4

Channels

SL-08

Every route personal data can take out of the department, and what is actually enforcing on each. A channel with policies but none enforcing is a channel with no control.

DischargesS.8(4)R.6
Channels monitored
6
Fully enforcing
5
Without enforcement
1
Blocked transfers
54

Coverage by channel

Email

3 policies · 27 incidents

3 enforcing
Enforcement coverage100%
  • Inspect body and attachments before delivery
  • Block, quarantine or encrypt messages containing classified personal data
  • Prevent auto-forwarding to unauthorised domains

Auto-forwarding rules on shared mailboxes are the most common way a quarantined message still leaves the department.

4 potential breaches27 blockedConsent-awareChildren
Highest severity seen
Critical
Endpoint

2 policies · 9 incidents

2 enforcing
Enforcement coverage100%
  • Prevent copying personal data to USB or removable media
  • Control screen capture, printing and clipboard actions
  • Detect bulk file staging prior to exfiltration

Staging detection matters more than the block itself — it catches intent before the transfer is attempted.

3 potential breaches9 blockedConsent-awareChildren
Highest severity seen
High
Cloud & SaaS

3 policies · 9 incidents

3 enforcing
Enforcement coverage100%
  • Monitor uploads and shares in cloud storage
  • Block public or external sharing of classified data
  • Detect abnormal download or sync activity

Anonymous-access links created by a migration script caused a real exposure in this dataset.

1 potential breaches9 blockedConsent-awareChildren
Highest severity seen
Critical
Web & API

3 policies · 9 incidents

3 enforcing
Enforcement coverage100%
  • Inspect uploads to external websites and APIs
  • Prevent submission to unauthorised services
  • Apply real-time controls on unsanctioned cloud usage

This is where shadow AI traffic surfaces first, before the AI Processing Guard sees a prompt.

3 potential breachesConsent-awareChildren
Highest severity seen
High
Database

2 policies · 9 incidents

2 enforcing
Enforcement coverage100%
  • Detect SELECT-INTO-FILE and unusual export tooling
  • Block mass export from classified tables
  • Work alongside Database Activity Monitoring for query-level context

Overlaps deliberately with SL-10: DLP blocks the transfer, DAM explains the query.

1 potential breaches9 blockedConsent-aware
Highest severity seen
Critical
Print

1 policy · 9 incidents

No enforcement
Enforcement coverage0%
  • Mask identifier columns in printed output
  • Log print events against classified documents

Currently in simulate mode at district offices — the false-positive rate is too high to enforce.

3 potential breaches
Highest severity seen
Medium