GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-017 Data Leakage Prevention

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Controls are in place to detect and prevent unauthorised exfiltration of sensitive and personal data from systems, networks and applications. This includes monitoring for anomalous bulk data access or export, egress filtering at network boundaries, and restrictions on unapproved data transfer mechanisms.

Rationale

Environments holding large volumes of customer data are high-value exfiltration targets. DLP controls reduce both insider and external threat impact.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (14)

DSP-17Sensitive Data Protectionpartial
DSP-17Sensitive Data Protectionpartial
GDPR-Art.32.1Technical and Organisational Security Measurespartial
GDPR-Art.5.1fIntegrity and Confidentiality (Security Principle)informative
8.12Data leakage preventionfull
NIS2-CIR-Art.3Significant Incident Criteria for the Relevant Entitiesinformative
AC-23Data Mining Protectionpartial
AU-13Monitoring for Information Disclosurepartial
PM-17Protecting Controlled Unclassified Information on External Systemsinformative
SI-20Taintingpartial
SI-4(18)System Monitoring | Analyze Traffic and Covert Exfiltrationpartial
MP-4.1-001AI Technology and Legal Risk Mapping | MP-4.1-001informative
MP-4.1-009AI Technology and Legal Risk Mapping | MP-4.1-009informative
LLM02Sensitive Information Disclosureinformative

Evidence (2)

tool_outputtechnicalautomated

DLP tool scan results or alert reports demonstrating that sensitive data egress is monitored and anomalous bulk data transfers are detected.

Example: DLP policy report from Microsoft Purview DLP, Nightfall AI, or equivalent, showing active policies covering email, cloud storage and API egress for Confidential and Restricted data, alert counts for the last 90 days, and any escalated incidents with disposition

Test: Request the DLP tool configuration and recent alert report. Verify: (1) DLP policies are active on all primary data egress channels (email, cloud storage, API exports, messaging), (2) policies cover at minimum: bulk PII exports, unencrypted sensitive data, and data matching Restricted classification, (3) alert workflow routes to a responsible reviewer, (4) no sustained high-volume alerts are unresolved.

configurationtechnicalautomated

Network egress filtering or cloud security group configuration showing that unapproved outbound data transfer channels are restricted at the network layer.

Example: AWS Security Group or VPC Network ACL export, or cloud firewall policy, showing outbound traffic restricted to approved destinations (internal services, approved SaaS), with all other egress blocked by default in production VPC

Test: Review the production network egress configuration. Verify: (1) outbound traffic is restricted by default and requires explicit allow rules, (2) allow-listed destinations are documented and reviewed, (3) bulk file transfer protocols (FTP, SMB) to external destinations are blocked unless explicitly approved, (4) configuration changes are logged.

Questions (2)

boolean

Does your organisation have technical controls to detect and prevent unauthorised exfiltration of sensitive and personal data?

DLP controls should monitor all major egress channels (email, cloud storage, API exports, messaging). Network egress should be restricted by default. Alerts should route to a responsible reviewer.

multi

Which data leakage prevention controls are active in your environment?

DLP tooling monitoring email and collaboration platforms for sensitive dataDLP policies covering API exports and bulk data downloads from the applicationNetwork egress filtering restricting outbound traffic to approved destinationsAnomaly detection alerts for bulk data access or unusual export volumesCloud access security broker (CASB) monitoring for unsanctioned data transfersNone of the above

A layered approach combining application-level DLP, network egress controls and anomaly detection provides the strongest coverage. At minimum, DLP should cover email and bulk export channels for Confidential and Restricted data.