It would all depend on your set up
- Is this a laptop user?
- What is the policy refresh interval setting for your agents?
- Do you have multiple primary and secondary domain controllers within your AD environment?
e.g. 'After a one day interval' for example suggests that the DLP policy is only getting refreshed after a reboot
Have you tried logging the user out and back in again after removing them from the group. Sometimes AD security settings are not refreshed on the fly and only at user login.