15 incidents classified as a potential personal data breach
Volume and classification suggest these may be reportable. Escalating starts the 72-hour Board clock, so the assessment needs to happen now rather than after the weekend.
Incidents (30 days)
72
Awaiting triage
12
ViewPotential breaches
15
Involving children
7
Blocked or quarantined
54
Agents needing attention
12
ViewEnforcement over the last fortnight
Blocked and quarantined transfers versus those allowed with a warning.
Incident classification
How each event was assessed.
- Policy violation37
- Security incident20
- Potential personal data breach15
Incidents by channel
Where data actually tries to leave.
Most-triggered policies
A high hit count with a high false-positive rate is a tuning problem, not a security win.
- MediumRedact identifiers in printed outputPrintSimulate38622.4% FP
- HighWarn on personal data submitted to unsanctioned web servicesWeb & API20414.6% FP
- CriticalBlock outbound email containing government identifiersEmail1483.1% FP
- HighPrevent bulk copy to removable mediaEndpoint918.9% FP
- CriticalQuarantine children's data leaving the departmentEmailCloud & SaaSWeb & APIConsent-aware626.4% FP
- CriticalBlock sharing of data with withdrawn consentEmailCloud & SaaSWeb & APIConsent-aware341.2% FP
Recent incidents
Newest first. Anything classified as a potential personal data breach can be escalated to the war-room in one click.
- HighDLP-2026-07103pension_reconciliation.xlsxSanjay Sharmaprint://HP-LJ-4th-FloorPolicy violationyesterday
- HighDLP-2026-07135health_claims_q2.xlsxShalini Chauhanhttps://chat.openai.comPotential personal data breach2 days ago
- MediumDLP-2026-07147health_claims_q2.xlsxRahul Bhattpartner-agency.org.inPotential personal data breach2 days ago
- MediumDLP-2026-07155health_claims_q2.xlsxsvc_reporting_3personal.gmail.comPotential personal data breach2 days ago
- CriticalDLP-2026-07125scholarship_shortlist.csvRitu Sharmausb://KINGSTON-4GBPolicy violation3 days ago
- HighDLP-2026-07127grievance_export.pdfJyoti Iyerhttps://filedrop.example.ioPolicy violation3 days ago
16 L records covered across all incidents in the period.
Related
PoliciesClassification-driven rules across every channel, including the consent-aware rule that blocks sharing after withdrawal.ChannelsEmail, endpoint, cloud, web and API, database and print — with coverage and enforcement mode for each.Tuning & simulationRun a policy in simulate mode and see what it would have blocked before it blocks anything.Classification workbenchDLP precision is bounded by classification quality. Fix it there and enforcement improves everywhere.