Data access control - Why data governance with third-party apps matters

Posted by Dallen Clark on Aug 10, 2026 • Updated on Aug 10, 2026

Nowadays, companies have data in all sorts of places. And nearly every single organization has sensitive, proprietary, or confidential information that has been unintentionally shared with external parties or tools. This is a major problem that's only been exacerbated by the growth of AI, and companies, technology, and legislation are still trying to catch up. 

Because this is such a massive issue, multiple enterprises and solutions have tackled how to stop sensitive data from being accessed by the wrong people, tools, and companies. These solutions fall under Data Governance, which, as a whole, are solutions and policies that focus on how data is secured, made available, and shared. 

For this article, we'll focus on a small section of data governance, including how data leakage happens, and then show some of the solutions to help restrict sensitive files from being given to third-party apps and tools. 

How data leakage happens

There are a lot of ways that data leakage happens, especially now that most businesses work with hundreds of different SaaS platforms. In a Proofpoint survey, over half of respondents claimed that insider threats were the top cause of data loss, citing risky behaviour from employees, partners, and contractors as a significant security threat.

But there are many other places where data is leaked, including:

  • Oversharing with employees
  • Providing access to external parties
  • Cyberattacks or system compromise
  • Giving data to unapproved AI tools
  • Sending data off to third-party SaaS providers

These last two make up a thin slice of data governance, focused around controlling data that is sent to third-party systems like SaaS platforms and AI tools.

Giving data to AI tools

Most employees wouldn't give confidential data to a consultant who cold calls with an offering to help the business, because that's obviously a massive risk. The data shows the same care isn't given to AI tools, however. 

One study from Telus Digital showed that 57% of employees admit to inputting sensitive info into GetAI assistants. Over half of employees are not only using AI, but using it with sensitive information. 

Maybe you don't think that's an issue, because your organization has a business or enterprise plan with a data processing agreement that negates the risks of this behavior. ChatGPT's Enterprise Privacy page, for instance, directly says that your organization retains ownership and control of your data and that it won't be used to train models. And as long as you don't explicitly choose to make data public, it stays private. 

These aren't the tools that are the problem. 

Multiple surveys and studies show that as much as 2/3 of employees are using company data with unsanctioned AI tools. These "shadow AI" tools tend to be consumer-facing, free versions on personal accounts. And most importantly, they don't have the same kinds of data protections as an enterprise account. 

It's not just AI tools either. Shadow IT, unapproved tools employees use (sometimes intentionally hiding them), has been a problem for security teams and IT service providers for decades. And it's only getting worse with the rise of SaaS services. 

 

Sending data to SaaS providers

Now that the SaaS model has become the norm, every business has third-party SaaS providers processing data in some way. In fact, a 2026 BetterCloud survey estimates that on average, companies have 106 different SaaS apps

All of these need to process data you provide them in some way. 

Since many of them are purpose-built, it makes sense for them to have access to specific types of data. For example, no one blinks about Stripe having access to payment details, because that's the entire point. But what about the app you're testing with a free trial? Or the marketplace app that slots into your CRM that can read all its data? 

Some SaaS apps have way more permissions than they need. It's similar to downloading a new app and leaving permissions to "see and edit all your data" (don't do that) and not thinking twice. Most SaaS apps are nowhere near this extreme, but they are still given much more access than they need to function. 

Organizations that are already concerned about data loss know this is a problem already. According to Proofpoint's 2025 data security landscape report, 46% of organizations cite data sprawl across cloud and SaaS apps as a top security challenge

These are the ones that have been approved too. Unapproved tools that haven't gone through the company's vetting process might not have the right data protections in place, or in the most egregious cases, can sell the data to third parties as part of their terms and conditions. Ideally, only approved applications would be used to stop this, but in reality nearly every single employee is using at least one Shadow IT app, and many have access to much more data than they should. 

Isn't Couchdrop a SaaS provider?

Yes, Couchdrop is technically one of these SaaS providers. However, as we're in the secure data space, we take it seriously. With Couchdrop, you have full control over where data processing activities happen and data streams directly between platforms; we never take custody of the files at any point.


Because of this, we are SOC 2 and GDPR compliant and can also work with HIPAA data via an exclusive HIPAA-ready infrastructure and will sign a BAA for customers needing compliance assurance.


For organizations requiring an even greater level of security, you can also disable support team access, meaning no one at Couchdrop can have visibility into your environment even for troubleshooting.

Solutions to stop data leakage to third parties

If organizations in all industries in all locations know that data leakage is a serious problem, what are they doing to stop it? 

With the amount of data a typical company has (terabytes to petabytes), manual inspection isn't an option. And even if it is, the data may be things the person shouldn't have access to in the first place like PHI. This can make it a Catch-22 because sensitive data might be flowing through to the wrong places, but there isn't someone who has both the technical abilities and approval to make sure that's the case. 

Because of this infeasibility, organizations are looking into tools to handle the oversight instead. Typically, the solution will be either a dedicated data governance platform or a DLP tool. 

Data governance platforms

A data governance platform is a centralized system that handles all aspects of data management. The platforms can be configured to monitor users and data stores, ensure all data policies are being followed, and stop sensitive data from being transferred to external companies. Some have even started detecting Shadow IT and AI, with features like prompt interference for LLMs that strip out prompts and attachments with certain content signatures from ever being sent to the AI tool. 

Some of these tools are extremely powerful and can significantly limit the opportunities for data to be sent to external parties or tools accidentally. But they aren't an option for every organization. 

The main downside is the cost. For most businesses, the cost of using a data governance platform is simply too high, and significantly outweighs the benefits. Large Enterprises in regulated industries like finance and healthcare will use the full capabilities of the platform, so the security and compliance assurances are worth the price. But for smaller businesses that have a limited amount of sensitive data, they often don't make sense. 

Recently, some platforms are trying a usage-based model that makes them much more affordable for small use cases. However, this carries some risk and cost volatility, especially when the platform is being overused or has been set up improperly. To be effective, the business already needs to have some idea of how much usage they require or else costs can quickly balloon.

As a result, many organizations look to other solutions like data loss prevention tools instead. DLP tools can be enough to give these smaller companies a protective safeguard without having to work within a full data governance platform. 

Data Loss Prevention tools

A data loss prevention tool is a tool that protects from data loss. Typically, they stop data from being sent to external parties and control access to internal data to prevent oversharing and improper access. 

Depending on the tool, they can do everything from inspecting the data to scrubbing out information that matches content signatures, such as social security numbers. More powerful tools can even regularly inspect data at rest and alert if there are files with content that shouldn't be stored where it is. These tools can not only stop access by the wrong people (whether inside or outside the organization), but also make data that would otherwise breach compliance safe to be used in a broader set of workflows. 

You can find out more about Data Loss Prevention and how it works in our article What is DLP? 

Like with data governance platforms, a lot of the effectiveness of DLP tools comes from the policies, configuration, and how much leeway there is. For example, some DLP tools can outright block data exchange that breaches policy, or they can notify an admin or manager while still letting it happen. Depending on the data involved and the workflows in question, one or the other approach may make more sense. 

For file transfers, it's not uncommon for the automated workflows to be tested, confirmed they're working, then put into production without worrying about them again. In some cases, this can cause sensitive data to fall through the cracks without anyone noticing, and if the files you receive or send to external parties change for some reason, the wrong people can get access. 

Couchdrop's Transfer Shield feature is designed specifically to simplify these types of scenarios and make it easy to stop sensitive data from ending up in the wrong place. 

 

Stopping data leakage at the transfer layer with Transfer Shield

One way to reduce data being sent by third parties is using a tool to automatically detect content signatures that match your policies and act accordingly. Transfer Shield can do this at the organization or folder level. 

For instance, if a customer list file is about to be sent to a trading partner or downstream system, Transfer Shield can identify that the file contains potentially sensitive information. Then, depending on the rules you set, either notify admins, require manual approval, or block the transfer from happening. 

Transfer Shield can detect hundreds of file types and content signatures, letting you match exactly what you need for your workflows. It helps you to stop sensitive data going to the wrong place and helps reduce the data governance risk profile in one area that is commonly overlooked. 

You can try Transfer Shield and other features as part of a Couchdrop free trial. Simply register for an account to get instant access for 14 days with no credit card required. Get started and start your free trial now