DLP fails on the paste into a chat box
Classic controls watch files leaving. The current leak is text typed into a browser tab.
SeverityHigh
8 minB2B Compliance & DLP
Data loss prevention was built around documents: attachments, uploads, removable media. The channel that now matters most produces no file at all. An employee pastes a customer list, a contract clause or a fragment of source into a text field, and the control never sees a document to inspect.
Blocking the destination outright is the common first response and it fails predictably: people move to a personal device, where there is no visibility whatsoever.
What worked instead
- Sanctioned tooling with a data processing agreement, so the useful path is also the compliant one.
- Inline warnings at paste time rather than blocks — a prompt that names the classification and lets the person decide.
- Classification applied at source, so the warning can be specific instead of generic.
- Logging the decision, not the content, which keeps the audit trail without creating a second copy of the secret.
Every block we added moved the behaviour somewhere we could not see. The warning worked better than the block.
What to watch
Whether regulators treat a paste into a third-party service as a processing event requiring its own basis. Nothing has been tested yet, and the answer would reshape a lot of policy.