openapi: 3.2.0 info: title: Privacy Automation - Data Subject Request (DSR) Automation… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, verification methods, and audit history. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Targeted Data Discovery description: APIs used to add, update, and retrieve structured or unstructured data discovery results linked to privacy requests. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json x-displayName: Targeted Data Discovery paths: /api/datasubject/v2/datadiscovery/groups/{groupId}/requestqueues/{requestQueueRefId}: get: operationId: getAllGroupAndAttachmentDetailsUsingGET summary: Get Targeted Data Discovery Group description: Use this API to retrieve results for a Targeted Data Discovery group for the specified request. tags: - Targeted Data Discovery x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: groupId in: path required: true schema: description: TDD Group Id type: string format: uuid - name: requestQueueRefId in: path required: true schema: description: Request queue ref ID type: string - name: includeAttachments in: query required: false schema: description: Set to true to include attachment information in the response. If false or omitted, attachments will not be included. type: boolean default: false responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE /api/datasubject/v2/datadiscovery/requestqueues/{requestQueueRefId}: get: operationId: getAllGroupByRequestUsingGET summary: Get List of Targeted Data Discovery Groups description: Use this API to retrieve a list of all Targeted Data Discovery groups for the specified request. The response will include details for each group along with the corresponding group ID, name, and order. tags: - Targeted Data Discovery x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Request queue reference Id type: string responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupResultV2Dto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE post: operationId: dataDiscoveryUpdatesUsingPOST summary: Add Targeted Data Discovery Results Summary to Request description: Use this API to add Targeted Data Discovery results to a request. tags: - Targeted Data Discovery x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Request queue reference Id type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupDto' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v3/datadiscovery/requestqueues/{requestQueueRefId}: post: operationId: unstructuredDataDiscoveryUpdatesUsingPOST summary: Add Data Points to Targeted Data Discovery Results Summary description: Use this API to add Targeted Data Discovery results that include unstructured data to a request. tags: - Targeted Data Discovery x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: Request queue reference Id type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupDto' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE components: schemas: PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentDto: type: object properties: fileName: description: Name of the file. type: string example: receipt.pdf fileId: description: Unique Identifier of the File. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad isRedact: type: boolean writeOnly: true emlAttachmentMetadata: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_EmlAttachmentMetadata' redact: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_PageDataDiscoveryResultsV2Dto: type: object properties: totalElements: type: integer format: int64 totalPages: type: integer format: int32 size: type: integer format: int32 content: items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryResultsV2Dto' type: array number: type: integer format: int32 sort: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject' first: type: boolean last: type: boolean numberOfElements: type: integer format: int32 pageable: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PageableObject' empty: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupV2Dto: type: object properties: groupName: description: Name of the group. type: string example: Salesforce Customer Data groupId: description: Unique Identifier of the group. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad dataDiscoveryResultsV2Dtos: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PageDataDiscoveryResultsV2Dto' dataDiscoveryAttachmentListDtos: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentListDto' PrivacyAutomation-DataSubjectRequestDSRAutomation_UnStructuredData: type: object properties: type: description: The type of unstructured data (e.g., document, image, email). type: string example: document status: description: The processing status of the unstructured data. type: string example: processed key: description: A unique identifier or name for the unstructured data item. type: string example: contract_2023 value: description: The content or reference to the unstructured data. type: string example: https://storage.example.com/documents/contract_2023.pdf isRedact: description: Indicates whether the data should be redacted in the response. type: boolean example: true attributes: description: Additional attributes or metadata associated with the unstructured data. type: object additionalProperties: type: string required: - key - type - value PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupResultV2Dto: type: object properties: groupName: description: Name of the group. type: string example: Salesforce Customer Data groupOrder: description: Order in which group has been created. type: integer format: int64 groupId: description: Unique Identifier of the group. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupDto: type: object properties: system: description: Name or identifier of the system from which this data is sourced. This will be displayed on the Results Summary. type: string example: Office365 results: description: Dataset that includes list of data groups with nested name-value-pairs to capture structured data. type: object additionalProperties: type: object additionalProperties: type: object unstructuredResults: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_UnStructuredData' attachments: description: Optional. List of name-value-pairs containing file names and IDs to attach. Use the Add File API to add file into OneTrust and retrieve the File IDs. These files will be visible in the Results Summary. type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentDto' required: - system PrivacyAutomation-DataSubjectRequestDSRAutomation_EmlAttachmentMetadata: type: object properties: attachmentId: type: string format: uuid emlSubject: type: string senderName: type: string sendDate: type: string format: date-time PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentListDto: type: object properties: id: type: string format: uuid fileName: description: Name of the file. type: string example: receipt.pdf fileId: description: Unique Identifier of the File. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad source: description: Name of the system where the attachment originated and displayed as targeted data discovery system for files added by user. type: string fileSize: description: Size of the file in kilobyte. type: integer format: int64 isSharable: type: boolean writeOnly: true sharable: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject: type: object properties: empty: type: boolean unsorted: type: boolean sorted: type: boolean PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryResultsV2Dto: type: object properties: id: description: Unique Identifier for field Id. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad fieldName: description: The name for a data field in the results summary type: string example: firstname value: description: This is the actual data element. type: string example: John system: description: Displays the name of the source of a particular data element. type: string example: Salesforce PrivacyAutomation-DataSubjectRequestDSRAutomation_PageableObject: type: object properties: offset: type: integer format: int64 sort: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject' paged: type: boolean pageNumber: type: integer format: int32 pageSize: type: integer format: int32 unpaged: type: boolean securitySchemes: PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_READ: Read-only access to DSAR objects scope for external systems DSAR_WRITE: Access to DSAR objects scope for external systems DSAR: Access to DSAR objects scope for external systems PrivacyAutomation-DROPManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_WRITE: Access to DROP objects scope for external systems x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0