On this page
fulfillPrivacyRequest
mutation · in the family Privacy and compliance
What it does
Mark a privacy request fulfilled, with the evidence.
Mark an in_progress PrivacyRequest FULFILLED: the affected records link back via the refs (the de-identified Consumer, the export target, the rectified records — provable WHICH request drove WHICH scrubbing). affectedRefs ≥1 REQUIRED — an evidence-less fulfill refuses CONFLICT/INCOMPLETE (retryable: finish the actions, fulfill again); refs are advisory + tombstone-tolerant. OCC on the passed revision. Template class (privacy & compliance).
What happens
List the records the work touched — the erased customer, the export, the corrections; at least one is required.
Careful
A fulfilled request is kept permanently and becomes immutable — the compliance proof.
Who may call it
Capability area: Privacy and compliance — Tax and fiscal configuration, certificates and privacy requests.
- Owner
- System Administrator
- An API key whose scope allows
api:fulfillPrivacyRequest
Arguments
| Name | Type | Required | Notes |
|---|---|---|---|
id | ID ID! | yes | The id of the record. |
revision | ID ID! | yes | The revision id you read on the record; the change is refused if an edit landed in the meantime. |
affectedRefs | TaskConstructRefInput [TaskConstructRefInput!]! | yes | No further notes. |
reason | String | no | No further notes. |
Returns
PrivacyRequest PrivacyRequest! — A PrivacyRequest — the GDPR/CCPA REQUEST REGISTER: every data-subject request RECEIVED (erasure · access · portability · rectification · opt_out) is recorded with full provenance — the regime (gdpr · ccpa), the arrival channel, the received instant, and the SUBJECT (a known Consumer ref OR an inline subjectRef handle — at least one; the register necessarily holds this identity: ⚠ IT IS THE ERASURE-SUPPRESSION LIST, governing any later archive download/use). The ladder: verify (the identity gate — v1 the verifier's assertion, the proof narrative on the revision cause) → start → fulfill (the BESPOKE system-edge driver: the affected records link back refs — provable WHICH request drove WHICH scrubbing; an evidence-less fulfill refuses CONFLICT/INCOMPLETE, retryable); reject serves received AND verified (ONE op, two edges — the reason is REQUIRED: a refused privacy request states its grounds). THE FULFILLMENT MECHANICS STAY THE EXISTING OPS (erasure = the live eraseConsumer [the Consumer doomed = de-identified terminal]; access/portability per-subject export = a named growth; rectification/opt-out = ordinary edits/consent ops) — the register RECORDS and LINKS, it never executes. NOT searchable (a compliance register holding subject PII — the -gated paginated listing); the listing pages NEWEST-first; rejected drops per page as doomed while fulfilled records stay listed.
Example request
mutation ExampleFulfillPrivacyRequest($id: ID!, $revision: ID!, $affectedRefs: [TaskConstructRefInput!]!, $reason: String) {
fulfillPrivacyRequest(id: $id, revision: $revision, affectedRefs: $affectedRefs, reason: $reason) {
id
sysId
type
caption
status
parentId
rootId
createdAt
updatedAt
revisionNum
revision
requestType
regime
channel
receivedAt
consumerId
subjectRef
}
}
Variables:
{
"id": "01900000-0000-7000-8000-37386ae00000",
"revision": "01900000-0000-7000-8000-b7960e180000",
"affectedRefs": [
{
"type": "<type>",
"id": "01900000-0000-7000-8000-37386ae00000"
}
],
"reason": "Correcting a miscount."
}
Send it with the envelope naming the version: "extensions": {"at": {"version": {"name":"genesis","number":0}}}.
Example response
{
"data": {
"fulfillPrivacyRequest": {
"id": "01900000-0000-7000-8000-37386ae00000",
"sysId": "PV-EXMP-0000-000F",
"type": "PrivacyRequest",
"caption": "Blue jeans",
"status": "received",
"parentId": "01900000-0000-7000-8000-065235280000",
"rootId": "01900000-0000-7000-8000-a093dd800000",
"createdAt": "2027-01-31T00:00:00.000Z",
"updatedAt": "2027-01-31T00:00:00.000Z",
"revisionNum": 1,
"revision": "01900000-0000-7000-8000-b7960e180000",
"requestType": "<request type>",
"regime": "<regime>",
"channel": "<channel>",
"receivedAt": "2027-01-31T00:00:00.000Z",
"consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
"subjectRef": "<subject ref>"
}
},
"extensions": {
"at": {
"callId": "01EXAMPLE-CALL-ID",
"version": {
"requested": {
"name": "genesis",
"number": 0
},
"serviced": {
"name": "genesis",
"number": 0
}
}
}
}
}
Errors this call can answer
VALIDATION/INVALID— Something in the request is not valid. (VALIDATION)AUTHN/REQUIRED— Sign in to do this. (AUTHN)AUTHZ/FORBIDDEN— Your role does not allow this action. (AUTHZ)RATE_LIMIT/THROTTLED— Too many requests in a short time. (RATE_LIMIT)NOT_FOUND/*— That record could not be found. (NOT_FOUND)CONFLICT/*— The record’s state, or a change made in the meantime, does not allow this; the codes are on the CONFLICT page. (CONFLICT)VALIDATION/VERSION_REQUIRED— The request did not say which app version it came from. (VALIDATION)