Data theft after an employee resignation: what leaves with them
TL;DR: When an employee resigns, the real risk is not the laptop they hand back, it is the copy they already made. Most Indian mid-market firms keep no record of what left, which is why a resignation turns into a data theft employee resignation problem only when a customer or a regulator asks the awkward question.
18:40 on a Friday. A 140-person logistics firm in Bhiwandi had just given a warm send-off to its billing executive of four years. Cake in the pantry, a group photo, the laptop returned to IT with the charger coiled neatly around it. Clean exit. The kind every HR head wants. Nobody in that room was thinking about data theft after an employee resignation. They were thinking about who would cover invoicing on Monday.
The laptop was wiped and reissued the next week. Ten days later a customer forwarded a rate quote from a competing transporter. The pricing was theirs, down to the slab. The layout was theirs. It had left with a person who no longer worked there, and no log in the building could say when.
The offboarding that looked perfect
Here is what buyers get wrong about a resignation. They treat it as an HR event with an IT step attached: collect the asset, disable the email, done. The asset came back. That is the part everyone watches, because it is physical, because you can hold it. The copy is the part nobody watches, because a copy makes no noise and leaves no gap on the shelf.
The billing executive had done nothing dramatic. Over her last three weeks she had emailed a few working files to her personal Gmail so she could “finish from home,” and dragged the master rate sheet onto a pen drive the way half the office moved files before a long weekend. No alarm sounded. There was no alarm to sound. This is the shape of data theft at employee resignation, the quiet kind, and it looks exactly like ordinary work right up until the day it does not.
Day two, and the amber signal I almost missed
They called us the following Tuesday. We ran a data-movement scan across the last ninety days, the same exercise we run inside Secure Data Guard for any firm that suspects something walked. By the afternoon we had a timeline. Files, destinations, timestamps. The pen drive, the personal email, an upload to a consumer file-sharing link at 22:10 on a working night.
I want to be honest about a mistake, because the mistake is the lesson. One of the first rows I looked at was a rule forwarding a copy of every finalised quote to an outside address. I read it as a vendor integration, noted it, moved on. It was not an integration. It was a forward the executive had set months earlier, and it had been mailing out priced quotes long before she ever typed her resignation. I had read an amber signal as background noise. It was, in fact, the whole story. The resignation did not start the leak. It just ended our chance to see it in time.
This is the argument I have with rooms full of smart people, so let me have it here in plain words. Data does not leave with an alarm. It leaves quietly on a resignation, a USB, or a personal email, and you find out when a customer or a regulator tells you. Every business thinks its data is not that sensitive until it reads what the law counts as personal data, which is basically anything that identifies a person. Customer numbers, employee records, KYC, rate cards, all of it walks out the door the day someone resigns. The question is not whether your data is sensitive. It is whether you would know if a copy left.
The math nobody did before the send-off
The direct loss here was a pricing book that took years to tune, handed to a competitor for free. Set that aside for a second and look at the regulatory side, because it is the one most firms discount. Under India’s Digital Personal Data Protection Act, a business that fails to protect personal data it holds can face penalties up to Rs 250 crore per instance (see the MeitY data protection framework). Those rate sheets also carried named consignee contacts. That is personal data leaving your custody without your knowledge, and “an employee took it when she left” is not a defence the rules recognise.
The frequency is not rare either. Verizon’s breach research has for years put insiders and simple human error behind a large share of incidents, not shadowy outside hackers (Verizon DBIR). And IBM’s annual study keeps pricing the average breach in the millions of dollars once you add detection, response, and lost business (IBM Cost of a Data Breach). We wrote up what those numbers translate to for an Indian mid-size firm in a separate calculation, and it lands harder than most CFOs expect.
What I told them to do, in order
The firm wanted to know if they should have “caught her.” Wrong frame. You do not catch a resignation. You make it so a copy cannot leave quietly in the first place, and so that if one does, you have the evidence in one document instead of forty. Two different jobs. Both are policy, not heroics.
The controls that would have changed this Friday are ordinary. Block or log removable drives. Watch uploads to consumer file-sharing and personal mail. Tie an offboarding checklist to the data logs, not just the asset register, so the last thirty days of a leaver’s file movement get a second pair of eyes before the exit interview, not after the customer calls. None of this is exotic. It is the day-to-day discipline of data loss prevention, and we walk through the human side of it in five scenarios your HR team should know.
If you are doing this yourself
You can run this in-house, and some firms do it well. But data loss prevention is not an install you switch on once. It is a policy you write, tune, and watch, and the day it fires an alert is the day it matters who is actually watching. Be honest about whether someone on your team owns that every single day, because a control nobody monitors is just a false sense of safety. We say that out loud even when it costs us the deal, because that honesty is the whole product.
Start small. Turn on USB and upload logging this month. Write a one-page offboarding data check and make it a sign-off step HR cannot skip. When your next auditor asks who moved the client file and when, you want to open one clean report, the way we prepared a firm for exactly that question in this audit-readiness walkthrough. If you would rather not build it in-house, Secure Data Guard runs from Rs 749 per device per month* with monitoring included, backed by our 24 working hours response commitment across India.
Key takeaways
- The returned laptop is the visible risk. The copy the leaver already made is the real one, and it leaves no gap on the shelf.
- Most data theft at resignation looks identical to ordinary work: a file emailed home, a rate sheet on a pen drive, an upload at night.
- Under the DPDP Act, personal data walking out with a leaver can expose you to penalties up to Rs 250 crore, and “an employee took it” is not a recognised defence.
- Offboarding should check the data logs, not only the asset register. Watch the last thirty days of a leaver’s file movement.
- A DLP control nobody monitors is a false sense of safety. Decide who owns the alert before you buy the tool.
Frequently asked questions
Is it really data theft if the employee just emailed files to themselves
Legally and practically, yes, once that data belongs to the company and leaves without authorisation. Intent rarely matters to a regulator or a customer whose information walked out. The file emailed “to finish from home” and the file taken to hand a competitor look identical in a log. That is exactly why you log it, so you can tell the two apart before someone else decides for you.
We disable the email account the moment someone resigns. Is that enough
It closes the front door and leaves the windows open. Disabling the account stops future access, but the copies made in the notice period are already gone, and a pen drive does not care whether the account is live. You need visibility into what moved before the resignation, not only a switch you flip after it.
Our company is under 100 people. Do we really need DLP for this
If you hold customer PII, KYC, pricing, or employee records, the exposure is the same at 40 people as at 400. What changes is scope. A small firm often needs logging and one clear offboarding policy, not a heavy platform. If you genuinely hold nothing regulated, we will tell you to keep your money. That honesty cuts both ways.
How fast can a data-movement scan tell us what a leaver took
If the logs exist, a ninety-day movement timeline usually comes together in a day or two. If they do not exist yet, the scan can only start from the day you switch it on, which is the honest reason to turn logging on before the next resignation, not after it.
Still deciding
If a resignation is coming and you are not sure what would leave with it, that uncertainty is the finding. We have run this data-movement scan for 200+ Indian businesses, delivered pan-India from Vashi, Navi Mumbai. It pairs naturally with a look at what the DPDP Act actually penalises, so you size the risk before you size the spend. Book a free data-exposure review, no card and no contract. WhatsApp +91 91375 93228 during 10 to 7 IST, or write to care@siriusstar.in.
P.S. Priya here. The Bhiwandi firm now runs a thirty-day data check as the first line of every offboarding, before the cake. Last month a leaver’s file log came back completely clean. The IT lead called just to tell me that, a little proud. A quiet resignation with nothing in the log is the only send-off worth celebrating.
*Indicative pricing. Actual scope and price depend on device count and modules, confirmed in writing before you commit.
The longer read for Indian buyers who want the real numbers before they commit.
Send me the field guide






