Skip to content

GDPR

POST /v1/customers/{customerId}/rights-requests

Section titled “POST /v1/customers/{customerId}/rights-requests”

Register a rights request

customers:write

Start here: export and erasure both require an identity-verified request for this exact customer (art. 12(6)). Returns the art. 12(3) one-month response deadline.

ParameterInTypeRequiredDescription
customerIdpathstringYes
Request body fields 3
FieldTypeRequiredDescription
typestringYesResource-specific type.
channelstringYesField in the request payload.
notestringNoField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/customers/9b2f1c1e-…/rights-requests \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"type": "INDSIGT",
"channel": "telefon"
}'
201 Success envelopeapplication/json
Response fields 3
FieldTypeDescription
data.iduuidRights-request id used for verification and erasure.
data.responseDeadlinedateArticle 12(3) response deadline.
data.identityVerifiedbooleanWhether identity verification is complete.
Possible errors 10
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404customer_not_foundThe customer does not exist or belongs to another organisation.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"type": {
"type": "string",
"enum": [
"INDSIGT",
"BERIGTIGELSE",
"SLETNING",
"BEGRAENSNING",
"PORTABILITET",
"INDSIGELSE"
]
},
"channel": {
"type": "string",
"enum": [
"telefon",
"email",
"brev",
"intern"
]
},
"note": {
"anyOf": [
{
"type": "string",
"maxLength": 4000
},
{
"type": "null"
}
]
}
},
"required": [
"type",
"channel"
],
"additionalProperties": false
}

POST /v1/customers/{customerId}/rights-requests/{requestId}/verify-identity

Section titled “POST /v1/customers/{customerId}/rights-requests/{requestId}/verify-identity”

Record identity verification

customers:write

Art. 12(6). You state HOW you established identity; we record it verbatim in the audit trail. A regulator may read it — be specific.

ParameterInTypeRequiredDescription
customerIdpathstringYes
requestIdpathstringYes
Request body fields 1
FieldTypeRequiredDescription
methodstringYesField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/customers/9b2f1c1e-…/rights-requests/9b2f1c1e-…/verify-identity \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"method": "…"
}'
204 No contentNo response body
Possible errors 10
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404customer_not_foundThe customer does not exist or belongs to another organisation.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"method": {
"type": "string",
"minLength": 1,
"maxLength": 200
}
},
"required": [
"method"
],
"additionalProperties": false
}

Access/portability extract (art. 15/20)

customers:read

Requires requestId of an identity-verified INDSIGT or PORTABILITET request. Includes the collections case if the customer crossed the invoice-to-collections bridge. CPR is reported as existence only, never re-disclosed.

ParameterInTypeRequiredDescription
customerIdpathstringYes
requestIdquerystringNoIdentity-verified rights request id (required)
Request exampleNo request body
curl https://api.rieckflow.com/v1/customers/9b2f1c1e-…/export \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Success envelopeapplication/json
Possible errors 5
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404customer_not_foundThe customer does not exist or belongs to another organisation.
429rate_limitedThe organisation’s rate budget is exhausted.

POST /v1/customers/{customerId}/erasure-requests

Section titled “POST /v1/customers/{customerId}/erasure-requests”

Erasure request (art. 17)

customers:write

Irreversible. Gated three times: identity-verified SLETNING request, no open claims (art. 17(3)(e)), then the retention balancing. Outcome is ANONYMISERET or LAAST_TIL_SLETNING with a date and a legal basis — never a false ‘deleted’.

ParameterInTypeRequiredDescription
customerIdpathstringYes
Request body fields 1
FieldTypeRequiredDescription
requestIdstringYesField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/customers/9b2f1c1e-…/erasure-requests \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"requestId": "9b2f1c1e-…"
}'
200 Success envelopeapplication/json
Response fields 3
FieldTypeDescription
data.outcomeANONYMISERET | LAAST_TIL_SLETNINGWhether data were erased now or retained until a legal deadline.
data.erasureDueAtdate-time | nullActual deletion date when retention applies.
data.retentionBasisstringLegal basis for any retention.
Possible errors 12
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
404customer_not_foundThe customer does not exist or belongs to another organisation.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
422open_claims_block_erasureOpen claims require continued processing and block immediate erasure.
422rights_request_not_usableThe rights request is not open and identity-verified for this action.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"requestId": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
}
},
"required": [
"requestId"
],
"additionalProperties": false
}