Export a data subject's data
GDPR Art. 15 access request. Owner or admin only. Returns contacts, lawful basis, messages, and suppressions for the address.
GDPR Art. 15 access request. Owner or admin only. Returns contacts, lawful basis, messages, and suppressions for the address.
Authorization
bearerAuth A Supabase Auth user access token for the signed-in SignalDock user, sent as Authorization: Bearer <token>. Paste one from a signed-in session, or obtain one through the oauth2 scheme; the API accepts either.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Data subject request keyed by email address (GDPR Art. 15 export / Art. 17 erasure).
Response Body
application/json
application/problem+json
application/problem+json
curl -X POST "https://example.com/compliance/dsar/export" \ -H "Content-Type: application/json" \ -d '{ "organizationId": "7bc05553-4b68-44e8-b7bc-37be63c6d9e9", "email": "user@example.com" }'{ "email": "string", "generated_at": "2019-08-24T14:15:22Z", "contacts": [ { "property1": null, "property2": null } ], "lawful_basis": [ { "property1": null, "property2": null } ], "messages": [ { "property1": null, "property2": null } ], "suppressions": [ { "property1": null, "property2": null } ]}Export audit events GET
Owner or admin on Growth or Scale. Audit events oldest first, at most 10,000 per call; continue from the last `created_at`. The export is itself audited.
Erase a data subject POST
GDPR Art. 17 erasure. Deletes the contacts (messages and lawful basis cascade) and keeps a suppression so the address is never re-imported.