curl --request POST \
--url https://public-api.sessionboard.com/v1/gdpr/requests \
--header 'Content-Type: application/json' \
--header 'x-access-token: <api-key>' \
--data '
{
"identityType": "email",
"identityValue": "[email protected]"
}
'import requests
url = "https://public-api.sessionboard.com/v1/gdpr/requests"
payload = {
"identityType": "email",
"identityValue": "[email protected]"
}
headers = {
"x-access-token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-access-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({identityType: 'email', identityValue: '[email protected]'})
};
fetch('https://public-api.sessionboard.com/v1/gdpr/requests', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://public-api.sessionboard.com/v1/gdpr/requests",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'identityType' => 'email',
'identityValue' => '[email protected]'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://public-api.sessionboard.com/v1/gdpr/requests"
payload := strings.NewReader("{\n \"identityType\": \"email\",\n \"identityValue\": \"[email protected]\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-access-token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://public-api.sessionboard.com/v1/gdpr/requests")
.header("x-access-token", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"identityType\": \"email\",\n \"identityValue\": \"[email protected]\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://public-api.sessionboard.com/v1/gdpr/requests")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-access-token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"identityType\": \"email\",\n \"identityValue\": \"[email protected]\"\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"org_id": "<string>",
"request_type": "erasure",
"identity_type": "email",
"identity_value": "<string>",
"status": "complete",
"matching_user_exists": true,
"response": {
"users": [
123
],
"org_users": [
"<string>"
],
"event_users": [
123
],
"contact_records": [
"<string>"
],
"people": [
"<string>"
],
"users_scrubbed": [
123
],
"users_retained": [
{}
],
"counts": {
"org_users": 123,
"event_users": 123,
"contact_records": 123,
"people": 123,
"users_identified": 123,
"users_scrubbed": 123,
"users_retained": 123
}
},
"created_at": "<string>",
"updated_at": "<string>"
}Create a GDPR request
Submit a GDPR data access or erasure request for one email address, and process it synchronously against the organization’s data.
For requestType: erasure the call returns once the erasure has run.
Read status to find out what happened — it is recorded by the
erasure itself and is never assumed:
complete— the email matched at least one record and erasure ran against it.no_records_found— nothing in this organization matched the email. Nothing was erased. Treat this as an outcome to escalate, not a fulfilled request.
response carries the identifiers that were matched, and on requests
processed recently also counts, users_scrubbed and
users_retained — the compliance evidence of what the erasure actually
did. A user account shared with another organization is retained rather
than scrubbed, and appears in users_retained.
A 502 means the erasure did not run and nothing was recorded or
erased; retry the request.
curl --request POST \
--url https://public-api.sessionboard.com/v1/gdpr/requests \
--header 'Content-Type: application/json' \
--header 'x-access-token: <api-key>' \
--data '
{
"identityType": "email",
"identityValue": "[email protected]"
}
'import requests
url = "https://public-api.sessionboard.com/v1/gdpr/requests"
payload = {
"identityType": "email",
"identityValue": "[email protected]"
}
headers = {
"x-access-token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-access-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({identityType: 'email', identityValue: '[email protected]'})
};
fetch('https://public-api.sessionboard.com/v1/gdpr/requests', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://public-api.sessionboard.com/v1/gdpr/requests",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'identityType' => 'email',
'identityValue' => '[email protected]'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://public-api.sessionboard.com/v1/gdpr/requests"
payload := strings.NewReader("{\n \"identityType\": \"email\",\n \"identityValue\": \"[email protected]\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-access-token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://public-api.sessionboard.com/v1/gdpr/requests")
.header("x-access-token", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"identityType\": \"email\",\n \"identityValue\": \"[email protected]\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://public-api.sessionboard.com/v1/gdpr/requests")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-access-token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"identityType\": \"email\",\n \"identityValue\": \"[email protected]\"\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"org_id": "<string>",
"request_type": "erasure",
"identity_type": "email",
"identity_value": "<string>",
"status": "complete",
"matching_user_exists": true,
"response": {
"users": [
123
],
"org_users": [
"<string>"
],
"event_users": [
123
],
"contact_records": [
"<string>"
],
"people": [
"<string>"
],
"users_scrubbed": [
123
],
"users_retained": [
{}
],
"counts": {
"org_users": 123,
"event_users": 123,
"contact_records": 123,
"people": 123,
"users_identified": 123,
"users_scrubbed": 123,
"users_retained": 123
}
},
"created_at": "<string>",
"updated_at": "<string>"
}Authorizations
Organization API token. Generate from Organization Settings → API Tokens.
Body
The type of GDPR request.
erasure, access The type of identity to look up.
email The identity value (e.g., an email address).
Response
The request was recorded and, for an erasure, processed. Check status for the outcome.
A GDPR data access or erasure request, and the record of what it did.
Identifier of the stored request. Quote this when evidencing a DSAR.
erasure, access email Outcome of the request.
complete— at least one record matched and was processed.no_records_found— nothing in this organization matched the email, so nothing was erased.pending— the request is stored but has not finished processing.
complete, no_records_found, pending True when the email matched at least one record of any kind.
What the request matched and what happened to it. people, users_scrubbed, users_retained and counts are present on requests processed recently and absent on older records; an absent field means "not recorded", not "zero".
Show child attributes
Show child attributes

