When we talk email security, we always discuss the side that comes to mind: inbound threats — phishing, malicious attachments, fake invoices. But a significant share of an organization's most expensive data incidents run the other way: from the inside out. A personnel file goes to the wrong "Ahmet," a customer list gets forwarded to a personal Gmail before it reaches a competitor, a draft contract leaks from a compromised account. What they share: none of them looks like an "attack." Most are a well-meaning employee's momentary mistake. And under Türkiye's data protection law (KVKK), even with good intent the outcome is the same: a data breach that must be reported.
In this Thematic Series article we cover the invisible half of email security: DLP (Data Loss Prevention) and its relationship with Türkiye's legal framework, KVKK (the Personal Data Protection Law No. 6698). The goal is the same as always: even a non-technical manager should get a clear answer to "how does data leak here, why does KVKK care, and how do we stop it."
1. What Is DLP and Why Is It the "Other Direction" of Email?
Most of our articles so far focused on the inbound threat. DLP is its mirror: it prevents sensitive data from leaving the organization in outbound traffic. A DLP engine reads and classifies outgoing email and attachments by content — recognizing patterns like national ID numbers, IBANs, credit cards, health data, "confidential"-stamped documents, or customer lists. Email matching a policy is blocked, quarantined, encrypted, or reported to an administrator.
The critical point: DLP doesn't ask about intent. All three scenarios below produce the same outcome, and DLP catches all three:
- Accident: Autocomplete picks the wrong recipient; a personnel file goes out.
- Negligence: An employee sends the customer list to their personal email to finish work from home.
- Malice or takeover: A departing employee carries data out, or a compromised account silently exfiltrates it.
2. The KVKK Connection: Why Is This a "Compliance" Matter?
KVKK obliges every organization processing personal data to ensure data security. A customer list, personnel file, or health record leaking out by email is a data breach under KVKK — and being accidental doesn't change that.
- Notification obligation: In a personal data breach, notification to the Data Protection Authority and the affected individuals is expected within the framework the Board sets. "We didn't notice" is not a defense.
- Technical and administrative measures: KVKK expects organizations to take "technical and administrative measures to ensure an appropriate level of security." The absence of a DLP control on outbound email can be assessed as a lack of measures.
- Burden of proof: When an incident occurs, to say "we had taken the necessary measures," those measures must exist and be recorded. DLP policies and logs are part of that proof.
Note: This article is for general information; your organization's specific obligations should be assessed together with legal counsel.
3. How Does Data Leak Over Email? (Four Ways)
3.1 Wrong Recipient (Misdelivery)
The most frequent and most insidious. Autocomplete picks the wrong "Ahmet" instead of "Ahmet Yılmaz"; a bulk email accidentally puts recipients in the visible field instead of BCC (exposing hundreds of addresses to each other). No malice — but a KVKK breach.
3.2 Forwarding to a Personal Channel (Shadow Exfiltration)
An employee sends corporate data to their personal Gmail/Outlook "to finish work from home." The intent may be innocent, but the data is now outside the organization's control; if that personal account is compromised, the data leaks too.
3.3 The Departing Employee
A resigning salesperson carries out the customer list, an engineer the technical documents, before they leave. This is the most common form of the IP leakage we touched on in our sector articles (machinery, aluminum).
3.4 Silent Exfiltration from a Compromised Account
The data dimension of the scenario in our ATO article: a compromised account silently copies inbound/outbound data to an external address via hidden forwarding rules. Here DLP, by catching the abnormal outbound data flow, also gives a late signal of ATO. (See our ATO article.)
4. Field Note: The "We Don't Send Sensitive Data by Email" Fallacy
The sentence we hear most often in the field: "Our employees don't send sensitive data by email." A DLP discovery scan that follows (without blocking, only observing) changes the picture almost every time: personnel files, IBAN lists, customer database exports, "confidential"-stamped contracts — all in outbound traffic, most of it well-meaning. Because the problem isn't a policy violation, it's the natural flow of daily work: HR sends the payroll file, sales sends a quote, accounting sends a statement. Without DLP, none of this flow is visible — until the wrong recipient is selected.
5. Defense: Making DLP Actually Work
Technology
Check Point Harmony Email & Collaboration provides the following on the DLP side:
- Content-aware classification: Recognizes national IDs, IBANs, credit cards, health data, and custom patterns (your organization-specific project codes, "confidential" stamps) in outgoing email and attachments.
- Flexible action: Blocking, quarantine, automatic encryption (the policy-based method from our encryption article), or admin notification for a matching email — according to risk.
- Wrong-recipient warning: Warning the user at send time on unusual recipient/domain combinations.
- Outbound anomaly detection: Flagging unusual data flow from a compromised account or a departing employee.
- Logging and reporting: Logging policy matches for the KVKK burden of proof.
Process and People
- Data classification policy: Defining what is "sensitive" (aligned with KVKK categories) is the foundation of DLP; without classification the engine can't know what to look for.
- Phased rollout: First discovery/observe mode (seeing the existing flow without blocking), then gradual blocking — to avoid locking up the workflow.
- Awareness: A "sending work data to a personal email isn't innocent" culture; the reflex to pause and look before sending, against wrong-recipient risk.
Frequently Asked Questions
Does DLP surveil my employees? Wouldn't that violate KVKK?
DLP works to detect policy patterns (like IBANs, national IDs), not to individually "read" content. Configured correctly, its purpose is not to monitor the employee but to protect the organization and data subjects. Still, the employee-monitoring dimension requires transparency under KVKK and labor law; when deploying DLP, informing employees and having a written policy is recommended.
Microsoft 365 has its own DLP — do I need anything else?
Microsoft 365 Purview DLP is a strong foundation and works in many scenarios; but it depends on license tier and its setup/management requires expertise. An API-based email security layer combines DLP with phishing/ATO/internal-traffic protection in the same panel and lets you manage incident response from one place. The two don't conflict; most organizations use one, or both in a layered way, according to need.
Won't false positives lock up the workflow?
That's why you start in discovery/observe mode: the engine first only observes, policies are tuned to your real flow, then you move to gradual blocking. A well-tuned DLP targets only real risks without slowing daily work.
Can we measure how much data flows out by email in our current state?
Yes — and this is usually the most revealing step. In a 14-day observe mode, without blocking any email, we report which types of sensitive data flow in outbound traffic and how often. For most organizations this report alone is convincing.
What Should You Do Now?
One question: "If an employee accidentally (or deliberately) sent a customer list out today, could we stop it — or even notice it?" If the answer is "no," you also have a clear gap in KVKK terms.
- Free Field Audit + DLP Observe Scan: We report the sensitive data (in KVKK categories) flowing in outbound traffic, without blocking.
- Phased DLP setup: Classification policy, transition from observe to blocking, and logging for the KVKK burden of proof.
About this article: Part of our Thematic Series; it covers the "outbound" direction of email security and the KVKK connection. Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. This content is for general information and is not a substitute for legal advice.