openapi: 3.2.0 info: title: Privacy Automation - Assessment Automation Assessment… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Assessment Automation APIs provide functionality for managing assessment template lifecycle operations, including template export and import for cross-environment migration, retrieving published template metadata with filtering by template type, and template deletion with comprehensive validation checks. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Assessment Management description: The Assessment Management APIs are used to modify, link, and manage existing assessments. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json x-displayName: Assessment Management paths: /api/assessment/v2/assessments/archive: put: operationId: archiveAssessmentsUsingPUT summary: Archive Assessment description: 'Use this API to archive a single assessment or multiple assessments. Multiple assessment IDs can be provided in the API request to archive assessments in bulk. > πŸ—’ Things to Know > > - Archived assessments will be moved into the Archive list after archiving. > > - Archived assessments will be read-only. > > - Dynamic Incident Notification Assessments, Program Benchmarking Assessments, and Maturity & Planning Assessments cannot be archived.' tags: - Assessment Management x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json requestBody: required: true content: application/json: schema: type: array items: type: string format: uuid examples: Assessment IDs: description: Assessment IDs value: - 550e8400-e29b-41d4-a716-446655440000 - 550e8400-e29b-41d4-a716-446655440001 responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-AssessmentAutomation_OAUTH2: - ASSESSMENT /api/assessment/v2/assessments/assessment-links: post: operationId: addManualAssessmentLinksUsingPOST summary: Link Assessments description: 'Use this API to link an assessment to multiple assessments. > πŸ—’ Things to Know > > - This API can be used for linking active and archived assessments. > > - Only assessments with the following template types can be linked: PIA, Vendor, ITRM, Control, Exchange, Incident and ESG.' tags: - Assessment Management x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-AssessmentAutomation_AssessmentManualLinkRequest' responses: '201': description: Created '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-AssessmentAutomation_OAUTH2: - ASSESSMENT /api/assessment/v2/assessments/un-archive: put: operationId: unarchiveAssessmentsUsingPUT summary: Unarchive Assessment description: 'Use this API to unarchive a single assessment or multiple assessments. Multiple assessment IDs can be provided in the API request to unarchive assessments in bulk. > πŸ—’ Things to Know > > - Unarchived assessments will be moved back to the Active list after unarchiving. > > - Unarchived assessments will be editable. > > - Dynamic Incident Notification Assessments, Program Benchmarking Assessments, and Maturity & Planning Assessments cannot be unarchived.' tags: - Assessment Management x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json requestBody: required: true content: application/json: schema: type: array items: type: string format: uuid examples: Single Assessment: summary: Unarchive a single assessment description: Single Assessment value: - 550e8400-e29b-41d4-a716-446655440000 Multiple Assessments: summary: Unarchive multiple assessments in bulk description: Multiple Assessments value: - 550e8400-e29b-41d4-a716-446655440000 - 550e8400-e29b-41d4-a716-446655440001 - 550e8400-e29b-41d4-a716-446655440002 responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-AssessmentAutomation_OAUTH2: - ASSESSMENT /api/assessment/v2/assessments/{assessmentId}/metadata: patch: operationId: updateBasicAssessmentDetailsUsingPATCH summary: Modify Assessment description: 'Use this API to update basic assessment details such as assessment name, assessment description, assessment deadline and reminder. > πŸ—’ Things to Know > > - If the assessment is in **Completed** stage, updates made using this API will be ignored. > > - If an update is made using this API, an event will be shown in the Assessment Activity. > > - This API can update assessments of the following types: PIA, Vendor, ITRM, Control, Exchange and Incident.' tags: - Assessment Management x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: assessmentId in: path description: UUID of the assessment to update required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-AssessmentAutomation_AssessmentBasicDetailsUpdateRequest' responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-AssessmentAutomation_OAUTH2: - ASSESSMENT /api/assessment/v2/assessments/{assessmentId}/primary-records: put: operationId: updatePrimaryRecordUsingPUT summary: Set Primary Record description: 'Use this API to edit the existing primary record or set a new primary record on an assessment. For the given `assessmentId`, the existing primary record will either be updated or a new primary record will be created using the attributes in the API request body. > πŸ—’ Things to Know > > - If the template has a question with the primary record enabled, then the primary record is set as the response to that question and the related attributes and inventory questions will be pre-populated. > > - The primary record can be edited for Inventory and Assess Control primary record types. > > - The primary record list cannot be greater than 1 for Inventory primary record types. > > - The primary record list can be greater than 1 for Assess Control primary record types.' tags: - Assessment Management x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: assessmentId in: path description: UUID of the assessment to update primary record for required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-AssessmentAutomation_AssessmentPrimaryRecordUpdateRequest' responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-AssessmentAutomation_OAUTH2: - ASSESSMENT /api/assessment/v2/assessments/{assessmentId}/soft-delete: put: operationId: softDeleteAssessmentUsingPUT summary: Move Assessment to Recycle Bin description: 'Use this API to soft delete an assessment by moving it to the recycle bin. The assessment will then be stored in the recycle bin until it is either restored or permanently deleted. > πŸ—’ Things to Know > > - Only assessments found in the PIA & DPIA Automation and IT & Security Risk Management modules can be soft deleted. > > - Dynamic Incident Notification Assessments, Program Benchmarking Assessments, and Maturity & Planning Assessments cannot be soft deleted.' tags: - Assessment Management x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: assessmentId in: path description: UUID of the assessment to soft delete required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-AssessmentAutomation_OAUTH2: - ASSESSMENT /api/assessment/v2/assessments/{assessmentId}/tags: put: operationId: addOrUpdateTagsUsingPUT summary: Update Assessment Tags description: 'Use this API to update the tags associated with a specific assessment. The tags submitted through this API will overwrite all existing tags on the assessment. > πŸ—’ Things to Know > > - The Get Assessment API can be used to retrieve the current list of assessment tags for the specified assessment. You can include these tags within the request of this API to keep them on the assessment. > > - New tags can be created using this API and can then be associated with an assessment.' tags: - Assessment Management x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: assessmentId in: path description: UUID of the assessment to update tags for required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: required: true content: application/json: schema: type: array items: type: string examples: Tags: description: Tags value: - GDPR - SIG - tag3 responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-AssessmentAutomation_OAUTH2: - ASSESSMENT components: schemas: PrivacyAutomation-AssessmentAutomation_AssessmentManualLinkRequest: type: object properties: fromId: description: The unique ID of the source assessment to create the link from type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 toIds: type: array items: type: string format: uuid example: 223e4567-e89b-12d3-a456-426614174001 maxItems: 2147483647 minItems: 1 uniqueItems: true required: - fromId - toIds PrivacyAutomation-AssessmentAutomation_AssessmentBasicDetailsUpdateRequest: type: object properties: name: description: The name of the assessment to be displayed in the UI type: string example: GDPR Compliance Assessment 2025 maxLength: 255 description: description: Detailed description of the assessment's purpose and scope type: string example: This assessment evaluates the organization's compliance with GDPR requirements and identifies potential data protection gaps maxLength: 4000 deadline: description: The date by which the assessment must be completed type: string format: date-time example: '2025-12-31T23:59:59.000Z' reminder: description: The number of days before the deadline when a reminder notification should be sent to respondents type: integer format: int32 example: 7 minimum: 1 PrivacyAutomation-AssessmentAutomation_AssessmentPrimaryRecordUpdateRequest: type: object properties: primaryRecordType: description: Type of Inventory record to be updated. type: string example: ASSETS enum: - ASSETS - PROCESSING_ACTIVITY - VENDORS - ENTITIES - ASSESS_CONTROL - ENGAGEMENT primaryRecordIds: description: The unique UUIDs of the primary records type: array items: type: string format: uuid example: - 550e8400-e29b-41d4-a716-446655440000 - 550e8400-e29b-41d4-a716-446655440001 minimum: 1 minItems: 1 uniqueItems: true required: - primaryRecordIds - primaryRecordType securitySchemes: PrivacyAutomation-AssessmentAutomation_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: ASSESSMENT: Access to assessment scope for external systems ASSESSMENT_READ: Access to read assessment scope for external systems Template_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: ASSESSMENT: Access to assessment scope for external systems ASSESSMENT_READ: Access to read assessment scope for external systems x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0