Question about Data Protector program exclusion

Recently Data Protector has been blocking some programs from writing logs to My Documents. Since I am unable to remove the folder because it is a default folder and greyed out, the only solution is to block the executable from Data Protection.

The purpose of Data Protection is to prevent programs from getting sensitive data. If I exclude the program so it can access the required subfolder in My Documents, what would prevent it from accessing data outside this folder?

Rather than creating an exception for an executable, shouldn't there be an option to create an exception for a folder? This way I can allow my executable to write to My Documents\some_folder while preventing it from also accessing My Documents\bank_info.