openapi: 3.2.0 info: title: Tech Risk & Compliance - Enterprise Policy Management… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Enterprise Policy Management APIs are used to integrate external systems and streamline the flow of data with Enterprise Policy Management in the OneTrust platform. servers: - url: https://{hostname}/api/enterprise-policy variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Document Attachments description: The Document Attachments APIs are used to manage attachments on document objects such as policies, standards, procedures, and privacy notices. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-enterprise-policy-management.json paths: /v1/{complianceType}/{policyId}/documents: post: operationId: addDocumentToPolicy summary: Add Document Attachments description: Use this API to add attachments to a policy, standard, procedure, or privacy notice. Attachments can include supporting files or related resources. tags: - Document Attachments x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-enterprise-policy-management.json parameters: - name: complianceType in: path description: The type of compliance document. required: true schema: type: string enum: - policies - standards - procedures - privacynotices example: policies - name: policyId in: path description: The unique identifier of the policy, standard, procedure, or privacy notice. This value is obtained using theĀ [Get List of Documents API](/onetrust/reference/getlatestpolicies). required: true schema: type: string format: uuid example: 6756206c-845c-4ecc-8826-0e25d12b0d0c requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DocumentCreateRequest' example: documentRequests: - documentId: a1b2c3d4-e5f6-7890-abcd-ef1234567890 fileName: Policy Supporting Document.pdf fileDescription: Additional documentation for policy compliance documentType: ATTACHMENT responses: '201': description: Documents successfully added to the policy '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - POLICY components: schemas: DocumentCreateRequest: type: object properties: documentRequests: description: The details of the attachments. type: array items: $ref: '#/components/schemas/DocumentRequest' maxItems: 100 minItems: 1 required: - documentRequests DocumentRequest: type: object properties: documentId: description: The unique identifier of the file attached to the policy, standard, procedure, or privacy notice. This value is obtained using the [Upload File API](/onetrust/reference/fileupload). type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 fileName: description: The name of the attachment. type: string example: Data Privacy Policy.pdf minLength: 1 fileDescription: description: The description of the attachment. type: string example: Supporting documentation for data privacy compliance documentLink: description: The URL link of the attachment. type: string format: url example: https://company.com/policies/data-privacy-policy.pdf documentType: description: The type of attachment. type: string enum: - FILE - URL source: description: The source of the attachment. type: string enum: - MANUAL - AI required: - fileName securitySchemes: OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: POLICY: Policy scope for external systems. POLICY_READ: Policy read scope for external systems. x-onetrust: spec-label: OpenAPI 3.1.0 links: - '[{''Policy Management Knowledge Base'': ''https://my.onetrust.com/s/topic/0TO1Q000000bHfCWAU/policy-management''}]' x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false