# privacyRequests

query · in the family [Privacy request](/reference/privacy-request/)

## What it does

Your group’s privacy-request register, newest first — every GDPR/CCPA request you received, forever.

The caller's org-group family's ACTIVE LISTING of PrivacyRequests — doomed records DROP from listings. PAGINATED: `limit` clamps to \[1, 200], default 100; `nextToken` = the prior page's cursor, verbatim — opaque + tenant-bound (a malformed or foreign token → VALIDATION/INVALID). Walk until `nextToken` is null (a page may hold fewer than `limit` — doomed drop per page).

## What happens

Reads only. This register is also the erasure-suppression list — it governs later use of archived data.

## Who may call it

Capability area: **Privacy and compliance** — Tax and fiscal configuration, certificates and privacy requests.

- Owner
- System Administrator
- An API key whose scope allows `api:privacyRequests`

## Arguments

| Name | Type | Required | Notes |
| --- | --- | --- | --- |
| `limit` | [Int](/types/#scalars) | no | How many records to answer at most; a page may hold fewer. |
| `nextToken` | [String](/types/#scalars) | no | The cursor from the previous page, passed back exactly as received. |

## Returns

[PrivacyRequestPage](/types/PrivacyRequestPage/) `PrivacyRequestPage!` — One page of the privacyRequests listing — the records + the opaque resume cursor.

This is a page: `items` holds the records and `nextToken` the cursor for the next page — pass it back verbatim until it is null. See [paging](/guides/paging-and-the-cursor-grammar/).

## Example request

```graphql
query ExamplePrivacyRequests($limit: Int) {
  privacyRequests(limit: $limit) {
    items {
      id
      sysId
      type
      caption
      status
      parentId
      rootId
      createdAt
      updatedAt
      revisionNum
      revision
      requestType
      regime
      channel
      receivedAt
      consumerId
      subjectRef
    }
    nextToken
  }
}
```

Variables:

```json
{
  "limit": 1
}
```

## Example response

```json
{
  "data": {
    "privacyRequests": {
      "items": [
        {
          "id": "01900000-0000-7000-8000-37386ae00000",
          "sysId": "PV-EXMP-0000-000F",
          "type": "PrivacyRequest",
          "caption": "Blue jeans",
          "status": "received",
          "parentId": "01900000-0000-7000-8000-065235280000",
          "rootId": "01900000-0000-7000-8000-a093dd800000",
          "createdAt": "2027-01-31T00:00:00.000Z",
          "updatedAt": "2027-01-31T00:00:00.000Z",
          "revisionNum": 1,
          "revision": "01900000-0000-7000-8000-b7960e180000",
          "requestType": "<request type>",
          "regime": "<regime>",
          "channel": "<channel>",
          "receivedAt": "2027-01-31T00:00:00.000Z",
          "consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
          "subjectRef": "<subject ref>"
        }
      ],
      "nextToken": "<the cursor from the previous page>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": null,
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

## Errors this call can answer

- `VALIDATION/INVALID` — Something in the request is not valid. ([VALIDATION](/errors/VALIDATION/))
- `AUTHN/REQUIRED` — Sign in to do this. ([AUTHN](/errors/AUTHN/))
- `AUTHZ/FORBIDDEN` — Your role does not allow this action. ([AUTHZ](/errors/AUTHZ/))
- `RATE_LIMIT/THROTTLED` — Too many requests in a short time. ([RATE_LIMIT](/errors/RATE_LIMIT/))
