Data Loss Prevention Best Practice #1: Protect Employee Privacy
Posted on Fri, Aug 28, 2009
An effective data loss prevention solution can be seen by employees as a powerful tool for maintaining market leadership. It can protect irreplaceable research and development efforts, valuable intellectual property, and trade secrets. A sound data loss prevention solution can also give employees the added assurance of brand protection by potentially saving the organization from an embarrassing incident. However, if not managed correctly it can also create an environment of employee mistrust—or worse; expose the organization to fines and lawsuits for privacy violations. For example, some solutions violate United States and European Union regulations by collecting all traffic. Others don’t provide role-based access controls to determine which monitors can see what data. Without the appropriate safeguards built into their software, these solutions potentially expose an unprotected organization to violations.
An efficient data loss prevention solution needs to balance the requirement for corporate protection with the need for employee privacy. It should deliver on the following three requirements of Global Employee Privacy Protection:
- Targeted, policy-based monitoring that allows an organization to define specific attributes of confidential data
- Highly accurate detection technology that finds targeted data while simultaneously minimizing the risk of false positives
- Role-based controls that limit viewing of quarantined data to only those individuals who are approved to see it
The process of monitoring internal data and employee communications carries with it the responsibility of adequately protecting employee privacy.