How to Configure Google Workspace Data Loss Prevention (DLP) Rules for Drive

Introduction

Data Loss Prevention (DLP) in Google Workspace allows administrators to protect sensitive information, such as credit card numbers or Social Security numbers, from being shared outside the organization. Configuring DLP for Google Drive ensures that files containing Restricted Data are automatically blocked or flagged. This guide explains how to create a basic DLP rule for Google Drive.

Prerequisites

You must have Google Workspace Enterprise Standard, Enterprise Plus, Education Standard, or Education Plus. You also need Super Administrator privileges or the specific DLP privileges.

Step 1: Access the Data Protection Dashboard

Log in to the Google Workspace Admin console (admin.google.com). From the main menu, navigate to Security > Data protection.

Step 2: Create a New DLP Rule

Click on Manage Rules, and then click Add Rule > New rule from templates. While you can build rules from scratch, templates are faster. Select the template for the region and data type you want to protect, for example, United States Financial Data.

Step 3: Define the Scope and Triggers

Name your rule and proceed to the Scope section. Apply the rule to the entire organizational unit (OU) or specific groups. Under Triggers, select File sharing. This ensures the rule scans files when a user attempts to share them externally.

Step 4: Configure Conditions

The conditions define what triggers the rule. The template will automatically include predefined content detectors (e.g., US Credit Card Number). You can adjust the threshold. For instance, you might trigger the rule only if a document contains more than 3 credit card numbers. Ensure the condition is set to trigger when the file is shared with External recipients.

Step 5: Set Actions and Alerts

Finally, define what happens when a violation occurs. Under Actions, check Block external sharing. You can optionally check Warn users to allow them to bypass the block if they provide a justification. Scroll down to Alerts and select Send to alert center so administrators are notified of policy violations. Click Create Rule to deploy the policy. It may take a few hours for the rule to enforce across the domain.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.