DLP for Drive FAQ

Supported editions for this feature: Frontline Standard and Frontline Plus; Enterprise Standard and Enterprise Plus; Education Fundamentals, Education Standard, and Education Plus; Enterprise Essentials Plus. Compare your edition

Frequently asked questions about DLP for Drive

Which predefined content detectors are supported?

DLP for Drive supports a large number of predefined detectors. We'll support more as DLP evolves.

Is detection 100% guaranteed?

No. We can't guarantee that all sensitive data will get caught and flagged. The DLP-detection system translates predefined templates into regular expressions and uses additional content parameters to determine the probability of a match. There might be false positives and negatives, which are triggered by many factors. In addition, not all file types are eligible for scanning and rule evaluation.

How long does it take before a DLP policy takes effect?

It can take up to 24 hours for a DLP policy to take effect.

What rule triggers are available in Drive DLP?

File modification is the trigger for Drive DLP. In addition, Google Forms scans files uploaded as question submissions during the form-submission process.

Can I create rules for specific file types or extensions?

Yes. You can target specific files by selecting File extension or File type as the Content type to scan. When entering file extensions, do not include a period (for example, enter pdf instead of .pdf).

Can I use an API to create and manage DLP rules?

There is no API access at this time.

Do DLP rules apply to Drive files attached in email?

If a user attaches a Drive file to email from "Insert files using Drive", DLP rules with the trigger "Message being sent" don't apply. However, if Google Drive sharing is also selected as a trigger, those rules apply to the Drive files prior to email attachment.

How can I investigate rules and their past results?

Use the security investigation tool. Go to Security investigation tool for details.

Can I create test DLP rules?

Yes, you can create an audit-only rule to test rules you create in the new DLP. This allows you to test a rule's potential impact. Like all rules, these rules trigger, but in this case, they take no action except to write results to the Rule log events. Go to Use audit-only rules to test rule results (optional, but recommended). Also, go to Rule log events or the Security investigation tool for log event data. Both the Rule log events and the Security investigation tool show entries for triggered DLP rules.

To see examples of sensitive content and to test your own content, try the Sensitive Data Protection Demo.

How many alerts can admins receive?

Admins can receive up to 50 alerts per rule per day. They receive alerts until this threshold is met.

If I add recipients to a rule alert, does that trigger a scan?

No. A scan is triggered if content is modified. Adding more recipients to an alert does not trigger a scan.

Do DLP rules apply to both My Drive and shared drives?

Yes. For files in My Drive, the DLP policy that applies to the file owner is in effect. For files in a shared drive, the shared drive is considered the file owner, and the DLP policy that applies to the shared drive is in effect.

When are alerts triggered?

Alerts are triggered when sensitive content, as defined by a DLP rule, is detected in a file. This can happen when either the file or the rule is created (if the content already exists). The actual sharing of the file doesn't trigger alerts.

What does "Triggering user" indicate in a DLP alert? Why is it blank sometimes?

A "Triggering user" is the last user whose change to the document resulted in a DLP scan. It's only populated when the DLP scan happens due to a document change (for example, it isn't set when the scan happens due to a policy change).