Beta update: Data loss prevention rules based on classification labels are now applied instantly in Gmail on the web
What’s changing
In November 2024, we announced an open beta for data classification labels in Gmail. To further enhance the experience, we’re pleased to announce that auto-classification labeling with data loss prevention (DLP) rules and actions triggered by classification labels detected in the message will now be applied instantly when using Gmail on the web. Previously, users were informed of any implications after messages left the inbox. With this update, the feedback is instant, providing the opportunity to educate users on why their message is classified, blocked or quarantined, and how to remedy the issue to keep their email communications flowing.
With this new functionality, and with this feature still in an open beta period, we strongly encourage you to continue providing feedback so we can optimize the feature for general availability. You can also use the form to sign-up for feedback sessions with the Google user research team to provide more detailed feedback.
Who’s impacted
Admins and end users
Why it matters
Google Workspace's expansion of data classification labels to Gmail gives admins the ability to mitigate data exfiltration and gain a deeper understanding of shared data based on information type and sensitivity level to apply data protection policies appropriately. Some ways you can use Data Protection Rules with Classification Labels are:
- Prevent messages based on a specific classification (e.g. Confidential, Internal, NTK) from being accidentally shared with unauthorized users.
- You can create a rule with specific label(s) as a condition and choose an action to trigger when a message is sent:
- Warn: users will see a notification that their message may contain sensitive information, helping to prevent accidental sharing. Note that this action does not block the message from being sent.
- Block: users will be notified that their message will not be sent unless the label is changed or removed (if data organization policy allows).
- You can also create a rule in a way that allows for sharing labeled messages only if confidential mode is enabled for the message.
- Enforce classification on every message or specific messages
- You can create a rule that warns users or blocks the message if a specific classification label is not found in the message. This can help educate users and drive adoption of your organization’s data classification policy among users.
- Automatically apply classification labels messages if specific information types are found in the message
- You can create a rule to automatically apply a specific classification label if certain criteria is met. For example, credit card information or medical information are contained within the email.
- You can also configure the rule to allow users to modify the label to a more appropriate one based on the situation and data classification policy of your organization.
Additional details
Getting started
- Admins:
- Gmail classification labels can be enabled at the domain, group level, or individual user level. You also have the option to enable existing classification labels used in Drive for use in Gmail. The Label Manager tool can be accessed by going to Security > Access and data control or admin.google.com/ac/dc/labels in the Admin console.
- Visit the Help Center to learn more about getting started with classification labels, Gmail DLP & automatic classification labels, and preventing data leaks in email and attachments.
- Please continue to share your feedback to help us optimize this feature for general availability.
- End users:
- Depending on the data loss prevention rules configured by your admin, you may see a dialog letting you know that your message cannot be shared and how to fix your message so it can safely be shared. Visit the Help Center to learn more about classification labels in Gmail.
Rollout pace
- Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on March 18, 2025
Availability
- Frontline Starter and Standard
- Business Standard and Plus
- Enterprise Standard and Plus
- Education Standard and Education Plus
- Essentials, Enterprise Essentials, and Enterprise Essentials Plus
- Enterprise Standard and Plus
- Education Fundamentals, Standard, Plus, and the Teaching & Learning Upgrade
- Frontline Standard
- Cloud Identity Premium (with a Workspace Edition that includes Gmail)
Resources
Google Workspace Admin Help: Gmail DLP & automatic classification labels (beta)
Google Workspace Admin Help: Get started as a classification labels admin
Google Workspace Admin Help: Prevent data leaks in email & attachments (beta)