openapi: 3.2.0 info: title: Privacy Automation - Data Subject Request (DSR) Automation… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, verification methods, and audit history. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Verification Methods description: APIs used to create, update, and retrieve methods for verifying a data subject's identity. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json x-displayName: Verification Methods paths: /api/datasubject/v2/requestqueues/{requestQueueRefId}/verificationmethods: get: operationId: getAllV2VerificationMethodsUsingGET summary: Get List of Verification Methods description: Use this API to retrieve a list of all verification methods for the specified request. The response will include details for each verification method along with the corresponding ID, description, and created date. tags: - Verification Methods x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: The unique reference ID of the privacy request for which to retrieve verification methods. type: string example: ZASHMHK2K7 - name: includeComments in: query required: true schema: description: Set to true to include comments and attachments in the response. If false, only basic verification method information will be returned. type: boolean default: false example: true - name: page in: query schema: description: Results page you want to retrieve. Page number starts with 0 (0..N) type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query schema: description: Number of records per page. Maximum page size allowed is 500 type: integer format: int32 default: 20 maximum: 500 minimum: 1 example: 20 - name: sort in: query schema: description: 'Sorting criteria in the format: property(,asc|desc). Default sort order is ascending.' type: string enum: - createdDate,asc - createdDate,desc - lastModifiedDate,asc - lastModifiedDate,desc example: createdDate,desc responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE put: operationId: updateV2VerificationMethodUsingPUT summary: Update Verification Method description: Use this API to update an existing verification method for a request. tags: - Verification Methods x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: request queue reference id type: string example: ZASHMHK2K7 - name: language in: query required: false schema: description: Language code type: string example: en-us - name: translate in: query required: false schema: description: Whether to translate the content type: boolean default: false example: false requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE post: operationId: createV2VerificationMethodUsingPOST summary: Create Verification Method description: Use this API to create a new verification method for the specified request. tags: - Verification Methods x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: request queue reference id type: string example: ZASHMHK2K7 - name: language in: query required: false schema: description: Language code type: string example: en-us - name: translate in: query required: false schema: description: Whether to translate the content type: boolean default: false example: false requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO' responses: '201': description: Created content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_WRITE /api/datasubject/v2/requestqueues/{requestQueueRefId}/{methodId}: get: operationId: getAllV2VerificationMethodsByIdUsingGET summary: Get Verification Method description: Use this API to retrieve a single verification method by its unique identifier for the specified request. tags: - Verification Methods x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json parameters: - name: requestQueueRefId in: path required: true schema: description: The unique reference ID of the privacy request for which to retrieve the verification method. type: string example: ZASHMHK2K7 - name: methodId in: path required: true schema: description: The unique identifier of the verification method to retrieve. type: string format: uuid example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad - name: includeComments in: query required: true schema: description: Set to true to include comments and attachments in the response. If false, only basic verification method information will be returned. type: boolean example: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: - DSAR - DSAR_READ - DSAR_WRITE components: schemas: PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentV2Dto: type: object properties: fileName: description: Attached file name type: string example: sample.txt maxLength: 200 minLength: 1 fileId: description: ID of attached file type: string format: uuid example: 3b47744c-eebf-44bb-bf4c-680966a448dc statusId: description: Status ID of the attachment type: integer format: int64 example: 10 resourcePath: description: Resource path of the attachment type: string example: /storage/attachments/sample.txt maxLength: 1000 required: - fileId - fileName PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2CommentsDto: type: object properties: id: description: The unique identifier for this comment. type: string format: uuid example: 3b47744c-eebf-44bb-bf4c-680966a448dc verificationMethodId: description: The identifier of the verification method this comment belongs to. type: string format: uuid example: 3b47744c-eebf-44bb-bf4c-680966a448dc comment: description: The text content of the comment providing details about the verification process. type: string example: Passport verified with photo matching the requester's profile picture. lastModifiedDate: description: The timestamp when this comment was last modified. type: string format: date-time example: '2020-01-08T11:49:48.657Z' type: description: The type of comment, represented as an integer code. type: integer format: int32 example: 1 attachments: description: A list of attachments associated with this comment, such as scanned documents or screenshots used in the verification process. type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentV2Dto' required: - comment - id - verificationMethodId PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO: type: object properties: id: description: The unique identifier for this verification method. type: string format: uuid example: 7a275364-d6e2-4581-b95b-843237cb232a verificationMethodName: description: The name of the verification method used to verify the data subject's identity. type: string example: Government ID maxLength: 100 minLength: 1 description: description: A detailed description of how the verification method was applied. type: string example: Verified government-issued photo ID matched with requester information. maxLength: 500 verificationStatus: description: The current status of the verification process. type: string example: VERIFIED enum: - UNVERIFIED - VERIFIED - REJECTED verificationComments: description: A list of comments and attachments associated with this verification method. This field is only populated when includeComments is set to true in the request. type: array items: $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2CommentsDto' verificationType: description: The type of verification process used. type: string example: MANUAL enum: - DEFAULT - MANUAL - KNOWLEDGE - DOCUMENT - EMAIL - PHONE createdDate: description: The timestamp when this verification method was created. type: string format: date-time example: '2020-01-03T12:41:13.820Z' lastModifiedDate: description: The timestamp when this verification method was last modified. type: string format: date-time example: '2020-01-03T12:41:13.820Z' securitySchemes: PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_READ: Read-only access to DSAR objects scope for external systems DSAR_WRITE: Access to DSAR objects scope for external systems DSAR: Access to DSAR objects scope for external systems PrivacyAutomation-DROPManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: DSAR_WRITE: Access to DROP objects scope for external systems x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0