Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryData Loss Prevention (DLP)
Glossary

Data Loss Prevention (DLP)

Data loss prevention (DLP) is a set of policies and tools that detect sensitive information and stop it from leaving the business by email, cloud or device.

Definition

What is Data Loss Prevention?

Data Loss Prevention (DLP) is a category of security controls that identify sensitive information, such as Social Security numbers, credit card data, or patient records, and stop it from being sent or copied somewhere it should not go. A DLP system inspects content as it moves and applies a policy: allow, warn the user, encrypt, block, or record the event for review.

DLP works by classifying data first. Rules look for patterns (a nine-digit number formatted like a Social Security number), keywords (a project codename), or labels a user applied to a document. Cloud platforms such as Microsoft 365 include DLP as part of Microsoft Purview, where a single policy can cover Exchange email, SharePoint, OneDrive, Teams chat, and Windows endpoints. When a policy matches, the system can stop an email to an outside address, prevent a file from being uploaded to a personal cloud account, or block a copy to a USB drive, and it can show the employee a message explaining why.

In a small or mid-sized business most data loss is accidental rather than malicious: a spreadsheet of client records attached to the wrong email, a contract synced to a personal Dropbox, a departing employee forwarding files to a home account. DLP catches these events and creates a record, which matters for firms subject to HIPAA, the FTC Safeguards Rule, or state privacy laws that require reasonable safeguards and proof they were in place. Tuning is the hard part. Policies that are too strict block legitimate work and get switched off.

NetSys deploys and tunes DLP as a managed service, using the policies already licensed in a client's Microsoft 365 tenant wherever possible. The work starts with an inventory of where sensitive data lives, then moves to policies in audit mode so real traffic can be reviewed before anything is blocked. NetSys's data loss prevention service page describes the process, and Latoya Reed, who covers cloud and Microsoft 365 for NetSys, writes about the configuration choices involved.

Why it matters for a small business

If your business holds anyone else's personal or financial information, you are responsible for where it goes. A single misdirected email with a client list can trigger breach notification duties and a regulator's questions. DLP is the control that catches the mistake before it leaves the building, and it produces the evidence auditors and insurers now ask for. For many companies the tooling is already paid for inside Microsoft 365; what is missing is someone to configure it carefully so it protects data without stopping people from doing their jobs.

Common Questions

Data Loss Prevention (DLP): FAQs

What is data loss prevention in simple terms?

Data loss prevention is software that watches for sensitive information, such as card numbers or medical records, and stops it from being emailed or uploaded to places it should not go. It works from policies that define what counts as sensitive and what should happen when it is detected: warn the user or block the action, and log the event. Most modern DLP lives inside cloud platforms like Microsoft 365 rather than as a separate appliance.

Does Microsoft 365 include DLP?

Yes, through Microsoft Purview, though the features available depend on the license. Business and enterprise plans include DLP policies that cover Exchange, SharePoint, OneDrive, and Teams, and endpoint DLP extends the same policies to Windows and macOS devices on higher tiers. The policies are off by default and need to be designed and tested before they help. Turning on a template without reviewing it usually blocks legitimate work or misses the data you care about.

Do small businesses need data loss prevention?

Any business that handles customer personal data, payment information, or health records benefits from it, and several regulations effectively require it. HIPAA, the FTC Safeguards Rule, and New York's SHIELD Act all expect reasonable technical safeguards against unauthorized disclosure. Beyond compliance, DLP prevents the most common breach in a small firm, which is an honest mistake by an employee. Starting with a few high-value policies in monitoring mode is a practical first step.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.