Your sales team is emailing client data to personal accounts
A 110-person equipment distributor in Nagpur found seventeen of its twenty-six salespeople mailing dealer files to their own Gmail. Not one of them was stealing anything.

Sales forwards client data to a personal account because the office system is slow on a phone, not because anyone is stealing. The exit route is convenience, and convenience beats policy every single time.
A hard block on consumer domains fails inside three weeks. The team routes around it with WhatsApp forwards, screenshots and a spouse’s laptop, and you lose the visibility you already had. Email data leakage prevention works when you give the field team a faster legitimate path and keep the record of what left.
Under the DPDP Rules the record is the obligation. If you cannot show which machine moved a customer file, on what date, and who approved it, you do not have a breach problem yet. You have a filing problem with a deadline attached.
16:40 on a Thursday, and the sales head had stopped writing things down.
We were three floors above a service yard in Nagpur, at a 110-person agricultural equipment distributor with a field team of twenty-six people spread across four states. Their IT lead, Devang, had pulled a report I had asked for a fortnight earlier. The sales head, Bhaskar, read one line of it, put his pen on the table, and said the sentence this article exists because of.
“If you block that, my team stops selling.”
He was not being difficult. He was right, in the way people are right when they are describing their own floor and you are describing a policy document. I want to be honest about where I stood at 16:40. I had walked into that room intending to recommend a hard block on outbound mail to consumer domains. I walked out having recommended something quite different, and the reason was sitting in Devang’s report.
Why sales forwards client data to a personal account
Bhaskar’s twenty-six people sell irrigation pumps to dealers and large farms. They live in a Bolero. A dealer calls at nine in the evening wanting the last three quotations and the current stock on two models, and the salesman is at a dhaba outside Amravati with one bar of signal.
The company system holds all of it. Opening it on a phone over a weak connection takes long enough that the dealer calls someone else. So on Sunday evening, from home, on a decent connection, the salesman pulls the dealer master and the quotation history into a spreadsheet and mails it to his own Gmail. Now it opens in four seconds from anywhere. Bas. Problem solved, from his seat, permanently.
Nobody sat down and decided this. It is jugaad, the working fix that beats the official one. One person does it, closes deals faster, and the floor copies him. By the time it reaches an IT report it has stopped being one salesman’s habit and become how the sales team works.
What the mail log actually showed
Devang’s report covered ninety days of outbound mail to consumer domains. I had expected a handful of repeat offenders. What came back was seventeen of twenty-six people, at least once, almost all of it clustered on Sunday evening and early Monday.
Two things in that report changed my recommendation.
The first was that nothing was going anywhere except the sender’s own mailbox. No competitor domains, no accounts belonging to somebody else, nothing that read as theft. Achha. That reframes the whole problem. A workflow was leaking. Nobody in that building was stealing anything.
The second was the attachment pattern, and it was the one that mattered. The files were dealer masters carrying phone numbers, addresses, and in several cases the proprietor’s PAN, because the accounts team had built that export years ago and nobody had revisited the column list since. So an ordinary convenience forward was moving regulated personal data every single time, and not one of the seventeen people knew it.
The Verizon Data Breach Investigations Report puts a useful frame around this. Among breaches caused by people inside the organisation, misdelivery accounts for roughly 72 percent of what end users actually do wrong, well ahead of anything malicious. Your leak is far more likely to be a filing error than a heist. That matches every mail log I have read in 17+ years of this work.
My own mistake belongs here. In the first ten minutes of that meeting, before Devang opened the report, I had already decided the answer was a block. I had read the situation the way a policy document reads it. Had we shipped that, we would have pushed twenty-six people onto WhatsApp forwards and photographs of screens within a month, and we would have had no log at all. Right instinct about the risk. Wrong instinct about the fix.
What the DPDP Rules actually ask you for
The thing that decided the meeting was not the risk of a leak. It was the record.
The MeitY explanatory note on the DPDP Rules, 2025 sets out what a data fiduciary owes on security. Rule 6 asks for access control, encryption or masking, and visibility on who accessed personal data through logs and monitoring that let you detect unauthorised access, investigate it, and stop it recurring. Those logs are to be retained for one year. Separately, the same MeitY note requires a personal data breach to be reported to the Board within 72 hours of you becoming aware of it, against a statutory penalty ceiling of ₹250 crore.
Read Rule 6 next to Bhaskar’s sales floor and the whole argument moves. A block gives you compliance theatre and a blind spot. A logged, warned, approved path gives you the artefact the regulator is asking for. The auditor will not admire your policy engine. The auditor will ask which laptop moved the dealer master, on what date, and who signed off. Bhaskar understood that version immediately, because it was a question about evidence rather than about trust in his team.
You are not deciding whether your sales team gets client data onto a phone. They decided that two years ago and it is why the quarter closed. You are deciding whether the copy they use is one you can see, log and produce on request, or one sitting in a personal mailbox you lose access to the day they resign.
The four questions we put on the whiteboard
We stopped arguing about blocking and wrote four questions instead. Every control had to answer all four. The ones that failed came off the list, and the fourth killed more ideas than the other three together.
| The question | Why it decides the control |
|---|---|
| Does the salesman still get his answer on a Sunday evening? | If the legitimate path is slower than the workaround, the workaround wins. Every time, in every company, regardless of what the policy says. |
| Does the movement leave a record we can produce next year? | This is the Rule 6 obligation. A blocked send that leaves no log is worth less to you at audit than an approved send that leaves one. |
| Does the person doing it find out what is in the file? | Seventeen people were moving PAN data without knowing. Awareness at the moment of sending changes behaviour faster than any training deck. |
| Can Devang run it alone in month nine? | A two-person IT team cannot maintain an exception list that grows the way exception lists grow. One console they understand beats two dashboards that disagree. |
What we turned on instead
Three changes, in this order.
We fixed the export first. The dealer master had been carrying PAN and proprietor date-of-birth columns for no current business reason at all. Accounts agreed to drop both in an afternoon. That single change took most of the regulated data out of the pipe before we touched a security control, and it cost nothing. Chalo, start with the free fix. Almost nobody does.
Then we put a warn-and-log prompt on outbound mail carrying dealer or customer records to a consumer domain. Not a block. The sender sees a banner telling him what the file contains and asking him to confirm, and the confirmation is logged with a reason attached. Most people stop when they read what is in the attachment. The ones who continue leave a business reason on record, which is exactly the artefact Rule 6 wants.
Third, and this is the part that made Bhaskar an ally rather than an obstacle, we gave the field team a faster sanctioned route. A mobile view of the dealer file that opens on a weak connection, so Sunday evening has an answer that is not Gmail. The security control and the workflow fix shipped together. Ship only the first and you will be reading about a new workaround by Diwali.
What to take away
- Convenience is the exit route, not malice. Seventeen of twenty-six people, all mailing to themselves, all clustered on Sunday evening. That is a workflow problem wearing a security costume.
- The export is where the regulated data enters the pipe. Somebody built that report years ago and every column has been travelling ever since. Auditing it costs an afternoon and no licence fee.
- Warn and log beats block. A block moves the traffic to WhatsApp and takes your visibility with it. A logged confirmation gives you the Rule 6 evidence and keeps the deal alive.
- Ship the workflow fix in the same project. A control that only takes something away gets routed around inside a month. Give the floor something faster than the habit you are replacing.
If you are running this argument yourself
Pull the outbound mail log before you write a single line of policy. Ninety days, consumer domains only, sender and attachment type. What you are looking for is whether it clusters by person or by moment. Clustering by moment means the problem is your workflow.
Bring the sales head into the room before you decide, not after. He knows why his people do it, and he will defend a control he helped shape. He will work around one that arrives as a memo.
And think about day one of enforcement before you sign anything. A control that makes a legitimate job harder and offers nothing in exchange does not reduce your risk. It moves it to a channel you cannot see.
One more thing, because we say the uncomfortable parts to clients too. If you already have a capable security team running endpoint controls and reading logs every week, you may not need us to own this at all. Use us as the escalation route instead. A control nobody watches is a false sense of safety with a licence fee attached.
Four terms in this piece, in plain English
- DLP, or data loss prevention
- Software that watches information on its way out of your company, over email, cloud uploads, USB or chat. It records who moved what and when, and it can warn the person or block the movement, depending on how you set it.
- DPDP Act 2023
- India’s Digital Personal Data Protection Act, the country’s main privacy law. It makes the company holding personal data responsible for protecting it, and sets penalties running to ₹250 crore for a failure of reasonable security safeguards.
- Data fiduciary
- The DPDP term for the company that decides why and how personal data gets processed. If you hold dealer records, customer phone numbers or employee files, that is you, and the obligations sit with you rather than with your software vendor.
- Exfiltration
- Data leaving your control. The word sounds like espionage, but it covers the deliberate theft and the Sunday evening forward equally, and in most Indian mid-market estates it is nearly always the second one.
Questions Bhaskar asked after the meeting
Is it really a breach if he mailed the file to himself?
Under the DPDP framework the test is whether personal data left the control of the data fiduciary, not whether the recipient meant any harm. A dealer master carrying PAN numbers sitting in somebody’s personal Gmail is outside your control, outside your retention policy, and outside any log you can produce for an auditor. It also survives his resignation, because the mailbox is his. Intent does not rescue you there. This is the point most Indian owners find hardest to accept, because the person involved is usually loyal, long-serving and genuinely trying to close business faster.
We have never had a breach, so why spend on this now?
Most companies have not had a breach they know about, which is a different sentence from not having had one. Data does not leave with an alarm. It leaves quietly on a resignation, a USB stick, or a personal email, and you find out when a customer or a regulator tells you. The point of email data leakage prevention is to see it while it is happening rather than read about it afterwards. If your budget is genuinely frozen this year, do the free half. Fix what your standard exports contain and pull ninety days of outbound mail. Both cost an afternoon.
Will this slow the sales team down?
The prompt adds a few seconds to a send that carries customer records, and nothing else changes. The part that decides whether your floor accepts it is the second half. In Nagpur we shipped a mobile view of the dealer file at the same time, so the Sunday evening job got faster than the workaround it replaced. A control that only takes something away will be routed around inside a month. Budget for the workflow fix in the same project, not the next one.
Can we run this ourselves?
You can, and some companies do it well. But this is not an install, it is a policy you have to write, tune and watch, and the day it fires a real alert is the day it matters who is actually watching. Be honest about whether someone on your team owns that every morning. If you already have a capable security team reading logs weekly, use us as the escalation route instead of the owner. A control nobody monitors is a false sense of safety with a licence fee attached.
Still deciding? These are the pages we send next.
- Email DLP in India: stop data leaks before they send
- How to stop data leaks over email in India: the four-control playbook
- Data theft after an employee resignation: what leaves with them
- How employees steal company data: 5 methods most Indian companies cannot detect
- Secure Data Guard, our data protection practice
Three months on, Devang sent me a screenshot of the log. The Sunday evening spike was gone, and the confirmations that did come through carried real reasons, mostly a dealer visit the next morning. What stayed with me was a line from one of Bhaskar’s seniors on the rollout call. Nobody had ever told him what was inside the file he had been mailing himself for two years. Theek hai. That was the whole project, in one sentence, from the person we were supposed to be worried about.
A read-only look at ninety days of outbound mail to consumer domains, plus a column audit of the reports your teams export every week. You get a written findings document: who is moving what, which fields carry regulated data, and the two changes that cost nothing.
Rule references, retention periods and breach reporting timelines follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as they stood at the time of writing, and all of that can change. Research figures are attributed to their publishers. The Nagpur engagement is one anonymised client matter with identifying details changed. A practitioner note on operating practice, not legal advice.






