User Rights API: Automated personal data erasure
The new User Rights API allows you to automate personal data erasure requests across VTEX applications.
The new User Rights API allows you to automate the deletion of a user's personal data across VTEX applications, in compliance with "Right to be Forgotten" regulations.
The user rights flows available in this API apply only to non-corporate shoppers. They don't apply to B2B buyers or Admin users.
What has changed?
Previously, deleting a user's personal data required a manual process through Copilot, as described in Erasing customer data. Now, you can integrate with the User Rights API to handle these requests programmatically.
The API provides two endpoints:
- Create data erasure job: Submit a user's email to start the deletion process and receive a job ID.
- Get data erasure job status: Poll the job ID to track the deletion progress until it completes.
Why did we make this change?
To provide merchants with a scalable, automated way to fulfill personal data erasure requests, eliminating the need for manual processing of each individual request.
What needs to be done?
No action is required. The existing manual flow remains available.
To adopt the automated workflow, refer to the User Rights API integration guide for step-by-step implementation instructions.