Endpoint
Authentication
Requires a developer API key in theAuthorization header.
Request Headers
Request Body
Example Request
Response — 201 Created
Response Fields
Export Data Object
Filtering to a data principal
WithdataPrincipalId, consent records and grievances are those of that
principal. audit_entries.principal_id is the principal of the grant the
entry was written under, which is the DPDP data principal only when an
integration keys both the same way (DPDP_ENFORCE_GRANT_PRINCIPAL=true
enforces it). The audit log therefore includes entries written under the
grants of the principal’s consent records, entries whose principal is
dataPrincipalId, and the platform’s DPDP audit entries about the principal.
(Grievances used to be included for every principal even when the export was
filtered.)
Creating an export is recorded on the audit chain as
grantex.dpdp.export_created. Exports expire after 7 days; reading one after
that answers 410 GONE and its data is purged. An erasure of a principal
deletes the stored exports about that principal when the server sets
DPDP_ERASURE_EXPANDED=true; otherwise they are kept until they expire.
Export Types
The GDPR Article 15 block
Agdpr-article-15 export with dataPrincipalId adds data.article15, the
information GDPR Art. 15(1) lists, as far as Grantex’s records allow. It
covers all of the principal’s consent records for the developer (up to
1,000), not only those in the date window:
The copy of the data itself is in
consentRecords, auditLog and grievances. Personal
data the controller processes in its own systems is not held by Grantex.
Without dataPrincipalId the export is produced as before, without the
block. With DPDP_EXPORT_GDPR_REQUIRES_PRINCIPAL=true (off by default) a
gdpr-article-15 export without dataPrincipalId answers 400.