> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an LGPD data-subject request

> Creates an LGPD access, portability, or erasure request scoped to the path institution. The acting admin subject is derived from the validated identity; the CPF/CNPJ is tokenized server-side and never echoed.



## OpenAPI

````yaml en/openapi/v3-current/sisbajud.yaml post /institutions/{institutionId}/lgpd/requests
openapi: 3.1.0
info:
  description: >-
    API for Lerian SISBAJUD — the participant-side rail that integrates the
    institution with Banco Central do Brasil's SISBAJUD (Sistema de Busca de
    Ativos do Poder Judiciário) system for judicial asset blocking and
    unblocking. It covers judicial-order administration, remittance and return
    file management, reconciliation, SLA monitoring, LGPD data-subject requests,
    and per-institution configuration and connector credentials.
  title: Lerian SISBAJUD API
  version: 1.0.0
servers:
  - url: https://sisbajud.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - description: >-
      Institution configuration lifecycle: create (with key provisioning), read,
      and partial update of a connector configuration addressed by institution
      id.
    name: Institution
  - description: >-
      LGPD data-subject access, portability, resolution, and cryptographic
      erasure operations, addressed by institution id.
    name: LGPD
  - description: >-
      Manual cryptographic key administration: KEK and tokenization-keyset
      rotation for an institution, addressed by institution id.
    name: Security
  - description: >-
      Judicial-order operational resilience write operations, such as
      reprocessing a FAILED order, addressed by institution id.
    name: Order Operations
  - description: >-
      Non-compliance-log administration, such as registering an SLA-breach
      justification, addressed by institution id.
    name: Non-Compliance
  - description: >-
      Manual reconciliation administration, such as triggering an on-demand
      reconciliation run.
    name: Reconciliation
  - description: >-
      Authenticated remittance-file reception: a caller notifies the service of
      a file already present in the inbound bucket and the service runs the
      receive and parse pipeline.
    name: Remittance File
  - description: >-
      Return (response) file administration, such as forcing an on-demand
      return-file generation outside the scheduled cron.
    name: Return File
  - description: >-
      Local/development-only admin routes (return-file content, monitoring
      close, unblock execute). Mounted only in local and development
      environments; never present in staging or production.
    name: Dev-Only
  - description: >-
      Admin read API: institution-scoped order, file, reconciliation, SLA, and
      processing-stats queries, plus audit-trail integrity verification. PII
      fields are masked unless the caller proves a cleartext grant.
    name: Admin
  - description: >-
      Connector credential registration and rotation: provisions an
      institution's per-connector outbound credential into the SecretStore and
      persists only its reference.
    name: Connector
  - description: >-
      Cross-organization subject summary: consolidates a subject's active blocks
      across the caller institution's Midaz organizations. Reading a subject by
      document is a privileged, audited PII access.
    name: Cross-Org
paths:
  /institutions/{institutionId}/lgpd/requests:
    post:
      tags:
        - LGPD
      summary: Create an LGPD data-subject request
      description: >-
        Creates an LGPD access, portability, or erasure request scoped to the
        path institution. The acting admin subject is derived from the validated
        identity; the CPF/CNPJ is tokenized server-side and never echoed.
      operationId: create-lgpd-request
      parameters:
        - description: >-
            The institution's unique identifier (UUID) the LGPD request is
            scoped to.
          in: path
          name: institutionId
          required: true
          schema:
            description: >-
              The institution's unique identifier (UUID) the LGPD request is
              scoped to.
            examples:
              - 44444444-4444-4444-4444-444444444444
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PostLgpdRequestBody'
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PostLgpdRequestResponse'
          description: Created
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
components:
  schemas:
    PostLgpdRequestBody:
      additionalProperties: false
      properties:
        cpfCnpj:
          description: >-
            The data subject's cleartext CPF or CNPJ (tokenized server-side;
            never echoed nor logged).
          examples:
            - '52998224725'
          type: string
        docType:
          description: >-
            The document type (cpf or cnpj); inferred from the subject value
            when omitted.
          examples:
            - cpf
          type: string
        legalJustification:
          description: >-
            The legal basis for the request (sealed verbatim into the audit
            payload).
          examples:
            - LGPD art. 18 data subject request
          type: string
        requestType:
          description: The LGPD request type (e.g. access, portability, erasure).
          examples:
            - access
          type: string
        requesterProtocol:
          description: The caller-supplied protocol identifier for correlation.
          examples:
            - PROT-2026-0001
          type: string
      required:
        - requestType
        - cpfCnpj
        - requesterProtocol
        - legalJustification
      type: object
    PostLgpdRequestResponse:
      additionalProperties: false
      properties:
        id:
          description: The newly created LGPD request id.
          examples:
            - 11111111-1111-1111-1111-111111111111
          type: string
        requesterProtocol:
          description: The caller-supplied protocol identifier echoed for correlation.
          examples:
            - PROT-2026-0001
          type: string
      required:
        - id
        - requesterProtocol
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````