PrivacyRequest
object type
A PrivacyRequest — the GDPR/CCPA REQUEST REGISTER: every data-subject request RECEIVED (erasure · access · portability · rectification · opt_out) is recorded with full provenance — the regime (gdpr · ccpa), the arrival channel, the received instant, and the SUBJECT (a known Consumer ref OR an inline subjectRef handle — at least one; the register necessarily holds this identity: ⚠ IT IS THE ERASURE-SUPPRESSION LIST, governing any later archive download/use). The ladder: verify (the identity gate — v1 the verifier's assertion, the proof narrative on the revision cause) → start → fulfill (the BESPOKE system-edge driver: the affected records link back refs — provable WHICH request drove WHICH scrubbing; an evidence-less fulfill refuses CONFLICT/INCOMPLETE, retryable); reject serves received AND verified (ONE op, two edges — the reason is REQUIRED: a refused privacy request states its grounds). THE FULFILLMENT MECHANICS STAY THE EXISTING OPS (erasure = the live eraseConsumer [the Consumer doomed = de-identified terminal]; access/portability per-subject export = a named growth; rectification/opt-out = ordinary edits/consent ops) — the register RECORDS and LINKS, it never executes. NOT searchable (a compliance register holding subject PII — the -gated paginated listing); the listing pages NEWEST-first; rejected drops per page as doomed while fulfilled records stay listed.
Fields
| Field | Type | Notes |
|---|---|---|
id | ID ID! | The record’s id — a UUID the platform assigned when the record was created; every reference to this record uses it. |
sysId | String String! | The group-scoped human-facing system id (PV-…). |
type | String String! | The kind of record — always PrivacyRequest here. |
caption | String String! | The record’s display name — what people see it called. |
status | String String! | The FSM state: received | verified | in_progress | fulfilled | rejected. |
parentId | ID ID! | The parent = the org GROUP; parentId === rootId always (the FraudAlert class — the register is group custody). |
rootId | ID ID! | The org-group family root. |
createdAt | String String! | When the record was created, as a UTC timestamp. |
updatedAt | String String! | When the record last changed, as a UTC timestamp. |
revisionNum | Int Int! | How many times this record has been edited; the first save is 0. |
revision | ID ID! | The OCC revision token — supply it on every mutation of this record; rotates on every write. |
refCaptions | RefCaption [RefCaption!]! | The server-composed captions of this record's declared references (the referenced-caption rule) — one row per referenced id; see RefCaption. |
requestType | String String! | WHICH data-subject right (erasure · access · portability · rectification · opt_out — the canon's five; canned). IMMUTABLE at birth (a changed ask is a fresh request). |
regime | String String! | WHICH regime (gdpr · ccpa — EU/CA first, extensible deliberately). IMMUTABLE at birth. |
channel | String String! | HOW it arrived (email · phone · in_store · web · mail). IMMUTABLE at birth. |
receivedAt | String String! | WHEN it arrived (may predate the recording; omitted at create ⇒ the create instant, stamped engine-side). |
consumerId | ID | The known subject; null for inline/guest subjects. |
subjectRef | String | The inline/guest subject handle (the requester's stated email/name, ≤200) — REQUIRED when consumerId is absent (at least one of the two names the subject). |
affectedRefs | TaskConstructRef [TaskConstructRef!]! | The fulfillment evidence (≤20 — the {type, id} structured-ref shape reused): EMPTY at birth, stamped by fulfillPrivacyRequest (the de-identified Consumer, the export target, the rectified records); advisory + tombstone-tolerant. |