---
title: How Can we protect our confidential drive data from getting exposed externally using Drive DLP?
description: Drive DLP
---

[Skip to content](https://support.econz.net/customer/how-can-we-protect-our-confidential-drive-data-from-getting-exposed-externally#main-content)

English

Show submenu for translations

[Customer portal](https://support.econz.net/portal?hsLang=en)

![logo.jpg\]](https://support.econz.net/hs-fs/hubfs/logo.jpg?height=40&name=logo.jpg)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Customer portal](https://support.econz.net/portal)
- Go to Econz Website

 Go to Econz Website

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.econz.net/customer?hsLang=en)
2. [Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en)
3. [Security](https://support.econz.net/customer/google-workspace?hsLang=en#security)

# How Can we protect our confidential drive data from getting exposed externally using Drive DLP?

## Drive DLP

Using data loss prevention (DLP), you can create and apply rules to control the content that users can share in files outside the organization. DLP gives you control over what users can share and prevents unintended exposure of sensitive information such as credit card numbers or identity numbers.

Using the data loss prevention (DLP) for Drive, you can create complex rules that combine triggers and conditions. You can also specify an action that sends a message to the user that their content has been blocked.                                                                                                                                   

**Create a Drive DLP rule**

- From the admin console navigate to  **Security** \> **Access and data control** \> **Data protection**.
- Click on **Manage Rules**

![](https://lh5.googleusercontent.com/yNftW-wDQkbfCOLaPGMbEi6WsaAA_Dlvz1pPRbeDk6KS4KAEXtNIKrBn5LqZieyajIME-wM1huXJ1UVCyUjN6BrfrTdiG9U-9AD7giapF93aSiRbnAZY1x-aGGGMcoSIif5X4frcoqAL3LOcNRofCAs)

 

- Then click **Add rule**\>**New rule**  **OR**click **Add rule**\>**New rule from template**.

 For templates, select a template from the Templates page.

![](https://lh5.googleusercontent.com/YqrCCZb9AIzHfiFO9Y_dNcTvX7D2ANjyhEoCYXsgzgmGDQudBXWu0ljEMNKMi80GyYJLV2rgjIw-5Qpnc7ZpJDAP2RXEnu-2JHX5SBcwb67R8dUMMsQAKCjkeP93yZeVH-QlNiiASdBvEfAV2qk-s6o)

 

- In the **Scope** section, choose **All in \<*domain.name*\>** or choose to apply this rule only to users in selected organizational units or groups.

If there's a conflict between organizational units and groups in terms of inclusion or exclusion, the group takes precedence.

![](https://lh4.googleusercontent.com/kx3aGTbSijIwr27yE7ZazP2SYZiSLBaPE5qcMT92eBS24NHw8k5UF83uy4bRJ_1mJoT1U7BOf0ilRoYgFxOTDY9W5-gETFpCzp1PQv_WvciHgLb_vS0ZbPNgC2xa1FOA3ZleTVBdD88sF_41Zpn0YNM)

- Click **Continue**.
- In the **Apps** section, choose the trigger for Google Drive, **File created, modified, uploaded or shared**.

![](https://lh6.googleusercontent.com/BFIVVNnmVzTGAINwAXXv2cW6UAVLcreBy1EKtkH5-XbpdIlFA5NlnRB8C_alC0wTFObAYChDpE_ZTUpN5DFiNreo7FdID_lKMfwj18vfQadaFg-u07Jj6l7IFNgD2Gftzzrhm4RvmqwZtejq65v5CEU)

- Click **Continue**.
- In the **Conditions** section, click **Add Condition.**

![](https://lh4.googleusercontent.com/W1oNMBxO0lMMtI2QoG-puPNTD5uSd0xbLcVNTN2bNpU0KYdHiXzk89CBZKrsT4LuPeC156RlhVPDJFO2QD8K8bQND1mMkeLnOYjCWncnEdDHJVx7Grd9G1K1O_3sIgKudiqnNTpF1jStUM_-MzRMZKw)

- Choose the **Content type to scan**: 
  
    - All content: All of the document, including the document title, body, and any suggested edits
    - Body: Body of the document
    - Drive label: Any [labels](https://support.google.com/a/answer/9292382) that are applied to the document.
    - Suggested edits: Content added to the document while in Suggestions mode
    - Title: Document title

![](https://lh3.googleusercontent.com/lvFzYv1-LppR__6f8sp369ynYZbldJB0GWJ6lyViAiFXXQxEx_jZ7siDunbeglD849E97nur4QaDQ2duXvV_Uzex9ii6XpHqWfco2nlW9wrOn-GFBGd2PV-wZLsurMNpYn1dH4m4WMHWJSF48MeH9-c)

- Choose **What to scan for**, then fill out the needed attributes for that type of scan, listed in the table below.

**Note:  What to scan for options vary according to the Content type to scan you chose in the previous step.** For example, if you choose 'Title' as the content type to scan, the **What to scan** for options will include **Ends with** and **Starts with**.

| **What to scan for** | **Attributes** |
| --- | --- |
| Matches predefined data type | Data type—Select a predefined data type. Get more information on predefined data types [here](https://support.google.com/a/answer/7047475). Likelihood Threshold—Select a likelihood threshold. Available thresholds are: - Very low - Low - Medium - High - Very high These thresholds reflect the DLP system’s confidence in the match result. In general, the *Very high* threshold will match fewer content and will be more precise. The *Very low* threshold is a wider net expected to match more files but will have lower precision. Minimum unique matches—The minimum number of times a matched result must uniquely occur in a document to trigger the action.  Minimum match count—The minimum number of times any matched results must appear in a document to trigger the action.  How do Minimum match count and Minimum unique matches work? For example, think of two lists of Social Security Numbers: the first list has 50 copies of the exact same number, and the second list has 50 unique numbers. In this case, if the Minimum match count value equals 10, results will trigger on both lists since there are at least 10 matches in both. Or, if the Minimum unique matches value equals 10, and the Minimum match count value equals 1, results will trigger only on the second list, since there are 10 matches and they're all matching unique values. |
| Contains text string | Enter contents to match—Enter a substring, number, or other characters to search on. Specify if the content is case sensitive.  In the case of the substring, the rule can contain the word *key*, and if the document contains the word *key*, there is a match. |
| Contains word | Enter contents to match—Enter the word, number, or other characters to search on. Specify if the content is case sensitive. |
| Matches regular expression | Regular expression name—a regular expression custom detector.Minimum times the pattern detected—The minimum number of times the pattern expressed by the regular expression appears in a document to trigger the action. |
| Matches words from word list | Word list name—Select a custom word list. Match mode—Select either Match any word or Match minimum number of unique words. Minimum unique words detected—The least number of unique words that must be detected to trigger the action. Minimum total times any word detected—The least number of times a word can be detected to trigger the action (for Match minimum number of unique words option only). |
| Ends with | Enter contents to match—Enter the word, number, or other characters to search on. Specify if the content is case sensitive. |
| Starts with | Enter contents to match—Enter the word, number, or other characters to search on. Specify if the content is case sensitive. |
| Is (Drive label  content type only) | Drive label—Choose an available Drive label from the dropdown list. Label field—Choose an available label field for the selected Drive label. Field option—Choose an available field option for the selected field. |

- You can use *AND*, *OR*, or *NOT* operators with conditions. Go to [DLP for Drive rule nested condition operator examples](https://support.google.com/a/answer/9657280) for details on using *AND*, *OR*, or *NOT* operators with conditions.

**Note:** If you create a DLP rule with no condition, the rule applies the specified action to all Drive files.

![](https://lh5.googleusercontent.com/4BvA1Vj73ZIlG2UrLyzJxr34ZTKyaxhw90cClmJkznUHk_5dDd-YlqgmoxLpbz_DMTW7U_u4epRJ2JSnfcf34QTqpMJcERdrq-WaU1CM9zymO2Lj0IiJzqNJzYxf8LgJEUq5Y_KKB-0LSOBmRgnl4R4)

 

In the below screenshot, we have chosen to take actions on the drive files **Contains text string “**Confidentia**l”**  in  **All content** andshared externally.

**You can choose the options according to your scenario.**

![](https://lh5.googleusercontent.com/wthEdVz9VfYd4Q_QnZTnXniyTucVYGQmekgbxWNCV3WPArRmLQJiSiNWiAxxz5ROnF2-jY6IfvTkxLqzm9bWvQkJtd9iNTu4cLL79_2WAxm9WMTkQYAa5RijeoQrV6FPF4slrAcOVuEaD7uoHu0Mkws)

- Click **Continue**.

In the **Actions** section,  you can optionally select the action to occur if sensitive data is detected in the scan:

- Block external sharing—Prevents sharing of the document.
- Warn on external sharing—Share the document, but warn of the violation.
- Disable download, print, and copy for commenters and viewers—Prevents downloading, printing, and copying unless the user has *editor* privilege or greater.
- Apply Drive labels—Applies an existing Drive label to matching files.  
  
                                                                                                                                                                     Follow these steps to configure:
  
    - Choose an available label from the Drive label dropdown list, then select an available Field and Field option for the label.
    - (Optional) Click Add label to add additional labels.
    - Choose whether to allow users to change labels and field values applied to their files.

![](https://lh4.googleusercontent.com/ikL34_pSnxjojPveIKvJdorv2SVIC5ZF12-VijO7EJbdt4MD553YefBi92AG0kY3K74W25a_cUFFWMoxb5hs7ViU5ciR8H2K8_8Bt8xj5b6yzUGKc0jiF8G61hvgdmm1Ke8Jow3lJbhuV3jMF4Fb-AU)

- In the **Alerting** section, choose a severity level (**Low, Medium, High**). The severity level affects how incidents are plotted in the DLP Incident dashboard (the number of incidents with High, Medium or Low severity) over time.
- Optionally, check **Send to alert cente**r to trigger notifications.

![](https://lh6.googleusercontent.com/_ifMGAk8n6P6zYz74jWnfG3ovs0kfV3R_gS1hE18UGI59zj6EkHse8x7biY2_M78NnX-WhIZ2vwGvyzBghpo7iHcvTNnX7FgY73WbabYthsuA6mOPTXsRxuYkb-AKDgIoAfv8tD9AOxmECD8dK5CP_I)

 

- Click **Continue** and review the rule details.
- In **Rule status**, choose an initial status for the rule:

        **Active**—Your rule runs immediately.  
        **Inactive**—Your rule exists but does not run immediately. This gives you time to review the            rule and share it with team members before implementing it. Activate the rule later by                      going  to Security \> Data protection \>Manage Rules. Click the Inactive status for the rule                and select Active. The rule runs after you activate it, and DLP scans for sensitive content.

![](https://lh5.googleusercontent.com/3x88mKguwI69mtZCBlmGSVgP0vP0PoKNtjoakAyTkUBMF55J4wQIK-QYj8ijvgc-oIkOs587nsOdgpH516fIPpngYUWLWQnMMKnAoiY6DnABzb-BXjKOmms2cKd6m2f868YMRp8CKcvYxjIDXedOiXg)

 

- Click Create.

Changes can take up to 24 hours but typically happen more quickly.

For more information please refer to [Create DLP for Drive rules and custom content detectors](https://support.google.com/a/answer/9655387)

 

- [Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en#main-content)

    - [Reset and recover passwords](https://support.econz.net/customer/google-workspace?hsLang=en#reset-and-recover-passwords)
    - [Email issue](https://support.econz.net/customer/google-workspace?hsLang=en#email-issue)
    - [catch-all address](https://support.econz.net/customer/google-workspace?hsLang=en#catch-all-address)
    - [Download Google Data](https://support.econz.net/customer/google-workspace?hsLang=en#download-google-data)
    - [Gmail](https://support.econz.net/customer/google-workspace?hsLang=en#gmail)
    - [MX Records](https://support.econz.net/customer/google-workspace?hsLang=en#mx-records)
    - [Company Logo](https://support.econz.net/customer/google-workspace?hsLang=en#company-logo)
    - [Sharing drive files to the trusted domains](https://support.econz.net/customer/google-workspace?hsLang=en#sharing-drive-files-to-the-trusted-domains)
    - [Mobile Device Management](https://support.econz.net/customer/google-workspace?hsLang=en#mobile-device-management)
    - [Restrict emails based on a size](https://support.econz.net/customer/google-workspace?hsLang=en#restrict-emails-based-on-a-size)
    - [Create Google Calendar Event](https://support.econz.net/customer/google-workspace?hsLang=en#create-google-calendar-event)
    - [less secure app](https://support.econz.net/customer/google-workspace?hsLang=en#less-secure-app)
    - [Drive & Docs](https://support.econz.net/customer/google-workspace?hsLang=en#drive-docs)
    - [Users](https://support.econz.net/customer/google-workspace?hsLang=en#users)
    - [Install GCPW](https://support.econz.net/customer/google-workspace?hsLang=en#install-gcpw)
    - [Add email aliases for user from google admin console](https://support.econz.net/customer/google-workspace?hsLang=en#add-email-aliases-for-user-from-google-admin-console)
    - [Set up Google Workspace user signatures in Gmail](https://support.econz.net/customer/google-workspace?hsLang=en#set-up-google-workspace-user-signatures-in-gmail)
    - [Add or remove printers](https://support.econz.net/customer/google-workspace?hsLang=en#add-or-remove-printers)
    - [New updates to Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en#new-updates-to-google-workspace)
    - [DNS](https://support.econz.net/customer/google-workspace?hsLang=en#dns)
    - [DNS Records](https://support.econz.net/customer/google-workspace?hsLang=en#dns-records)
    - [Admin roles](https://support.econz.net/customer/google-workspace?hsLang=en#admin-roles)
    - [Security](https://support.econz.net/customer/google-workspace?hsLang=en#security)
    - [Forms & Surveys](https://support.econz.net/customer/google-workspace?hsLang=en#forms-surveys)
    - [password](https://support.econz.net/customer/google-workspace?hsLang=en#password)
    - [Calendar](https://support.econz.net/customer/google-workspace?hsLang=en#calendar)
    - [Google vault](https://support.econz.net/customer/google-workspace?hsLang=en#google-vault)
    - [har file](https://support.econz.net/customer/google-workspace?hsLang=en#har-file)
    - [Cloud Data Sync](https://support.econz.net/customer/google-workspace?hsLang=en#cloud-data-sync)
    - [LDAP](https://support.econz.net/customer/google-workspace?hsLang=en#ldap)
    - [Routing](https://support.econz.net/customer/google-workspace?hsLang=en#routing)
    - [Data Migration](https://support.econz.net/customer/google-workspace?hsLang=en#data-migration)
    - [Organizational Unit(OU)](https://support.econz.net/customer/google-workspace?hsLang=en#organizational-unitou)
    - [License and subscription](https://support.econz.net/customer/google-workspace?hsLang=en#license-and-subscription)
    - [GWSMO](https://support.econz.net/customer/google-workspace?hsLang=en#gwsmo)
    - [Report and Audit](https://support.econz.net/customer/google-workspace?hsLang=en#report-and-audit)
    - [SMTP](https://support.econz.net/customer/google-workspace?hsLang=en#smtp)
    - [GWMME](https://support.econz.net/customer/google-workspace?hsLang=en#gwmme)
    - [password sync](https://support.econz.net/customer/google-workspace?hsLang=en#password-sync)
    - [Google Sites](https://support.econz.net/customer/google-workspace?hsLang=en#google-sites)
    - [Google services](https://support.econz.net/customer/google-workspace?hsLang=en#google-services)
    - [jamboard](https://support.econz.net/customer/google-workspace?hsLang=en#jamboard)
    - [Google Add-ons](https://support.econz.net/customer/google-workspace?hsLang=en#google-add-ons)
    - [GCPW](https://support.econz.net/customer/google-workspace?hsLang=en#gcpw)
    - [Keep](https://support.econz.net/customer/google-workspace?hsLang=en#keep)
    - [outlook](https://support.econz.net/customer/google-workspace?hsLang=en#outlook)
    - [Devices](https://support.econz.net/customer/google-workspace?hsLang=en#devices)
    - [Apps](https://support.econz.net/customer/google-workspace?hsLang=en#apps)
    - [Spam, phishing, and malware](https://support.econz.net/customer/google-workspace?hsLang=en#spam-phishing-and-malware)
    - [Windows](https://support.econz.net/customer/google-workspace?hsLang=en#windows)
    - [Meet Hardware](https://support.econz.net/customer/google-workspace?hsLang=en#meet-hardware)
    - [user settings](https://support.econz.net/customer/google-workspace?hsLang=en#user-settings)
    - [Google takeout](https://support.econz.net/customer/google-workspace?hsLang=en#google-takeout)
    - [Chrome Device Management](https://support.econz.net/customer/google-workspace?hsLang=en#chrome-device-management)
    - [networks](https://support.econz.net/customer/google-workspace?hsLang=en#networks)
    - [Chrome Enterprise Management](https://support.econz.net/customer/google-workspace?hsLang=en#chrome-enterprise-management)

[![](https://support.econz.net/hs-fs/hubfs/econz%20logo.png?width=600&height=164&name=econz%20logo.png)](http://econz.cloud)

Help Center

Copyright © 2026, Econz IT Services Pvt Ltd