Elastic Path Personal Data Erasure Requests API

Erasure requests enable you to exercise the right, referred to in regulations such as GDPR, as the right to be forgotten or right to erase. Erasure requests allow you to wipe out personal data from Commerce in an automated way, including: * All related resources (for example, addresses, customers, and so on.) * Personal Data Logs Erasure requests can be created for any data entry in the personal data set (see [Personal Data Concept](/docs/api/personal-data/personal-data-introduction) for details), and the result is the same. :::note Currently, it does not include flows or data external to Commerce. ::: Erasure requests are processed asynchronously. The POST requests return immediately, and processing continues in the background. You can use the GET endpoint to poll for results until you see `{..."status":"SUCCESS"...}` in the response body. In the unlikely event an erasure request fails (if the status is not equal to `SUCCESS`), you are advised to retry by creating another erasure request. If the problem persists, contact Support. :::note Currently, personal data management is only enabled for a limited set of endpoints. See the [personal data concepts page](/docs/api/personal-data/personal-data-introduction) for the list of endpoints that support personal data management. ::: Seller Admin & IT users have full access to Erasure Requests, and Support users have read access.

OpenAPI Specification

elastic-path-personal-data-erasure-requests-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  version: 25.1126.6886238
  x-version-timestamp: 2025-11-26 19:10:23+00:00
  title: Addresses Introduction Account Addresses Personal Data Erasure Requests API
  description: 'The Addresses API allows you to organize account addresses. Addresses are a sub-resource of `account` resources, an account can have multiple addresses, such as home, work, and neighbour.


    You can use an account address with either [client_credentials access token](/docs/api/authentication/create-an-access-token) or a combination of [implicit access token](/docs/api/authentication/create-an-access-token) and [Account Management authentication](/docs/api/accounts/post-v-2-account-members-tokens) token.

    '
  contact:
    name: Elastic Path
    url: https://www.elasticpath.com
    email: support@elasticpath.com
  license:
    url: https://elasticpath.dev
    name: MIT
servers:
- url: https://useast.api.elasticpath.com
  description: US East
- url: https://euwest.api.elasticpath.com
  description: EU West
security:
- BearerToken: []
tags:
- name: Personal Data Erasure Requests
  description: 'Erasure requests enable you to exercise the right, referred to in regulations such as GDPR, as the right to be

    forgotten or right to erase.

    Erasure requests allow you to wipe out personal data from Commerce in an automated way, including:


    * All related resources (for example, addresses, customers, and so on.)

    * Personal Data Logs


    Erasure requests can be created for any data entry in the personal data set (see [Personal Data Concept](/docs/api/personal-data/personal-data-introduction) for details), and the result is the same.


    :::note

    Currently, it does not include flows or data external to Commerce.

    :::


    Erasure requests are processed asynchronously. The POST requests return immediately, and processing continues in

    the background. You can use the GET endpoint to poll for results until you see `{..."status":"SUCCESS"...}` in the

    response body.


    In the unlikely event an erasure request fails (if the status is not equal to `SUCCESS`), you are advised to retry

    by creating another erasure request. If the problem persists, contact Support.


    :::note

    Currently, personal data management is only enabled for a limited set of endpoints. See

    the [personal data concepts page](/docs/api/personal-data/personal-data-introduction) for the list of endpoints that support personal data

    management.

    :::


    Seller Admin & IT users have full access to Erasure Requests, and Support users have read access.

    '
paths:
  /v2/personal-data/erasure-requests:
    post:
      tags:
      - Personal Data Erasure Requests
      summary: Create Personal Data Erasure Request
      description: 'This request serves to create a new erasure request for a given resource ID and Type. All resources that belong to the same personal data set will be erased.

        '
      operationId: post-erasure-request
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
              - data
              properties:
                data:
                  $ref: '#/components/schemas/ErasureRequest'
                  required:
                  - type
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    $ref: '#/components/schemas/ErasureRequestResponse'
              examples:
                postErasureRequest:
                  value:
                    data:
                      id: fb25ecd9-c610-4659-97d6-0a7550ac0ddc
                      type: erasure_request
                      resource_id: 98140362-6caf-4829-b93d-953ac6adbe6e
                      resource_type: account
                      initiator:
                        access-token-email: accounts@molt.in
                        access-token-id: '1222341536243515939'
                        access-token-name: moltin test team
                        access-token-store-id: 15ea9633-278c-4807-80f7-2009fed63c7e
                        access-token-type: client-credentials-token
                      status: CREATED
                      status_description: The erasure request successfully created
                      created_at: '2022-06-07T12:25:38.52Z'
                      updated_at: '2022-06-07T12:25:38.69Z'
                      links:
                        self: https://useast.api.elasticpath.com/v2/personal-data/erasure-requests/fb25ecd9-c610-4659-97d6-0a7550ac0ddc
        '400':
          $ref: '#/components/responses/BadRequestError'
        default:
          $ref: '#/components/responses/InternalServerError'
    get:
      tags:
      - Personal Data Erasure Requests
      summary: Get all Personal Data Erasure Request
      description: 'Gets a list of erasure requests for a specific resource id and resource type.


        You can use pagination with this resource. For more information, see [pagination](/guides/Getting-Started/pagination).


        ## Filtering


        The following operator and attributes are **required** for [filtering](/guides/Getting-Started/filtering)

        erasure requests.


        | Operator | Description                                                                                          |

        |:---------|:-----------------------------------------------------------------------------------------------------|

        | `eq`     | Checks whether the values of two operands are equal. If the values are equal, the condition is true. |


        | Attribute       | Type | Operator | Example                                                 |

        |:----------------| :--- | :--- |:--------------------------------------------------------|

        | `resource_type` | `string` | `eq`  | `eq(resource_type,customer)`                            |

        | `resource_id`   | `string` | `eq`  | `eq(resource_id,0f850c15-d643-480a-a2b4-9e3c26067178\)` |

        '
      operationId: get-erasure-requests
      parameters:
      - $ref: '#/components/parameters/PageOffset'
      - $ref: '#/components/parameters/PageLimit'
      - $ref: '#/components/parameters/Filter'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ErasureRequestResponse'
                  meta:
                    $ref: '#/components/schemas/PaginationMeta'
                  links:
                    $ref: '#/components/schemas/PaginationLinks'
              examples:
                postErasureRequest:
                  value:
                    meta:
                      page:
                        limit: 10
                        offset: 0
                        current: 1
                        total: 1
                      results:
                        total: 1
                    data:
                    - id: 43eb23ef-9a97-466f-9315-d0e0c9df25b5
                      type: erasure_request
                      resource_id: abe71c87-974d-4ced-9f83-6b8d5502b0e8
                      resource_type: account
                      initiator:
                        access-token-email: accounts@molt.in
                        access-token-id: '1222341536243515939'
                        access-token-name: moltin test team
                        access-token-store-id: 15ea9633-278c-4807-80f7-2009fed63c7e
                        access-token-type: client-credentials-token
                      status: FAILURE
                      status_description: There was an error processing your request, you can retry it or report it using the id
                      created_at: '2022-05-25T10:10:58.623Z'
                      updated_at: '2022-05-25T10:10:58.676Z'
                    - id: eeb182ed-f929-4197-bb43-7104afa852f2
                      type: erasure_request
                      resource_id: 74f98b7a-dbbf-49ed-b7a7-eaea766b8e38
                      resource_type: address
                      initiator:
                        access-token-email: accounts@molt.in
                        access-token-id: '1222341536243515939'
                        access-token-name: moltin test team
                        access-token-store-id: 15ea9633-278c-4807-80f7-2009fed63c7e
                        access-token-type: client-credentials-token
                      status: SUCCESS
                      status_description: The erasure request is successfully processed
                      created_at: '2022-05-26T08:25:37.618Z'
                      updated_at: '2022-05-26T08:25:37.698Z'
                    - id: 39787c4b-a338-4bd7-ace9-456d1ae8e90b
                      type: erasure_request
                      resource_id: 3327fb93-b687-4c0c-a850-ee95e0303ef1
                      resource_type: account
                      initiator:
                        access-token-email: accounts@molt.in
                        access-token-id: '1222341536243515939'
                        access-token-name: moltin test team
                        access-token-store-id: 15ea9633-278c-4807-80f7-2009fed63c7e
                        access-token-type: client-credentials-token
                      status: FAILURE
                      status_description: There was an error processing your request, you can retry it or report it using the id
                      created_at: '2022-05-26T08:48:56.183Z'
                      updated_at: '2022-05-26T08:48:56.365Z'
                    links:
                      current: https://useast.api.elasticpath.com/v2/personal-data/erasure-requests?filter=eq(resource_type,account_member):eq(resource_id,00000000-0000-1000-8000-000f00000300)&page[offset]=0&page[limit]=10
                      first: https://useast.api.elasticpath.com/v2/personal-data/erasure-requests?filter=eq(resource_type,account_member):eq(resource_id,00000000-0000-1000-8000-000f00000300)&page[offset]=0&page[limit]=10
                      last: https://useast.api.elasticpath.com/v2/personal-data/erasure-requests?filter=eq(resource_type,account_member):eq(resource_id,00000000-0000-1000-8000-000f00000300)&page[offset]=0&page[limit]=10
                      next: 'null'
                      prev: 'null'
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        default:
          $ref: '#/components/responses/InternalServerError'
  /v2/personal-data/erasure-requests/{erasure_request_id}:
    get:
      parameters:
      - $ref: '#/components/parameters/ErasureRequestId'
      tags:
      - Personal Data Erasure Requests
      summary: Get Personal Data Erasure Request
      description: 'This request serves to get an existing erasure request by its ID.

        '
      operationId: get-erasure-request
      responses:
        '200':
          description: Created
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    $ref: '#/components/schemas/ErasureRequestResponse'
              examples:
                postErasureRequest:
                  value:
                    data:
                      id: fb25ecd9-c610-4659-97d6-0a7550ac0ddc
                      type: erasure_request
                      resource_id: 98140362-6caf-4829-b93d-953ac6adbe6e
                      resource_type: account
                      initiator:
                        access-token-email: accounts@molt.in
                        access-token-id: '1222341536243515939'
                        access-token-name: moltin test team
                        access-token-store-id: 15ea9633-278c-4807-80f7-2009fed63c7e
                        access-token-type: client-credentials-token
                      status: CREATED
                      status_description: The erasure request successfully created
                      created_at: '2022-06-07T12:25:38.52Z'
                      updated_at: '2022-06-07T12:25:38.69Z'
                      links:
                        self: https://useast.api.elasticpath.com/v2/personal-data/erasure-requests/fb25ecd9-c610-4659-97d6-0a7550ac0ddc
        '404':
          $ref: '#/components/responses/NotFoundError'
        default:
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    PageOffset:
      name: page[offset]
      description: The current offset by number of records, not pages. Offset is zero-based. The maximum records you can offset is 10,000. If no page size is set, the [page length](/docs/api/settings/settings-introduction#page-length) store setting is used.
      in: query
      required: false
      schema:
        type: integer
        format: int64
        minimum: 0
        maximum: 10000
        example: 0
    ErasureRequestId:
      name: erasure_request_id
      in: path
      required: true
      description: The id of the Personal-Data Erasure Request.
      schema:
        type: string
      example: 3fa85f64-5717-4562-b3fc-2c963f66afa6
    Filter:
      name: filter
      in: query
      required: false
      description: Filter attributes. For more information, see the [Filtering](/guides/Getting-Started/filtering) section.
      schema:
        type: string
        format: string
        example: eq(resource_id,0f850c15-d643-480a-a2b4-9e3c26067178)
    PageLimit:
      name: page[limit]
      description: The maximum number of records per page for this response. You can set this value up to 100. If no page size is set, the [page length](/docs/api/settings/settings-introduction#page-length) store setting is used.
      in: query
      required: false
      schema:
        type: integer
        format: int64
        minimum: 0
        example: 100
  schemas:
    ErasureRequestResponse:
      properties:
        id:
          type: string
          format: uuid
          description: The unique identifier for the log entry.
        resource_type:
          type: string
          description: The type of the data entry to be erased.
          example: account
        resource_id:
          type: string
          format: uuid
          description: The ID of the data entry to be erased (note that also all data entries in the personal data set will be erased).
          example: 98140362-6caf-4829-b93d-953ac6adbe6e
        type:
          type: string
          const: erasure_request
          description: The type of the object. Always equal to `erasure_request`.
        initiator:
          type: object
          description: Specifies who initiated the erasure request.
          properties:
            access-token-email:
              type: string
              example: accounts@elasticpath.com
            access-token-id:
              type: string
              example: 1222341536243515939
            access-token-name:
              type: string
              example: elastic path test team
            access-token-store-id:
              type: string
              format: uuid
              example: 15ea9633-278c-4807-80f7-2009fed63c7e
            access-token-type:
              type: string
              example: client-credentials-token
        status:
          type: string
          description: Specifies the status of the erasure request.
        status_description:
          type: string
          description: Elaborates on the erasure request status.
        created_at:
          type: string
          description: Specifies the status of the erasure request.
        updated_at:
          type: string
          description: Elaborates on the erasure request status.
        links:
          type: object
          properties:
            self:
              type: string
              description: The self link.
    ErrorResponse:
      required:
      - errors
      properties:
        errors:
          type: array
          items:
            $ref: '#/components/schemas/Error'
    Error:
      required:
      - status
      - title
      properties:
        title:
          type: string
          description: A brief summary of the error.
          examples:
          - Bad Request
        status:
          type: string
          format: string
          description: The HTTP response code of the error.
          examples:
          - '400'
        detail:
          type: string
          description: Optional additional detail about the error.
          examples:
          - The field 'name' is required
    ErasureRequest:
      properties:
        resource_type:
          type: string
          description: The type of the data entry to be erased.
          example: account
        resource_id:
          type: string
          format: uuid
          description: The ID of the data entry to be erased (note that also all data entries in the personal data set will be erased).
          example: 98140362-6caf-4829-b93d-953ac6adbe6e
        type:
          type: string
          const: erasure_request
          description: The type of the object. Always equal to `erasure_request`.
    PaginationMeta:
      type: object
      required:
      - page
      - results
      properties:
        results:
          type: object
          properties:
            total:
              description: Total number of results for the entire collection.
              type: integer
              example: 1
        page:
          type: object
          properties:
            limit:
              description: The maximum number of records for all pages.
              type: integer
              example: 100
            offset:
              description: The current offset by number of pages.
              type: integer
              example: 0
            current:
              description: The current number of pages.
              type: integer
              example: 1
            total:
              description: The total number of records for the entire collection.
              type: integer
              example: 1
    PaginationLinks:
      required:
      - current
      - first
      - last
      - next
      - prev
      type: object
      properties:
        current:
          description: Always the current page.
          type:
          - string
          - 'null'
          format: uri
        first:
          description: Always the first page.
          type:
          - string
          - 'null'
          format: uri
        last:
          description: Always `null` if there is only one page.
          type:
          - string
          - 'null'
          format: uri
        next:
          description: Always `null` if there is only one page.
          type:
          - string
          - 'null'
        prev:
          description: Always `null` if the user is on the first page.
          type:
          - string
          - 'null'
  responses:
    NotFoundError:
      description: Not Found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            not-found-error:
              summary: Not Found
              value: "{\n  \"errors\": [\n    {\n      \"detail\": \"not found\",\n      \"status\": \"404\",\n      \"title\": \"Not Found\"\n    }\n  ]\n}\n"
    UnauthorizedError:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            unauthorized-error:
              summary: Unauthorized
              value: "{\n  \"errors\": [\n    {\n      \"title\": \"Unauthorized\",\n      \"status\": \"401\"\n    }\n  ]\n}\n"
    InternalServerError:
      description: Internal server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            internal-server-error:
              summary: Internal server error
              value: "{\n  \"errors\": [\n    {\n      \"title\": \"Internal Server Error\",\n      \"status\": \"500\",\n      \"detail\": \"there was a problem processing your request\"\n    }\n  ]\n}\n"
    BadRequestError:
      description: Bad Request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            bad-request-error:
              summary: Required field missing
              value: "{\n  \"errors\": [\n    {\n      \"title\": \"Bad Request\",\n      \"status\": \"400\",\n      \"detail\": \"Validation failed: field 'Type' on the 'ttl-type' tag.\"\n    }\n  ]\n}\n"
  securitySchemes:
    BearerToken:
      type: http
      scheme: bearer