> ## Documentation Index
> Fetch the complete documentation index at: https://spreecommerce.org/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Open a data request

> Opens a GDPR request for a copy of the customer's personal data (`access`)
or its erasure (`erasure`). The work happens in the background and the
response is the pending request.

An erasure request requires the account password. A request of the same
kind that is still in flight is returned instead of starting a second one.




## OpenAPI

````yaml /api-reference/store.yaml post /api/v3/store/customers/me/data_requests
openapi: 3.0.3
info:
  title: Store API
  contact:
    name: Spree Commerce
    url: https://spreecommerce.org
    email: hello@spreecommerce.org
  description: >
    Spree Store API v3 - Customer-facing storefront API for building headless
    commerce experiences.


    ## Authentication


    The Store API uses two authentication methods:


    ### API Key (Required)

    All requests must include a publishable API key in the `x-spree-api-key`
    header.


    ### JWT Bearer Token (For authenticated customers)

    After login, include the JWT token in the `Authorization: Bearer <token>`
    header.


    ### Order Token (For guest checkout)

    When creating an order, a `token` is returned. Include this in the
    `x-spree-token` header

    for guest access to that specific order.


    ## Response Format


    All responses are JSON. List endpoints return paginated responses with
    `data` and `meta` keys.


    ## Error Handling


    Errors return a consistent format:

    ```json

    {
      "error": {
        "code": "record_not_found",
        "message": "Product not found"
      }
    }

    ```
  version: v3
servers:
  - url: http://{defaultHost}
    variables:
      defaultHost:
        default: localhost:3000
security: []
tags:
  - name: Authentication
    description: Customer authentication (login, logout, token refresh)
  - name: Product Catalog
    description: Products and categories
  - name: Carts
    description: Shopping cart management
  - name: Orders
    description: Order lookup
  - name: Customers
    description: Customer account, addresses, saved payment methods, and order history
  - name: Markets
    description: Markets, countries, currencies, and locales
  - name: Wishlists
    description: Customer wishlists
  - name: Newsletter Subscribers
    description: Guest and customer newsletter subscriptions (double opt-in)
  - name: Policies
    description: Store policies (return policy, privacy policy, terms of service)
  - name: Digitals
    description: Digital product downloads
paths:
  /api/v3/store/customers/me/data_requests:
    post:
      tags:
        - Customers
      summary: Open a data request
      description: >
        Opens a GDPR request for a copy of the customer's personal data
        (`access`)

        or its erasure (`erasure`). The work happens in the background and the

        response is the pending request.


        An erasure request requires the account password. A request of the same

        kind that is still in flight is returned instead of starting a second
        one.
      parameters:
        - name: x-spree-api-key
          in: header
          required: true
          schema:
            type: string
        - name: Authorization
          in: header
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                kind:
                  type: string
                  enum:
                    - access
                    - erasure
                  description: Defaults to access
                current_password:
                  type: string
                  description: Required for erasure
      responses:
        '202':
          description: request accepted
          content:
            application/json:
              example:
                id: dsr_UkLWZg9DAJ
                number: DSR1001
                kind: access
                status: pending
                requested_at: '2026-01-15T12:00:00Z'
                completed_at: null
                expires_at: null
                download_url: null
              schema:
                $ref: '#/components/schemas/DataRequest'
        '422':
          description: erasure without the account password
          content:
            application/json:
              example:
                error:
                  code: current_password_invalid
                  message: Current password is invalid or missing
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - api_key: []
          bearer_auth: []
components:
  schemas:
    DataRequest:
      type: object
      properties:
        id:
          type: string
        number:
          type: string
        kind:
          type: string
          enum:
            - access
            - erasure
        status:
          anyOf:
            - type: string
              enum:
                - pending
                - processing
                - completed
                - failed
            - type: string
          description: The values listed are the built-in ones; extensions may add more.
        requested_at:
          type: string
          nullable: true
        completed_at:
          type: string
          nullable: true
        expires_at:
          type: string
          nullable: true
        download_url:
          type: string
          nullable: true
      required:
        - id
        - number
        - kind
        - status
        - requested_at
        - completed_at
        - expires_at
        - download_url
      x-typelizer: true
    ErrorResponse:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              example: record_not_found
            message:
              type: string
              example: Record not found
            details:
              type: object
              description: Field-specific validation errors
              nullable: true
              example:
                name:
                  - is too short
                  - is required
                email:
                  - is invalid
          required:
            - code
            - message
      required:
        - error
      example:
        error:
          code: validation_error
          message: Validation failed
          details:
            name:
              - is too short
            email:
              - is invalid
  securitySchemes:
    api_key:
      type: apiKey
      name: x-spree-api-key
      in: header
      description: Publishable API key for store access
    bearer_auth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: JWT token for authenticated customers

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.