Checking what leaves the organisation against its own data-handling policy
Inspects outbound mail, file uploads and text pasted into external services for the categories the policy says must not leave — customer identifiers, source code, unreleased numbers — and blocks, quarantines or warns the sender, recording what was matched, on which rule, and who owns that rule.
- Effort
- Weeks of work
- Skill level
- Some technical skill
- Organisation size
- Enterprise
- Value
- Risk reduced
Tools named for this
- Detectors for the narrow, formatted categories — account numbers, identifiers, key material — tuned on the organisation's own documents
- A policy layer where every rule states its owner and its remedy
- An appeal path a blocked sender can use, showing the reason the message was held
What to check before you ship it in India
- For service providers, intermediaries, data centres, body corporate and Government organisations a data leak is on the list of incidents that must be reported to CERT-In within six hours of noticing it. The detector is therefore also the clock: the six hours run from noticing the incident or being brought to notice of it, not from the moment a reviewer confirms it — triage time is inside the window, not before it, and a queue reviewed the following morning has already spent it.
- The inspection surface is every employee's outbound communication, and a quarantine store ends up holding the most sensitive copy of it. Section 8(5) requires reasonable security safeguards over personal data in the fiduciary's control, which applies to the enforcement tool itself before it applies to anything the tool is watching.
Sources
Every claim on this page traces to one of these, on the date it was read.
- CERT-In Directions No. 20(3)/2022-CERT-In under sub-section (6) of section 70B of the Information Technology Act, 2000, dated 28 April 2022 — direction (ii) read with Annexure I(xii) · Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics and Information Technology · a rule · read 2026-09-01
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) — most obligations commence 13 May 2027 under the DPDP Rules 2025 — s.8(5) · Ministry of Electronics and Information Technology · a rule · read 2026-09-01
- Insider Threat Test Dataset (CERT Division) · Software Engineering Institute, Carnegie Mellon University (CERT Division, with ExactData LLC, sponsored by DARPA I2O) · that this is done · read 2026-09-01