Skip to content
AnalysisSH-2026-0176

DLP fails on the paste into a chat box

Classic controls watch files leaving. The current leak is text typed into a browser tab.

SeverityHigh

8 minB2B Compliance & DLP

Data loss prevention was built around documents: attachments, uploads, removable media. The channel that now matters most produces no file at all. An employee pastes a customer list, a contract clause or a fragment of source into a text field, and the control never sees a document to inspect.

Blocking the destination outright is the common first response and it fails predictably: people move to a personal device, where there is no visibility whatsoever.

What worked instead

  • Sanctioned tooling with a data processing agreement, so the useful path is also the compliant one.
  • Inline warnings at paste time rather than blocks — a prompt that names the classification and lets the person decide.
  • Classification applied at source, so the warning can be specific instead of generic.
  • Logging the decision, not the content, which keeps the audit trail without creating a second copy of the secret.
Every block we added moved the behaviour somewhere we could not see. The warning worked better than the block.
Data protection officer, insurance group

What to watch

Whether regulators treat a paste into a third-party service as a processing event requiring its own basis. Nothing has been tested yet, and the answer would reshape a lot of policy.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined