DLP Reports
SL-08Tamper-proof logs of what was blocked and what was allowed, with the mapping between classification and enforcement decision. This is what turns a security control into regulatory evidence.
Blocked transfers against incidents that still had to be escalated as potential breaches. A healthy ratio means the last-mile control is doing its job.
Where enforcement is decisive and where it is still only advisory.
Report templates
Each knows the clauses it evidences, so the pack it produces is traceable rather than narrative.
Every blocked and allowed action with the classification that drove the decision, plus the policy version in force at the time. This is the artefact that demonstrates continuous monitoring rather than asserting it.
All enforcement events involving data classified as a child's personal data, with the guardian-consent status of each affected record.
Attempts to share or transfer data whose consent had been withdrawn, and what the platform did about each. Evidence that withdrawal is honoured operationally, not only recorded.
Every incident classified as a potential personal data breach, the assessment made, and whether it was escalated. A documented decision not to escalate is evidence; an undocumented one is not.
Who changed which policy, when, and from what to what — including moves between simulate and enforce.
Policy coverage summary
- Block outbound email containing government identifiersS.8(4)R.6Enforcing148
- Quarantine children's data leaving the departmentS.9R.10R.6Enforcing62
- Block sharing of data with withdrawn consentS.6S.8(7)Enforcing34
- Prevent bulk copy to removable mediaS.8(4)R.6Enforcing91
- Block public or external sharing in cloud storageS.8(4)R.6Enforcing27
- Warn on personal data submitted to unsanctioned web servicesS.8(4)R.6Enforcing204
- Detect mass database exportS.8(4)R.6Enforcing11
- Redact identifiers in printed outputR.6Disabled386