ISO 27001 data leakage prevention is Annex A control 8.12, and it is one of the very few controls in the standard whose own guidance tells you to speak to a lawyer before you speak to a vendor. Most teams read the control title, go shopping for a DLP product, and present the dashboard at the audit. The auditor is looking for something else: proof that you worked out what needs protecting, which channels it leaves by, and whether the monitoring you switched on is lawful where your people actually work.
A.8.12 is also one of the eleven controls that did not exist in ISO/IEC 27001:2013, so if you transitioned rather than certified fresh, there is probably nothing behind it at all. This guide covers what the control requires, the legal check that comes first, the two neighbouring controls that fail alongside it, and the evidence a certification auditor will actually ask to see.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
What ISO 27001 data leakage prevention requires under A.8.12
The control is short. It asks you to apply data leakage prevention measures to systems, networks and any other devices that process, store or transmit sensitive information. Its stated purpose is to detect and prevent the unauthorised disclosure and extraction of information, by people or by systems.
Read it carefully and ISO 27001 data leakage prevention resolves into three obligations, in order:
| Obligation | What it means in practice | What the auditor looks at |
|---|---|---|
| Identify sensitive information | Know which data types matter and where they live. The standard does not define “sensitive” — your classification scheme does. | Classification scheme, data inventory, mapping of classified data to systems |
| Monitor the channels it can leave by | Email, web uploads, cloud sync, removable media, file transfer, print, mobile devices, developer copies | Channel list with a decision against each one, and the configuration backing it |
| Act to prevent leakage | Block, quarantine, alert, strip, or require authorisation — whatever the risk assessment supports | Rule set, alert triage records, exception approvals |
The words “any other devices” do a lot of work in A.8.12. They pull in laptops, phones, USB drives, multifunction printers and anything else that can hold a copy. A control scoped to the email gateway alone is an easy finding.
Note what the control does not say. It never names a product category, never requires an agent on every endpoint, and never sets a detection rate. ISO 27001 data leakage prevention is a set of measures proportionate to your risk assessment, not a licence you buy.
Free ISO 27001 risk assessment
Which of your risks sit above your appetite line?
Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free risk assessment → or View premium report sample
Why ISO 27001 data leakage prevention has no 2013 ancestor
ISO 27001 data leakage prevention is genuinely new. The 2022 edition restructured Annex A into 93 controls across four themes — 37 organizational, 8 people, 14 physical and 34 technological — and added eleven controls with no predecessor. Three of those eleven are about data rather than systems:
| Control | Title | Status in 2022 | Question it answers |
|---|---|---|---|
| A.8.10 | Information deletion | New | Is the data still here when it no longer needs to be? |
| A.8.11 | Data masking | New | Is real data exposed where fake data would do? |
| A.8.12 | Data leakage prevention | New | Can the data leave, and would you know? |
The 2013 edition did govern the channels. A.13.2.1 (information transfer policies and procedures), A.13.2.2 (agreements on information transfer) and A.13.2.3 (electronic messaging) all map forward to A.5.14 Information transfer, and the removable media controls A.8.3.1 to A.8.3.3 map to A.7.10 Storage media. What 2013 never asked was the harder question: which data, specifically, must not leave by those channels.
That gap shows up in most transitioned management systems. There is a mature information transfer policy from 2015 with a version history, and nothing at all underneath A.8.12 except a tick in the Statement of Applicability. If your transition was a mapping exercise, this is one of the controls to check first.
The legal check that comes before the tool
ISO/IEC 27002:2022’s guidance for 8.12 ends with a note most implementation blogs skip entirely: these tools work by monitoring personnel communications and online activity, which raises legal questions that need settling before deployment. It specifically points at privacy and data protection law, employment law, and law on the interception of telecommunications.
That makes ISO 27001 data leakage prevention unusual among the technical controls. For almost every other technical control, you implement and then evidence it. Here, switching the control on without a lawful basis and proper notice can itself create a nonconformity — or a regulator’s letter.
| Jurisdiction | What it requires | Where it bites DLP |
|---|---|---|
| New York (private employers with a place of business in the state) | Civil Rights Law § 52-c, added by S.2628 (signed 8 November 2021, effective 7 May 2022): written or electronic notice of monitoring of phone, email and internet use on hiring, with employee acknowledgement, plus a notice posted conspicuously. Enforced by the Attorney General, up to $500 for a first offence, $1,000 for a second and $3,000 thereafter. | The exception covers processes performed solely for system maintenance or protection that do not target a particular individual. Content-inspecting rules that raise per-user alerts sit well outside that, so get advice rather than assuming the carve-out applies. |
| Connecticut | Gen. Stat. § 31-48d: prior written notice to affected employees of the types of electronic monitoring; a conspicuous posting satisfies it. Civil penalties rise to $3,000 for repeat violations. | Notice is by monitoring type, so adding endpoint or screen monitoring later can outrun the notice you posted. |
| Delaware | 19 Del. C. § 705: either a daily electronic notice when the employee accesses monitored systems — a login banner serves — or a one-time written notice with documented acknowledgement. | The login-banner route is usually the cheapest control to implement and the easiest to evidence at audit. |
| United Kingdom | The ICO’s guidance Employment practices and data protection: monitoring workers (3 October 2023, replacing the 2011 Employment Practices Code) expects a lawful basis, the least intrusive means that achieves the purpose, and workers to be informed. It treats keystroke monitoring as high risk and recommends a DPIA whether or not one is strictly required. | A DPIA on the DLP deployment is the document that proves proportionality. Covert monitoring is only justifiable exceptionally and should be authorised by senior management. |
| EU member states | A GDPR lawful basis under Article 6 and, for high-risk monitoring, a DPIA under Article 35. In several states, employee representative bodies have consultation or co-determination rights over technology that monitors behaviour. | Works council timelines, not tooling, set your go-live date. Check locally before you commit to one. |
The practical consequence is that your ISO 27001 data leakage prevention evidence pack starts with a dated record of a legal and HR review, the notice text actually issued, the acknowledgements, and a DPIA where one applies. None of that comes from the vendor.
ISO 27001 data leakage prevention depends on classification
Every ISO 27001 data leakage prevention rule is written in the language of data types: card numbers, national identifiers, source code, pricing models, product designs, patient records. If your classification scheme is a three-line policy nobody applies, the rules have nothing to match on and the deployment stalls in tuning forever.
This is why A.8.12 is the control that quietly tests whether A.5.12 (classification of information) and A.5.13 (labelling of information) are real. Our guide to data classification covers building the scheme itself; the point for A.8.12 is that the scheme must be specific enough to turn into a detection rule.
| Label | Example content | Detection approach | Typical action |
|---|---|---|---|
| Restricted | Card data, national ID numbers, credentials, health records | Pattern plus validation (checksum, proximity keywords) | Block and alert; narrow approved route only |
| Confidential | Customer contracts, pricing models, source code, designs | Fingerprinting, document labels, repository origin | Warn the user, log, require justification |
| Internal | Routine operational documents | Label-based only | Monitor, no interruption |
| Public | Published material | Out of scope | No rule |
Run new ISO 27001 data leakage prevention rules in monitor-only mode first. Blocking on day one produces a workaround within a week, and the workaround is always a channel you are not watching: a personal webmail account, a phone camera, a USB drive bought at lunchtime.
The channels A.8.12 expects you to cover
ISO/IEC 27002’s guidance ranges wider than most tool deployments do. It talks about restricting copy, paste and upload to external services where necessary, requiring approval from the data owner for bulk exports and holding users accountable for them, encrypting backups that contain sensitive information, and hardening gateways against espionage and intellectual property theft. It even mentions decoys and honeypots to mislead an attacker.
The most honest item in the guidance is screenshots and photography: it suggests handling those through terms of employment, awareness training and auditing. That is the standard conceding that the technical fix does not exist — and it maps your control straight back to contracts and security awareness training.
| Channel | How data leaves | Typical measure | Evidence |
|---|---|---|---|
| Attachment or body to an external address | Gateway content rules, quarantine, encryption for approved routes | Rule export, quarantine log, release approvals | |
| Web and cloud storage | Upload to personal or unsanctioned accounts | Tenant restrictions, upload inspection, allow-list of sanctioned services | Policy configuration, sanctioned service register |
| Removable media | Copy to USB or external drive | Default deny with documented exceptions, encryption where allowed | Endpoint policy, exception register (links to A.7.10) |
| Endpoint interaction | Copy and paste, screenshots, printing | Clipboard and print rules where feasible; contract and training terms where not | Configuration plus signed acceptable use terms |
| Bulk export | Report or database extract | Data owner approval, named accountability, export logging | Approval records, export logs |
| Non-production copies | Production data loaded into test or analytics | Masking (A.8.11), test data control (A.8.33) | Masking job records, test data inventory |
| Backups | Unencrypted media or third-party copy | Encryption of backups holding sensitive data | Backup configuration, key management records |
Where your own encryption works against your DLP
Content inspection needs to read the content. End-to-end encrypted messaging, password-protected archives and TLS sessions you do not terminate are all invisible to a DLP engine, and ISO/IEC 27002’s guidance for A.8.24 flags exactly this — the impact of encryption on controls that rely on inspecting content.
There is no clean answer here. You decide which traffic is inspected and which is accepted as opaque, and you record the decision as a risk, not as an oversight. Our guide to the ISO 27001 cryptography policy covers the A.8.24 side of the same trade-off. A policy that mandates encryption everywhere while the SoA claims full DLP coverage is a contradiction an experienced auditor will find in minutes.
A.8.10 and A.8.11: the controls that fail alongside A.8.12
These three controls arrived together in 2022 and they work as a set with ISO 27001 data leakage prevention. Data you deleted cannot leak. Data that is masked leaks harmlessly. Both are cheaper than detection.
| Control | What it asks for | How it reduces leakage risk | Evidence that satisfies an auditor |
|---|---|---|---|
| A.8.10 Information deletion | Delete information in systems, devices and media when it is no longer required, using methods appropriate to your legal and business requirements | Shrinks the amount of sensitive data in reach of any channel | Retention schedule, deletion method per data store, and records of deletion results — the guidance asks you to keep them as evidence |
| A.8.11 Data masking | Mask, pseudonymise or anonymise data in line with your access control policy and applicable law | Removes the reason production data ever reaches test, development or analytics | Masking configuration, a sample before-and-after record, confirmation that non-production holds no unmasked copies |
Deletion in cloud services deserves its own line in the register. You need the provider’s documented deletion method and timescale, because “deleted” in a tenant console and erased from the provider’s backups are not the same event.
ISO 27001 data leakage prevention evidence your auditor will ask for
- The Statement of Applicability line for A.8.12, with the justification for inclusion and the implementation status
- Whichever document carries the rules — a standalone policy, or the relevant section of your acceptable use and information transfer policies
- The classification scheme in force, and the mapping from labels to detection rules
- The dated legal and HR review, the monitoring notice issued to personnel, acknowledgements, and a DPIA where one applies
- The current rule set, exported rather than described
- Alert triage records for a recent period, showing that someone looked at them and what happened next
- Approvals for bulk exports, and the exception register for removable media and unsanctioned services
- An effectiveness review — false positive rate, tuning changes, incidents detected
- Deletion records for A.8.10 and masking evidence for A.8.11
The two items that fail most often in an ISO 27001 data leakage prevention review are alert triage and the effectiveness record. Producing alerts is easy; proving somebody acts on them is the same weakness that sinks ISO 27001 logging under A.8.15, where the verb that gets missed is “analyse”.
Can you exclude A.8.12 from the Statement of Applicability?
You can. Clause 6.1.3 requires the Statement of Applicability to record which Annex A controls are necessary, which are excluded, and the justification either way — so exclusion is a legitimate outcome, not a failure. It just has to survive questioning.
Excluding ISO 27001 data leakage prevention stands up only if nothing in scope holds information whose disclosure would matter, which is rare for any scope that handles customer or personnel data. What works far more often is a documented partial implementation: full measures on the channels your risk assessment prioritises, and non-technical measures with a stated rationale where no proportionate technical control exists. Write that in the Statement of Applicability rather than claiming coverage you do not have.
Worth knowing: a DLP policy is not on the list of documents ISO 27001 explicitly requires. The obligation is the control and the evidence, not a particular document title. The full set of Annex A controls and how they fit together is covered in our guide to the ISO 27001:2022 controls.
Five ISO 27001 data leakage prevention mistakes that cost findings
- Buying the tool before classifying the data. The rules have nothing to key on, the pilot never exits tuning, and the audit finds a licence instead of a control.
- Blocking from day one. People route around it, and the route they choose is the channel you are not monitoring.
- No lawful basis and no notice. The control itself becomes the privacy problem, and in several US states an unnotified deployment is a statutory violation before it is an audit issue.
- Alerts nobody triages. Detection without a named owner and a response record is not an implemented control.
- Treating email as the whole scope. USB, print, cloud sync, personal webmail and non-production copies are all in scope under “systems, networks and any other devices”.
ISO 27001 data leakage prevention FAQ
Is a DLP tool mandatory for ISO 27001 certification?
No. ISO 27001 data leakage prevention requires measures proportionate to your risk assessment, and the standard names no product. A small organisation can satisfy it with tenant-level sharing restrictions, removable media policy enforced in endpoint configuration, bulk export approvals, and contractual and training measures — provided the risk assessment supports that and the evidence exists.
Do we need a separate data leakage prevention policy document?
Not necessarily. ISO 27001 data leakage prevention is not among the documents ISO 27001 explicitly mandates, and many organisations carry it inside the acceptable use and information transfer policies. A standalone document helps if your rule set is large or the legal position is complicated, because it gives the legal review and the notice obligations somewhere to live.
Does A.8.12 still apply if everything runs in SaaS?
Yes. ISO 27001 data leakage prevention reaches systems, networks and devices that process, store or transmit sensitive information, whoever operates them. In a SaaS-only estate the measures shift to tenant configuration: external sharing restrictions, allow-listed domains, download and sync policy on unmanaged devices, and the provider’s own content rules. Managed endpoints are still in scope, because that is where copies land.
How is A.8.12 different from A.8.16 monitoring activities?
ISO 27001 data leakage prevention is about information leaving by a channel; A.8.16 monitoring activities is about anomalous behaviour across networks, systems and applications. They overlap in tooling and diverge in purpose, so keep separate evidence for each. Writing one combined “we have a SIEM” answer for both is a reliable way to collect a finding against the control you did not actually address.
Can we monitor employee email to satisfy ISO 27001 data leakage prevention?
Usually, with conditions. You need a lawful basis, transparency with the people being monitored, the least intrusive means that achieves the purpose, and a DPIA where the monitoring is high risk. The ICO’s position is that workers must be informed except in genuinely exceptional covert cases, and several US states require notice before monitoring begins. Our guide to using legitimate interests for employee monitoring walks through the balancing test.
How long does implementing A.8.12 take?
As a typical range for ISO 27001 data leakage prevention in a mid-sized organisation that already has a working classification scheme: two to four weeks to write the policy, run the legal and HR review and issue notice; four to eight weeks of monitor-only operation to tune rules before anything blocks; then an effectiveness review at the first internal audit. Starting without a classification scheme adds roughly a month at the front.
Documenting it without starting from a blank page
The documentation load for ISO 27001 data leakage prevention is heavier than the control’s length suggests: a policy or policy section, a classification scheme the rules can key on, a monitoring notice, a legal review record, an exception register, and the deletion and masking records that come with A.8.10 and A.8.11. Writing all of that from nothing is where most implementations lose a month.
The ISO 27001 Toolkit ships 165 editable templates covering all 93 Annex A controls and the clause 4 to 10 management system requirements, including the ISO 27001 data leakage prevention, information transfer, acceptable use, classification and retention policies this control depends on, for $99. You keep the judgement calls; it removes the blank page.
The A.8.12 control text itself is in ISO/IEC 27001:2022 (edition 3, October 2022), with the free climate action amendment published separately in 2024. The implementation guidance behind A.8.12, including the legal note, is in ISO/IEC 27002:2022.