Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 data leakage prevention under Annex A control 8.12 — identify, monitor and act on sensitive data channels

ISO 27001 Data Leakage Prevention: Complete 2026 Guide

ISO 27001 data leakage prevention is Annex A control 8.12, and it is one of the very few controls in the standard whose own guidance tells you to speak to a lawyer before you speak to a vendor. Most teams read the control title, go shopping for a DLP product, and present the dashboard at the audit. The auditor is looking for something else: proof that you worked out what needs protecting, which channels it leaves by, and whether the monitoring you switched on is lawful where your people actually work.

A.8.12 is also one of the eleven controls that did not exist in ISO/IEC 27001:2013, so if you transitioned rather than certified fresh, there is probably nothing behind it at all. This guide covers what the control requires, the legal check that comes first, the two neighbouring controls that fail alongside it, and the evidence a certification auditor will actually ask to see.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

What ISO 27001 data leakage prevention requires under A.8.12

The control is short. It asks you to apply data leakage prevention measures to systems, networks and any other devices that process, store or transmit sensitive information. Its stated purpose is to detect and prevent the unauthorised disclosure and extraction of information, by people or by systems.

Read it carefully and ISO 27001 data leakage prevention resolves into three obligations, in order:

ObligationWhat it means in practiceWhat the auditor looks at
Identify sensitive informationKnow which data types matter and where they live. The standard does not define “sensitive” — your classification scheme does.Classification scheme, data inventory, mapping of classified data to systems
Monitor the channels it can leave byEmail, web uploads, cloud sync, removable media, file transfer, print, mobile devices, developer copiesChannel list with a decision against each one, and the configuration backing it
Act to prevent leakageBlock, quarantine, alert, strip, or require authorisation — whatever the risk assessment supportsRule set, alert triage records, exception approvals

The words “any other devices” do a lot of work in A.8.12. They pull in laptops, phones, USB drives, multifunction printers and anything else that can hold a copy. A control scoped to the email gateway alone is an easy finding.

Note what the control does not say. It never names a product category, never requires an agent on every endpoint, and never sets a detection rate. ISO 27001 data leakage prevention is a set of measures proportionate to your risk assessment, not a licence you buy.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

Why ISO 27001 data leakage prevention has no 2013 ancestor

ISO 27001 data leakage prevention is genuinely new. The 2022 edition restructured Annex A into 93 controls across four themes — 37 organizational, 8 people, 14 physical and 34 technological — and added eleven controls with no predecessor. Three of those eleven are about data rather than systems:

ControlTitleStatus in 2022Question it answers
A.8.10Information deletionNewIs the data still here when it no longer needs to be?
A.8.11Data maskingNewIs real data exposed where fake data would do?
A.8.12Data leakage preventionNewCan the data leave, and would you know?

The 2013 edition did govern the channels. A.13.2.1 (information transfer policies and procedures), A.13.2.2 (agreements on information transfer) and A.13.2.3 (electronic messaging) all map forward to A.5.14 Information transfer, and the removable media controls A.8.3.1 to A.8.3.3 map to A.7.10 Storage media. What 2013 never asked was the harder question: which data, specifically, must not leave by those channels.

That gap shows up in most transitioned management systems. There is a mature information transfer policy from 2015 with a version history, and nothing at all underneath A.8.12 except a tick in the Statement of Applicability. If your transition was a mapping exercise, this is one of the controls to check first.

ISO/IEC 27002:2022’s guidance for 8.12 ends with a note most implementation blogs skip entirely: these tools work by monitoring personnel communications and online activity, which raises legal questions that need settling before deployment. It specifically points at privacy and data protection law, employment law, and law on the interception of telecommunications.

That makes ISO 27001 data leakage prevention unusual among the technical controls. For almost every other technical control, you implement and then evidence it. Here, switching the control on without a lawful basis and proper notice can itself create a nonconformity — or a regulator’s letter.

JurisdictionWhat it requiresWhere it bites DLP
New York (private employers with a place of business in the state)Civil Rights Law § 52-c, added by S.2628 (signed 8 November 2021, effective 7 May 2022): written or electronic notice of monitoring of phone, email and internet use on hiring, with employee acknowledgement, plus a notice posted conspicuously. Enforced by the Attorney General, up to $500 for a first offence, $1,000 for a second and $3,000 thereafter.The exception covers processes performed solely for system maintenance or protection that do not target a particular individual. Content-inspecting rules that raise per-user alerts sit well outside that, so get advice rather than assuming the carve-out applies.
ConnecticutGen. Stat. § 31-48d: prior written notice to affected employees of the types of electronic monitoring; a conspicuous posting satisfies it. Civil penalties rise to $3,000 for repeat violations.Notice is by monitoring type, so adding endpoint or screen monitoring later can outrun the notice you posted.
Delaware19 Del. C. § 705: either a daily electronic notice when the employee accesses monitored systems — a login banner serves — or a one-time written notice with documented acknowledgement.The login-banner route is usually the cheapest control to implement and the easiest to evidence at audit.
United KingdomThe ICO’s guidance Employment practices and data protection: monitoring workers (3 October 2023, replacing the 2011 Employment Practices Code) expects a lawful basis, the least intrusive means that achieves the purpose, and workers to be informed. It treats keystroke monitoring as high risk and recommends a DPIA whether or not one is strictly required.A DPIA on the DLP deployment is the document that proves proportionality. Covert monitoring is only justifiable exceptionally and should be authorised by senior management.
EU member statesA GDPR lawful basis under Article 6 and, for high-risk monitoring, a DPIA under Article 35. In several states, employee representative bodies have consultation or co-determination rights over technology that monitors behaviour.Works council timelines, not tooling, set your go-live date. Check locally before you commit to one.

The practical consequence is that your ISO 27001 data leakage prevention evidence pack starts with a dated record of a legal and HR review, the notice text actually issued, the acknowledgements, and a DPIA where one applies. None of that comes from the vendor.

ISO 27001 data leakage prevention depends on classification

Every ISO 27001 data leakage prevention rule is written in the language of data types: card numbers, national identifiers, source code, pricing models, product designs, patient records. If your classification scheme is a three-line policy nobody applies, the rules have nothing to match on and the deployment stalls in tuning forever.

This is why A.8.12 is the control that quietly tests whether A.5.12 (classification of information) and A.5.13 (labelling of information) are real. Our guide to data classification covers building the scheme itself; the point for A.8.12 is that the scheme must be specific enough to turn into a detection rule.

LabelExample contentDetection approachTypical action
RestrictedCard data, national ID numbers, credentials, health recordsPattern plus validation (checksum, proximity keywords)Block and alert; narrow approved route only
ConfidentialCustomer contracts, pricing models, source code, designsFingerprinting, document labels, repository originWarn the user, log, require justification
InternalRoutine operational documentsLabel-based onlyMonitor, no interruption
PublicPublished materialOut of scopeNo rule

Run new ISO 27001 data leakage prevention rules in monitor-only mode first. Blocking on day one produces a workaround within a week, and the workaround is always a channel you are not watching: a personal webmail account, a phone camera, a USB drive bought at lunchtime.

The channels A.8.12 expects you to cover

ISO/IEC 27002’s guidance ranges wider than most tool deployments do. It talks about restricting copy, paste and upload to external services where necessary, requiring approval from the data owner for bulk exports and holding users accountable for them, encrypting backups that contain sensitive information, and hardening gateways against espionage and intellectual property theft. It even mentions decoys and honeypots to mislead an attacker.

The most honest item in the guidance is screenshots and photography: it suggests handling those through terms of employment, awareness training and auditing. That is the standard conceding that the technical fix does not exist — and it maps your control straight back to contracts and security awareness training.

ChannelHow data leavesTypical measureEvidence
EmailAttachment or body to an external addressGateway content rules, quarantine, encryption for approved routesRule export, quarantine log, release approvals
Web and cloud storageUpload to personal or unsanctioned accountsTenant restrictions, upload inspection, allow-list of sanctioned servicesPolicy configuration, sanctioned service register
Removable mediaCopy to USB or external driveDefault deny with documented exceptions, encryption where allowedEndpoint policy, exception register (links to A.7.10)
Endpoint interactionCopy and paste, screenshots, printingClipboard and print rules where feasible; contract and training terms where notConfiguration plus signed acceptable use terms
Bulk exportReport or database extractData owner approval, named accountability, export loggingApproval records, export logs
Non-production copiesProduction data loaded into test or analyticsMasking (A.8.11), test data control (A.8.33)Masking job records, test data inventory
BackupsUnencrypted media or third-party copyEncryption of backups holding sensitive dataBackup configuration, key management records

Where your own encryption works against your DLP

Content inspection needs to read the content. End-to-end encrypted messaging, password-protected archives and TLS sessions you do not terminate are all invisible to a DLP engine, and ISO/IEC 27002’s guidance for A.8.24 flags exactly this — the impact of encryption on controls that rely on inspecting content.

There is no clean answer here. You decide which traffic is inspected and which is accepted as opaque, and you record the decision as a risk, not as an oversight. Our guide to the ISO 27001 cryptography policy covers the A.8.24 side of the same trade-off. A policy that mandates encryption everywhere while the SoA claims full DLP coverage is a contradiction an experienced auditor will find in minutes.

A.8.10 and A.8.11: the controls that fail alongside A.8.12

These three controls arrived together in 2022 and they work as a set with ISO 27001 data leakage prevention. Data you deleted cannot leak. Data that is masked leaks harmlessly. Both are cheaper than detection.

ControlWhat it asks forHow it reduces leakage riskEvidence that satisfies an auditor
A.8.10 Information deletionDelete information in systems, devices and media when it is no longer required, using methods appropriate to your legal and business requirementsShrinks the amount of sensitive data in reach of any channelRetention schedule, deletion method per data store, and records of deletion results — the guidance asks you to keep them as evidence
A.8.11 Data maskingMask, pseudonymise or anonymise data in line with your access control policy and applicable lawRemoves the reason production data ever reaches test, development or analyticsMasking configuration, a sample before-and-after record, confirmation that non-production holds no unmasked copies

Deletion in cloud services deserves its own line in the register. You need the provider’s documented deletion method and timescale, because “deleted” in a tenant console and erased from the provider’s backups are not the same event.

ISO 27001 data leakage prevention evidence your auditor will ask for

  • The Statement of Applicability line for A.8.12, with the justification for inclusion and the implementation status
  • Whichever document carries the rules — a standalone policy, or the relevant section of your acceptable use and information transfer policies
  • The classification scheme in force, and the mapping from labels to detection rules
  • The dated legal and HR review, the monitoring notice issued to personnel, acknowledgements, and a DPIA where one applies
  • The current rule set, exported rather than described
  • Alert triage records for a recent period, showing that someone looked at them and what happened next
  • Approvals for bulk exports, and the exception register for removable media and unsanctioned services
  • An effectiveness review — false positive rate, tuning changes, incidents detected
  • Deletion records for A.8.10 and masking evidence for A.8.11

The two items that fail most often in an ISO 27001 data leakage prevention review are alert triage and the effectiveness record. Producing alerts is easy; proving somebody acts on them is the same weakness that sinks ISO 27001 logging under A.8.15, where the verb that gets missed is “analyse”.

Can you exclude A.8.12 from the Statement of Applicability?

You can. Clause 6.1.3 requires the Statement of Applicability to record which Annex A controls are necessary, which are excluded, and the justification either way — so exclusion is a legitimate outcome, not a failure. It just has to survive questioning.

Excluding ISO 27001 data leakage prevention stands up only if nothing in scope holds information whose disclosure would matter, which is rare for any scope that handles customer or personnel data. What works far more often is a documented partial implementation: full measures on the channels your risk assessment prioritises, and non-technical measures with a stated rationale where no proportionate technical control exists. Write that in the Statement of Applicability rather than claiming coverage you do not have.

Worth knowing: a DLP policy is not on the list of documents ISO 27001 explicitly requires. The obligation is the control and the evidence, not a particular document title. The full set of Annex A controls and how they fit together is covered in our guide to the ISO 27001:2022 controls.

Five ISO 27001 data leakage prevention mistakes that cost findings

  1. Buying the tool before classifying the data. The rules have nothing to key on, the pilot never exits tuning, and the audit finds a licence instead of a control.
  2. Blocking from day one. People route around it, and the route they choose is the channel you are not monitoring.
  3. No lawful basis and no notice. The control itself becomes the privacy problem, and in several US states an unnotified deployment is a statutory violation before it is an audit issue.
  4. Alerts nobody triages. Detection without a named owner and a response record is not an implemented control.
  5. Treating email as the whole scope. USB, print, cloud sync, personal webmail and non-production copies are all in scope under “systems, networks and any other devices”.

ISO 27001 data leakage prevention FAQ

Is a DLP tool mandatory for ISO 27001 certification?

No. ISO 27001 data leakage prevention requires measures proportionate to your risk assessment, and the standard names no product. A small organisation can satisfy it with tenant-level sharing restrictions, removable media policy enforced in endpoint configuration, bulk export approvals, and contractual and training measures — provided the risk assessment supports that and the evidence exists.

Do we need a separate data leakage prevention policy document?

Not necessarily. ISO 27001 data leakage prevention is not among the documents ISO 27001 explicitly mandates, and many organisations carry it inside the acceptable use and information transfer policies. A standalone document helps if your rule set is large or the legal position is complicated, because it gives the legal review and the notice obligations somewhere to live.

Does A.8.12 still apply if everything runs in SaaS?

Yes. ISO 27001 data leakage prevention reaches systems, networks and devices that process, store or transmit sensitive information, whoever operates them. In a SaaS-only estate the measures shift to tenant configuration: external sharing restrictions, allow-listed domains, download and sync policy on unmanaged devices, and the provider’s own content rules. Managed endpoints are still in scope, because that is where copies land.

How is A.8.12 different from A.8.16 monitoring activities?

ISO 27001 data leakage prevention is about information leaving by a channel; A.8.16 monitoring activities is about anomalous behaviour across networks, systems and applications. They overlap in tooling and diverge in purpose, so keep separate evidence for each. Writing one combined “we have a SIEM” answer for both is a reliable way to collect a finding against the control you did not actually address.

Can we monitor employee email to satisfy ISO 27001 data leakage prevention?

Usually, with conditions. You need a lawful basis, transparency with the people being monitored, the least intrusive means that achieves the purpose, and a DPIA where the monitoring is high risk. The ICO’s position is that workers must be informed except in genuinely exceptional covert cases, and several US states require notice before monitoring begins. Our guide to using legitimate interests for employee monitoring walks through the balancing test.

How long does implementing A.8.12 take?

As a typical range for ISO 27001 data leakage prevention in a mid-sized organisation that already has a working classification scheme: two to four weeks to write the policy, run the legal and HR review and issue notice; four to eight weeks of monitor-only operation to tune rules before anything blocks; then an effectiveness review at the first internal audit. Starting without a classification scheme adds roughly a month at the front.

Documenting it without starting from a blank page

The documentation load for ISO 27001 data leakage prevention is heavier than the control’s length suggests: a policy or policy section, a classification scheme the rules can key on, a monitoring notice, a legal review record, an exception register, and the deletion and masking records that come with A.8.10 and A.8.11. Writing all of that from nothing is where most implementations lose a month.

The ISO 27001 Toolkit ships 165 editable templates covering all 93 Annex A controls and the clause 4 to 10 management system requirements, including the ISO 27001 data leakage prevention, information transfer, acceptable use, classification and retention policies this control depends on, for $99. You keep the judgement calls; it removes the blank page.

The A.8.12 control text itself is in ISO/IEC 27001:2022 (edition 3, October 2022), with the free climate action amendment published separately in 2024. The implementation guidance behind A.8.12, including the legal note, is in ISO/IEC 27002:2022.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.