The paper discusses data loss prevention (DLP) in higher education institutions, since data breaches are becoming more and more common in the recent years. Data compromised in higher education extend far beyond personal and financial data, including also sensitive research data. The environment of openness and collaboration between universities, as well as the typical access of many portable devices make access easier for hackers and detection of unauthorized access difficult. We argue that DLP is of high importance for universities, since they work with a variety of types of data, which are subject to different regulations and besides the necessity some of the data to be kept confidential there is also a counter need some of the data to be made available to the public (as results of academic research for example). The paper discusses how universities can define their critical data, the risks of data loss and strategies to keep their data safe. We discuss 3 main critical data loss prevention objectives, namely personal information protection/compliance, intellectual property (IP) protection and business partner compliance.The most common types of data breaches occurring in the higher education systems are hacking and malware, unintentional disclosure, and portable device breaches. The paper also presents a showcase of how Bulgarian universities address the issues described above.
Keywords: data loss prevention, universities, risk management, intellectual property.