Skip to content
arrow_back
search
Annex A 8.12 verified ISO/IEC 27001:2022

Data Leakage Prevention Measures

Implement measures to stop sensitive data from being leaked or stolen from your systems.

record_voice_over

Plain language

Data leakage prevention is about making sure sensitive information doesn't slip out of an organisation's control and into the wrong hands. This matters because if your private data leaks, it could lead to financial losses, legal troubles, or damage to your reputation. It's like locking the door when you leave your house to keep burglars out, ensuring your data stays safe and sound.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Data leakage prevention measures shall be applied to systems, networks and any other devices that process, store or transmit sensitive information.
verified ISO/IEC 27001:2022 Annex A 8.12
priority_high

Why it matters

Without DLP controls, sensitive data may be exfiltrated via email, web uploads or removable media, causing financial loss, reputational damage and regulatory penalties.

settings

Operational notes

Regularly tune DLP policies for email, endpoints and cloud apps; validate alerts, review false positives, and ensure incidents are triaged and remediated promptly.

Mapping detail

Mapping

Direction

Controls