This guide explains the ten essential Microsoft 365 security controls we recommend for charities to reduce cyber risk, improve governance and strengthen long-term resilience.

Control 9 of 10 Next Control >

Bunker Snapshot - Data Loss Prevention (DLP) at a glance

Estimated reading time 🕒 45 seconds

Everything you need to know about this security control in under 60 seconds.

Business impact

🔴 Security improvement
🔴 Risk reduction
🟡 Operational impact

High
Very High
Medium

Related Controls

Next Steps

Identify the types of sensitive information your charity stores, configure Data Loss Prevention policies and test how Microsoft 365 detects and protects confidential data.

Charity Insight

Many charities don’t experience data breaches because of sophisticated hackers—they occur through accidental sharing of documents, misdirected emails or incorrectly configured permissions. Data Loss Prevention helps prevent these common mistakes before sensitive information leaves your organisation.

What it does

Prevents sensitive information from being accidentally or deliberately shared outside your organisation by monitoring and controlling how data is stored, accessed and shared across Microsoft 365.

Why it matters

Protects donor information, financial records, employee data and other sensitive information, helping reduce the risk of data breaches and supporting compliance with UK data protection requirements.

Time to implement

3–6 hours

(Depending on the number of policies and sensitivity labels required.)

Who it affects

All Microsoft 365 users who create, access or share sensitive information through Exchange Online, SharePoint, OneDrive and Microsoft Teams.

Implementation difficulty

MEDIUM

Licensing

Basic data protection capabilities are available with selected Microsoft 365 licences. Advanced Data Loss Prevention features require Microsoft 365 Business Premium, Microsoft 365 E5 or Microsoft Purview licensing, depending on the functionality needed.