openapi: 3.2.0 info: title: Privacy Automation - Data Subject Request (DSR) Automation… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, verification methods, and audit history. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Results Summary description: APIs used to share results summaries. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json x-displayName: Results Summary paths: /api/datasubject/v2/requestqueues/results-summary/share/{requestQueueRefId}: post: operationId: shareResultsSummaryUsingPOST summary: Share Results Summary description: 'Use this API to share data discovery results summary with the data subject via email. The API supports sharing results in CSV or PDF format. When sharing as PDF, you must provide a report template ID to customize the output format. > 🗒 Things to Know > > - The report template ID (not name) must be provided for PDF reports. > - The API processes sharing asynchronously. For tracking, you can either mark a specific subtask as complete\n by providing the subtaskId (the request will auto-progress when the subtask is completed), or you can mark the entire request as complete using the markRequestAsComplete flag. > - Comments in the request body support HTML content and will be sanitized. > - The report name format is: `{YYYYMMD}_{RequestRefId}___Report` (e.g., `2025113_HMVBKRYTYE___Report`).' tags: - Results Summary x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path description: Request Reference ID (10-character ID that is unique to each request) required: true schema: type: string maxLength: 10 minLength: 10 example: HMVBKRYTYE requestBody: required: true content: application/json: schema: oneOf: - $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_CsvResultsSummaryShareRequest' - $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PdfResultsSummaryShareRequest' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE components: schemas: PrivacyAutomation-DataSubjectRequestDSRAutomation_PdfResultsSummaryShareRequest: allOf: - $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AbstractResultsSummaryShareRequest' - type: object properties: reportTemplate: description: Template ID (UUID) for PDF report generation. This is required for PDF exports. type: string format: uuid example: 3bacb8fd-e581-438f-b713-fb5ac8160387 required: - comment - reportTemplate - reportType title: Share results summary in PDF format PrivacyAutomation-DataSubjectRequestDSRAutomation_AbstractResultsSummaryShareRequest: type: object properties: comment: description: Comment to include in the shared report. Supports HTML content. type: string example:
Please review the attached summary.
maxLength: 500000 minLength: 1 markRequestAsComplete: description: Flag to mark the request as complete when sharing results type: boolean example: true default: 'false' subtaskId: description: Optional subtask ID that will be marked complete after the results summary share finishes successfully. type: string format: uuid example: 76e50bb5-cd9c-4af2-88ff-ab0f8cba9e9b reportType: description: Type of report to generate. Use 'CSV' for structured data export or 'PDF' for formatted report with template. type: string example: CSV enum: - CSV - PDF discriminator: propertyName: reportType mapping: CSV: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_CsvResultsSummaryShareRequest' PDF: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PdfResultsSummaryShareRequest' required: - comment - reportType PrivacyAutomation-DataSubjectRequestDSRAutomation_CsvResultsSummaryShareRequest: allOf: - $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AbstractResultsSummaryShareRequest' required: - comment - reportType title: Share results summary in CSV format securitySchemes: PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_READ: Read-only access to DSAR objects scope for external systems DSAR_WRITE: Access to DSAR objects scope for external systems DSAR: Access to DSAR objects scope for external systems PrivacyAutomation-DROPManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_WRITE: Access to DROP objects scope for external systems x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0