openapi: 3.2.0 info: title: Privacy Automation - Data Subject Request (DSR) Automation… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, verification methods, and audit history. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Resolutions description: APIs used to create, update, delete, and retrieve resolution codes for privacy requests and subtasks. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json x-displayName: Resolutions paths: /api/datasubject/v2/resolutions: get: operationId: getAllV2ResolutionsUsingGET summary: Get List of Resolutions description: Use this API to retrieve a list of all request resolutions. The response will include details for each resolution along with the corresponding ID, type, and translations. tags: - Resolutions x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: language in: query required: false schema: description: The language code for which to retrieve resolution code translations. For example, 'en-us' for English, 'fr' for French, 'de' for German, etc. type: string example: en-us - name: includeSubTaskResolutions in: query required: false schema: description: Set to true to include resolution codes that are applicable to subtasks. If false or omitted, only request-level resolution codes will be returned. type: boolean default: false example: true - name: page in: query schema: description: Results page you want to retrieve. Page number starts with 0 (0..N) type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query schema: description: Number of records per page. Maximum page size allowed is 500 type: integer format: int32 default: 20 maximum: 500 minimum: 1 example: 20 - name: sort in: query schema: description: 'Sorting criteria in the format: property(,asc|desc). Default sort order is ascending.' type: string enum: - createdDate,asc - createdDate,desc - lastModifiedDate,asc - lastModifiedDate,desc example: createdDate,desc responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestResolutionV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE post: operationId: addNewResolutionUsingPOST summary: Create Resolution description: Use this API to create a new resolution. tags: - Resolutions x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestResolutionV2Dto' responses: '201': description: Created content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestResolutionV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/resolutions/{resolutionId}: put: operationId: updateResolutionUsingPUT summary: Update Resolution description: Use this API to update an existing resolution. tags: - Resolutions x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: resolutionId in: path required: true schema: description: resolutionId type: string format: uuid example: c29c36f5-1281-48bf-b486-170cae7d8727 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestResolutionV2Dto' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestResolutionV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE delete: operationId: deleteResolutionUsingDELETE summary: Delete Resolution description: Use this API to delete an existing resolution. tags: - Resolutions x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: resolutionId in: path required: true schema: description: The unique identifier of the resolution code to be deleted. type: string format: uuid example: c29c36f5-1281-48bf-b486-170cae7d8727 responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE components: schemas: PrivacyAutomation-DataSubjectRequestDSRAutomation_RequestResolutionV2Dto: type: object properties: id: description: The unique identifier for the resolution code. This is automatically generated when a new resolution code is created, not required in resolution creation payload. type: string format: uuid example: 682488af-c26f-463e-9941-2f1582c6d4da readOnly: true close: description: Indicates whether this resolution code should be available as an option when closing a request. Set to true to make it available for closing requests. type: boolean example: true reject: description: Indicates whether this resolution code should be available as an option when rejecting a request. Set to true to make it available for rejecting requests. type: boolean example: true complete: description: Indicates whether this resolution code should be available as an option when completing a request. Set to true to make it available for completing requests. type: boolean example: false type: description: Specifies the type of resolution code, which determines where it appears in the UI. By default, this is set to 10 for request-level resolutions. Use 20 for subtask resolutions. type: integer format: int32 enum: - '10' - '20' x-enumDescriptions: '10': RequestQueue resolutions '20': Subtask resolutions titleTranslations: description: A map of language codes to translated titles for this resolution code. English (en-us) translation is required. Each translation must be unique per language and type across all resolution codes. type: object example: en-us: Opt Out fr: Se désinscrire de: Abmelden additionalProperties: type: string descriptionTranslations: description: A map of language codes to translated descriptions for this resolution code. The default English (en-us) translation must be present. type: object example: en-us: Opt Out the Request fr: Se désinscrire de la demande de: Anfrage abmelden additionalProperties: type: string required: - close - complete - reject securitySchemes: PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_READ: Read-only access to DSAR objects scope for external systems DSAR_WRITE: Access to DSAR objects scope for external systems DSAR: Access to DSAR objects scope for external systems PrivacyAutomation-DROPManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_WRITE: Access to DROP objects scope for external systems x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0