AlmondTill/G3N API

PrivacyRequest

object type

A PrivacyRequest — the GDPR/CCPA REQUEST REGISTER: every data-subject request RECEIVED (erasure · access · portability · rectification · opt_out) is recorded with full provenance — the regime (gdpr · ccpa), the arrival channel, the received instant, and the SUBJECT (a known Consumer ref OR an inline subjectRef handle — at least one; the register necessarily holds this identity: ⚠ IT IS THE ERASURE-SUPPRESSION LIST, governing any later archive download/use). The ladder: verify (the identity gate — v1 the verifier's assertion, the proof narrative on the revision cause) → start → fulfill (the BESPOKE system-edge driver: the affected records link back refs — provable WHICH request drove WHICH scrubbing; an evidence-less fulfill refuses CONFLICT/INCOMPLETE, retryable); reject serves received AND verified (ONE op, two edges — the reason is REQUIRED: a refused privacy request states its grounds). THE FULFILLMENT MECHANICS STAY THE EXISTING OPS (erasure = the live eraseConsumer [the Consumer doomed = de-identified terminal]; access/portability per-subject export = a named growth; rectification/opt-out = ordinary edits/consent ops) — the register RECORDS and LINKS, it never executes. NOT searchable (a compliance register holding subject PII — the -gated paginated listing); the listing pages NEWEST-first; rejected drops per page as doomed while fulfilled records stay listed.

Fields

FieldTypeNotes
idID ID!The record’s id — a UUID the platform assigned when the record was created; every reference to this record uses it.
sysIdString String!The group-scoped human-facing system id (PV-…).
typeString String!The kind of record — always PrivacyRequest here.
captionString String!The record’s display name — what people see it called.
statusString String!The FSM state: received | verified | in_progress | fulfilled | rejected.
parentIdID ID!The parent = the org GROUP; parentId === rootId always (the FraudAlert class — the register is group custody).
rootIdID ID!The org-group family root.
createdAtString String!When the record was created, as a UTC timestamp.
updatedAtString String!When the record last changed, as a UTC timestamp.
revisionNumInt Int!How many times this record has been edited; the first save is 0.
revisionID ID!The OCC revision token — supply it on every mutation of this record; rotates on every write.
refCaptionsRefCaption [RefCaption!]!The server-composed captions of this record's declared references (the referenced-caption rule) — one row per referenced id; see RefCaption.
requestTypeString String!WHICH data-subject right (erasure · access · portability · rectification · opt_out — the canon's five; canned). IMMUTABLE at birth (a changed ask is a fresh request).
regimeString String!WHICH regime (gdpr · ccpa — EU/CA first, extensible deliberately). IMMUTABLE at birth.
channelString String!HOW it arrived (email · phone · in_store · web · mail). IMMUTABLE at birth.
receivedAtString String!WHEN it arrived (may predate the recording; omitted at create ⇒ the create instant, stamped engine-side).
consumerIdIDThe known subject; null for inline/guest subjects.
subjectRefStringThe inline/guest subject handle (the requester's stated email/name, ≤200) — REQUIRED when consumerId is absent (at least one of the two names the subject).
affectedRefsTaskConstructRef [TaskConstructRef!]!The fulfillment evidence (≤20 — the {type, id} structured-ref shape reused): EMPTY at birth, stamped by fulfillPrivacyRequest (the de-identified Consumer, the export target, the rectified records); advisory + tombstone-tolerant.

Used by