Start here: export and erasure both require an identity-verified request for this exact customer (art. 12(6)). Returns the art. 12(3) one-month response deadline.
Parameter In Type Required Description customerIdpath stringYes
Request body fields 3
Field Type Required Description typestringYes Resource-specific type. channelstringYes Field in the request payload. notestringNo Field in the request payload.
Request example application/json
curl -X POST https://api.rieckflow.com/v1/customers/9b2f1c1e-…/rights-requests \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 " \
-H " Content-Type: application/json " \
const svar = await rieck . request ( " POST " , " /v1/customers/9b2f1c1e-…/rights-requests " , {
"id" : " 9b2f1c1e-6b87-4d9b-91a0-47c8d72b8440 " ,
"receivedAt" : " 2026-08-04T09:32:11Z " ,
"responseDeadline" : " 2026-09-04 " ,
"identityVerified" : false
201 Success envelope application/json
Response fields 3
Field Type Description data.iduuidRights-request id used for verification and erasure. data.responseDeadlinedateArticle 12(3) response deadline. data.identityVerifiedbooleanWhether identity verification is complete.
Possible errors 10
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 400 invalid_requestThe request body or parameter failed validation. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 customer_not_foundThe customer does not exist or belongs to another organisation. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 413 payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit. 429 rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema "additionalProperties" : false
Art. 12(6). You state HOW you established identity; we record it verbatim in the audit trail. A regulator may read it — be specific.
Parameter In Type Required Description customerIdpath stringYes requestIdpath stringYes
Request body fields 1
Field Type Required Description methodstringYes Field in the request payload.
Request example application/json
curl -X POST https://api.rieckflow.com/v1/customers/9b2f1c1e-…/rights-requests/9b2f1c1e-…/verify-identity \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 " \
-H " Content-Type: application/json " \
const svar = await rieck . request ( " POST " , " /v1/customers/9b2f1c1e-…/rights-requests/9b2f1c1e-…/verify-identity " , {
204 No content No response body
Possible errors 10
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 400 invalid_requestThe request body or parameter failed validation. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 customer_not_foundThe customer does not exist or belongs to another organisation. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 413 payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit. 429 rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema "additionalProperties" : false
Requires requestId of an identity-verified INDSIGT or PORTABILITET request. Includes the collections case if the customer crossed the invoice-to-collections bridge. CPR is reported as existence only, never re-disclosed.
Parameter In Type Required Description customerIdpath stringYes requestIdquery stringNo Identity-verified rights request id (required)
Request example No request body
curl https://api.rieckflow.com/v1/customers/9b2f1c1e-…/export \
-H " Authorization: Bearer $RIECK_API_KEY "
const svar = await rieck . request ( " GET " , " /v1/customers/9b2f1c1e-…/export " );
"subjectId" : " 467a0d8d-b9b2-4df3-bf7b-17d649442890 " ,
"extractedAt" : " 2026-08-04T09:32:11Z " ,
"controller" : " Acme ApS " ,
"name" : " Example Customer " ,
"deletionStatus" : " active " ,
"deletionLockExpires" : null ,
"deletionLockReason" : null
200 Success envelope application/json
Possible errors 5
HTTP Code Meaning 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 customer_not_foundThe customer does not exist or belongs to another organisation. 429 rate_limitedThe organisation’s rate budget is exhausted.
Irreversible. Gated three times: identity-verified SLETNING request, no open claims (art. 17(3)(e)), then the retention balancing. Outcome is ANONYMISERET or LAAST_TIL_SLETNING with a date and a legal basis — never a false ‘deleted’.
Parameter In Type Required Description customerIdpath stringYes
Request body fields 1
Field Type Required Description requestIdstringYes Field in the request payload.
Request example application/json
curl -X POST https://api.rieckflow.com/v1/customers/9b2f1c1e-…/erasure-requests \
-H " Authorization: Bearer $RIECK_API_KEY " \
-H " Idempotency-Key: order-2041 " \
-H " Content-Type: application/json " \
"requestId": "9b2f1c1e-…"
const svar = await rieck . request ( " POST " , " /v1/customers/9b2f1c1e-…/erasure-requests " , {
" requestId " : " 9b2f1c1e-… "
"outcome" : " LAAST_TIL_SLETNING " ,
"retentionRule" : " BOOKKEEPING " ,
"retentionBasis" : " Danish Bookkeeping Act " ,
"erasureDueAt" : " 2031-01-01T00:00:00Z " ,
"key" : " gdpr.erasure.retained " ,
200 Success envelope application/json
Response fields 3
Field Type Description data.outcomeANONYMISERET | LAAST_TIL_SLETNINGWhether data were erased now or retained until a legal deadline. data.erasureDueAtdate-time | nullActual deletion date when retention applies. data.retentionBasisstringLegal basis for any retention.
Possible errors 12
HTTP Code Meaning 400 invalid_idempotency_keyIdempotency-Key is missing or malformed. 400 invalid_requestThe request body or parameter failed validation. 401 invalid_api_keyThe API key is missing, invalid, expired or revoked. 403 api_not_includedThe organisation’s plan does not include API access. 403 insufficient_scopeThe key does not have the required scope. 404 customer_not_foundThe customer does not exist or belongs to another organisation. 409 idempotency_conflictThe same key was used with a different request. 409 idempotency_in_progressThe same operation is currently being processed. Retry later. 413 payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit. 422 open_claims_block_erasureOpen claims require continued processing and block immediate erasure. 422 rights_request_not_usableThe rights request is not open and identity-verified for this action. 429 rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema "pattern" : " ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$ "
"additionalProperties" : false