OneTrust Targeted Data Discovery API

APIs used to add, update, and retrieve structured or unstructured data discovery results linked to privacy requests.

Operations 4

GET /api/datasubject/v2/datadiscovery/groups/{groupId}/requestqueues/{requestQueueRefId} Get Targeted Data Discovery Group #
GET /api/datasubject/v2/datadiscovery/requestqueues/{requestQueueRefId} Get List of Targeted Data Discovery Groups #
POST /api/datasubject/v2/datadiscovery/requestqueues/{requestQueueRefId} Add Targeted Data Discovery Results Summary to Request #
POST /api/datasubject/v3/datadiscovery/requestqueues/{requestQueueRefId} Add Data Points to Targeted Data Discovery Results Summary #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-targeted-data-discovery-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-targeted-data-discovery-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Privacy Automation - Data Subject Request (DSR) Automation…
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  description: The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, verification methods, and audit history.
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: Targeted Data Discovery
  description: APIs used to add, update, and retrieve structured or unstructured data discovery results linked to privacy requests.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
  x-displayName: Targeted Data Discovery
paths:
  /api/datasubject/v2/datadiscovery/groups/{groupId}/requestqueues/{requestQueueRefId}:
    get:
      operationId: getAllGroupAndAttachmentDetailsUsingGET
      summary: Get Targeted Data Discovery Group
      description: Use this API to retrieve results for a Targeted Data Discovery group for the specified request.
      tags:
      - Targeted Data Discovery
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: groupId
        in: path
        required: true
        schema:
          description: TDD Group Id
          type: string
          format: uuid
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: Request queue ref ID
          type: string
      - name: includeAttachments
        in: query
        required: false
        schema:
          description: Set to true to include attachment information in the response. If false or omitted, attachments will not be included.
          type: boolean
          default: false
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupV2Dto'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_READ
        - DSAR_WRITE
  /api/datasubject/v2/datadiscovery/requestqueues/{requestQueueRefId}:
    get:
      operationId: getAllGroupByRequestUsingGET
      summary: Get List of Targeted Data Discovery Groups
      description: Use this API to retrieve a list of all Targeted Data Discovery groups for the specified request. The response will include details for each group along with the corresponding group ID, name, and order.
      tags:
      - Targeted Data Discovery
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: Request queue reference Id
          type: string
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupResultV2Dto'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_READ
        - DSAR_WRITE
    post:
      operationId: dataDiscoveryUpdatesUsingPOST
      summary: Add Targeted Data Discovery Results Summary to Request
      description: Use this API to add Targeted Data Discovery results to a request.
      tags:
      - Targeted Data Discovery
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: Request queue reference Id
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupDto'
      responses:
        '200':
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_WRITE
  /api/datasubject/v3/datadiscovery/requestqueues/{requestQueueRefId}:
    post:
      operationId: unstructuredDataDiscoveryUpdatesUsingPOST
      summary: Add Data Points to Targeted Data Discovery Results Summary
      description: Use this API to add Targeted Data Discovery results that include unstructured data to a request.
      tags:
      - Targeted Data Discovery
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: Request queue reference Id
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupDto'
      responses:
        '200':
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_WRITE
components:
  schemas:
    PrivacyAutomation-DataSubjectRequestDSRAutomation_EmlAttachmentMetadata:
      type: object
      properties:
        attachmentId:
          type: string
          format: uuid
        emlSubject:
          type: string
        senderName:
          type: string
        sendDate:
          type: string
          format: date-time
    PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupResultV2Dto:
      type: object
      properties:
        groupName:
          description: Name of the group.
          type: string
          example: Salesforce Customer Data
        groupOrder:
          description: Order in which group has been created.
          type: integer
          format: int64
        groupId:
          description: Unique Identifier of the group.
          type: string
          format: uuid
          example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad
    PrivacyAutomation-DataSubjectRequestDSRAutomation_UnStructuredData:
      type: object
      properties:
        type:
          description: The type of unstructured data (e.g., document, image, email).
          type: string
          example: document
        status:
          description: The processing status of the unstructured data.
          type: string
          example: processed
        key:
          description: A unique identifier or name for the unstructured data item.
          type: string
          example: contract_2023
        value:
          description: The content or reference to the unstructured data.
          type: string
          example: https://storage.example.com/documents/contract_2023.pdf
        isRedact:
          description: Indicates whether the data should be redacted in the response.
          type: boolean
          example: true
        attributes:
          description: Additional attributes or metadata associated with the unstructured data.
          type: object
          additionalProperties:
            type: string
      required:
      - key
      - type
      - value
    PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentDto:
      type: object
      properties:
        fileName:
          description: Name of the file.
          type: string
          example: receipt.pdf
        fileId:
          description: Unique Identifier of the File.
          type: string
          format: uuid
          example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad
        isRedact:
          type: boolean
          writeOnly: true
        emlAttachmentMetadata:
          $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_EmlAttachmentMetadata'
        redact:
          type: boolean
    PrivacyAutomation-DataSubjectRequestDSRAutomation_PageDataDiscoveryResultsV2Dto:
      type: object
      properties:
        totalElements:
          type: integer
          format: int64
        totalPages:
          type: integer
          format: int32
        size:
          type: integer
          format: int32
        content:
          items:
            $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryResultsV2Dto'
          type: array
        number:
          type: integer
          format: int32
        sort:
          $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject'
        first:
          type: boolean
        last:
          type: boolean
        numberOfElements:
          type: integer
          format: int32
        pageable:
          $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PageableObject'
        empty:
          type: boolean
    PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryResultsV2Dto:
      type: object
      properties:
        id:
          description: Unique Identifier for field Id.
          type: string
          format: uuid
          example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad
        fieldName:
          description: The name for a data field in the results summary
          type: string
          example: firstname
        value:
          description: This is the actual data element.
          type: string
          example: John
        system:
          description: Displays the name of the source of a particular data element.
          type: string
          example: Salesforce
    PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupV2Dto:
      type: object
      properties:
        groupName:
          description: Name of the group.
          type: string
          example: Salesforce Customer Data
        groupId:
          description: Unique Identifier of the group.
          type: string
          format: uuid
          example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad
        dataDiscoveryResultsV2Dtos:
          $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_PageDataDiscoveryResultsV2Dto'
        dataDiscoveryAttachmentListDtos:
          type: array
          items:
            $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentListDto'
    PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryGroupDto:
      type: object
      properties:
        system:
          description: Name or identifier of the system from which this data is sourced. This will be displayed on the Results Summary.
          type: string
          example: Office365
        results:
          description: Dataset that includes list of data groups with nested name-value-pairs to capture structured data.
          type: object
          additionalProperties:
            type: object
            additionalProperties:
              type: object
        unstructuredResults:
          type: array
          items:
            $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_UnStructuredData'
        attachments:
          description: Optional. List of name-value-pairs containing file names and IDs to attach. Use the Add File API to add file into OneTrust and retrieve the File IDs. These files will be visible in the Results Summary.
          type: array
          items:
            $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentDto'
      required:
      - system
    PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject:
      type: object
      properties:
        empty:
          type: boolean
        unsorted:
          type: boolean
        sorted:
          type: boolean
    PrivacyAutomation-DataSubjectRequestDSRAutomation_DataDiscoveryAttachmentListDto:
      type: object
      properties:
        id:
          type: string
          format: uuid
        fileName:
          description: Name of the file.
          type: string
          example: receipt.pdf
        fileId:
          description: Unique Identifier of the File.
          type: string
          format: uuid
          example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad
        source:
          description: Name of the system where the attachment originated and displayed as targeted data discovery system for files added by user.
          type: string
        fileSize:
          description: Size of the file in kilobyte.
          type: integer
          format: int64
        isSharable:
          type: boolean
          writeOnly: true
        sharable:
          type: boolean
    PrivacyAutomation-DataSubjectRequestDSRAutomation_PageableObject:
      type: object
      properties:
        offset:
          type: integer
          format: int64
        sort:
          $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_SortObject'
        paged:
          type: boolean
        pageNumber:
          type: integer
          format: int32
        pageSize:
          type: integer
          format: int32
        unpaged:
          type: boolean
  securitySchemes:
    PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            DSAR_READ: Read-only access to DSAR objects scope for external systems
            DSAR_WRITE: Access to DSAR objects scope for external systems
            DSAR: Access to DSAR objects scope for external systems
    PrivacyAutomation-DROPManagement_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            DSAR_WRITE: Access to DROP objects scope for external systems
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false
x-onetrust:
  spec-label: OpenAPI 3.1.0