Skip to main content
POST
Create a GDPR request

Authorizations

x-access-token
string
header
required

Organization API token. Generate from Organization Settings → API Tokens.

Body

application/json
requestType
enum<string>
required

The type of GDPR request.

Available options:
erasure,
access
identityType
enum<string>
required

The type of identity to look up.

Available options:
email
identityValue
string
required

The identity value (e.g., an email address).

Response

The request was recorded and, for an erasure, processed. Check status for the outcome.

A GDPR data access or erasure request, and the record of what it did.

id
string

Identifier of the stored request. Quote this when evidencing a DSAR.

org_id
string
request_type
enum<string>
Available options:
erasure,
access
identity_type
enum<string>
Available options:
email
identity_value
string
status
enum<string>

Outcome of the request.

  • complete — at least one record matched and was processed.
  • no_records_found — nothing in this organization matched the email, so nothing was erased.
  • pending — the request is stored but has not finished processing.
Available options:
complete,
no_records_found,
pending
matching_user_exists
boolean

True when the email matched at least one record of any kind.

response
object

What the request matched and what happened to it. people, users_scrubbed, users_retained and counts are present on requests processed recently and absent on older records; an absent field means "not recorded", not "zero".

created_at
string
updated_at
string