What is ISO 27001 Annex A 8.12 – Data Leakage Prevention?
ISO 27001 Annex A 8.12 focuses on preventing the unauthorized disclosure, transfer, copying, or extraction of information from an organization.
Data leakage can happen intentionally or accidentally.
Examples include:
- An employee emailing a confidential customer file to a personal email address
- Uploading company documents to an unauthorized cloud-storage service
- Copying sensitive information to a USB drive
- Sharing confidential information through public links
- Uploading source code to an external AI or collaboration tool without authorization
- Sending customer PII to the wrong recipient
- Downloading large amounts of customer data
- Copying production data into an uncontrolled development environment
- Sharing screenshots containing sensitive information
- An attacker extracting information after compromising an account
Simple Explanation
Know what information must be protected, where it can go, who can send it, and how to detect or prevent unauthorized movement.
Why is Data Leakage Prevention Important?
Organizations can lose sensitive information without experiencing a traditional “hack.”
A legitimate employee account can be used to:
- Download customer records
- Copy source code
- Export financial information
- Send confidential documents
- Upload data to an external service
- Share files publicly
The account may be valid, but the information transfer may not be authorized.
Example
A support employee downloads 50,000 customer records to investigate an issue.
The employee then stores the file on a personal Google Drive.
There may have been:
- No malware
- No compromised password
- No firewall attack
- No unauthorized login
Yet sensitive information has still leaked.
Simple Principle
A valid user does not automatically have the right to move sensitive information anywhere they want.
What Does Annex A 8.12 Require?
The organization should implement appropriate measures to prevent data leakage based on:
- Information classification
- Business requirements
- Risk
- Data sensitivity
- User roles
- Access requirements
- Technology environment
- Remote working
- Cloud services
- Regulatory requirements
- Customer requirements
- Third-party relationships
The organization should consider how sensitive information can leave its controlled environment and implement appropriate preventive and detective measures.
ISO 27001 does not require every organization to deploy an enterprise DLP product.
The control should be implemented proportionately to the organization’s risks.
What is Data Leakage?
Data leakage occurs when information is exposed, transferred, copied, shared, or made available to an unauthorized person, system, location, or organization.
Examples:
| Scenario | Possible Leakage |
|---|---|
| Employee emails confidential file externally | Yes |
| Public cloud-storage link | Yes |
| Source code copied to personal repository | Yes |
| Customer data uploaded to unauthorized SaaS | Yes |
| Lost unencrypted laptop | Potential leakage |
| Sensitive screenshot posted publicly | Yes |
| Wrong email recipient | Yes |
| Unauthorized database export | Yes |
Data leakage can be:
Accidental
Example:
Employee sends the wrong customer spreadsheet to another customer.
Intentional
Example:
Employee deliberately copies confidential company information before leaving.
Malicious
Example:
Compromised account downloads thousands of customer records.
Technical
Example:
Misconfigured cloud storage exposes customer files publicly.
Data Leakage vs Data Breach
These terms are related but not identical.
Data leakage generally refers to unauthorized exposure, transfer, disclosure, or loss of information.
A data breach may be a security incident involving unauthorized access, disclosure, alteration, loss, or other compromise of protected information, depending on the applicable legal or contractual definition.
Organizations should use their applicable legal, regulatory, and contractual definitions when determining whether an incident constitutes a reportable breach.
Common Data Leakage Channels
A startup should identify how information can leave the organization.
- Personal email
- External recipients
- Wrong recipient
- Unapproved attachments
Cloud Storage
- Personal Google Drive
- Dropbox
- OneDrive
- Public links
- Unapproved file-sharing services
Messaging Platforms
- Slack
- Microsoft Teams
- Other collaboration platforms
USB and Removable Media
- USB drives
- External HDDs
- External SSDs
- Memory cards
Web Uploads
- File-sharing websites
- Personal cloud storage
- External forms
- Unapproved applications
Source Code
- Personal GitHub repositories
- Unauthorized repositories
- External development platforms
Printing
- Confidential documents
- Unattended printouts
- Unauthorized copies
Screenshots and Photography
- Customer information
- Security dashboards
- Source code
- Credentials
- Internal documents
AI Tools
Employees may accidentally paste:
- Customer information
- Source code
- Contracts
- Credentials
- Internal architecture
- Security reports
into unauthorized AI services.
Organizations should establish rules for using AI services according to their information-security and data-protection requirements.
Activities Required to Implement Annex A 8.12
1. Identify Sensitive Information
Start with information classification.
Examples:
- Customer PII
- Financial information
- Payment information
- Employee information
- Source code
- Security information
- Credentials
- Business strategy
- Contracts
- Intellectual property
This connects directly with A.5.12 – Classification of Information.
2. Identify Where Sensitive Data Exists
Create a data inventory or data-flow map.
Example:
Customer
↓
Application
↓
Production Database
↓
Backup
↓
Analytics
↓
Support
↓
Development / Testing
↓
Third Parties
For each location, ask:
How can this information leave the environment?
3. Identify Data Leakage Channels
Create a simple leakage-channel register.
| Channel | Example Risk | Control |
|---|---|---|
| External disclosure | Email security/DLP | |
| USB | Data copying | Device controls |
| Cloud storage | Public sharing | CASB/DLP/access control |
| Git repository | Source-code leakage | Repository controls |
| Browser | Unauthorized upload | Web controls |
| Printing | Physical disclosure | Printer controls |
| Messaging | Sensitive information sharing | Policy/monitoring |
| AI tools | Sensitive prompt/data upload | AI usage policy |
| Screenshots | Visual disclosure | Policy/technical controls |
4. Define Information Handling Rules
Employees should understand what they can and cannot do with sensitive information.
For example:
Confidential Customer Data
Allowed:
- Approved business applications
- Authorized employees
- Approved support processes
- Approved storage locations
Not allowed:
- Personal email
- Personal cloud storage
- Public links
- Personal USB drives
- Unauthorized applications
5. Apply Access Restrictions
Data leakage prevention starts with access control.
Users should only receive access to information required for their role.
Relevant controls include:
- A.5.15 Access Control
- A.5.18 Access Rights
- A.8.2 Privileged Access Rights
- A.8.3 Information Access Restriction
The less unnecessary information a user can access, the less information they can accidentally or intentionally leak.
6. Control External Sharing
Cloud applications make information sharing extremely easy.
Examples:
Internal File
↓
Share Button
↓
Anyone With Link
↓
Potential Data Leakage
Organizations should define appropriate rules for:
- External sharing
- Public links
- Guest users
- External collaboration
- File downloads
- File exports
- Sharing sensitive information
7. Control Removable Media
Where sensitive information can be copied to removable media, consider:
- USB restrictions
- Approved USB devices
- Encryption
- Device controls
- Authorization
- Logging
- Malware protection
- Secure disposal
This connects with A.7.10 – Storage Media.
8. Monitor High-Risk Data Transfers
Depending on risk, monitor activities such as:
- Large downloads
- Bulk exports
- External file sharing
- Uploads to unauthorized destinations
- Sensitive email attachments
- Unusual data transfers
- Source-code exports
- Database exports
Monitoring should be proportionate to risk and should also consider privacy and applicable employment/legal requirements.
9. Implement DLP Technology Where Appropriate
For organizations with higher data-leakage risks, DLP solutions can help identify and control sensitive information movement.
Potential DLP areas include:
- Endpoint DLP
- Email DLP
- Cloud DLP
- SaaS DLP
- Network DLP
- Browser controls
- USB/device controls
However:
DLP software is a tool, not the control by itself.
An effective program also requires:
- Data classification
- Policies
- Access control
- User awareness
- Monitoring
- Incident response
- Review
10. Configure Detection Rules
Example DLP rules:
| Rule | Example Action |
|---|---|
| Credit-card pattern sent externally | Alert/block |
| Large customer database export | Alert |
| Confidential document shared publicly | Alert/block |
| Source code uploaded to personal repository | Alert/block |
| Sensitive file copied to USB | Alert/block |
| PII sent to unauthorized domain | Alert |
| Bulk download from CRM | Alert |
These are examples, not mandatory ISO 27001 settings.
11. Define Response Procedures
When a possible leakage event occurs:
Detect
↓
Validate
↓
Assess Information
↓
Determine Impact
↓
Contain
↓
Investigate
↓
Collect Evidence
↓
Notify Appropriate Parties
↓
Recover
↓
Learn and Improve
Relevant controls include:
- A.5.24 Incident Management Planning and Preparation
- A.5.25 Assessment and Decision on Information Security Events
- A.5.26 Response to Information Security Incidents
- A.5.27 Learning from Information Security Incidents
- A.5.28 Collection of Evidence
Startup Example
Example: 60-Person SaaS Company
The startup stores customer information in:
- AWS
- PostgreSQL
- CRM
- Google Workspace
- Support platform
- Analytics platform
Employees also use:
- Slack
- GitHub
- Laptops
- Mobile devices
- AI tools
Risk
A developer exports customer information to investigate a production issue and uploads the file to a personal cloud-storage account.
Poor Model
Production
↓
Full Export
↓
Developer Laptop
↓
Personal Cloud
Better Model
Production
↓
Minimum Required Data
↓
Masked Data Where Appropriate
↓
Approved Development Environment
↓
Controlled Access
↓
Secure Deletion
Where technical DLP is appropriate:
Sensitive Data
↓
Attempted External Upload
↓
DLP Detection
↓
Alert / Block
↓
Security Review
Data Leakage Prevention Matrix
A startup can maintain a simple matrix:
| Information | Channel | Risk | Preventive Control | Detective Control |
|---|---|---|---|---|
| Customer PII | High | DLP/access rules | Email monitoring | |
| Source code | GitHub | High | Repository restrictions | Audit logs |
| Financial data | Cloud storage | High | Sharing restrictions | Activity monitoring |
| Employee records | USB | Medium/High | USB restrictions | Endpoint logs |
| Security reports | AI tools | High | AI usage policy | CASB/DLP where applicable |
| Customer tickets | Support platform | Medium | RBAC | Access logs |
Data Leakage Risk Assessment
| Scenario | Likelihood | Impact | Risk | Treatment |
|---|---|---|---|---|
| Customer PII emailed externally | Medium | High | High | DLP + policy |
| Source code copied to personal repo | Medium | High | High | Repository controls |
| Public cloud link | Medium | High | High | Sharing restrictions |
| USB data copying | Low/Medium | High | Medium/High | Device controls |
| Wrong email recipient | Medium | Medium | Medium | User awareness + controls |
| Unauthorized AI upload | Emerging | High | High | AI usage rules + controls |
Risk ratings should be based on the organization’s own risk methodology.
Data Leakage Prevention for Remote Workers
Remote working increases the number of locations from which information can be accessed.
Consider:
- Company-managed endpoints
- Device encryption
- Screen locking
- MFA
- Secure Wi-Fi
- VPN where appropriate
- Cloud access controls
- External sharing restrictions
- USB controls
- Secure printing
- Privacy screens where appropriate
- Employee awareness
- Lost-device reporting
This connects with A.6.7 – Remote Working and A.7.9 – Security of Assets Off-Premises.
Data Leakage Through Email
Email is one of the most common accidental leakage channels.
Example:
Employee
↓
Attaches Customer Database
↓
Wrong Recipient
↓
Email Sent
↓
Potential Data Leakage
Possible controls include:
- DLP
- External-recipient warnings
- Attachment restrictions
- Sensitive-data detection
- Encryption where appropriate
- User confirmation for external recipients
- Security awareness
Data Leakage Through Cloud Storage
Cloud collaboration creates another important risk.
Example:
Confidential File
↓
Google Drive
↓
"Anyone With Link"
↓
External Access
Appropriate controls can include:
- Restrict public links
- Restrict external sharing
- Require approved accounts
- Review guest users
- Monitor sensitive file sharing
- Apply DLP rules where appropriate
- Periodically review sharing permissions
Data Leakage Through Source Code
For technology companies, source code is a critical information asset.
Potential leakage routes include:
- Personal repositories
- Public repositories
- Unapproved SaaS tools
- Developer laptops
- USB devices
- Screenshots
- Logs
- CI/CD artifacts
This connects strongly with A.8.4 – Access to Source Code.
Data Leakage Through AI Tools
Modern organizations should specifically consider AI-assisted work.
Employees may copy:
Customer Data
Source Code
Contracts
Security Reports
Credentials
Internal Architecture
into an AI service.
Organizations should establish rules covering:
- Which AI tools are approved
- What information can be entered
- What information must not be entered
- Enterprise vs personal accounts
- Customer-data handling
- Source-code handling
- Confidential information
- Security credentials
- Review and monitoring requirements
A simple rule for employees can be:
Do not enter confidential, customer, personal, credential, or proprietary information into an AI service unless the organization has explicitly approved that use.
Data Leakage Prevention and Data Masking
A.8.11 and A.8.12 work together.
A.8.11
Mask sensitive information.
A.8.12
Prevent unauthorized leakage of information.
Example:
Production Customer Data
↓
A.8.11 – Mask Sensitive Fields
↓
Approved Test Environment
↓
A.8.12 – Prevent Unauthorized Export
Audit Evidence for Annex A 8.12
An auditor may request:
Governance
- Data Leakage Prevention Policy
- Information Security Policy
- Data Classification Policy
- Acceptable Use Policy
- Data Handling Procedure
- Remote Working Policy
- AI Usage Policy
Technical Controls
- DLP configuration
- Email DLP settings
- Endpoint DLP
- Cloud DLP
- CASB controls
- USB restrictions
- Cloud-sharing restrictions
- Browser controls
- Repository controls
Monitoring
- DLP alerts
- Security logs
- File-sharing reports
- Bulk-export alerts
- Cloud activity reports
- Endpoint events
Operational Evidence
- Data leakage incidents
- Investigation records
- Incident-response tickets
- Corrective actions
- User training
- Periodic reviews
ISO 27001 Annex A 8.12 Audit Checklist
| Question | Yes/No | Evidence |
|---|---|---|
| Is sensitive information identified? | Data inventory | |
| Is information classified? | Classification records | |
| Are data leakage risks assessed? | Risk assessment | |
| Are important leakage channels identified? | Leakage-channel register | |
| Are external sharing rules defined? | Policy | |
| Is access to sensitive information restricted? | Access matrix | |
| Are removable media risks addressed? | Device/media controls | |
| Are cloud-sharing permissions controlled? | Cloud configuration | |
| Are high-risk data transfers monitored? | Logs/reports | |
| Is DLP technology used where appropriate? | DLP configuration | |
| Are employees trained? | Training records | |
| Are AI data-sharing risks addressed? | AI usage policy | |
| Are data leakage incidents reported and investigated? | Incident records | |
| Are DLP rules periodically reviewed? | Review records | |
| Are exceptions documented and approved? | Exception register |
Common Mistakes
1. Buying DLP Software and Stopping There
DLP technology without classification, policies, ownership, and response processes will not provide a complete control environment.
2. No Data Classification
If the organization does not know what information is sensitive, it becomes difficult to protect it effectively.
3. Allowing “Anyone With the Link”
Public cloud-sharing links can create unnecessary exposure.
4. Ignoring SaaS Applications
Data can leak through:
- CRM
- Support systems
- HR platforms
- Analytics
- Collaboration tools
- AI services
5. Ignoring Developers
Source code, customer data, credentials, and production exports can be highly sensitive.
6. Ignoring Accidental Leakage
Not every incident involves a malicious employee.
Wrong recipients and accidental sharing are common scenarios organizations should consider.
7. Blocking Everything
Overly aggressive DLP can disrupt legitimate business operations.
Controls should be risk-based and practical.
8. No Incident Response
Detecting a potential leakage event is only the beginning.
The organization needs a process for:
Detect → Assess → Contain → Investigate → Respond → Learn
9. No Evidence
A policy saying “employees must not leak information” is not enough.
Auditors will look for evidence that controls are actually implemented.
Practical Startup Implementation Model
A startup can use the following approach:
Step 1 – Identify
Identify sensitive information.
Step 2 – Classify
Determine sensitivity and handling requirements.
Step 3 – Map
Identify where information is stored and where it can go.
Step 4 – Restrict
Apply least privilege and appropriate access controls.
Step 5 – Prevent
Use policies and technical controls to prevent inappropriate transfers.
Step 6 – Detect
Monitor important leakage scenarios.
Step 7 – Respond
Investigate and contain suspected leakage.
Step 8 – Review
Improve controls based on incidents, changes, and risk.
Identify → Classify → Map → Restrict → Prevent → Detect → Respond → Improve
Startup Minimum Viable DLP
A small startup does not necessarily need an expensive enterprise DLP platform on day one.
A practical starting point can be:
Governance
- Information Classification Policy
- Data Handling Policy
- Acceptable Use Policy
- AI Usage Policy
- Data Leakage Prevention Procedure
Access
- MFA
- Least privilege
- Role-based access
- Restricted external sharing
Endpoint
- Device encryption
- Endpoint protection
- Screen lock
- USB controls where appropriate
Cloud
- Restricted public links
- Controlled external sharing
- Access reviews
- Audit logging
Development
- Source-code access controls
- Repository restrictions
- Secret scanning
- Controlled production-data usage
Monitoring
- Security alerts
- Cloud audit logs
- DLP capabilities where justified
- Bulk-export monitoring
Response
- Data leakage incident procedure
- Investigation process
- Evidence collection
- Corrective actions
Policy vs. Process vs. Evidence
| Layer | Example |
|---|---|
| Policy | Sensitive information must not be shared through unauthorized channels |
| Process | Employees follow an approved process for external data sharing |
| Technical Control | DLP blocks or alerts on prohibited transfers |
| Evidence | DLP logs, approvals, alerts, incident records |
| Review | Periodic review of leakage risks and DLP rules |
A strong ISO 27001 implementation connects all five.
Relationship With Other ISO 27001 Controls
A.8.12 does not operate in isolation.
A.5.10 – Acceptable Use
Defines acceptable use of information and assets.
A.5.12 – Classification of Information
Determines which information requires stronger protection.
A.5.14 – Information Transfer
Addresses secure transfer of information.
A.5.15 – Access Control
Defines access-control requirements.
A.5.18 – Access Rights
Manages user access rights.
A.5.19–5.22 – Supplier Security
Addresses information risks involving suppliers.
A.5.34 – Privacy and Protection of PII
Addresses protection of personal information.
A.7.9 – Assets Off-Premises
Addresses physical assets outside organizational premises.
A.7.10 – Storage Media
Addresses storage media handling.
A.8.1 – User Endpoint Devices
Protects endpoints from which data may be copied or transferred.
A.8.3 – Information Access Restriction
Restricts access to information.
A.8.4 – Access to Source Code
Protects source code from unauthorized access.
A.8.11 – Data Masking
Reduces exposure of sensitive information.
A.8.15 – Logging
Provides records that can support detection and investigation.
A.8.16 – Monitoring Activities
Supports monitoring of relevant security events.
A.8.12 vs A.8.11
| Control | Primary Question |
|---|---|
| A.8.11 Data Masking | How can we hide sensitive information when the original is not required? |
| A.8.12 Data Leakage Prevention | How can we prevent unauthorized information from leaving the organization? |
Example:
Mask customer data before giving it to developers → A.8.11
Prevent developers from uploading customer data to personal cloud storage → A.8.12
A.8.12 vs A.5.14
| Control | Focus |
|---|---|
| A.5.14 Information Transfer | Protect information during authorized transfer |
| A.8.12 Data Leakage Prevention | Prevent unauthorized disclosure or extraction |
Example:
Sending a confidential contract to an approved customer through an approved secure channel:
A.5.14
Employee uploading the same contract to a personal cloud account:
A.8.12
A.8.12 vs A.8.3
| Control | Focus |
|---|---|
| A.8.3 | Restrict access to information |
| A.8.12 | Prevent unauthorized leakage/extraction |
Access restriction reduces the number of people who can access sensitive information.
DLP helps address what happens when someone attempts to move or disclose information.
Questions an Auditor May Ask
1. What information is considered sensitive?
Show your classification framework.
2. What are your major data-leakage risks?
Show your risk assessment.
3. How can employees transfer sensitive information?
Explain email, cloud, USB, messaging, repositories, AI tools, and other relevant channels.
4. How do you prevent unauthorized external sharing?
Show policies and technical controls.
5. Do you use DLP?
If yes, demonstrate it.
If no, explain the risk-based justification and alternative controls.
6. Can employees share company files publicly?
Show cloud-sharing configuration.
7. How do you control source-code leakage?
Show repository access and monitoring.
8. How do you handle AI tools?
Show AI usage/data-handling requirements.
9. What happens when potential data leakage is detected?
Show the incident-response workflow.
10. How do you know the controls are working?
Show:
- Alerts
- Logs
- Reviews
- Incidents
- Testing
- Management reporting
Useful Resources
Organizations implementing Annex A 8.12 may maintain:
- Data Leakage Prevention Policy – [Insert Draft Document Link]
- Data Handling Policy – [Insert Draft Document Link]
- Information Classification Policy – [Insert Draft Document Link]
- Data Transfer Procedure – [Insert Draft Document Link]
- External Data Sharing Procedure – [Insert Draft Document Link]
- DLP Configuration Standard – [Insert Draft Document Link]
- Data Leakage Risk Assessment – [Insert Draft Document Link]
- Data Leakage Channel Register – [Insert Draft Document Link]
- Cloud Sharing Review Checklist – [Insert Draft Document Link]
- AI Usage and Data Protection Policy – [Insert Draft Document Link]
- Data Leakage Incident Procedure – [Insert Draft Document Link]
- DLP Review Checklist – [Insert Draft Document Link]
- Data Leakage Audit Checklist – [Insert Draft Document Link]
Startup-Focused Quick Summary
For a startup, begin by answering five questions:
1. What information would hurt us if leaked?
Customer data, source code, credentials, financial information, contracts, employee data, etc.
2. Where does that information exist?
Cloud databases, SaaS platforms, laptops, repositories, email, backups, analytics, etc.
3. How could it leave?
Email, cloud sharing, USB, downloads, screenshots, repositories, AI tools, vendors, etc.
4. What controls prevent it?
Access control, classification, policies, endpoint controls, cloud controls, DLP, monitoring, user awareness.
5. What happens if it occurs?
Detect → Assess → Contain → Investigate → Respond → Learn.
Startup-Focused Final Takeaway
ISO 27001 Annex A 8.12 is not simply about installing a Data Loss Prevention (DLP) product.
It is about understanding:
What information is sensitive → Where it exists → Who can access it → Where it can go → How unauthorized movement is prevented or detected.
For a modern SaaS startup, data leakage can happen through:
Email + Cloud Storage + Endpoints + Source Code + APIs + Vendors + Messaging + AI Tools + Human Error
A practical implementation can start small and mature as the organization grows.
Simple Startup Model
Know your sensitive data. Limit who can access it. Control where it can go. Detect unusual movement. Respond quickly when something goes wrong.
One-Line Summary
ISO 27001 Annex A 8.12 requires organizations to implement appropriate measures to prevent unauthorized disclosure, transfer, copying, or extraction of information, using a combination of classification, access control, policies, technical controls, monitoring, and incident response.
