GDPR Data Action 403 on PII Masking Endpoint

Just noticed that the Data Action configured for GDPR compliance is returning a 403 Forbidden when attempting to invoke the ServiceNow REST API endpoint for PII masking. The OAuth token is valid, and the ServiceNow user role has explicit write permissions on the target table. Is there a specific IP whitelisting requirement for Genesys Cloud webhook outbound traffic that I am missing in the documentation?