Request erasure of a customer's personal data
POST/gdpr/v1/erasure
Submit a right-to-erasure request for one of your customers. Pass their email and your own data-protection request reference. The reference is recorded in Two's audit trail alongside the erasure and echoed back to you. This is irreversible. Names, email addresses, phone numbers and identity verification data are replaced in place with anonymised placeholders. There is no undo and Two cannot restore erased personal data, so confirm the email address first — call GET /gdpr/v1/lookup before this one. A 202 means the request has been accepted for processing — it is not confirmation that the data has been erased, and it should not be treated as one. The response reports no outcome: there is no completion timestamp to poll for and no failure status to handle. Only your own customers are in scope, and a request naming an address we hold no records for, or one whose records cannot be erased — because orders are financial records Two must retain under Article 17(3)(b) — is accepted in exactly the same way and then does nothing. GET /gdpr/v1/lookup is how you find out which of those applies, which is why it is worth calling first. Retrying is safe: resubmitting the same reference returns the same 202 and erases nothing twice. Where a record is shared with another merchant, only your side of it is erased.
Request
Responses
- 202
- 400
- 429
- default
The erasure request has been accepted.
Validation error or invalid request body
Rate limit exceeded
Error response