What needs protecting
Together we decide which information is critical: personnel files, health data, customer lists with pricing, project drawings, bids for a public tender. The list is shorter than people expect.
A data leak rarely looks like theft. Far more often it is a salesperson forwarding the customer portfolio to a personal Gmail two weeks before joining a competitor, an administrator sending the payroll sheet through WhatsApp Web because email “would not take an attachment that big”, or a technician copying the database to a USB drive to get ahead over the weekend. None of them feels like a thief and most of them are not, but the data has left. Leak prevention is not about watching staff; it is about making sure sensitive information is identified and that risky exit routes warn, ask for a reason or close. Wherever possible we deploy it with the tools already included in Microsoft 365 or Google Workspace, starting in warning mode so daily work carries on.
The trick is not to classify everything. We start with two or three kinds of information that would do real harm if they got out, and leave the rest alone.
Together we decide which information is critical: personnel files, health data, customer lists with pricing, project drawings, bids for a public tender. The list is shorter than people expect.
A simple scheme such as Public, Internal, Confidential and Special category data, with automatic labelling when a document contains a DNI or NIE, an IBAN, a Social Security number or medical terms.
A warning or a block when labelled data is sent to outside addresses, when a payroll sheet is shared through a public OneDrive link or when mail is forwarded to personal email domains.
Through Intune and Defender, control over copying to USB sticks, unapproved cloud services and personal apps on company phones, with justified exceptions for those who need them.
Confidential documents are encrypted along with their label, so a file forwarded outside the company will not open without an authorised account.
Incidents reach a named person with the context needed to decide, rather than a flood of notifications nobody reads.
Watch first, act later. A month in audit mode shows how information really moves before anything is blocked.
A video call with management, HR and department heads to agree which information is critical and who may send it outside.
Rules in audit mode for three or four weeks. We see how many sends would have been blocked and which of them were legitimate.
We refine the rules and turn on user warnings with an option to justify the send. Most accidental leaks stop at this point.
Only for the most serious cases, such as clinical records going to personal email or payslips in public links, with a documented exception process.
Preventing leaks is not the same as spying on employees. In Spain, the use of digital devices at work and how employers may monitor them is governed by Article 87 of the LOPDGDD, and staff must know the rules of use. That is why our rules target types of data, not people, and why we suggest HR and staff representatives hear about the project before it goes live.
It depends on your plan. Microsoft 365 Business Premium includes sensitivity labels and DLP for email and files; some features, such as DLP on the devices themselves or more advanced auto-labelling, need E3, E5 or add-ons. We check what your subscription covers before recommending anything.
No. The tool scans content for patterns such as ID or IBAN numbers without anyone reading the messages. Opening a specific email is another matter altogether, with clear legal limits under Article 87 of the LOPDGDD and employment case law, and it is a decision for your employment adviser, not for IT.
Offer a convenient alternative before banning anything. Teams or Google Chat for internal messages, shared folders with expiry dates for sending documents to clients, and on managed phones, a block on saving work files into personal apps. A ban with no alternative will not last a week.
They use the intended channel: the right label, the authorised recipient and encryption where appropriate. An accountancy practice sending payslips to the occupational insurer, or a clinic sharing a report with another specialist, keeps working as before, just along the controlled route.
Tell us which kinds of data worry you and which email and file tools you use. We will suggest where to start without slowing work down.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.