An enterprise cybersecurity and GDPR/CCPA audit identified that sensitive Personally Identifiable Information (PII)—including Social Security Numbers (SSN), credit card tokens, phone numbers, and personal emails—is currently stored in plain unmasked text across Databricks Unity Catalog and Snowflake analytical schemas. Over 140 business analysts have unrestricted access to raw customer identifiers. Engineering must implement tag-based Dynamic Data Masking (DDM) and role-based access policies without disrupting existing reporting or production ML pipelines.