# PrivacyRequest

object type

A PrivacyRequest — the GDPR/CCPA REQUEST REGISTER: every data-subject request RECEIVED (erasure · access · portability · rectification · opt_out) is recorded with full provenance — the regime (gdpr · ccpa), the arrival channel, the received instant, and the SUBJECT (a known Consumer ref OR an inline subjectRef handle — at least one; the register necessarily holds this identity: ⚠ IT IS THE ERASURE-SUPPRESSION LIST, governing any later archive download/use). The ladder: verify (the identity gate — v1 the verifier's assertion, the proof narrative on the revision cause) → start → fulfill (the BESPOKE system-edge driver: the affected records link back refs — provable WHICH request drove WHICH scrubbing; an evidence-less fulfill refuses CONFLICT/INCOMPLETE, retryable); reject serves received AND verified (ONE op, two edges — the reason is REQUIRED: a refused privacy request states its grounds). THE FULFILLMENT MECHANICS STAY THE EXISTING OPS (erasure = the live eraseConsumer \[the Consumer doomed = de-identified terminal]; access/portability per-subject export = a named growth; rectification/opt-out = ordinary edits/consent ops) — the register RECORDS and LINKS, it never executes. NOT searchable (a compliance register holding subject PII — the -gated paginated listing); the listing pages NEWEST-first; rejected drops per page as doomed while fulfilled records stay listed.

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `id` | [ID](/types/#scalars) `ID!` | The record’s id — a UUID the platform assigned when the record was created; every reference to this record uses it. |
| `sysId` | [String](/types/#scalars) `String!` | The group-scoped human-facing system id (PV-…). |
| `type` | [String](/types/#scalars) `String!` | The kind of record — always `PrivacyRequest` here. |
| `caption` | [String](/types/#scalars) `String!` | The record’s display name — what people see it called. |
| `status` | [String](/types/#scalars) `String!` | The FSM state: received \| verified \| in_progress \| fulfilled \| rejected. |
| `parentId` | [ID](/types/#scalars) `ID!` | The parent = the org GROUP; parentId === rootId always (the FraudAlert class — the register is group custody). |
| `rootId` | [ID](/types/#scalars) `ID!` | The org-group family root. |
| `createdAt` | [String](/types/#scalars) `String!` | When the record was created, as a UTC timestamp. |
| `updatedAt` | [String](/types/#scalars) `String!` | When the record last changed, as a UTC timestamp. |
| `revisionNum` | [Int](/types/#scalars) `Int!` | How many times this record has been edited; the first save is 0. |
| `revision` | [ID](/types/#scalars) `ID!` | The OCC revision token — supply it on every mutation of this record; rotates on every write. |
| `refCaptions` | [RefCaption](/types/RefCaption/) `[RefCaption!]!` | The server-composed captions of this record's declared references (the referenced-caption rule) — one row per referenced id; see RefCaption. |
| `requestType` | [String](/types/#scalars) `String!` | WHICH data-subject right (erasure · access · portability · rectification · opt_out — the canon's five; canned). IMMUTABLE at birth (a changed ask is a fresh request). |
| `regime` | [String](/types/#scalars) `String!` | WHICH regime (gdpr · ccpa — EU/CA first, extensible deliberately). IMMUTABLE at birth. |
| `channel` | [String](/types/#scalars) `String!` | HOW it arrived (email · phone · in_store · web · mail). IMMUTABLE at birth. |
| `receivedAt` | [String](/types/#scalars) `String!` | WHEN it arrived (may predate the recording; omitted at create ⇒ the create instant, stamped engine-side). |
| `consumerId` | [ID](/types/#scalars) | The known subject; null for inline/guest subjects. |
| `subjectRef` | [String](/types/#scalars) | The inline/guest subject handle (the requester's stated email/name, ≤200) — REQUIRED when consumerId is absent (at least one of the two names the subject). |
| `affectedRefs` | [TaskConstructRef](/types/TaskConstructRef/) `[TaskConstructRef!]!` | The fulfillment evidence (≤20 — the {type, id} structured-ref shape reused): EMPTY at birth, stamped by fulfillPrivacyRequest (the de-identified Consumer, the export target, the rectified records); advisory + tombstone-tolerant. |

## Used by

- [createPrivacyRequest](/reference/privacy-request/createPrivacyRequest/)
- [fulfillPrivacyRequest](/reference/privacy-and-compliance/fulfillPrivacyRequest/)
- [privacyRequest](/reference/privacy-request/privacyRequest/)
- [rejectPrivacyRequest](/reference/privacy-request/rejectPrivacyRequest/)
- [startPrivacyRequest](/reference/privacy-request/startPrivacyRequest/)
- [verifyPrivacyRequest](/reference/privacy-request/verifyPrivacyRequest/)
