openapi: 3.2.0 info: title: Privacy Automation - Data Subject Request (DSR) Automationโ€ฆ version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, verification methods, and audit history. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Request Queues description: APIs used to create, search, update, and manage privacy request queues. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json x-displayName: Request Queues paths: /api/datasubject/v2/requestqueues: post: operationId: createRequestQueueFromMessageUsingPOST summary: Create Request description: '> โ—๏ธ End of Support Notification > > As of March 3, 2022, this API is now deprecated. Any customers leveraging this API are encouraged to migrate to the Create Request API. For more information, see OneTrust API Sunsetting & Deprecation Guidelines. Use this API to create a request for a given hosted web form. The webform must already be created.' tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DSARRequestDto' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error deprecated: true security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/requestqueues/bulkdelete/{language}: put: operationId: bulkDeleteUsingPUT summary: Delete Requests description: Use this API to delete requests in bulk. The associated subtasks, attachments, and Results Summaries will also be deleted. Request deletion is a permanent action that should be exercised with caution. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: language in: path required: true schema: description: "A language code that identifies the language in which the request data should be returned, assuming translations are available for that language. \nExamples: en-us for English, de for German, fr for French, etc." type: string example: en-us requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueBulkDeleteV2Dto' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueBulkDeleteResponseDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR_WRITE /api/datasubject/v2/requestqueues/delete-certificate/{requestRefId}: get: operationId: getDeletionCertificateUsingGET summary: Get Deletion Certificate description: 'Use this API to retrieve a deletion certificate for a deleted request. The response will serve as the deletion certification and will include details such as the retention policy (if applicable), deletion date and time, and deletion mode. > ๐Ÿ—’ Things to Know > > - Certificate data is available only for requests deleted within the past 360 days.' tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestRefId in: path required: true schema: description: Deleted Request Reference ID (10-character ID that is unique to each request) type: string example: SL244HWD6D responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DeletionCertificateV2DTO' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/requestqueues/id/{requestQueueId}/requesthistory: get: operationId: getRequestHistoryByIdUsingGET summary: Get Request Audit History description: Use this API to retrieve the audit history of a request. The response will include details such as field updates and the date and time when changes were made. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueId in: path required: true schema: description: GUID that is unique to each request. This GUID can be obtained either from the response of the GET /requestqueues/{language} API orfrom the url by navigating to the request details page within the DSAR module in the application. If the request is deleted,obtain the ID by navigating to the request URL from the assignee email. type: string format: uuid - name: page in: query schema: description: Results page you want to retrieve. Page number starts with 0 (0..N) type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query schema: description: Number of records per page. type: integer format: int32 default: 20 maximum: 500 minimum: 1 example: 20 responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestAuditInfoResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/requestqueues/search/{language}: post: operationId: searchForRequestUsingPOST summary: Search Requests description: Use this API to search for requests by key terms, such as the data subjectโ€™s first name, last name, email address, or request ID. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: language in: path required: true schema: description: "A language code that identifies the language in which the request data should be searched, assuming translations are available for that language. \nExamples: en-us for English, de for German, fr for French, etc." type: string example: en-us - name: createddate in: query required: false schema: description: A date (yyyyMMdd). Include to retrieve a list of requests created on or after the specified date. For example, if you want to retrieve requests created on or after January 30, 2019, include the createddate=20190130 parameter in your query. type: string format: date example: 20190130 - name: page in: query schema: description: Results page you want to retrieve. Page number starts with 0 (0..N) type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query schema: description: Number of records per page. type: integer format: int32 default: 20 maximum: 500 minimum: 1 example: 20 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SearchV2Request' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SearchResultPage' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/requestqueues/status/{requestTraceId}: get: operationId: getRequestCreationLogsUsingGET summary: Get Request Creation Logs description: 'Use this API to retrieve the creation details of a request by trace ID. The response will return the created date, creation status, and request ID. > ๐Ÿ‘ > > For more information, see Using the Asynchronous Request Creation API.' tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestTraceId in: path required: true schema: description: Request trace ID type: string format: uuid responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_CreateRequestLogDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/requestqueues/{language}: get: operationId: getAllRequestQueuesV2UsingGET summary: Get List of Requests description: Use this API to retrieve a list of all requests. The response will include details for each request along with the approver, date created, and data subject's first and last name. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: language in: path required: true schema: description: "A language code that identifies the language in which the request data should be returned, assuming translations are available for that language. \nExamples: en-us for English, de for German, fr for French, etc." type: string example: en-us - name: modifieddate in: query required: false schema: description: A date (yyyyMMdd). Include to retrieve a list of requests modified on or after the specified date. For example, if you want to retrieve requests modified on or after January 30, 2019, include the modifieddate=20190130 parameter in your query. type: string format: date example: 20190130 - name: createddate in: query required: false schema: description: A date (yyyyMMdd). Include to retrieve a list of requests created on or after the specified date. For example, if you want to retrieve requests created on or after January 30, 2019, include the createddate=20190130 parameter in your query. type: string format: date example: 20190130 - name: status in: query required: false schema: description: Filter requests by stage name. Parameters must be URL encoded. type: string example: NEW - name: ignoreUserRequests in: query required: false schema: description: A flag to exclude requests associated with user if they are not associated with specified organization. type: boolean default: false - name: page in: query schema: description: Results page you want to retrieve. Page number starts with 0 (0..N) type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query schema: description: Number of records per page. Maximum page size allowed is 500 type: integer format: int32 default: 20 maximum: 500 minimum: 1 example: 20 - name: sort in: query schema: description: 'Sorting criteria in the format: property(,asc|desc). Default sort order is ascending.' type: string example: createdDate,desc responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/comments: put: operationId: addCommentsUsingPUT summary: Add Comment to Request description: Use this API to add a comment to a request. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Request queue reference Id type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_CommentV2Request' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/customfields/{language}: put: operationId: updateCustomFieldsUsingPUT summary: Update Request Custom Fields description: Use this API to update the fields of a request. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Reference ID of the request type: string - name: language in: path required: true schema: description: "A language code that identifies the language in which the request data should be returned after the move, assuming translations are available for that language. \nExamples: en-us for English, de for German, fr for French, etc." type: string example: en-us - name: mapOptionKeyToNameKey in: query description: If true, call will map form fields option keys with their respective form field name keys. If false or not included, field keys will not be mapped. required: false schema: type: boolean default: false requestBody: required: true content: application/json: schema: type: object additionalProperties: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/language/{language}: get: operationId: getRequestByIdUsingGET summary: Get Request description: Use this API to retrieve a single request by its unique identifier along with the associated approver details, date created, and data subject's first and last name. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Reference ID of the request type: string example: A1B2C3D46E - name: language in: path required: true schema: description: "A language code that identifies the language in which the request data should be returned, assuming translations are available for that language. \nExamples: en-us for English, de for German, fr for French, etc." type: string example: en-us responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestByIdV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/linkrequest: put: operationId: linkRequestsUsingPUT summary: Link Requests description: Use this API to link or unlink an existing request to one or multiple related requests. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Request Reference ID type: string example: SYS69ZCGXP requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_LinkV2Request' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/movestages/{language}: put: operationId: moveStatusByRequestRefIdUsingPUT summary: Update Request Stage description: 'Use this API to update the workflow stage for a specific request. > ๐Ÿ—’ Things to Know > > - The following system default statuses can be passed as parameter values in the request when moving to a different stage: `NEW`, `VERIFYING_IDENTITY`, `IN_PROGRESS`, `REJECTED`, and `COMPLETE`. > - The `resolutionTitle`, `comments`, and `isInternalComment` parameters are only used when the `nextStage` parameter is set to `REJECTED`. > - You will not be able to advance the request to the next stage if the current stage has required subtasks that have not been completed. > ๐Ÿ‘ > > For more information, see Processing a Request, Closing a Request, and Rejecting a Request.' tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path description: The 10-character unique identifier of the request. required: true schema: description: Reference ID of the request type: string - name: language in: path description: The language code of the request data, such as `en-us` for English, `de` for German, `fr` for French, etc. required: true schema: description: 'The ISO language code for OneTrust supported languages.Examples: en-us for English, de for German, fr for French, etc.' type: string example: en-us requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2StageUpdateRequest' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2StageUpdateDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/pausedeadline: put: operationId: pauseOrResumeDeadlineUsingPUT summary: Pause Request Deadline description: 'Use this API to pause the deadline of a request. > ๐Ÿ—’ Things to Know > > - The deadline will be removed from the request until it is resumed. Once resumed, it will be adjusted based on the time that the deadline was paused. > - The request will be automatically resumed when the data subject responds. Manually resuming is also supported. > ๐Ÿ‘ > > For more information, see Pausing and Resuming a Request Deadline.' tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Request Reference ID type: string example: PBF7HD9YWT requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PauseDeadlineV2Request' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/requesthistory: get: operationId: getRequestHistory summary: Get Request Audit History description: Use this API to retrieve the audit history of a request. The response will include details such as field updates and the date and time when changes were made. tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: 10-character ID that is unique to each request. This ID can be obtained either from the response of the GET /requestqueues/{language} api or by navigating to the Requests section within the DSAR module in the application type: string - name: page in: query schema: description: Results page you want to retrieve. Page number starts with 0 (0..N) type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query schema: description: Number of records per page. type: integer format: int32 default: 20 maximum: 500 minimum: 1 example: 20 responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestAuditInfoResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/requestqueues/{templateId}: post: operationId: createRequestQueueV2UsingPOST summary: Create Request description: 'Use this API to create a new request for the specified web form. > ๐Ÿ—’ Things to Know > > - Visibility rules configured for the web form associated to the specified template will not be inherited after request creation. For more information, see Configuring Dynamic Fields with Visibility Rules.' tags: - Request Queues x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: templateId in: path required: true schema: description: 'Every request is created against a webform template. The template ID is the GUID corresponding to a particular webform. This can be obtained from the url by navigating to the webform. e.g. in this url, ''https://trial.onetrust.com/app/#/pia/dsar/webform/manage/6519ffd5-fe6b-4804-8dfc-1c2ae2da212d'', ''6519ffd5-fe6b-4804-8dfc-1c2ae2da212d'' is the templateId.' type: string format: uuid requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_CreateRequestQueue' responses: '201': description: Created content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE components: schemas: PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueListDto: type: object properties: firstName: type: string lastName: type: string email: type: string requestQueueId: type: string format: uuid requestQueueRefId: type: string orgGroupId: type: string format: uuid daysLeft: type: integer format: int32 status: type: integer format: int64 dateCreated: type: string format: date-time isExtended: type: boolean reviewer: type: string reviewerId: type: string format: uuid language: type: string templateId: type: string format: uuid currentStage: type: string requestTypes: type: array items: type: string subjectTypes: type: array items: type: string deadline: type: string format: date-time workflowDetailDto: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueWorkflowDetailDto' totalSubtasks: type: integer format: int64 completedSubtasks: type: integer format: int64 remainingSubtasks: type: integer format: int64 dsLanguageName: type: string webformName: type: string workflowName: type: string workflowReferenceId: type: string format: uuid resolution: type: string lastUpdated: type: string format: date-time authEnabled: type: boolean lastPublicCommentDate: type: string format: date-time lastDSReplyDate: type: string format: date-time state: type: string country: type: string closureDate: type: string format: date-time countryCode: type: string webFormVersion: type: integer format: int64 remainingDaysForMaxDeadline: type: integer format: int32 numberOfLinkedRequests: type: integer format: int32 maxDeadlineExtensionDate: type: string format: date-time selectFields: type: object additionalProperties: type: array items: type: string properties: all: type: object additionalProperties: type: string writeOnly: true empty: type: boolean inputFields: type: object additionalProperties: type: string totalDataCount: type: integer format: int32 retentionStatus: type: integer format: int32 resultsSummaryDataCount: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_ResultsSummaryDataCountDto' slaExceeded: type: string visited: type: boolean attentionRequired: type: boolean seededOtherData: type: object additionalProperties: type: string lastDsAccessDate: type: string format: date-time assignedTogroup: type: boolean additionalStatuses: type: string enum: - '0' - '10' daysPaused: type: number format: double dsAccessRevoked: type: boolean testRequest: type: boolean taskMode: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_DeletionCertificateV2DTO: type: object properties: requestId: description: The request GUID type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad requestRefId: description: Reference ID of the request. This is a 10-character ID that is unique to each request. type: string example: SL244HWD6D retentionPolicy: description: The name of the retention policy that deleted the request. Null if deletion mode is not RETENTION_POLICY. If the policy is deleted, this will show the policy ID. type: string example: Cyprus Default Policy deletionDate: description: Timestamp when the request was deleted. type: string format: date-time example: '2025-09-02T12:44:20.740Z' deletionMode: description: Mode of deletion type: string example: RETENTION_POLICY enum: - MANUAL - API - RETENTION_POLICY userId: description: The ID of the user who manually deleted the request. This is null if the deletion was not manual. type: string format: uuid example: de8bf5bd-4c24-4aa6-a2c6-0e537bc06e36 PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueWorkflowDetailDto: type: object properties: stage: type: string allowRequestQueueUpdate: type: boolean beginDeadlineCalc: type: boolean allowDeadlineEdit: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_UploadDataDto: type: object properties: refId: type: string format: uuid filename: type: string fileSize: type: integer format: int64 contentType: type: string qualifiedName: type: string PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2AttachmentDto: type: object properties: fileName: type: string fileId: type: string format: uuid PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2StageUpdateRequest: type: object properties: nextStage: description: The name of the workflow stage to which the request will be moved. type: string example: Rejected resolutionTitle: description: The `titleTranslation` parameter value of the resolution. This value should be the translation that corresponds to the language code defined in the `language` parameter of this payload, if available. This value is obtained using the [Get List of Resolutions API](https://developer.onetrust.com/onetrust/reference/getallv2resolutionsusingget). This parameter is only used when the `nextStage` parameter is set to `REJECTED`. type: string example: Not a privacy-related request comments: description: The comments to add when rejecting the request. This parameter is only used when the `nextStage` parameter is set to `REJECTED`. type: string example: Any comment isInternalComment: description: This flag indicates whether the comment added when rejecting a request is for internal use only and will not appear in the Privacy Portal. type: boolean example: true required: - nextStage PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2CommentDto: type: object properties: commentString: type: string commentId: type: string format: uuid commentStatus: type: integer format: int64 commentAuthor: type: string commentTimeStamp: type: string format: date-time attachments: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2AttachmentDto' internalComment: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject: type: object properties: empty: type: boolean unsorted: type: boolean sorted: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueV2Dto: type: object properties: requestQueueRefId: description: Reference ID of the request. This is a 10-character ID that is unique to each request. type: string example: SL244HWD6D requestQueueId: description: The request GUID type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad firstName: description: First name of the data subject. type: string example: Jonny lastName: description: Last name of the data subject. type: string example: Sardar organization: description: Organization to which this request is assigned. type: string example: my own org status: description: 'Current stage of the request. Various stages in the order of progression are: New, Verifying identity, In progress, Rejected, Complete.' type: string example: NEW requestTypes: description: Request types selected while submitting the request. type: array items: type: string example: - Data Portability, Update Data deadline: description: Deadline for the request. type: string format: date-time example: '2019-09-08T12:49:47.920Z' isExtended: description: Returns true if the request complete time is being extended. type: boolean example: false dateCreated: description: Date on which request is submitted. type: string format: date-time example: '2019-08-09T12:49:47.983Z' dateUpdated: description: Last activity date on the request. type: string format: date-time example: '2019-09-25T06:50:15.470Z' subjectTypes: description: 'Subject types selected while submitting the request. Subject type can be: Prospective Employee, Student, Customer, Contractor, Employee, Patient.' type: array items: type: string example: - Student approver: description: Approver or assignee for the request. type: string example: Jonny Sardar Sadmin language: description: Language in which the request is created. type: string example: en-us countryCode: description: The code for the country as per ISO 3166. e.g. US for the United States, DE for Germany. type: string example: DZ countryName: description: Name of the country. type: string example: Algeria email: description: Email provided while submitting the request. type: string example: abcd@gmail.com workflow: description: Name of the request workflow. type: string example: Default Workflow webform: description: Name of the webform. type: string example: '!! Nikki' dateCompleted: description: Date on which the request is completed. type: string format: date-time example: '2019-05-31T12:43:24.173Z' resolution: description: Resolution selected if the request is rejected. type: string example: Not a privacy-related request remainingDaysForMaxDeadline: description: Legal Deadline + Maximum Number of Extension Days based on country of request + Total Pause days. type: integer format: int32 example: 30 maxDeadlineExtensionDate: description: Legal Deadline + Maximum Number of Extension Days based on country of request + Total Pause days. type: string format: date-time example: '2023-09-08T12:49:47.920Z' assignedToGroup: description: Indicates if the request reviewer is assigned to a usergroup or not. type: boolean example: false additionalStatuses: description: Status of the request timer, such as PAUSED or ACTIVE. type: string example: PAUSED enum: - '0' - '10' legalDeadLineInfo: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueListDto' writeOnly: true PrivacyAutomation-DataSubjectRequestDSRAutomation_ResultsSummaryDataCountDto: type: object properties: dataPoints: type: integer format: int32 unstructuredData: type: integer format: int32 attachments: type: integer format: int32 excluded: type: integer format: int32 PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentV2Dto: type: object properties: fileName: description: Attached file name type: string example: sample.txt maxLength: 200 minLength: 1 fileId: description: ID of attached file type: string format: uuid example: 3b47744c-eebf-44bb-bf4c-680966a448dc statusId: description: Status ID of the attachment type: integer format: int64 example: 10 resourcePath: description: Resource path of the attachment type: string example: /storage/attachments/sample.txt maxLength: 1000 required: - fileId - fileName PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueBulkDeleteResponseDto: type: object properties: requestsDeleted: description: Number of requests which are deleted in the API call (up to a maximum of 50 requests). type: integer format: int32 requestsPending: description: Number of requests which match the filter criteria which have not been deleted in this call.API should be called again to delete additional requests. type: integer format: int32 PrivacyAutomation-DataSubjectRequestDSRAutomation_CreateRequestQueue: type: object properties: firstName: description: First name of the respondent. type: string example: Test lastName: description: Last name of the respondent. type: string example: User email: description: Email address of the respondent. type: string example: testuser@onetrust.com language: description: 'The ISO language code for OneTrust supported languages. Examples: en-us for English, de for German, fr for French, etc.' type: string example: en-us minLength: 1 additionalData: description: Additional fields in key value format, required for request processing. These could be webform or non webform fields type: object example: key: value additionalProperties: type: string requestTypes: description: Respondents privacy request type. This should match with the webform request type. type: array items: type: string example: '[' subjectTypes: description: Respondents subject type or relation ship with tenant. This should match with the webform subject type. type: array items: type: string example: '[' multiselectFields: type: object additionalProperties: type: array items: type: string requestTraceId: description: Unique trace id for request. This can be used to avoid creating duplicate request. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad attachments: description: File attachment details for request. type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentV2Dto' PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestByIdV2Dto: type: object properties: requestQueueRefId: description: Reference ID of the request. This is a 10-character ID that is unique to each request. type: string example: SL244HWD6D requestQueueId: description: The request GUID type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad firstName: description: First name of the data subject. type: string example: Jonny lastName: description: Last name of the data subject. type: string example: Sardar organization: description: Organization to which this request is assigned. type: string example: my own org status: description: 'Current stage of the request. Various stages in the order of progression are: New, Verifying identity, In progress, Rejected, Complete.' type: string example: NEW requestTypes: description: Request types selected while submitting the request. type: array items: type: string example: - Data Portability, Update Data deadline: description: Deadline for the request. type: string format: date-time example: '2019-09-08T12:49:47.920Z' isExtended: description: Returns true if the request complete time is being extended. type: boolean example: false dateCreated: description: Date on which request is submitted. type: string format: date-time example: '2019-08-09T12:49:47.983Z' dateUpdated: description: Last activity date on the request. type: string format: date-time example: '2019-09-25T06:50:15.470Z' subjectTypes: description: 'Subject types selected while submitting the request. Subject type can be: Prospective Employee, Student, Customer, Contractor, Employee, Patient.' type: array items: type: string example: - Student approver: description: Approver or assignee for the request. type: string example: Jonny Sardar Sadmin language: description: Language in which the request is created. type: string example: en-us countryCode: description: The code for the country as per ISO 3166. e.g. US for the United States, DE for Germany. type: string example: DZ countryName: description: Name of the country. type: string example: Algeria email: description: Email provided while submitting the request. type: string example: abcd@gmail.com workflow: description: Name of the request workflow. type: string example: Default Workflow webform: description: Name of the webform. type: string example: '!! Nikki' dateCompleted: description: Date on which the request is completed. type: string format: date-time example: '2019-05-31T12:43:24.173Z' resolution: description: Resolution selected if the request is rejected. type: string example: Not a privacy-related request remainingDaysForMaxDeadline: description: Legal Deadline + Maximum Number of Extension Days based on country of request + Total Pause days. type: integer format: int32 example: 30 maxDeadlineExtensionDate: description: Legal Deadline + Maximum Number of Extension Days based on country of request + Total Pause days. type: string format: date-time example: '2023-09-08T12:49:47.920Z' assignedToGroup: description: Indicates if the request reviewer is assigned to a usergroup or not. type: boolean example: false additionalStatuses: description: Status of the request timer, such as PAUSED or ACTIVE. type: string example: PAUSED enum: - '0' - '10' daysToRespond: description: Number of days to respond to the request. type: integer format: int32 example: 3 hoursWorked: description: Number of hours worked. type: number format: double example: 40 workflowID: description: ID of the workflow associated with the request. type: string format: uuid totalCost: description: Total cost associated with the request. type: string additionalData: description: Both "additionalData" and "requestAdditionalData" hold identical information. Opt for "requestAdditionalData" for improved parsing and to prevent issues related to Unicode characters. type: string requestV2CommentDtos: description: List of comments associated with the request. type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2CommentDto' multiselectFields: description: Map of multi-select field values. type: object additionalProperties: type: array items: type: string approverEmail: description: Approver or assignee's email. type: string example: js@onetrust.com legalDeadLineInfo: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueListDto' writeOnly: true requestAdditionalData: description: The "requestAdditionalData" can include both the fields from a Webform Template and query parameters that are provided through the Webform URL when creating or updating a request. type: object example: Address = Bangalore additionalProperties: type: string PrivacyAutomation-DataSubjectRequestDSRAutomation_CreateRequestLogDto: type: object properties: requestTraceID: type: string format: uuid creationstatus: type: string exceptionDescription: type: string createdDate: type: string format: date-time requestRefId: type: string PrivacyAutomation-DataSubjectRequestDSRAutomation_AuditFieldValue: type: object properties: name: type: string PrivacyAutomation-DataSubjectRequestDSRAutomation_BasicTenantUserInfoResponse: type: object properties: email: type: string fullName: type: string userId: type: string format: uuid internal: type: boolean disabled: type: boolean deleted: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestQueueBulkDeleteV2Dto: type: object properties: RequestIDs: description: An array of 10-character Unique IDs of the Request(s) to be deleted. type: array items: type: string example: - 8KDL2A4JAM - S62QF8K5PJ maxItems: 2000 minItems: 0 CreatedDateRange: description: A date range for outlining start date and end date. All requests with a Created Date within this range will be deleted. $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DateRangeDto' EndDateRange: description: A date range for outlining start date and end date. All requests with an End Date within this range will be deleted. $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DateRangeDto' ModifiedDateRange: description: A date range for outlining start date and end date. All requests with a Modified Date within this range will be deleted. $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DateRangeDto' Status: description: Filter requests by the Stage name. Only requests in this stage will be deleted. type: string example: EXPIRED Organization: description: Filter requests by Organization. Only requests in this organization will be deleted. type: string example: BRAND A Country: description: Filter requests by Country code. Only requests with this Country selected will be deleted. type: string example: US WorkflowID: description: Filter requests by Workflow ID. Only requests using this workflow will be deleted. type: string example: 4f068b73-4edc-4920-a00c-9f39cd01c5f6 WebformID: description: Filter requests by Web Form ID. Only requests using this web form will be deleted. type: string example: 0388dd81-0c41-4181-a47c-1e2777727b73 RequestType: description: Filter requests by Request Type. Only requests with the Request Type will be deleted. type: string example: Opt Out SubjectType: description: Filter requests by Subject Type. Only requests with the Subject Type will be deleted. type: string example: Employee PrivacyAutomation-DataSubjectRequestDSRAutomation_CommentV2Request: type: object properties: comment: description: Comment if any. type: string example: This is a test comment internalComment: description: Comments on the request can be internal or public. This flag determines if the comment is internal or public. type: boolean example: false language: description: 'This is the ISO language code for OneTrust supported languages. The language code provided here informs the language of the comment. Examples: en-us for English, de for German, fr for French, etc' type: string example: en-us isInternalComment: type: boolean attachments: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentV2Dto' required: - comment - internalComment PrivacyAutomation-DataSubjectRequestDSRAutomation_DateRangeDto: type: object properties: StartDate: description: Start date for filter, provide in yyyy-MM-dd'T'HH:mm:ss.SSS'Z' format type: string example: '2019-05-31T12:43:24.173Z' EndDate: description: End date for filter, provide in yyyy-MM-dd'T'HH:mm:ss.SSS'Z' format type: string example: '2019-05-31T12:44:24.173Z' PrivacyAutomation-DataSubjectRequestDSRAutomation_AuditRecordDetail: type: object properties: description: description: The description of the request attribute audited. type: string fieldName: description: The name of the request attribute audited. type: string example: Country oldValue: description: The old of attribute value. $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AuditFieldValue' newValue: description: The value of attribute audited. $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AuditFieldValue' PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentResponse: type: object properties: Id: type: string format: uuid Name: type: string FileName: type: string FileSize: type: integer format: int64 CreatedById: type: string format: uuid CreatedBy: type: string Type: type: integer format: int32 RefId: type: string format: uuid IsInternal: type: boolean Location: type: string PrivacyAutomation-DataSubjectRequestDSRAutomation_LinkV2Request: type: object properties: LinkRequests: type: array items: type: string writeOnly: true UnlinkRequests: type: array items: type: string writeOnly: true comment: description: A comment to accompany the current action of linking/ unlinking requests type: string minLength: 1 PrivacyAutomation-DataSubjectRequestDSRAutomation_SearchResultPage: type: object properties: content: items: type: object type: array pageable: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PageableObject' searchTime: type: integer format: int64 totalTime: type: integer format: int64 searchTerms: type: object additionalProperties: type: string last: type: boolean totalElements: type: integer format: int64 totalPages: type: integer format: int32 size: type: integer format: int32 number: type: integer format: int32 sort: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject' first: type: boolean numberOfElements: type: integer format: int32 empty: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestV2StageUpdateDto: type: object properties: requestQueueId: description: The 10-character unique identifier of the request. type: string currentStage: description: The name of the current workflow stage. type: string statusCode: description: 'The numeric identifier for the resolution code. ' type: integer format: int64 PrivacyAutomation-DataSubjectRequestDSRAutomation_PauseDeadlineV2Request: type: object properties: pauseDeadline: description: If PauseDeadline is marked true, the deadline will be paused. If PauseDeadline is marked false, the deadline will be resumed. type: boolean example: true comment: description: Internal comment to be added on pause or resume. type: string example: Pausing request minLength: 1 language: description: 'This is the ISO language code for OneTrust supported languages. The language code provided here informs the language of the comment. Examples: en-us for English, de for German, fr for French, etc' type: string example: en-us required: - pauseDeadline PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestAuditInfoResponse: type: object properties: description: description: The description of the request attribute audited. type: string changeDateTime: description: The timestamp when the change was done. type: string format: date-time example: '2020-12-04T15:52:41.954300Z' recordedDateTime: description: The timestamp when the audit was recorded. type: string format: date-time example: '2020-12-04T15:52:41.954300Z' userDetail: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_BasicTenantUserInfoResponse' changes: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AuditRecordDetail' PrivacyAutomation-DataSubjectRequestDSRAutomation_DSARRequestDto: type: object properties: templateId: type: string format: uuid firstName: description: First name of the respondent. type: string example: Test lastName: description: Last name of the respondent. type: string example: User email: description: Email address of the respondent. type: string example: testuser@onetrust.com language: description: 'The ISO language code for OneTrust supported languages. Examples: en-us for English, de for German, fr for French, etc.' type: string example: en-us minLength: 1 additionalData: description: Additional fields in key value format, required for request processing. These could be webform or non webform fields type: object example: key: value additionalProperties: type: string requestTypes: description: Respondents privacy request type. This should match with the webform subject type key, key values are part for webform submission payload. type: array items: type: object example: '[' subjectTypes: description: Respondents subject type or relation ship with tenant. This should match with the webform subject type key, key values are part for webform submission payload. type: array items: type: object example: '[' attachments: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_UploadDataDto' attachmentResponses: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentResponse' requestTraceId: description: Unique trace id for request. This can be used to avoid creating duplicate request. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad multiselectFields: type: object additionalProperties: type: array items: type: string PrivacyAutomation-DataSubjectRequestDSRAutomation_SearchV2Request: type: object properties: term: type: string PrivacyAutomation-DataSubjectRequestDSRAutomation_PageableObject: type: object properties: offset: type: integer format: int64 sort: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject' paged: type: boolean pageNumber: type: integer format: int32 pageSize: type: integer format: int32 unpaged: type: boolean securitySchemes: PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_READ: Read-only access to DSAR objects scope for external systems DSAR_WRITE: Access to DSAR objects scope for external systems DSAR: Access to DSAR objects scope for external systems PrivacyAutomation-DROPManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_WRITE: Access to DROP objects scope for external systems x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0