Data loss prevention (DLP) is software that spots sensitive information, such as bank details or passport numbers, in emails, files and uploads, then warns, blocks or logs before it leaves the business. You need it once staff routinely handle client personal or financial data. Microsoft 365 Business Premium includes it; Business Standard doesn't.
DLP is good at a narrow job and weak outside it. It recognises structured data very reliably: card numbers, account numbers, passport and ID formats. It struggles with confidential material that has no fixed pattern, such as a tender price buried in a paragraph or a client's divorce mentioned in an email, unless files are labelled. And it only watches the channels it's switched on for, so Microsoft's email and file DLP won't see a member of staff pasting client text into a free AI app in a personal browser. For a small firm, DLP is one layer beside rules and habits, not a replacement for them.
How a DLP rule works, from detector to action
Every DLP system does the same three things. It looks for a pattern, checks the circumstances, and takes an action.
- Detectors recognise types of sensitive information. Both Microsoft and Google ship dozens of predefined ones (Google's Data Protection Insights reports use 48-50), covering things like card numbers and passport numbers, and you can add your own, such as your client reference format.
- Conditions narrow when a rule fires: sent to someone outside the business, more than a set number of matches, a file with a particular label.
- Actions decide what happens. Google's Gmail DLP, for example, can block a message, warn the user and let them continue, quarantine it for an admin to review, simply log it ("audit only"), apply a classification label, or add a custom note.
A realistic first rule, written out in plain words:
RULE: Card and bank details leaving by email
Detect: credit card numbers OR bank account numbers
Condition: recipient is outside the organisation
AND 3 or more matches in one message or attachment
Action: block, show the sender a tip explaining why,
allow override with a written business reason
Report to: [first name], weekly summary
Microsoft's version of the "allow override" choice lets the sender override with a business justification or report a false positive, which is what keeps a strict rule from grinding normal work to a halt. The weekly summary is where you learn whether the rule is catching real problems or just annoying people.
Which plans include DLP in September 2026
| Plan (list price, per user a month) | DLP included? | What you actually get |
|---|---|---|
| Microsoft 365 Business Basic ($7) or Business Standard ($14) | No | No Purview DLP without an add-on |
| Microsoft 365 Business Premium ($22) | Yes | Purview DLP for email, SharePoint and OneDrive (including Teams files), plus sensitivity labels, message encryption and Compliance Manager |
| Purview Suite for Business Premium (add-on, $10, paid yearly) | Extends it | DLP across apps, devices and cloud services, insider risk tools, and policy controls for AI experiences and Copilot |
| Google Workspace Business Starter, Standard or Plus (about $7, $14, $22) | Reports only | Data Protection Insights reports: they find sensitive content shared externally but don't block anything |
| Google Workspace Enterprise Standard or Plus (price on quote) | Yes | DLP rules for Gmail and Drive that can block, warn, quarantine or audit |
Two things stand out. On Microsoft, the jump from Business Standard to Business Premium is $8 a user a month, and DLP is only one of the things it buys; for most small firms the device management and security in Premium matter as much. Business Premium versus Standard for AI security weighs the whole package. On Google, active DLP rules need an Enterprise edition, which is a much bigger step for a small firm, so Business customers should start with the free reports and tighter sharing settings.
Four tests for whether your business needs DLP yet
- What sensitive data do you hold, and in what shape? ID documents, bank details, payroll records and health information are exactly what DLP detects well. If your sensitive material is mostly drawings, prices and ideas, DLP helps less and labels help more.
- How many people can send it outside? Two partners who handle everything themselves carry less accidental-leak risk than eight staff emailing clients all day.
- Who's asking? Clients' security questionnaires, cyber insurers' proposal forms and contracts increasingly ask how you stop data leaving. A "yes, with DLP rules and a weekly review" is a stronger answer than "we trust our staff".
- How much do staff use AI tools? The more people paste into AI tools, the more a browser-level control is worth, though that needs more than Business Premium's email and file DLP.
Run four of the example businesses through those tests and the answers differ:
| Business | Sensitive data | Verdict |
|---|---|---|
| Eight-person accountancy practice | Client ID documents, bank details, payroll, tax references | Yes. This is DLP's home ground |
| Nine-person architect practice | Drawings, fee proposals, some homeowner details | Partly. Labels on confidential projects matter more than pattern detection |
| Four-person surveying firm on Google Workspace | Property addresses, some client ID for instructions | Start with the free reports and sharing settings; revisit in a year |
| Two-person kitchen fitter | Customer names, addresses, deposits paid by bank transfer | Not yet. A written rule and two-step sign-in do more for the money |
Switching DLP on at an eight-person accountancy practice
Here's the main worked example. The practice runs Microsoft 365 Business Standard and handles passports, bank statements and payroll for about 300 clients. Its cyber insurer's proposal form has started asking how it prevents data leaving by email.
The cost. Moving eight users from Business Standard ($14) to Business Premium ($22) adds $8 a user, so $64 a month or $768 a year at list price on annual billing.
Week 1: build three rules and run them in simulation mode (about 2 hours). Purview's simulation mode runs a policy as if it were enforced, logging every match without blocking anything. The three rules: card or bank details sent outside the practice; passport or ID numbers sent outside; and anything with the practice's own client reference format sent to a personal email domain.
Weeks 1-2: read the results (30 minutes a week). Illustrative results after two weeks:
- 41 matches in total.
- 26 were legitimate: bank details sent to the bank itself, payroll reports sent to clients through the agreed route.
- 9 were false positives. The practice's invoice numbers happened to pass the check that card-number detectors use, so invoices were being flagged. The fix: raise the threshold and exclude the invoice template.
- 6 were genuine concerns: 4 passport scans sent to clients' personal addresses at the client's request, and 2 staff forwarding client files to their own personal email to work at home.
Week 3: enforce with overrides (1 hour). The ID rule blocks with an override that needs a written reason; the personal-email rule blocks outright; the bank-details rule warns. The managing partner explains the change at a team meeting before it goes live, including what the practice can see and why.
What it bought. The two forwarding cases were the finding that mattered: a habit nobody knew about, now stopped, with a better way offered (secure access from home). For $768 a year the practice also gets a factual answer for its insurer and its clients' security questionnaires. What cyber insurers ask about AI and data shows how that answer is used.
Google Workspace firms: getting value without Enterprise
On Business Starter, Standard or Plus you can't write blocking rules, but you can see the problem. Google's Data Protection Insights reports scan Drive and Gmail with its predefined detectors and show how much sensitive content is shared or sent outside the business. They're set up in the Admin console under Security, then Access and data control, then Data protection, in the "Data insights scanning and report" settings; Google says Drive reports default to on.
At an illustrative four-person surveying firm, the first report showed 212 Drive files containing sensitive content, 31 of them shared outside the business, mostly through "anyone with the link" sharing on old instruction folders from finished jobs. No DLP rule was needed to fix that: the owner changed the default sharing setting so new files are shared only with named people, spent an hour removing link sharing from old job folders, and set a reminder to recheck the report monthly. Google notes the reports can contain false positives, so treat the numbers as a map of where to look, not an audit result.
Sensitivity labels for material that has no pattern
Pattern detection can't tell a confidential fee proposal from a brochure. Sensitivity labels can, because a person who knows the content applies them. Business Premium includes labels in Word, Excel, PowerPoint and Outlook, and Microsoft's setup guide gives examples such as Normal, Personal, Private and Confidential; you can create your own. A label can then become the condition in a DLP rule, so "block external sharing of anything labelled Confidential" works even when the file contains nothing a detector would recognise.
Take the nine-person architect practice from the verdict table. Its risk isn't card numbers; it's a competition entry or a high-profile client's floor plans reaching the wrong inbox. A workable setup:
- Two labels only, "Internal" and "Client confidential", because a long list means nobody picks the right one.
- Project leads label the folders and key files for any project under an NDA when it starts, which takes minutes per project.
- One DLP rule: files labelled "Client confidential" can't be shared outside the practice except with the client's named contacts, and anything else needs an override with a written reason.
One limit to know: on Business Premium, staff apply labels themselves. Microsoft lists automated classification and labelling among the extras in the Purview Suite add-on, so a small practice relying on Premium alone needs labelling to be part of project set-up, not an afterthought. The payoff can come later too: Microsoft's policy controls for Copilot and other AI experiences, sold in that same add-on, build on the classification you've already done, so labelling a project once isn't wasted if you extend your controls to AI.
Where DLP meets AI tools
This is where DLP has changed most. Microsoft's documentation for Edge for Business describes inline browser DLP that can block sharing sensitive information with unmanaged cloud apps, "including generative AI tools like ChatGPT, DeepSeek, and Gemini". Its own example is a finance employee trying to paste bank account numbers into ChatGPT and Edge blocking it. For small businesses, that kind of device and browser control generally sits beyond Business Premium's email and file DLP, in the Purview Suite add-on or higher licences, so confirm the licensing with Microsoft or your reseller before planning around it.
An illustrative engineering consultancy shows why it matters. Staff paste specification extracts into AI tools to summarise them. Email DLP never sees that; the text goes from a document to a browser tab. The consultancy's options, cheapest first:
- Give staff an approved business AI plan that doesn't train on content, so there's a sanctioned place to paste.
- Write a one-page rule on what may and may not be pasted anywhere.
- Block unapproved AI sites on work devices.
- Add browser or endpoint DLP to catch sensitive patterns going into any AI site, once the first three are in place.
The order matters. Blocking without an approved alternative just moves the pasting to personal phones, where no DLP reaches. Stopping staff pasting client data into free tools covers the first three steps in detail.
What DLP won't do, whatever the sales page says
- It won't understand context. A tender price, a planning strategy or a client's health mentioned in passing has no pattern to detect. Sensitivity labels on those files, applied by the people who know what's in them, do that job; classifying business data before using AI tools gives a simple way to decide what gets which label.
- It won't stop a phone camera. Anyone can photograph a screen. DLP reduces accidents and casual leaks; it doesn't stop a determined insider.
- It won't run itself. Rules need tuning, alerts need a named person to read them, and exceptions need decisions. Budget 30 minutes a week for the first month and 30 minutes a month after that.
- It isn't backup. The name misleads: DLP stops information leaving, not files being lost. Deletion, ransomware and hardware failure are backup problems, covered in the business data backup checklist.
One realistic failure shows the tuning point. A practice switches a strict rule straight to "block" with no override, on a Monday in the busy season. By Tuesday, staff can't send payroll reports to clients, three partners have complained, and someone has switched the policy off entirely. Two weeks in simulation mode, then a block with an override and a written reason, would have got to the same protection without the revolt.
A one-page DLP starter plan, filled in
If the tests say yes, write the plan down before switching anything on. Here's a version for the accountancy practice above:
DLP STARTER PLAN: [practice name] Owner: [first name]
Platform: Microsoft 365 Business Premium (Purview DLP)
Rules: 1. Card/bank details to outside recipients: WARN
2. Passport/ID numbers to outside recipients: BLOCK,
override with written business reason
3. Client reference format to personal email domains:
BLOCK, no override
Rollout: 2 weeks simulation mode; review matches; tune; enforce
Exclusions: invoice template (false positives on card detector)
Alerts: weekly summary to [first name]; 30 minutes each Monday
Staff: told at team meeting on [date] what is checked and why;
one-page note in the staff handbook
Review: after 1 month, then every 6 months, or after any incident
After the first month, four numbers tell you whether it's working. Matches per week should fall as habits change; if they don't, the rule or the training needs another look. Override reasons should be specific ("client requested ID copy by email, confirmed by phone"), not "needed to send". False positives should be a small share of matches; if they're half of them, tune the detectors before people learn to ignore every tip. And the weekly review should take under half an hour; if it takes longer, the rules are too broad for a firm this size.
A plan like this is also what makes the answer to a client's or insurer's question credible. If the firm later adds Copilot or other AI tools with access to its files, the labels and rules it already has are the starting point for controlling what those tools can reach, which is one more reason to set them up carefully the first time.
Data loss prevention: follow-up questions
Is data loss prevention the same as backup?
No. Despite the name, DLP is about sensitive information leaving the business, by email, sharing or upload. Losing files to deletion, ransomware or a failed drive is a backup problem. A business can have excellent DLP and still lose everything if its backups aren't separate and tested, so treat the two as different jobs with different tools.
Will DLP read my staff's emails?
It scans content automatically for patterns such as card or account numbers; nobody reads messages as a routine. When a rule matches, the admin can see the matched item in reports, so be open with staff about what's switched on and why. Tell them before you start, and name who reviews alerts; data-protection law may also expect you to explain monitoring.
Can DLP stop staff pasting client data into ChatGPT?
Microsoft's browser and endpoint DLP can block sensitive information being pasted or uploaded into AI sites such as ChatGPT from managed devices, but that usually needs licensing beyond Business Premium's email and file DLP. Without it, the practical controls are a business AI plan staff are allowed to use, a written rule, and blocking unapproved AI sites on work devices.
Further reads
- How to Keep Customer Data Private When Your Team Uses AI — The wider rules for customer data when your team uses AI.
- AI Security Checklist Before Connecting Tools to Email and Files — Checks before AI tools connect to the email and files DLP watches.
- Is Gemini Safe for Confidential Business Data in Workspace? — How Gemini in Workspace handles the files DLP protects.
- Does Microsoft 365 Copilot Keep Your Business Data Private? — What Copilot does with data your DLP rules cover.
- How to Anonymise Client Data Before You Paste It Into AI — A habit that works on every plan, with or without DLP.
- How to Spot Deepfake Voice and Video Scams Aimed at Your Business — Scams that trick staff into sending the files DLP flags.
- What Is Prompt Injection and Should a Small Business Worry? — How hidden instructions in emails, web pages and CVs hijack AI assistants, a five-minute exposure check, and the controls that work without an IT team.
- Cloud AI vs On-Device AI: Which Is Safer for Business Data? — Where cloud and on-device AI each put the risk for business data, what Recall and Apple Intelligence keep local, and a per-task way to choose.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Microsoft Learn (Set up information protection capabilities in Business Premium; DLP simulation mode; DLP policy tips; DLP in Microsoft Edge for Business), Microsoft's Purview Suite for Business Premium page and Microsoft Q&A licensing answers; Google Workspace admin help (About DLP for Gmail; About DLP for Drive; DLP Data Protection Insights reports); Microsoft 365 and Google Workspace list prices as of September 2026.