Security advisor for data protection
Supported editions for this feature: Frontline Plus; Business Plus; Enterprise Standard and Enterprise Plus. Compare your edition
With Security advisor’s data protection feature, you can warn (or block) your users when they try to share sensitive data outside your organization. You can protect against sharing of the following data type categories:
- Personal identifiable information (PII)—email addresses, Social Security numbers, full names and addresses
- Financial data—Bank account numbers, credit card numbers
- Healthcare data—National insurance numbers
- Global sensitive data—IMEI numbers, IP addresses
Security advisor for data protection helps keep your Google Drive files and Gmail messages secure as you work. When you create or share content, it can identify sensitive information and warn you before this data leaves your organization.
Default settings
Default Security advisor data protection settings vary according to your Google Workspace edition.
For all accounts that have DLP enabled (Frontline Plus, Business Plus, Enterprise Standard, and Enterprise Plus):
- Data protection is ON by default (Warn mode) for new accounts.
- Older accounts might have different default settings. For details on turning on data protection, go to the next section. For details on previous settings, go to Turn on recommended settings.
View Security advisor data protection settings
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu and thenSecurity > Access and data control > Data protection.
Requires having the View DLP rule and Manage DLP rule administrator privileges.
- In the Security advisor section, click Go to security advisor for data protection.
The main settings page shows the four data type categories:
- Personal identifiable information (PII)
- Financial data
- Healthcare
- Global sensitive data
Each category contains a subset of data types. You can apply a setting to the category as a whole, or make custom settings for each data type in the category.
Change Security advisor data protection settings
About data typesSecurity advisor for data protection data types are a subset of the predefined content detectors that are available in Workspace’s data loss prevention (DLP) feature. For details on a specific data type:
- Go to How to use predefined content detectors.
- Locate and expand the category that matches the data type. For example, for Canada - Passport, expand the Canada section.
- Locate the specific detector in the table.
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu and thenSecurity > Access and data control > Data protection.
Requires having the View DLP rule and Manage DLP rule administrator privileges.
- In the Security advisor section, click Go to security advisor for data protection.
- For the data type category that you want to apply a setting to, select Warn users, Block users, or Off.
The category-level setting applies to all the data types in the category and resets any customized settings that you have made to individual data types in the category.
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu and thenSecurity > Access and data control > Data protection.
Requires having the View DLP rule and Manage DLP rule administrator privileges.
- In the Security advisor section, click Go to security advisor for data protection.
- For the data type category, select Customize.
The data types in that category are shown.
- For the data type that you want to apply settings to, select Warn users, Block users, or Off.
- Click Back to return to the main settings page.
The data type category setting changes to Customized to indicate that you’ve made individual settings for that category.
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu and thenSecurity > Access and data control > Data protection.
Requires having the View DLP rule and Manage DLP rule administrator privileges.
- In the Security advisor section, click Go to security advisor for data protection.
- For the data type category that you want to apply settings to, select Customize.
The data types in that category are shown.
- For the data type, select Customize.
The Select the Action by app box opens.
- For Drive and Gmail, select Warn users, Block users, or Off.
- Click Save.
- Click Back to return to the main settings page.
The data type category setting changes to Customized to indicate that you’ve made individual settings for that category.
Edit default data protection rules
Security advisor data protection settings have associated default data protection rules, which you can view and edit. For Frontline Plus, Enterprise Standard, and Enterprise Plus, admins can customize or create rules beyond the default.
- For default rules, editing is limited—you can change the action associated with the data protection setting (Warn, Block), or turn the rule on or off.
- For Frontline Plus and Enterprise customers, we recommend reviewing the default protection rules to ensure that they don’t conflict with any existing DLP custom rules you may already have in effect.
To edit a default protection rule:
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu and thenSecurity > Access and data control > Data protection.
Requires having the View DLP rule and Manage DLP rule administrator privileges.
- To show default rules:
- (Frontline Plus and Enterprise) In the Data protection rules and detectors section, click Manage rules.
- (Business Plus) In the Data protection rules section, click Manage rules.
In the rule list, Security advisor data protection rules have a [Default] prefix.
- (Optional) To turn a rule on or off from the rule list, change the setting in the Status column to Active or Inactive.
Note: This is equivalent to turning the setting to Off in Security advisor data protection settings.
- (Optional) Click a default rule to open its settings page.
- At the left, click the status menu to make a rule Active or Inactive.
To change actions for the data type, go to Apply settings to specific data types within a category on this page.
Any changes you make to the default rules are shown in the rule status in Security advisor data protection settings.
Known Gmail DLP Security advisor limitations
- Google Groups alias email addresses are treated as internal recipients. If the Google Group includes external members, Security advisor rules intended for external messages aren’t applied.
- Security advisor rules in Warn mode don’t apply to Google Groups. If a message is sent on behalf of a Google Group, these rules aren't applied.
- Security advisor rules don’t apply to email addresses or phone numbers in Gmail messages.