The attendees of various information security conferences are well informed about sessions dedicated to the privacy implications from monitoring of company’s network traffic. Such monitoring is usually performed by Data Loss Prevention (DLP) systems that take the content scanning to the higher level in order to identify security risks that could be missed by regular tools or resulted from malicious or unintentional employees’ actions.
However, like all tools, you can cut yourself with it if you use it incorrectly: DLP will automatically gather large amounts of personal and sensitive personal information, and there is a risk that organization using such system may inadvertently infringe the privacy of employees or third parties during investigations. Furthermore, the DLP logs will itself be very sensitive informational asset and must be protected appropriately.
InfoWatch follows closely the advices of Data Security laws and practices’ developers. These guides reiterate the importance of intention and action for data protection compliance: say what you are going to do, then do it...