Skip to main content

Automate Data Subject Rights Requests from OneTrust

LiveRamp integration with OneTrust allows customers to deliver opt-out and deletion requests from OneTrust directly to LiveRamp, as opposed to SFTP file submission or calls to the Privacy API. This integration lets OneTrust send privacy requests automatically from your existing privacy workflow to LiveRamp's Privacy API, while LiveRamp handles identity resolution and downstream processing

Requirements

From LiveRamp:

  • Approval by LiveRamp to integrate with OneTrust. Talk to a LiveRamp representative to find out if you are eligible.

  • Service account credentials. Contact your LiveRamp representative for your service account username (Account ID) and your password (Secret Key). You should receive a JSON file that includes those credentials.

  • Your Connect organization ID.

From OneTrust:

  • An Integration Manager role.

  • Access to a Privacy Rights Automation (PRA) request workflow.

  • A valid email address on each data subject request.

Overall Steps

Integrating OneTrust with LiveRamp involves the following steps:

  1. Obtain required credentials from LiveRamp.

  2. Add the credentials in OneTrust.

  3. Add the deletion and opt-out request workflows via OneTrust's Integration Gallery.

  4. Attach the workflows to data subject rights requests.

  5. Confirm requests are sent to LiveRamp.

Add Credentials in OneTrust

  1. Log in to OneTrust.

  2. From the navigation menu, select Integrations → Credentials.

  3. Click Add credential.

  4. From the Select existing system field, search for "LiveRamp" and select it from the list.

    Select_System_OneTrust.png
  5. Click Next.

  6. Configure the credential details with the following values:

    • Credential Name: A unique name (e.g. LiveRamp Staging [Your Company])

    • Configuration Type: Configure manually

    • Application Type: Web App

    • Authentication Method: OAuth 2.0

    • Grant Type: Password Credentials

    • Access Token URL: https://serviceaccounts.liveramp.com/authn/v1/oauth2/token

    • User name: The username from your service account JSON file

    • Password: The password from your service account JSON file

    • Client ID: liveramp-api

    • Client Secret:The password from your service account JSON file

  7. Then, click the Advanced settings arrow to display additional fields that you must configure with the following values:

    • Protocol: HTTPS

    • Hostname: One of the following URLs:

      • https://privacy-api.liveramp.com to default requests to the production environment

      • https://privacy-api.staging.liveramp.com to default requests to the staging environment

    • Send authentication parameters in: Form URL Encoded

    • Send credentials in: HTTPS headers

    • Allow mTLS: No

    • Classify as sensitive: No

  8. Under "Authentication Parameters", add the following parameters and their values for each row:

    • grant_type: password

    • username: The same value as the "User name" field in step 6.

    • password: The same value as the "Password" field in step 6.

    • client_id: liveramp-api

    • scope: openid

    • response_type: token

  9. Click the Test settings arrow to test the credential and validate the connection. In the Test URL field, enter the following staging URL: https://privacy-api.staging.liveramp.com/v1 /requests, then click Test credentials.

    A successful test confirms OAuth and connectivity to LiveRamp’s staging Privacy API.

    Note

    For production workflows, requests are sent to https://privacy-api.liveramp.com.

  10. Click Save.

Add the Deletion and Opt-Out Workflows

  1. From the navigation menu in OneTrust, select Integrations → Gallery.

  2. Search for LiveRamp and open its integration tile.

    LiveRamp_Integration_Tile.png
  3. There are two workflows you must add individually:

    • [PRA] Fulfill request - Create data deletion request in LiveRamp

    • [PRA] Fulfill request - Create data opt-out request in LiveRamp

  4. For each of the workflows above:

    1. Click Add.

    2. Enter a unique workflow name.

    3. Select the LiveRamp credentials that correspond to the environment you’re working in (staging or production).

    4. Set a notification email.

    5. Click Create, then Activate.

Attach Workflows Manually to Data Subject Requests

The workflows can be run in two ways:

  • Automatically when a request reaches a configured workflow stage, or

  • Manually as a subtask on an active request (recommended for initial testing)

Procedure. To attach a workflow to a request manually:
  1. From the navigation menu in OneTrust, select Privacy Rights Automation → Requests.

  2. Click a data deletion or opt-out request to open its details page.

  3. Select the Subtasks tab and click Add connection.

    Add_Connection_Subtask.png
  4. From the side panel that opens, select Create a new subtask.

  5. Search for the LiveRamp workflow you've created and check its box. Click Next.

    Create_Subtask_OneTrust.png
  6. Enter a subtask name, and then click Add.

The subtask you've created will display. Its status should move from "Processing" to "Complete" if the run was successful.

Subtast_Completed_OneTrust.png

Confirm Requests are Sent to LiveRamp

When a subtask runs, OneTrust calls LiveRamp’s Privacy API to create the request. LiveRamp returns a response with the status of your request.

You can check your request status and diagnose errors in OneTrust by opening the integration logs of the applicable workflow.

LiveRamp_Response.png

Note

A positive is_duplicate response is expected for opt-out requests. If a deletion request is flagged as a duplicate, see "Troubleshooting" below.

Alternatively, you can create a GET request to the Privacy API endpoint to retrieve your requests. See our developers' documentation for more details about the Privacy API.

Your request status updates as LiveRamp processes your request. See what each status means below:

  • ACCEPTED: Your request is being queued for processing.

  • PROCESSING: LiveRamp is processing your request.

  • COMPLETED: Your request has been successfully processed.

  • FAILED: Processing failed. Troubleshoot required in OneTrust.

LiveRamp processes the request through the standard Privacy API pipeline. Your request should move from Accepted to Processing within a day and from Processing to Completed within 15 to 45 days.

Troubleshooting

Symptom

Likely Cause

What to Do

Subtask fails immediately

Missing or invalid email

Confirm the data subject request has a valid email mapped.

401 Unauthorized

Expired or incorrect credentials

Compare your OneTrust credential fields against your service account credentials JSON.

403 Forbidden

Organization ID or permission mismatch

Contact your LiveRamp representative to confirm your organization ID and API access.

Subtask stuck in PROCESSING

LiveRamp is still processing the request

Wait for the next batch cycle, then check the request status.

Subtask failed

An API or processing error occurred

Retry the task in OneTrust. If it fails again, review the integration log for the error.

Deletion request flagged as duplicate in response

A deletion request with the same email is already queued (status ACCEPTED)

Review the integration log and wait for the duplicate request to move to PROCESSING or COMPLETED, then resubmit if still needed.