Proofpoint is expanding its data security capabilities across Asia Pacific and Japan (APJ), with India emerging as a key market. The move comes as enterprises accelerate AI adoption while facing growing data sovereignty and regulatory requirements.
Proofpoint has announced a regional expansion of its data security capabilities across Asia Pacific and Japan (APJ).
The Proofpoint data security expansion brings its unified, intent-based data security platform closer to organisations across the region. The company says the move will help enterprises protect sensitive information as artificial intelligence changes how data is accessed, processed and used.
The expansion includes local data centre infrastructure, Data Security Posture Management (DSPM), AI data access governance and automated compliance mapping.
India, Singapore and Japan are among the markets targeted by the regional rollout.
AI adoption raises enterprise data security risks
AI adoption is moving rapidly from experimentation into enterprise workflows.
Proofpoint’s 2026 AI and Human Risk Landscape report found that 86% of APJ organisations have moved AI assistants beyond the pilot stage. Another 74% are advancing autonomous agents.
However, the security posture is not keeping pace.
According to the report, 51% of APJ organisations describe their security posture as catching up, inconsistent or reactive.
This creates a significant governance challenge. AI assistants and autonomous agents can inherit permissions assigned to human users and enterprise applications.
Excessive permissions can consequently expose sensitive information to AI systems at unprecedented speed and scale.
Proofpoint also identifies shadow AI and AI over-permissioning as emerging challenges for security teams.
George Lee, Senior Vice President, Asia Pacific and Japan, Proofpoint, said organisations now need to address data protection and regulatory compliance as connected challenges.
The company argues that protection must understand how data is actually being used while supporting local requirements for data hosting and governance.
India becomes a major focus of the expansion
India is central to the Proofpoint data security expansion.
The company already supports locally delivered Email Data Loss Prevention (DLP), Endpoint DLP/Insider Threat Management (ITM) SaaS and Cloud DLP capabilities in India.
Proofpoint plans to add locally delivered DSPM capabilities in India during Q3 2026.
The timing is significant for enterprises navigating India’s evolving privacy framework, including the Digital Personal Data Protection (DPDP) Act.
Proofpoint also plans automated compliance mapping capabilities. These can map data risk findings to recommended controls aligned with regional regulatory requirements and more than 25 compliance and regulatory frameworks.
For Indian enterprises, this could provide greater visibility into sensitive data exposure while connecting data security controls with compliance requirements.
Proofpoint expands local infrastructure across APJ
The regional rollout extends beyond India.
In Singapore, locally delivered Email DLP, Endpoint DLP/ITM SaaS and Cloud DLP are planned for Q4 2026. DSPM is planned for Q2 2027.
In Japan, Cloud DLP and DSPM are planned for Q1 2027.
Australia already has locally delivered Email DLP, Endpoint DLP/ITM SaaS and Cloud DLP capabilities.
The expansion reflects the growing importance of data residency and sovereignty for multinational organisations.
Enterprises operating across APJ must increasingly manage different privacy and data protection requirements across individual jurisdictions.
Local infrastructure can therefore become an important component of broader enterprise data governance strategies.
AI data access governance addresses over-permissioning
A key element of the Proofpoint data security expansion is AI data access governance.
Security teams will be able to understand which employees and AI agents can access sensitive data. They can then identify and remediate excessive access before those permissions are inherited or amplified by AI systems.
This changes the focus of data security.
Instead of asking only where sensitive data is stored, organisations also need to understand who or what can access it, what they can access and whether that access is appropriate.
The issue becomes particularly important as enterprises deploy AI assistants and autonomous agents across business processes.
An employee with excessive permissions creates one potential exposure. An AI agent operating with those permissions could potentially interact with sensitive information across multiple workflows.
Data loss remains a significant APJ problem
The scale of the challenge is highlighted by Proofpoint’s latest Voice of the CISO research.
The company reports that 99% of CISOs in India experienced material data loss during the past year.
In Singapore, the figure stood at 91%.
Both figures are substantially higher than the reported 66% global average.
The findings are notable because DLP adoption is already widespread across the region.
This suggests that the challenge is moving beyond simply deploying DLP technology. Security teams increasingly need visibility across sensitive data, user behaviour, access permissions and threat context.
From fragmented controls to unified data security
Proofpoint is positioning its platform as an alternative to fragmented approaches that treat users and data separately.
The platform combines Data Security Posture Management, Enterprise DLP, Adaptive Email DLP and Insider Threat Management.
These capabilities are intended to help organisations discover and classify sensitive data, prevent its loss across business channels and detect risky behaviour involving careless, compromised or malicious users.
The approach also accounts for the growing presence of AI within enterprise workflows.
Email, cloud applications and collaboration platforms are increasingly becoming environments where employees and AI systems interact with corporate information.
A unified approach can therefore provide security teams with a broader view of how sensitive data moves across those environments.
Data sovereignty becomes a strategic priority
The Proofpoint data security expansion also highlights the growing importance of data sovereignty across APJ.
India’s DPDP Act, Singapore’s Personal Data Protection Act (PDPA), Japan’s Act on the Protection of Personal Information (APPI) and Australia’s Privacy Act represent different regulatory environments for organisations handling sensitive information.
For multinational enterprises, managing these requirements consistently can be complex.
Proofpoint’s regional strategy combines local delivery capabilities with compliance mapping and data security controls.
The objective is to help organisations understand their data exposure while aligning security practices with regulatory requirements in individual markets.

What the expansion means for Indian enterprises
The Proofpoint data security expansion arrives as Indian organisations move increasingly from AI experimentation to operational deployment.
That transition introduces a new dimension to enterprise cybersecurity.
Security teams must now consider AI assistants and autonomous agents alongside employees, applications and conventional endpoints.
They must also understand how AI systems interact with sensitive information and whether existing permissions remain appropriate when those systems gain access.
For India, the planned local DSPM capability in Q3 2026 adds to Proofpoint’s existing locally delivered DLP capabilities.
The broader APJ rollout also reflects a larger industry shift: AI security, data security and regulatory compliance are increasingly becoming interconnected enterprise priorities.
As organisations expand their use of AI, protecting sensitive information will require more than preventing accidental data loss. It will require continuous visibility into data, users, permissions, AI agents and the regulatory environment governing them.

