You are here:
Create a Dynamic Data Masking Policy for Structured Data in Data 360
Protect sensitive information by restricting data visibility based on user roles and permissions.
Required Editions
Before You Begin
Review these important considerations to ensure your masking policies work as expected.
- If a field used in a data graph is governed by a masking policy, users can’t access this data graph.
- If a Boolean field is masked, the value is always displayed as False, regardless of the field’s actual value.
| Available in: All Editions supported by Data 360. See Data 360 edition availability. |
| User Permissions Needed | |
|---|---|
| To create a dynamic data masking policy: | Permission set:
|
- In Data Cloud, go to the Data Governance tab.
- In the left pane, click Policies.
- Click New, select Dynamic Data Masking, and click Next.
-
In Policy Builder, enter a unique policy name, and an optional description.
The policy API name is auto-filled based on your policy name, but you can change it.
- Click Next.
-
Select Rules, and select the resources to protect. In the
Resource dropdown, select Field in Structured
Data.
By default, the rule applies across all data spaces. As new data spaces are added, these rules apply to their resources.
- To restrict policies to specific data space scopes, click Customize Scope, deselect Apply to the resources in all Data Spaces in Data Cloud, and select the desired data spaces.
- Click Save.
- Select the action you want to take on the resource. From the Action dropdown, select Mask.
-
Select one of the following masking methods.
- Redaction - Replace masked characters with X. Select the number of characters to redact.
- Nullification - Replace data with NULL.
- Datetime Rounding - Simplify date and time display by showing only the year or the year and month.
- Numeric Rounding - Round numbers to the nearest whole number or the specified decimal places.
- Define the conditions when this action must take place. For example, set a condition to trigger the rule if the Financial Data.Account Info tag is present in the object. Or, if the Personal Data.Digital Identifier.Browsing History tag is not present in the object.
- To add more conditions, click Add Condition.
- To group your conditions into different sets, click Add Group. You can use the OR operator to take action when any group meets the rule conditions.
- Click Save and Activate.
Did this article solve your issue?
Let us know so we can improve!

