> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grantex.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Export

> Generate a compliance export: a DPDP audit, a GDPR Article 15 access report for one person, or an EU AI Act evidence pack.

## Endpoint

```
POST /v1/dpdp/exports
```

## Authentication

Requires a developer API key in the `Authorization` header.

## Request Headers

| Header | Value |
| - | - |
| `Authorization` | `Bearer <api_key>` |
| `Content-Type` | `application/json` |

## Request Body

| Field | Type | Required | Description |
| - | - | - | - |
| `type` | `string` | Yes | Export type: `dpdp-audit`, `gdpr-article-15`, `eu-ai-act-evidence`, or `eu-ai-act-conformance` (see Export Types) |
| `dateFrom` | `string` | Yes | ISO-8601 start date or date-time for the export window |
| `dateTo` | `string` | Yes | ISO-8601 end date or date-time; not before `dateFrom` |
| `format` | `string` | No | Output format. Only `"json"` (the default) is produced; any other value is `400` |
| `includeActionLog` | `boolean` | No | Include audit log entries (default: `true`) |
| `includeConsentRecords` | `boolean` | No | Include consent records (default: `true`) |
| `dataPrincipalId` | `string` | No | Filter the export to one data principal (see below). Needed for the `article15` block of `gdpr-article-15`, and required for that type when `DPDP_EXPORT_GDPR_REQUIRES_PRINCIPAL=true`. Not accepted for `eu-ai-act-evidence` |

## Example Request

```bash theme={null}
curl -X POST https://api.grantex.dev/v1/dpdp/exports \
  -H "Authorization: Bearer gx_..." \
  -H "Content-Type: application/json" \
  -d '{
    "type": "dpdp-audit",
    "dateFrom": "2026-01-01T00:00:00.000Z",
    "dateTo": "2026-04-01T00:00:00.000Z",
    "includeActionLog": true,
    "includeConsentRecords": true
  }'
```

## Response -- 201 Created

```json theme={null}
{
  "exportId": "exp_01HXYZ...",
  "type": "dpdp-audit",
  "format": "json",
  "recordCount": 42,
  "truncated": false,
  "auditLogLimit": 1000,
  "dataPrincipalId": null,
  "data": {
    "exportType": "dpdp-audit",
    "dateRange": {
      "from": "2026-01-01T00:00:00.000Z",
      "to": "2026-04-01T00:00:00.000Z"
    },
    "generatedAt": "2026-04-05T14:00:00.000Z",
    "developerId": "dev_01HXYZ...",
    "consentRecords": [...],
    "auditLog": [...],
    "grievances": [...],
    "truncated": false,
    "auditLogLimit": 1000
  },
  "expiresAt": "2026-04-12T14:00:00.000Z",
  "createdAt": "2026-04-05T14:00:00.000Z"
}
```

## Response Fields

| Field | Type | Description |
| - | - | - |
| `exportId` | `string` | Unique export ID |
| `type` | `string` | Export type |
| `format` | `string` | Output format |
| `recordCount` | `number` | Total number of records in the export |
| `truncated` | `boolean` | `true` when the audit log had more than `auditLogLimit` entries in the window and only the newest `auditLogLimit` are included. For `eu-ai-act-evidence`, `true` when any section left rows out; for `gdpr-article-15` with `dataPrincipalId`, also when the principal had more than 1,000 grievances in the window. The sections and the `article15` block also carry their own `truncated` |
| `auditLogLimit` | `number` | The audit log cap (1000) |
| `dataPrincipalId` | `string \| null` | The principal the export is filtered to, if any |
| `data` | `object` | The export data payload (see below) |
| `expiresAt` | `string` | ISO-8601 expiry timestamp (7 days from creation) |
| `createdAt` | `string` | ISO-8601 creation timestamp |

### Export Data Object

| Field | Type | Description |
| - | - | - |
| `exportType` | `string` | The export type |
| `dateRange` | `object` | `{ from, to }` ISO-8601 timestamps |
| `generatedAt` | `string` | ISO-8601 generation timestamp |
| `developerId` | `string` | Developer who generated the export |
| `consentRecords` | `object[]` | Consent records in the date range (if `includeConsentRecords`) |
| `auditLog` | `object[]` | Audit log entries in the date range (if `includeActionLog`, newest first, at most 1000; see `truncated`) |
| `grievances` | `object[]` | Grievances in the date range: for `dpdp-audit`, and for `gdpr-article-15` with `dataPrincipalId` (the principal's own, newest first, at most 1,000, with `description`; counted in `recordCount`) |
| `truncated` | `boolean` | As above |
| `auditLogLimit` | `number` | As above |

### Filtering to a data principal

With `dataPrincipalId`, consent records and grievances are those of that
principal. `audit_entries.principal_id` is the principal of the grant the
entry was written under, which is the DPDP data principal only when an
integration keys both the same way (`DPDP_ENFORCE_GRANT_PRINCIPAL=true`
enforces it). The audit log therefore includes entries written under the
grants of the principal's consent records, entries whose principal is
`dataPrincipalId`, and the platform's DPDP audit entries about the principal.
(Grievances used to be included for every principal even when the export was
filtered.)

Creating an export is recorded on the audit chain as
`grantex.dpdp.export_created`. Exports expire after 7 days; reading one after
that answers `410 GONE` and its data is purged. An erasure of a principal
deletes the stored exports about that principal when the server sets
`DPDP_ERASURE_EXPANDED=true`; otherwise they are kept until they expire.

## Export Types

| Type | Description | Includes Grievances |
| - | - | - |
| `dpdp-audit` | India DPDP Act audit export | Yes |
| `gdpr-article-15` | GDPR right of access (Article 15) report; with `dataPrincipalId` it adds the `article15` block below | With `dataPrincipalId` (that principal's only) |
| `eu-ai-act-evidence` | EU AI Act evidence pack: structured sections instead of the generic keys; see [EU AI Act Evidence Pack](/api-reference/dpdp/eu-ai-act-evidence) | No |
| `eu-ai-act-conformance` | Kept for compatibility: the generic keys as before, plus the evidence pack's sections when the export is not filtered to a principal. It is not a conformity assessment | No |

### The GDPR Article 15 block

A `gdpr-article-15` export with `dataPrincipalId` adds `data.article15`, the
information GDPR Art. 15(1) lists, as far as Grantex's records allow. It
covers all of the principal's consent records for the developer (up to
1,000), not only those in the date window:

| Field | Description |
| - | - |
| `purposes` | Each purpose code the principal consented to, with the records that name it; `grantPurposes` lists the purposes recorded on the grants |
| `recipients` | The agents the principal authorised through grants (consent-record grants and grants whose principal is the data principal), each with its grant ids, scopes and the resource servers (`audiences`) the grants name |
| `retention` | Per record `processingExpiresAt`, `retentionUntil`, `withdrawnAt` and `erasedAt`, and how audit entries are kept |
| `source` | Per record the consent notice id, version and language, and when consent was given |
| `grievances` | `{ count, limit, truncated, statement }` for the grievances copy in `data.grievances`: the principal's grievances filed in the date window |
| `automatedDecisionMaking` | `recorded: false`: Grantex does not record GDPR Art. 22 decisions |
| `truncated` | `true` when more than 1,000 records, grants or grievances exist |

The copy of the data itself is in `consentRecords`, `auditLog` and `grievances`. Personal
data the controller processes in its own systems is not held by Grantex.

Without `dataPrincipalId` the export is produced as before, without the
block. With `DPDP_EXPORT_GDPR_REQUIRES_PRINCIPAL=true` (off by default) a
`gdpr-article-15` export without `dataPrincipalId` answers `400`.

## Error Responses

| Status | Code | Description |
| - | - | - |
| 400 | `BAD_REQUEST` | Missing required fields, invalid `type`, an invalid date, `dateFrom` after `dateTo`, a `format` other than `json`, `dataPrincipalId` with `eu-ai-act-evidence`, or (under `DPDP_EXPORT_GDPR_REQUIRES_PRINCIPAL=true`) `gdpr-article-15` without `dataPrincipalId` |
| 401 | `UNAUTHORIZED` | Invalid or missing API key |

## SDK Examples

<CodeGroup>
  ```typescript TypeScript theme={null}
  import { Grantex } from '@grantex/sdk';

  const grantex = new Grantex({ apiKey: 'gx_...' });

  const report = await grantex.dpdp.createExport({
    type: 'dpdp-audit',
    dateFrom: '2026-01-01T00:00:00.000Z',
    dateTo: '2026-04-01T00:00:00.000Z',
  });
  // report.recordCount → 42
  // report.data.consentRecords → [...]
  ```

  ```python Python theme={null}
  from grantex import CreateExportParams, Grantex

  grantex = Grantex(api_key="gx_...")

  report = grantex.dpdp.create_export(
      CreateExportParams(
          type="dpdp-audit",
          date_from="2026-01-01T00:00:00.000Z",
          date_to="2026-04-01T00:00:00.000Z",
      )
  )
  ```
</CodeGroup>

## Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: [sanjeev@orchestrum.in](mailto:sanjeev@orchestrum.in) or [mishra.sanjeev@gmail.com](mailto:mishra.sanjeev@gmail.com).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.