistakes

The most common mistake is installing a product and switching everything to block mode. In week one, sales proposals stop going out, work grinds to a halt and the rules are quietly relaxed. The second is skipping classification: a rule written before anyone defines what is sensitive either catches everything or nothing.

The third is treating DLP as an IT project. Which data may go to which recipient is a business decision, so legal, HR and department heads need to be at the table. Framing that ownership within a data governance framework is what makes the programme last.

Finally, monitoring employees is itself personal data processing under KVKK, just as it is under the GDPR. The purpose of DLP logging, who can see the logs and how long they are kept should appear in the privacy notice, and the principle of proportionality applies.

How we handle this at Digital Bridge

We start DLP work with discovery, not a product pitch. As part of our cyber security consultancy, we map your data inventory and exit channels with you and make visible which data leaves through which channel and how often. We link this to our data protection compliance service so that technical rules speak the same language as your processing inventory and privacy notices.

The second phase is a pilot. We pick one department and one or two channels, usually email and file sharing, run the rules in monitor mode and weed out false positives. The pilot results drive a joint decision on enforcement levels and wider rollout, and we make the classification scheme and data ownership stick through data governance and quality work.

On integration, we work with your existing email, file servers and document systems. Where sensitive documents are scattered across shared folders and need to move into a structure with defined permissions, our document management system service comes in. We also handle multi-factor authentication and access revocation in the same project, because a stolen password defeats even the best DLP rule.

Where Smart360 reduces leak risk

Smart360 is not a DLP product, and it is not positioned as a system that scans and blocks every outbound item of data. What it does is bring more control to the two channels DLP programmes struggle with most: email and file sharing. In SmartMail, the author of a message leaving in the company's name can route it to one or more approvers before it is sent, with approval, reasoned revision and rejection each logged with a timestamp. If you make it an internal rule that proposals and contracts go to a manager for approval, the approver sees the recipient and the attachment before anything leaves, giving you a chance to catch a wrong recipient or wrong file before it is sent.

Nine separate permissions per mailbox (viewing, writing and sending, deleting, quarantine and others) mean an employee can read a shared mailbox without being able to send from it. In SmartFiles, eight independent permissions are granted to people or departments in a single matrix. Download and preview links expire within minutes, so a forwarded link is of little use for long, and because nothing is overwritten, earlier versions of every file are kept.

With a single identity (SmartID), a leaver's access to every product closes in one action, and a change of department updates access across all products together. Sessions are listed with device details and can be ended remotely. Each organisation's data sits in its own database, and in groups running several companies, none can see another's data.

Next step: map where your data can leak

The quickest way into DLP is to map the data inventory and exit channels for one department. In a first conversation we identify which data is critical, which channels are open and which area suits a pilot. For more guides in this area, see our Cyber Security and Compliance topic page.

To arrange a call, get in touch through our contact page or phone +90 552 380 25 25.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

What is data loss prevention in simple terms?

Data loss prevention (DLP) is a set of policies, processes and tools that notices when sensitive data is leaving an organisation without authorisation and stops it. Data is classified first, then exit channels such as email, file sharing, USB and cloud apps are monitored against rules. When a rule is broken, the user is warned, the action is sent for approval or it is blocked.

Can you prevent data leaks without buying DLP software?

To a large extent, yes. A data inventory, a simple classification scheme, department-based permissions, a USB policy, time-limited share links and same-day removal of leavers' access cut most of the risk without a dedicated DLP product. A content-inspecting DLP tool makes sense once those foundations are in place; bought without them, it mostly generates false positives.

Is monitoring employees with DLP lawful under KVKK?

DLP logs contain employees' personal data, so in Türkiye they count as processing under KVKK. The information security purpose must be stated clearly, a legal basis for the processing identified, staff informed, only necessary data collected and access to the logs restricted. A proportionate DLP set-up with a defined retention period helps support the law's duty to take security measures; for the details of your own set-up, it is sensible to take legal advice.

What drives the cost of data loss prevention?

DLP cost is never a single licence line. It depends on the number of users and devices covered, which channels are in scope (email, endpoint, cloud, web), how deeply content is inspected, integration with existing systems and the consultancy effort spent tuning rules. The largest hidden item is usually internal staff time for weeding out false positives and reviewing incidents regularly.

How is DLP different from email encryption?

Email encryption stops third parties reading a message in transit or on a server; it does not care who the message is addressed to. DLP asks whether the message should go at all: is the content sensitive, is the recipient authorised, is this the right channel? Neither replaces the other. Encryption protects data going to the right person; DLP stops data heading to the wrong one.

Where should a small company start with DLP?

Pick your single most critical data type and your busiest channel; for most firms that means customer or pricing data and email. Map where that data lives and who can reach it, run rules in monitor-only mode, and after a few weeks add warnings or approval steps based on what you see. Widen the scope once the pilot results are in.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.