How is SAP UI masking different from database encryption or DAM?
Encryption and network controls protect data at rest and in transit. Database masking protects query results. SAP UI Data Protection redacts sensitive fields at the application / screen layer on SAP GUI, Fiori, and Web Dynpro โ so authorized users still cannot see unrestricted PII unless policy allows a logged reveal.
Which SAP landscapes and UIs are supported?
Rules apply across SAP ECC, SAP S/4HANA, and SAP RISE on SAP GUI, Fiori, and Web Dynpro. Coverage checks highlight missing UI masking setup and related authorization objects before audits or go-lives. Enterprises also use it where SuccessFactors and Ariba feed personal or commercial data into SAP screens.
How does click-to-reveal and break-glass work?
Authorized users can reveal masked fields via Instant, Toggle (session), Workflow (request + approval), or Break-glass (emergency with mandatory justification). Reveals can require reason codes, respect session timeout, and always write to a field-access audit trail for compliance and incident response.
How does this support DPDP (India) and GDPR?
UI masking enforces purpose limitation and need-to-know on HR, payroll, vendor, and customer screens; provides reveal logs for fiduciary / accountability inquiries; and implements privacy by design and by default (GDPR Arts. 25 & 32) on production UIs. It also maps to PDPA, CCPA/CPRA, PCI-DSS, SOX, HIPAA, and ISO 27001 control narratives.
Do I need custom ABAP for each system?
No. Define rules once in AI Tech Secure โ including industry vertical packs for manufacturing, retail, FMCG, telecom, pharma, and public sector โ then deploy via the connector framework. Packs are editable for display names, categories, masking actions, and reveal settings without custom ABAP.