You are here:
Create a Dynamic Data Masking Policy for Unstructured Data (Beta)
Define a masking policy to protect sensitive information in unstructured files such as PDFs and text documents.
Required Editions
| Available in: All Editions supported by Data 360. See Data 360 edition availability. |
Note Content tagging and unstructured data masking is a pilot or beta
service that is subject to the Beta Services Terms at Agreements - Salesforce.com or a written Unified Pilot Agreement if executed by
Customer, and applicable terms in the Product Terms Directory. Use of this pilot or beta service is at the
Customer's sole discretion.
| User permission needed | |
|---|---|
| To create a dynamic data masking policy: | Data Cloud Architect permission set |
To create a dynamic data masking policy:
- In Data Cloud, go to the Data Governance tab.
- In the left pane, click Policies.
- Click New, select Dynamic Data Masking, and click Next.
- In Policy Builder, enter a unique policy name and an optional description. The policy API name is automatically filled based on your policy name, but you can change it.
- Click Next.
-
Select Rules, and select the resources to protect. In the Resource dropdown, select
String in Unstructured Data.
By default, the system applies the rule across all data spaces. As new data spaces are added, the system rules apply to their resources.
- To restrict policies to specific data space scopes, click Customize Scope, deselect Apply to the resources in all Data Spaces in Data Cloud, and select the desired data spaces.
- Click Save.
- Select the action to take on the resource. From the Action dropdown, select Mask.
-
Select one of these masking methods:
- Redaction - Replace masked characters with X. Select the number of characters to redact.
- Nullification - Replace data with NULL.
-
Define the conditions when this action takes place.
For example, set a condition to trigger the rule if the
Financial Data.Account Infotag is present in the object. Or set a condition if thePersonal Data.Digital Identifier.Browsing Historytag isn't present in the object. - To apply the policy to users, select Users.
- Apply the policy to all users or to users who meet specific AND and OR conditions. The conditions are based on custom permissions assigned to users.
- To add more conditions, click Add Condition.
- You can also group your conditions into different sets and use the OR operator to take action when a group meets the rule conditions. To add a group, click Add Group.
- Click Save and Activate.
Did this article solve your issue?
Let us know so we can improve!

