Hands holding a phone with a dark screen beside an open laptop on a wooden desk in an Indian office, late afternoon light

Your team is sending customer files on WhatsApp

A 190-person home textiles exporter in Karur lost a buyer’s costing sheet to a competitor. Every log the company kept came back clean.

Hands holding a phone with a dark screen beside an open laptop on a wooden desk in an Indian office, late afternoon light
The device on the left keeps a record. The one on the right does not. The file was on both.
The short version

WhatsApp data leak prevention is not really a WhatsApp problem. The app runs on a handset you do not own, so there is nothing at that end to instrument. The work you can actually do sits one step upstream, on the machine that produced the file.

WhatsApp Web is the part you can see. It links to a company laptop, it drops media into a folder on that laptop, and it leaves a session your endpoint agent can read. Most Indian mid-market estates have never opened that folder once.

Under the DPDP Rules the obligation is the record. If you cannot show which company device produced a customer file, and when, you do not have a breach investigation. You have a filing problem with a deadline attached.

11:20 on a Tuesday, and nobody in the room wanted to say the buyer’s name out loud.

We were in Karur, at a 190-person home textiles exporter that ships bed linen to two European retail chains. Three weeks earlier their oldest buyer had run a re-quote. A competitor had come in within about two percent of a costing the exporter had built over eleven days, on a spec sheet the buyer swore had gone to nobody else.

The managing director, Sethu, had done the sensible thing and asked for the logs before he asked for a theory. That is rarer than it sounds. Their IT lead, Ganesh, is one person covering 62 machines and a plant floor, and he had pulled everything he had.

What every log we asked for actually said

Ninety days of outbound mail through the gateway. No attachment to any domain outside the approved list. Clean.

USB ports blocked at the endpoint on all 40 office desktops. That was the one control they had bought outright, two years earlier, after reading something frightening. It had held. Clean.

The endpoint agent was on 40 machines out of 62, which is a gap, but not the gap. The 22 uncovered machines were on the plant floor and none of them had ever seen a costing sheet.

Cloud storage was the next place I looked, because it usually pays. Their Microsoft 365 tenant showed no external sharing links created in the window, which surprised me, and then stopped surprising me when Ganesh explained that hardly anyone there uses the file share at all. A company that never adopted a tool cannot leak through it. Call it luck rather than design.

Then Ganesh opened the ERP export log, and the room got quieter. Somebody had pulled the full costing workbook for that buyer on a Thursday afternoon, which was ordinary, because that person built it. Achha. So the file was created legitimately, by the right person, on a company desktop, and then it stopped being visible to anybody.

WhatsApp data leak prevention starts on the device you own

The costing workbook was on the merchandiser’s desktop. So was WhatsApp Web, linked to his phone, open in a browser tab the way it is open on most desks in most Indian offices between ten and seven.

He had sent the workbook to a group. The group was called after the office cricket team, which is why it took us a while to work out that it was the primary coordination channel for that account. Eleven members. Nine of them staff.

The other two belonged to a freight forwarder. They had been added in March for a delayed container, they had been useful, and nobody had removed them. Bas. That is the whole leak. No heist, no angry exit. A group outlived its reason and a file walked out inside it.

The merchandiser was not hiding this. He had been sending files into that group for two years, in full view, from a company desktop, and at no point had anyone told him it was a data movement. When we asked what he thought the rule was, he said he assumed IT would have blocked it if it were a problem. That is the most common sentence in this line of work and it is usually fair.

I want to be honest about my first two days on this, because they were wasted. I spent them on the mail gateway, re-running exports and asking Ganesh for rule sets, because outbound mail is where I have found this shape of problem for most of 17+ years. I was auditing the route I knew. The route that mattered was sitting open in a browser tab about four feet from where I was working.

What the DPDP Rules actually oblige you to hold

Sethu asked the question every owner asks at this point, which is whether he was now in trouble. The leak is his commercial problem. The record is his legal one, and the two run on different clocks.

The MeitY explanatory note on the DPDP Rules is worth an hour of any Indian business owner’s time, and the PRS summary of the Digital Personal Data Protection Act, 2023 covers the obligations in plainer language than the statute does. Both point at the same operating reality. You are expected to know what personal data you hold and where it goes, and to be able to say so on the day somebody asks.

A buyer costing sheet on its own is commercial data. The buyer contact block inside it, with names, mobile numbers, a shipping address and in two rows a proprietor’s GST registration, is personal data, and that is the column set that turns a lost quote into a reportable question. Penalties under the Act run to Rs 250 crore for the serious categories, as set out in the PRS legislative summary of the Digital Personal Data Protection Act, 2023, and that is a number built to be quoted in board meetings rather than collected often.

On monitoring, the Act does allow processing for employment purposes without separate consent, within limits set out in the legitimate uses provisions. Read practically, that covers reasonable logging on a device the company owns and issues. It does not stretch to putting an agent on somebody’s personal handset. We tell clients that before they ask, because the alternative is an expensive project that a labour lawyer unwinds in one meeting.

There is a standards frame for this too, if your buyers are the kind who send security questionnaires. ISO/IEC 27001 treats logging and evidence as a control area in its own right, separate from prevention. The point it makes, in committee language, is the one Sethu had arrived at by Tuesday lunchtime. Stopping the bad thing and being able to describe what happened are two different capabilities, and most mid-market estates have bought the first and skipped the second.

Where a WhatsApp file leaves a trace, and where it does not

Ganesh drew a version of this on the whiteboard and it changed the conversation, so we have kept using it since.

How the file movedRecord on a device you controlWhat you can actually do
Sent from WhatsApp Web on a work laptopYes. Linked-device event, browser session, media folder on the machineLog it, review it weekly, and set a rule for customer files
Opened on the work laptop, then sent from the personal phonePartial. The open and the copy show up, the send does notWatch the export and the open, not the send
Phone to phone, file never touched a company machineNo. Nothing at allPrevent upstream. There is no downstream control to buy
Photograph of a work screen, sent from a personal phoneRarely. Only if your agent captures screen eventsWatermark the report and accept the residual risk
Exported from the ERP, then shared anywhereYes. User, timestamp, report nameThe cheapest control you already own and probably ignore
Saved from work email, then forwarded on chatYes at the mail step. Attachment name and recipientClassify at the point of export, not at the point of send
Company-issued handset with a managed work containerYes. Container policy and managed app dataThe only clean answer for a field team that lives on chat

Read the middle column downwards and the strategy writes itself. Four of the seven rows are visible, and all four go through a machine the company bought. That is where the money goes.

What we turned on in Karur

Nothing dramatic, and nothing that took a quarter.

The export log came first, because it already existed and nobody read it. Ganesh now gets a weekly list of every costing and customer report pulled out of the ERP, with the user against it. Eleven minutes on a Monday. In the first month it caught a second habit nobody had mentioned, an accounts assistant exporting the full buyer master because filtering it was slower.

Second, the linked-device event on company machines is now logged rather than blocked. We argued about this. Sethu wanted WhatsApp Web gone from the network entirely, and I understand the instinct, but a hard block on a floor that coordinates shipments over chat lasts about three weeks. After that the work moves onto personal phones, and you have traded the one route you could see for the one you cannot. Chalega is a poor security posture. A control the floor routes around by Friday is worse.

Third, group hygiene. Every WhatsApp group carrying company work now has a named owner and a quarterly member review. It sounds like a policy nobody follows. It took Ganesh one afternoon and it removed 31 outsiders across nine groups, including a former employee who had been reading shipment chatter for seven months.

Fourth, the 14 field merchandisers moved to company handsets with a managed work container. That is the only row in the table that closes properly, and it is worth spending on for the people who genuinely live on chat. For the other 176 staff it would have been an expensive answer to a question they were not asking.

What to take away

  1. Control the machine, not the appThe device that produced the file is the only place you can legally instrument. Everything useful starts there.
  2. WhatsApp Web is visible and almost nobody looksLinked-device events and the media download folder sit on machines you already own and already have an agent on.
  3. Your export log is the cheapest control in the buildingIt exists in every ERP. Reading it weekly finds workflow leaks before they find you.
  4. Groups outlive their reasonFreight forwarders and ex-staff sit in them for months after the shipment closed. An owner and a quarterly review fixes this for free.
  5. A block the floor routes around makes you blinderIf the legitimate path is slower than the workaround, the workaround wins and takes your visibility with it.

If you are running this postmortem yourself

Start with the export log, not the mail gateway. I say that having done it the other way round in Karur and lost two days to it. Pull ninety days of report exports and read the names.

Then list every chat group that carries company work. Ask a floor supervisor, not IT, because IT will not know they exist. Count the members who are not on your payroll.

Then open the WhatsApp media download folder on five random company machines and look at what is in it. This is a fifteen minute job and it is the single most useful fifteen minutes in this whole exercise. In 17+ years we have seen that folder hold salary sheets and a scan of somebody’s PAN card more often than we have seen it hold nothing.

Then decide what you are willing to enforce. Write down only the rules you will still be enforcing in month nine, when the person who wrote them has moved on and the exceptions list has grown the way exceptions lists grow.

Four terms in this piece, in plain English

WhatsApp Web and linked devices
Running the chat app in a browser or desktop client on a computer, tied to a phone account. The computer keeps its own copy of whatever gets sent or received, in a folder on that machine.
Endpoint agent
A small program on a laptop or desktop that records what happens on it, such as files copied, ports used, or applications launched. It is what turns a machine into something you can produce evidence from.
Data fiduciary
The DPDP term for the organisation that decides why and how personal data gets handled. If it is your customer list, you are the fiduciary, and the obligation to know where it went is yours.
Export log
The record your ERP or accounting system keeps of who pulled which report, and when. Almost every system has one. Almost nobody reads it until after something goes wrong.

Questions Sethu asked after the postmortem

Can we just block WhatsApp on the office network?

You can, and for a plant floor or a back office it is sometimes right. For a team that coordinates shipments and buyer queries on chat, a hard block holds for about three weeks. After that the work moves to personal phones on mobile data, which is a network you do not run and a device you cannot log. You will feel more secure and be less able to answer an auditor. Block it where the work does not need it, log it where the work does.

Can we legally monitor an employee’s WhatsApp?

On a company-owned and company-issued device, reasonable logging for employment purposes sits inside what the DPDP framework contemplates, provided you have told people clearly and you are not collecting more than the purpose needs. On a personal handset the answer is effectively no, and attempting it creates a labour exposure that is worse than the data exposure you were worried about. Publish an acceptable use note, get it acknowledged, and keep the monitoring on assets you own. This is not legal advice and your counsel should see the wording.

The file went phone to phone and never touched a company machine. Can we find it?

No. There is no product that recovers that, and any vendor who tells you otherwise is selling you a feeling. What you can do is make sure the file could not have reached a personal phone in a useful form in the first place, which means controlling the export and the classification rather than the send. That is why the export log matters more than anything downstream of it. Every honest DLP conversation ends up at this same wall.

We are 190 people with one IT person. Where do we start?

Two things, both free. Read ninety days of ERP report exports and see who pulls customer data. Then audit the membership of every chat group that carries work, and remove everyone who is not on your payroll. Between them these two jobs take about a day and they resolve most of what a first-round assessment would have told you. Buy tooling after that, once you know which route your own floor actually uses.

P.S. Priya here.
The re-quote was lost and it stayed lost. Sethu did not get that buyer back on the old margin, and I am not going to write an ending where he did. What he got was the second call, four months later, from a different buyer running vendor due diligence, who asked how he controlled data movement. He sent the export log process and the group policy in one page. He got the order. Theek hai. Sometimes the control you built after the loss is what wins the next thing.
Free data exit route review
Find out which company machines are linked to a personal chat account

A read-only look at linked-device sessions and chat media folders across a sample of your endpoints, plus ninety days of ERP report exports read against your customer data. You get a written findings document: which machines, which files, who pulled them, and the two changes that cost you nothing.

Get my free exit route review

Free. 200+ Indian businesses work with us, from Vashi, Navi Mumbai. Fill a short form and we reply inside 24 working hours, or write to care@siriusstar.in.

Obligations, monitoring grounds and penalty ranges follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as they stood at the time of writing, and all of that can change. The Karur engagement is one anonymised client matter with identifying details changed. A practitioner note on operating practice, not legal advice.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *