Managing and responding to DLP policy violations
In the case where a DLP policy alerts an admin that a DLP policy violation has occurred, it can have multiple meanings. It does not always mean that data loss has occurred or has been stopped. You will get alerted if a policy violation has been observed; however, the policy will not take any action based on the reason for trying to share the data that is protected. Escalating any violation to the organization's security team is a reactive action you can take, and you would work with them and key stakeholders to investigate the issue.
A good example is if you are working for an organization that protects highly sensitive information (financial data is a common example) to stop any sharing of client data with third parties. You get several alerts at the end of the month that there have been violations of the specific policy in place for this. When you look at the reports, you see a high level of emails from a department within...