It's not always that.
Let's use the "filtering chars from password" example above. You can't put some special chars in password field, and you want to change that so it's doing normal hashing where special chars don't matter.
In a larger org, even changing a practice like that so that it "makes more sense" can have a big ripple effect.
You have to
* explain to someone else on the team who came up with the original process that it's flawed (and why)
* explain to other dept that they need to update their testing process (and why)
* get support dept to change their language/process
* change outbound messaging in all affected places (perhaps with code you can't touch, involving other teams)
* possibly have a flag that deals with 2 versions of data
Even if your change brings you in to line with normal/safe practices, you may have to fight multiple inane battles, spend loads of time and political capital, and at the end of the day, you'll be able to also accept a !"@+'$ in a password field? Most people will not grasp the bigger issue at play.