# Answer a privacy request

Record the request the moment it arrives, verify the requester, mark the work underway, erase the shopper’s personal data when the right is erasure, and close it fulfilled with the evidence — or reject it with your grounds.

Compliance · a play in 4 steps.

## The steps

1. Record it — who asked, which right, under which law. — [createPrivacyRequest](/reference/privacy-request/createPrivacyRequest/)
2. Verify the requester — the proof method goes in the reason — and mark the work underway. — [verifyPrivacyRequest](/reference/privacy-request/verifyPrivacyRequest/), [startPrivacyRequest](/reference/privacy-request/startPrivacyRequest/)
3. Erase the shopper’s personal data when the right is erasure — permanent, the one-way door. — [eraseConsumer](/reference/consumer/eraseConsumer/)
4. Close it fulfilled, with the evidence — the compliance proof — or reject it with your grounds. — [fulfillPrivacyRequest](/reference/privacy-and-compliance/fulfillPrivacyRequest/), [rejectPrivacyRequest](/reference/privacy-request/rejectPrivacyRequest/)

## The calls

Every operation this use case runs, in the order it first appears, with the request and the response its reference page shows.

### createPrivacyRequest

[createPrivacyRequest](/reference/privacy-request/createPrivacyRequest/) — mutation · Record a privacy request the moment it arrives — who asked, for which right, under which law.

**Example request**

```graphql
mutation ExampleCreatePrivacyRequest($input: NewPrivacyRequestInput!) {
  createPrivacyRequest(input: $input) {
    id
    sysId
    type
    caption
    status
    parentId
    rootId
    createdAt
    updatedAt
    revisionNum
    revision
    requestType
    regime
    channel
    receivedAt
    consumerId
    subjectRef
  }
}
```

Variables:

```json
{
  "input": {
    "caption": "Blue jeans",
    "requestType": "<request type>",
    "regime": "<regime>",
    "channel": "<channel>"
  }
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

**Example response**

```json
{
  "data": {
    "createPrivacyRequest": {
      "id": "01900000-0000-7000-8000-37386ae00000",
      "sysId": "PV-EXMP-0000-000F",
      "type": "PrivacyRequest",
      "caption": "Blue jeans",
      "status": "received",
      "parentId": "01900000-0000-7000-8000-065235280000",
      "rootId": "01900000-0000-7000-8000-a093dd800000",
      "createdAt": "2027-01-31T00:00:00.000Z",
      "updatedAt": "2027-01-31T00:00:00.000Z",
      "revisionNum": 1,
      "revision": "01900000-0000-7000-8000-b7960e180000",
      "requestType": "<request type>",
      "regime": "<regime>",
      "channel": "<channel>",
      "receivedAt": "2027-01-31T00:00:00.000Z",
      "consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
      "subjectRef": "<subject ref>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

### verifyPrivacyRequest

[verifyPrivacyRequest](/reference/privacy-request/verifyPrivacyRequest/) — mutation · Mark the requester’s identity as verified.

**Example request**

```graphql
mutation ExampleVerifyPrivacyRequest($id: ID!, $revision: ID!, $reason: String) {
  verifyPrivacyRequest(id: $id, revision: $revision, reason: $reason) {
    id
    sysId
    type
    caption
    status
    parentId
    rootId
    createdAt
    updatedAt
    revisionNum
    revision
    requestType
    regime
    channel
    receivedAt
    consumerId
    subjectRef
  }
}
```

Variables:

```json
{
  "id": "01900000-0000-7000-8000-37386ae00000",
  "revision": "01900000-0000-7000-8000-b7960e180000",
  "reason": "Correcting a miscount."
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

**Example response**

```json
{
  "data": {
    "verifyPrivacyRequest": {
      "id": "01900000-0000-7000-8000-37386ae00000",
      "sysId": "PV-EXMP-0000-000F",
      "type": "PrivacyRequest",
      "caption": "Blue jeans",
      "status": "received",
      "parentId": "01900000-0000-7000-8000-065235280000",
      "rootId": "01900000-0000-7000-8000-a093dd800000",
      "createdAt": "2027-01-31T00:00:00.000Z",
      "updatedAt": "2027-01-31T00:00:00.000Z",
      "revisionNum": 1,
      "revision": "01900000-0000-7000-8000-b7960e180000",
      "requestType": "<request type>",
      "regime": "<regime>",
      "channel": "<channel>",
      "receivedAt": "2027-01-31T00:00:00.000Z",
      "consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
      "subjectRef": "<subject ref>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

### startPrivacyRequest

[startPrivacyRequest](/reference/privacy-request/startPrivacyRequest/) — mutation · Start fulfilling a verified privacy request.

**Example request**

```graphql
mutation ExampleStartPrivacyRequest($id: ID!, $revision: ID!, $reason: String) {
  startPrivacyRequest(id: $id, revision: $revision, reason: $reason) {
    id
    sysId
    type
    caption
    status
    parentId
    rootId
    createdAt
    updatedAt
    revisionNum
    revision
    requestType
    regime
    channel
    receivedAt
    consumerId
    subjectRef
  }
}
```

Variables:

```json
{
  "id": "01900000-0000-7000-8000-37386ae00000",
  "revision": "01900000-0000-7000-8000-b7960e180000",
  "reason": "Correcting a miscount."
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

**Example response**

```json
{
  "data": {
    "startPrivacyRequest": {
      "id": "01900000-0000-7000-8000-37386ae00000",
      "sysId": "PV-EXMP-0000-000F",
      "type": "PrivacyRequest",
      "caption": "Blue jeans",
      "status": "received",
      "parentId": "01900000-0000-7000-8000-065235280000",
      "rootId": "01900000-0000-7000-8000-a093dd800000",
      "createdAt": "2027-01-31T00:00:00.000Z",
      "updatedAt": "2027-01-31T00:00:00.000Z",
      "revisionNum": 1,
      "revision": "01900000-0000-7000-8000-b7960e180000",
      "requestType": "<request type>",
      "regime": "<regime>",
      "channel": "<channel>",
      "receivedAt": "2027-01-31T00:00:00.000Z",
      "consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
      "subjectRef": "<subject ref>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

### eraseConsumer

[eraseConsumer](/reference/consumer/eraseConsumer/) — mutation · Erase a shopper’s personal data — the right-to-be-forgotten act.

**Example request**

```graphql
mutation ExampleEraseConsumer($id: ID!, $revision: ID!, $reason: String) {
  eraseConsumer(id: $id, revision: $revision, reason: $reason) {
    id
    sysId
    type
    caption
    status
    parentId
    rootId
    createdAt
    updatedAt
    revisionNum
    revision
    email
    displayName
    phones
    priceGroupId
    tagIds
    locale
    displayCurrency
    dateOfBirth
    commsFrequency
    commsFormat
    commsTopics
    interests
    preferredLogicalFacilityId
  }
}
```

Variables:

```json
{
  "id": "01900000-0000-7000-8000-37386ae00000",
  "revision": "01900000-0000-7000-8000-b7960e180000",
  "reason": "Correcting a miscount."
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

**Example response**

```json
{
  "data": {
    "eraseConsumer": {
      "id": "01900000-0000-7000-8000-37386ae00000",
      "sysId": "CN-EXMP-0000-000F",
      "type": "Consumer",
      "caption": "Blue jeans",
      "status": "active",
      "parentId": "01900000-0000-7000-8000-065235280000",
      "rootId": "01900000-0000-7000-8000-a093dd800000",
      "createdAt": "2027-01-31T00:00:00.000Z",
      "updatedAt": "2027-01-31T00:00:00.000Z",
      "revisionNum": 1,
      "revision": "01900000-0000-7000-8000-b7960e180000",
      "email": "<the person’s email address>",
      "displayName": "Blue jeans",
      "phones": [
        "<phones>"
      ],
      "priceGroupId": "01900000-0000-7000-8000-c7ffbf680000",
      "tagIds": [
        "01900000-0000-7000-8000-decd62770000"
      ],
      "locale": "en-CA",
      "displayCurrency": "<display currency>",
      "dateOfBirth": "<date of birth>",
      "commsFrequency": "<comms frequency>",
      "commsFormat": "<comms format>",
      "commsTopics": [
        "<comms topics>"
      ],
      "interests": [
        "<interests>"
      ],
      "preferredLogicalFacilityId": "01900000-0000-7000-8000-23734f810000"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

### fulfillPrivacyRequest

[fulfillPrivacyRequest](/reference/privacy-and-compliance/fulfillPrivacyRequest/) — mutation · Mark a privacy request fulfilled, with the evidence.

**Example request**

```graphql
mutation ExampleFulfillPrivacyRequest($id: ID!, $revision: ID!, $affectedRefs: [TaskConstructRefInput!]!, $reason: String) {
  fulfillPrivacyRequest(id: $id, revision: $revision, affectedRefs: $affectedRefs, reason: $reason) {
    id
    sysId
    type
    caption
    status
    parentId
    rootId
    createdAt
    updatedAt
    revisionNum
    revision
    requestType
    regime
    channel
    receivedAt
    consumerId
    subjectRef
  }
}
```

Variables:

```json
{
  "id": "01900000-0000-7000-8000-37386ae00000",
  "revision": "01900000-0000-7000-8000-b7960e180000",
  "affectedRefs": [
    {
      "type": "<type>",
      "id": "01900000-0000-7000-8000-37386ae00000"
    }
  ],
  "reason": "Correcting a miscount."
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

**Example response**

```json
{
  "data": {
    "fulfillPrivacyRequest": {
      "id": "01900000-0000-7000-8000-37386ae00000",
      "sysId": "PV-EXMP-0000-000F",
      "type": "PrivacyRequest",
      "caption": "Blue jeans",
      "status": "received",
      "parentId": "01900000-0000-7000-8000-065235280000",
      "rootId": "01900000-0000-7000-8000-a093dd800000",
      "createdAt": "2027-01-31T00:00:00.000Z",
      "updatedAt": "2027-01-31T00:00:00.000Z",
      "revisionNum": 1,
      "revision": "01900000-0000-7000-8000-b7960e180000",
      "requestType": "<request type>",
      "regime": "<regime>",
      "channel": "<channel>",
      "receivedAt": "2027-01-31T00:00:00.000Z",
      "consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
      "subjectRef": "<subject ref>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

### rejectPrivacyRequest

[rejectPrivacyRequest](/reference/privacy-request/rejectPrivacyRequest/) — mutation · Reject a privacy request — the reason is required.

**Example request**

```graphql
mutation ExampleRejectPrivacyRequest($id: ID!, $revision: ID!, $reason: String!) {
  rejectPrivacyRequest(id: $id, revision: $revision, reason: $reason) {
    id
    sysId
    type
    caption
    status
    parentId
    rootId
    createdAt
    updatedAt
    revisionNum
    revision
    requestType
    regime
    channel
    receivedAt
    consumerId
    subjectRef
  }
}
```

Variables:

```json
{
  "id": "01900000-0000-7000-8000-37386ae00000",
  "revision": "01900000-0000-7000-8000-b7960e180000",
  "reason": "Correcting a miscount."
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

**Example response**

```json
{
  "data": {
    "rejectPrivacyRequest": {
      "id": "01900000-0000-7000-8000-37386ae00000",
      "sysId": "PV-EXMP-0000-000F",
      "type": "PrivacyRequest",
      "caption": "Blue jeans",
      "status": "received",
      "parentId": "01900000-0000-7000-8000-065235280000",
      "rootId": "01900000-0000-7000-8000-a093dd800000",
      "createdAt": "2027-01-31T00:00:00.000Z",
      "updatedAt": "2027-01-31T00:00:00.000Z",
      "revisionNum": 1,
      "revision": "01900000-0000-7000-8000-b7960e180000",
      "requestType": "<request type>",
      "regime": "<regime>",
      "channel": "<channel>",
      "receivedAt": "2027-01-31T00:00:00.000Z",
      "consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
      "subjectRef": "<subject ref>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```
