Skip to main content
POST
Request an approval

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
kind
enum<string>
required
Available options:
purposes,
policy_loosening,
retention,
operators,
transfer,
access_review,
ripd
project_id
string<uuid>
required
subject_ref
string
required

What is approved: a pending diff's id (purposes, policy_loosening, retention), add:<role>:<entity id> or end:<party id> (operators), the new operator's tenant id (transfer), a purpose (ripd); ignored for access_review.

Required string length: 1 - 512

Response

Successful Response

An approval asked of the project's controller. The link goes only to its DPO's e-mail.

approval_id
string<uuid>
required
document_hash
string
required

SHA-256 of the canonical JSON of what the controller approves.

expires_at
string<date-time>
required
kind
enum<string>
required
Available options:
purposes,
policy_loosening,
retention,
operators,
transfer,
access_review,
emergency_access,
ripd
project_id
string<uuid>
required
requested_at
string<date-time>
required
status
enum<string>
required
Available options:
pending,
approved,
rejected,
expired
subject_ref
string
required
decided_at
string<date-time> | null