top of page

How can businesses prevent data leaks when employees leave?

To prevent data leaks when employees leave, businesses must control access throughout the employment lifecycle, monitor bulk data exports, deploy Data Loss Prevention, and standardize offboarding procedures.

Customer data is not only threatened by external hackers. Employees, contractors, and third-party personnel with legitimate access may also copy information through export functions, personal email accounts, cloud storage services, USB devices, or artificial intelligence tools.

Preventing data leaks when employees leave should therefore not begin on their final working day. Businesses need access controls, monitoring, and data protection measures throughout the employment lifecycle, supported by coordination between human resources, IT, cybersecurity, legal teams, and direct managers.

How did the alleged customer data copying incident happen?

A post in the r/Entrepreneurs community claimed that an employee exported a database containing 340 customer records two days before their final working day. The data allegedly included contact information, project histories, and internal notes. The author also claimed that two customers moved to a competing business after the incident.

customer-data
Customer data includes not only names and phone numbers, but also a wealth of other information.

However, the post did not identify the company, provide investigation records, or include independent confirmation. Some Reddit users also questioned whether the story was authentic. The figures should therefore be treated as claims made by the author, not as facts from a verified data breach.

Although the account remains unverified, it illustrates a common risk pattern: an employee uses legitimate access to export data shortly before leaving, while the business lacks alerts for unusual download or export activity.

A more clearly documented legal case was analyzed by Ius Laboris in the Netherlands. In that case, an employee transferred 791 documents from a company server to a personal Dropbox account after learning that their contract would not be renewed. The court found that immediate dismissal was justified because the employer had established an IT policy and repeatedly reminded employees of its requirements.

Data exposure during employee departures does not always begin with malware or unauthorized system access. Employees may use the accounts, devices, and export features legitimately provided by the organization to transfer information outside the business.

Why must data leakage be prevented before an employee’s final day?

A customer list usually contains more than names, phone numbers, and email addresses. In a customer relationship management system, each record may include decision-makers, transaction histories, pricing, undisclosed requirements, contract status, internal notes, and future purchasing plans.

This information can provide a significant advantage to a competitor. A person with access to the data may know whom to approach, when to contact them, which price to offer, and which weaknesses in the existing customer relationship to exploit.

Data type

Risk if copied

Priority control

Contact information

Unauthorized outreach, spam, fraud

Role-based access control

Transaction history

Price and contract competition

Field-level access restrictions

Internal notes

Exposure of customer needs and weaknesses

Data classification and DLP

Quotations and contracts

Loss of commercial advantage

Download restrictions and watermarking

Personal data

Complaints and compliance exposure

Incident assessment and evidence preservation

Conway, Deuth & Schmiesing recommends that businesses determine who can access customer lists, whether privileges are limited according to business need, whether employees can download an entire database, and whether activity logs are reviewed regularly.

Preventing data leaks when employees leave should therefore be treated as part of data governance and insider-risk management, rather than as an administrative task performed only on an employee’s final day.

Which channels can employees use to transfer data outside the business?

One of the most common channels is a legitimate export feature in a CRM, ERP, or customer management platform. Employees may also send files to personal email accounts, upload them to Google Drive or Dropbox, copy them to USB devices, transfer them through messaging applications, or store them on personal devices.

social-channels
Besides social media, employees can also transmit data by taking screenshots.

Less visible techniques include taking screenshots, printing documents, manually copying small amounts of information, or photographing data with a mobile phone. Monitoring file downloads alone may not generate clear alerts for these activities.

Generative AI tools introduce another potential leakage channel. “Shadow AI” refers to employees using AI platforms that have not been approved or controlled by the organization. Customer information, contracts, source code, and internal documents may be submitted in prompts for summarization, analysis, or content generation.

Once information has been sent to an external service, the business may not know how long it will be retained, where it will be processed, or whether it could be used to improve a model. An AI policy should therefore define which tools are permitted, which categories of data cannot be uploaded, and which use cases require prior approval.

Businesses using Microsoft 365 can refer to the approach described in protecting corporate data from transfer through Zalo PC. Combining Microsoft Purview Endpoint DLP with Microsoft Intune can help identify sensitive documents, restrict application access, and record events for investigation.

For AI usage, the article enterprise AI adoption and related legal risks provides additional context on AI policies, data classification, and controls for information submitted to external platforms.

Personal email, cloud storage, USB devices, messaging applications, screenshots, and AI tools can all become data exfiltration channels. DLP should be combined with device management, access control, monitoring, and policies governing external services.

What legal obligations may apply to exposed data in Vietnam?

Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 took effect on January 1, 2026. The Law on Data No. 60/2024/QH15 took effect on July 1, 2025, while the Law on Artificial Intelligence No. 134/2025/QH15 took effect on March 1, 2026.

When a customer list contains information that can identify an individual, the incident may need to be assessed from a personal data protection perspective. Businesses must also examine confidentiality obligations in contracts, customer agreements, labor rules, and internal information-system policies.

Whether an organization must notify customers or a competent authority depends on the type of information involved, the scope of the incident, the roles of the relevant parties, and the results of a legal assessment. A company should not issue notifications before verifying the facts, but it should not delay the assessment process.

A general confidentiality clause in an employment contract may not cover every possible form of misconduct. In the Dutch case analyzed by Ius Laboris, the court accepted the grounds for dismissal but rejected a contractual penalty claim because the confidentiality provision did not sufficiently cover the transfer of documents to a personal account.

Employment contracts, nondisclosure agreements, IT policies, AI policies, and employee-monitoring procedures should be reviewed under Vietnamese law. Monitoring must also be transparent, based on a legitimate purpose, and proportionate to the identified risk.

What should a business do immediately after detecting a possible data leak?

The first objectives are to prevent further access and preserve evidence. A business should not immediately delete accounts, reformat devices, or confront the employee before collecting the logs and investigation data that may be required.

Checklist for the first 24 hours

  • Suspend relevant accounts, active sessions, and access tokens.

  • Revoke access to CRM, email, VPN, cloud platforms, and SaaS applications.

  • Preserve logs for downloads, sharing, email, USB usage, and endpoint activity.

  • Identify affected files, data fields, and the number of records accessed.

  • Review related devices, IP addresses, and destination accounts.

  • Notify human resources, IT, legal counsel, cybersecurity teams, and responsible executives.

  • Determine whether the information includes personal data or trade secrets.

  • Prepare customer communications based only on verified facts.

TRG International also emphasizes clearly dividing responsibilities between IT and human resources, managing accounts centrally, and revoking access promptly when an employee leaves.

Prevention checklist for the next 30–90 days

  • Apply Role-Based Access Control and the principle of least privilege.

  • Require approval for bulk exports from CRM systems.

  • Create alerts for abnormal downloads and after-hours access.

  • Classify customer data and develop appropriate DLP policies.

  • Standardize offboarding across HR, IT, legal, and management teams.

  • Review nondisclosure agreements, data clauses, and asset-return obligations.

  • Audit employee and contractor access regularly.

  • Establish rules for personal email, cloud storage, USB devices, and AI tools.

  • Deliver role-based training to personnel who handle sensitive information.

Preventing data leaks when employees leave requires controls before, during, and after offboarding. Disabling an account is only one step; businesses must also monitor data exports, identify abnormal behavior, and preserve evidence.

What does IPSIP’s expert perspective indicate?

Root Cause: Weaknesses that commonly enable this type of incident include excessive access privileges, insufficient data classification, uncontrolled export functions, and poor coordination between human resources and IT.

Attack Vector: Employees may use legitimate accounts to export CRM records, forward emails, upload files to cloud services, copy information to personal devices, or submit data to AI tools. This is an insider-risk scenario and does not necessarily involve an external intrusion.

Business Impact: An organization may lose customers, revenue, pricing advantages, contractual information, and trust. When personal data is affected, the business may also face compliance assessments, complaints, investigation costs, and incident-response expenses.

Lessons Learned: Organizations should not wait until an employee resigns to review access rights. Prevention depends on how privileges are designed, how data is classified, and whether unusual activity is detected throughout the employment period.

What can businesses implement internally?

Businesses should create an inventory of systems that store customer information, assign data owners, and grant access according to actual business needs. Bulk downloads, sharing, permission changes, and deletion activities should be logged.

Unusual export events should be forwarded to a SIEM or centralized monitoring platform. Encryption can reduce the usability of copied information, but it does not replace DLP, access management, and behavioral monitoring.

Offboarding procedures should also use different risk levels. Sales employees, senior executives, and personnel with access to sensitive information may require stricter controls than standard user accounts.

Which IPSIP solutions are relevant?

  1. Data Encryption and Data Loss Prevention: Businesses need to limit sensitive data transfers through email, cloud services, USB devices, and unauthorized applications. IPSIP’s enterprise data encryption solution can be combined with data classification and DLP to improve control over information stored on user devices and cloud platforms.

  2. 24/7 Security Operations Center: When an organization lacks continuous monitoring capabilities, IPSIP’s 24/7 SOC service can support centralized log collection, alert analysis, and the detection of unusual account or endpoint activity.

  3. Security Awareness Training: Employees must understand which information cannot be sent to personal email accounts, cloud platforms, or AI tools. IPSIP’s enterprise cybersecurity training can be adapted to specific roles and real-world data-handling scenarios.

Preventing data leaks when employees leave cannot depend solely on trust, confidentiality agreements, or disabling an account on the final working day. Vietnamese businesses need to combine human resource governance, technical access controls, DLP, log monitoring, and personal data protection assessments.

The immediate priorities are to review CRM export permissions, standardize offboarding procedures, and establish alerts for abnormal download activity. Controls implemented before an incident are far more effective than attempts to recover information after it has already left the organization.

---------------------------


Frequently Asked Questions (FAQ)

Should an account be locked immediately after an employee resigns?

Not in every case. Businesses should assess the employee’s role, the data they can access, and the associated risk. Unnecessary privileges should be revoked, while sensitive activities may require additional monitoring or approval.

No. A business generally needs to demonstrate that the information has commercial value, is not publicly available, and has been protected through reasonable measures. Unrestricted access may weaken the organization’s ability to claim that the data was confidential.

No. DLP can detect or restrict many channels, including email, USB devices, cloud services, and applications, but it must be combined with device management, access controls, monitoring, and employee training.

Only when the tool has been approved and the processing purpose is appropriate. Sensitive information should be minimized, anonymized, or removed before being submitted to an external platform.

That depends on device ownership, previously communicated policies, consent, and applicable law. Businesses should obtain legal advice before accessing or collecting information from a personally owned device.

--------------

Refferal

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page