---
title: "Get Assessment"
method: GET
path: "/api/assessment/v2/assessments/{assessmentId}/export"
tags: ["Assessments"]
---

# Get Assessment

`GET /api/assessment/v2/assessments/{assessmentId}/export`

Use this API to retrieve details of a specific assessment. The response will include details such as basic assessment information, respondents, approvers, assessment questions and responses, and assessment risks.

> 🗒 Things to Know
> 
> - The API response body will include all assessment responses received for that assessment after the assessment was launched. If a response record references an object (such as vendors, engagements, or assets) that was subsequently deleted from the OneTrust Platform after the assessment was launched, that record would still be included within the response body but would no longer exist in the OneTrust Platform.

## Path parameters

- `assessmentId` string, uuid, required

## Query parameters

- `excludeSkippedQuestions` boolean

## Response `200`

OK

- PrivacyAutomationAssessmentAutomationAssessmentExportInformation
  - `assessmentId` string, uuid — Unique identifier of the assessment
  - `assessmentNumber` integer — Sequential number assigned to the assessment
  - `name` string — Name of the assessment
  - `description` string — Description of the assessment
  - `welcomeText` string — Welcome text displayed at the beginning of the assessment
  - `orgGroup` PrivacyAutomationAssessmentAutomationBasicEntityDetail
    - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
    - `name` string — Display name of the entity (organization name or user's full name)
    - `nameKey` string — Translation key for the name, used for internationalization
  - `template` PrivacyAutomationAssessmentAutomationBasicEntityDetail
    - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
    - `name` string — Display name of the entity (organization name or user's full name)
    - `nameKey` string — Translation key for the name, used for internationalization
  - `status` 'NOT_STARTED' | 'IN_PROGRESS' | 'UNDER_REVIEW' | 'COMPLETED' — Current status of the assessment
  - `createdBy` PrivacyAutomationAssessmentAutomationBasicEntityDetail
    - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
    - `name` string — Display name of the entity (organization name or user's full name)
    - `nameKey` string — Translation key for the name, used for internationalization
  - `createdDT` string, date-time — Date and time when the assessment was created (in UTC)
  - `sections` PrivacyAutomationAssessmentAutomationAssessmentSectionInformation[] — List of sections in the assessment with their questions and responses
    - `header` PrivacyAutomationAssessmentAutomationHeader
      - `sectionId` string, uuid — Unique identifier for the section
      - `name` string — Name of the section
      - `description` string — Description of the section
      - `sequence` integer — Sequence number indicating the order of the section in the assessment
      - `hidden` boolean — Indicates if the section is hidden based on navigation rules
      - `invalidQuestionIds` unknown[]
        - unknown
      - `requiredUnansweredQuestionIds` unknown[]
        - unknown
      - `requiredQuestionIds` unknown[]
        - unknown
      - `unansweredQuestionIds` unknown[]
        - unknown
      - `effectivenessQuestionIds` string[]
      - `autoAnsweredQuestionIds` string[]
      - `riskStatistics` PrivacyAutomationAssessmentAutomationRiskStatistics
        - `sectionId` string, uuid
        - `riskCount` integer
        - `maxRiskLevel` integer
      - `status` string — Current status of the section
      - `nameKey` string — Translation key for the section name
      - `descriptionKey` string — Translation key for the section description
      - `openNMIQuestionIds` unknown[]
        - unknown
      - `sectionUserType` 'APPROVER' | 'RESPONDENT' — Type of user assigned to the section (e.g., RESPONDENT, APPROVER)
      - `submitted` boolean
    - `questions` PrivacyAutomationAssessmentAutomationAssessmentQuestionInformation[]
      - `question` PrivacyAutomationAssessmentAutomationQuestionInformation
        - `id` string, uuid
        - `rootVersionId` string, uuid
        - `sequence` integer
        - `questionType` 'TEXTBOX' | 'MULTICHOICE' | 'YESNO' | 'DATE' | 'STATEMENT' | 'INVENTORY' | 'INCIDENT' | 'ATTRIBUTE' | 'PERSONAL_DATA' | 'YES_NO_PARTIALLY' | 'CONTROL' | 'CONTRACT' | 'ENGAGEMENT' | 'ASSESS_CONTROL' | 'ASSESS_RISK' | 'ASSESS_ISSUE' | 'CUSTOM_ENTITY' | 'RELATIONSHIP' | 'DISCLOSURE'
        - `required` boolean
        - `attributes` string
        - `friendlyName` string
        - `description` string
        - `hint` string
        - `parentQuestionId` string, uuid
        - `prePopulateResponse` boolean
        - `linkAssessmentToInventory` boolean
        - `options` PrivacyAutomationAssessmentAutomationOptionInformation[]
          - `id` string, uuid
          - `option` string
          - `optionKey` string
          - `sequence` integer
          - `hint` string
          - `hintKey` string
          - `attributes` string
          - `optionType` 'NOT_SURE' | 'NOT_APPLICABLE' | 'OTHERS' | 'DEFAULT'
          - `score` integer
          - `preSelectedOption` boolean
          - `translationIdentifier` string, uuid
        - `valid` boolean
        - `businessKeyReference` string
        - `topic` string
        - `questionLaws` PrivacyAutomationAssessmentAutomationLawInformation[]
          - `name` string
        - `attachmentRequired` boolean
        - `responseFilter` PrivacyAutomationAssessmentAutomationResponseFilter
          - `Collection of key-value(s) pairs` object
          - `operator` string
        - `linkAssessmentToResponseEntity` boolean
        - `attachmentIds` string[]
        - `readOnly` boolean
        - `translationIdentifier` string, uuid
        - `optionMetadata` PrivacyAutomationAssessmentAutomationAttributeOptionMetadataInformation
          - `entityTypeName` string — Option Source Entity Type
          - `basicServiceContextPath` string — Basic Url for the Option source Service
          - `optionUrl` string — Api URL for the Drop Down Api
          - `viewType` string — This will help to identify the view type of list
        - `type` 'TEXTBOX' | 'MULTICHOICE' | 'YESNO' | 'DATE' | 'STATEMENT' | 'INVENTORY' | 'INCIDENT' | 'ATTRIBUTE' | 'PERSONAL_DATA' | 'YES_NO_PARTIALLY' | 'CONTROL' | 'CONTRACT' | 'ENGAGEMENT' | 'ASSESS_CONTROL' | 'ASSESS_RISK' | 'ASSESS_ISSUE' | 'CUSTOM_ENTITY' | 'RELATIONSHIP' | 'DISCLOSURE'
        - `schema` PrivacyAutomationAssessmentAutomationSchemaIdentifier
          - `schemaName` string
          - `moduleName` string
        - `allowJustification` boolean
        - `attributeId` string, uuid
        - `allowMultiSelect` boolean
        - `assetQuestion` boolean
        - `vendorQuestion` boolean
        - `entityQuestion` boolean
        - `paquestion` boolean
        - `inventoryTypeEnum` 'ASSETS' | 'PROCESSING_ACTIVITY' | 'VENDORS' | 'DATA_SUBJECTS' | 'DATA_ELEMENTS' | 'DATA_CATEGORIES' | 'ENTITIES' | 'PERSONAL_DATA'
        - `seeded` boolean
        - `forceOther` boolean
        - `requireJustification` boolean
        - `content` string
        - `isParentQuestionMultiSelect` boolean
      - `sectionInformation` PrivacyAutomationAssessmentAutomationAssessmentQuestionSectionBasicInfo
        - `id` string, uuid — UUID of the section
        - `name` string — Name of the section
        - `description` string — Description of the section
        - `sequence` integer — Sequence number indicating the order of the section in the assessment
      - `hidden` boolean — Indicates if the question should be hidden or not based on the responses provided so far
      - `lockReason` 'LAUNCH_FROM_INVENTORY, LAUNCH_FROM_INCIDENT, LAUNCH_FROM_CONTROL_IMPLEMENTATION' — Reason why the question is locked, if applicable
      - `copyErrors` string[]
      - `hasNavigationRules` boolean — Indicates if the question has navigation rules associated with it
      - `questionResponses` PrivacyAutomationAssessmentAutomationAssessmentQuestionResponseInformation[]
        - `responses` PrivacyAutomationAssessmentAutomationAssessmentResponseInformation[]
          - `responseId` string, uuid
          - `response` string
          - `responseKey` string
          - `type` 'NOT_SURE, JUSTIFICATION, NOT_APPLICABLE, DEFAULT, OTHERS'
          - `responseSourceType` 'LAUNCH_FROM_INVENTORY/LAUNCH_FROM_INCIDENT/INCIDENT_TEMPLATE/LAUNCH_FROM_CONTROL_IMPLEMENTATION/AI_IMPORT/AI_ACCEPT'
          - `errorCode` 'ATTRIBUTE_DISABLED' | 'ATTRIBUTE_OPTION_DISABLED' | 'INVALID_RESPONSE_VALUE' | 'INVENTORY_NOT_EXISTS' | 'RELATED_INVENTORY_ATTRIBUTE_DISABLED' | 'DATA_ELEMENT_NOT_EXISTS' | 'DATA_SUBJECT_NOT_EXISTS' | 'DUPLICATE_INVENTORY' | 'INVENTORY_ASSOCIATION_TYPE_INVALID' | 'INVENTORY_ASSOCIATION_TYPE_NOT_APPLICABLE' | 'MULTIPLE_SERVICE_PROVIDER_VENDOR_ASSET_RELATION' | 'EMAIL_INVALID' | 'RELATIONSHIP_ATTRIBUTE_OPTION_DISABLED' | 'CONTRACT_NOT_FOUND' | 'VENDOR_CHILD_ATTRIBUTE_INVALID_VALUE_FORMAT' | 'VENDOR_CHILD_ATTRIBUTE_VALUE_LONG' | 'CONTRACT_INVALID_NAME' | 'ENGAGEMENT_NOT_FOUND' | 'DUPLICATE_ENGAGEMENT' | 'INVALID_ENTITY' | 'NOT_FOUND_LINK_TYPE' | 'LINK_TYPE_DOES_NOT_BELONG_TO_ENTITY_TYPE' | 'LINK_RECORD_CANNOT_BE_CREATED_BETWEEN_SAME_ENTITY' | 'LINK_TYPE_DISABLED' | 'INVALID_CONTROL' | 'GENERIC_EXCEPTION' | 'UNKNOWN_MODULE_CLIENT_ERROR' — not required
          - `errorTranslationKey` string — not required
          - `responseMap` object — only applicable for inventory type responses. Allowable values for the key: ASSETS, PROCESSING_ACTIVITY, VENDORS, DATA_SUBJECTS, DATA_ELEMENTS, DATA_CATEGORIES
          - `scaleResponseMap` object — only applicable for YES_NO_PARTIALLY type responses. key should be OVERALL or LAW Name
          - `controlResponse` PrivacyAutomationAssessmentAutomationControlResponse
            - `control id` string, uuid
            - `control identifier` string
            - `control name` string
            - `framework id` string, uuid
            - `framework name` string
            - `category id` string, uuid
            - `category name` string
          - `responseAdditionalDetails` PrivacyAutomationAssessmentAutomationResponseAdditionalDetails
            - `entity Number` integer
            - `source Id` string, uuid
            - `source Name` string
            - `source type` 'Risks, Assets, ProcessingActivities, Vendors, Entities'
            - `Business key` string
          - `contractResponse` PrivacyAutomationAssessmentAutomationContractAdditionalResponseInformation
            - `attachmentId` string, uuid
          - `relationshipResponseDetails` PrivacyAutomationAssessmentAutomationRelationshipResponseDetailsDto[]
            - `relationshipNodeType` string — Type of the relationship node
            - `entityId` string, uuid, required — Unique identifier of the related entity
            - `entityDisplayName` string — Display name of the related entity
            - `entityType` PrivacyAutomationAssessmentAutomationEntityTypeInformation, required
              - …
          - `valid` boolean — not required
          - `textRedacted` boolean — Applicable for attribute text questions
          - `lastModifiedDate` string, date-time
          - `assessmentDetailId` string, uuid — Assessment Detail Identifier of the question response
          - `personalDataDetailId` string, uuid — Pre-generated ID for AssessmentPersonalDataDetail entity, used in AI auto-suggestion mode
          - `dataSubject` PrivacyAutomationAssessmentAutomationBasicEntityDetail
            - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
            - `name` string — Display name of the entity (organization name or user's full name)
            - `nameKey` string — Translation key for the name, used for internationalization
          - `dataCategory` PrivacyAutomationAssessmentAutomationBasicEntityDetail
            - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
            - `name` string — Display name of the entity (organization name or user's full name)
            - `nameKey` string — Translation key for the name, used for internationalization
          - `dataElement` PrivacyAutomationAssessmentAutomationBasicEntityDetail
            - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
            - `name` string — Display name of the entity (organization name or user's full name)
            - `nameKey` string — Translation key for the name, used for internationalization
        - `justification` string — Justification text provided for the response
        - `maturityScale` integer — Maturity scale value selected for the question
        - `effectivenessScale` integer — Effectiveness scale value selected for the question
        - `parentAssessmentDetailId` string, uuid — Identifier of the parent assessment detail
      - `risks` PrivacyAutomationAssessmentAutomationAssessmentQuestionRiskInformation[]
        - `questionId` string, uuid — Identifier of the question associated with this risk
        - `parentQuestionResponseDetailId` string, uuid — Identifier of the parent question response detail
        - `riskId` string, uuid — Unique identifier of the risk
        - `level` integer — Risk level value
        - `score` integer — Numerical risk score
        - `probability` integer — Probability component of risk score
        - `impactLevel` integer — Impact level component of risk score
        - `riskLevelValue` string — Display value of the risk level (e.g., 'High', 'Medium', 'Low')
        - `riskLevelValueKey` string — Key for the risk level value for localization
        - `riskLevelColorCode` string — Color code associated with the risk level for UI display
        - `attributeOptionId` string, uuid — Identifier of the attribute option associated with this risk level
      - `rootRequestInformationIds` unknown[]
        - unknown
      - `totalAttachments` integer — Total number of attachments for this question
      - `attachmentIds` unknown[]
        - unknown
      - `canReopenWithAllowEditOption` boolean — Indicates if a question can be opened for allowing a response to be edited. If true, it means the question has no skip logic tied to it, or it is not an inventory/attribute/incident question.
      - `riskCreationAllowed` boolean — Indicates if the question can be allowed to flag risk manually
      - `riskDeletionPopupAllowed` boolean — Indicates if risk deletion alert popup is allowed on this question
      - `allowMaturityScaleOnQuestions` boolean — Indicates if Maturity Scale is allowed on this question
      - `questionAssociations` PrivacyAutomationAssessmentAutomationQuestionAssociationInformation[]
        - `associationType` 'SOURCE' | 'TARGET' | 'ADDITIONAL_LINK_1' | 'ADDITIONAL_LINK_2' | 'RESTRICT_RESPONSE_OPTIONS'
        - `associatedQuestionIds` string[]
      - `attachmentsById` object
      - `issues` PrivacyAutomationAssessmentAutomationAssessmentQuestionIssueInformation[]
        - `questionId` string, uuid
        - `issueId` string, uuid
        - `parentQuestionResponseDetailId` string, uuid
      - `responseEditableWhileUnderReview` boolean
    - `hasNavigationRules` boolean — Indicates if the section has navigation rules that affect question flow
    - `submittedBy` PrivacyAutomationAssessmentAutomationSubmittedBy
      - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
      - `name` string — Display name of the entity (organization name or user's full name)
      - `nameKey` string — Translation key for the name, used for internationalization
    - `submittedDt` string, date-time — Date and time when the section was submitted
    - `name` string — Name of the section
    - `isHidden` boolean — Indicates if the section is hidden
    - `isValid` boolean — Indicates if the section is valid
    - `submitted` boolean
    - `description` string — Description of the section
    - `sectionId` string, uuid — Unique identifier for the section
    - `sequence` integer — Sequence number of the section
  - `approvers` PrivacyAutomationAssessmentAutomationApproverInformation[] — List of users who are approvers for the assessment
    - `id` string, uuid
    - `workflowStageId` string, uuid
    - `name` string
    - `approver` PrivacyAutomationAssessmentAutomationBasicUserEntityDetail
      - `id` string, uuid — Unique identifier of the user
      - `fullName` string — Full name of the user
      - `email` string — Email address of the user
      - `deleted` boolean — Flag indicating whether the user has been deleted
      - `assigneeType` string — Type of assignee (e.g., USER, GROUP)
    - `approvedOn` string, date-time
    - `approvalState` 'OPEN' | 'APPROVED' | 'REJECTED'
    - `resultId` string, uuid
    - `resultName` string
    - `resultNameKey` string
  - `respondents` PrivacyAutomationAssessmentAutomationBasicEntityDetail[] — List of users who are respondents for the assessment
    - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
    - `name` string — Display name of the entity (organization name or user's full name)
    - `nameKey` string — Translation key for the name, used for internationalization
  - `respondent` PrivacyAutomationAssessmentAutomationBasicEntityDetail
    - `id` string, uuid — Unique identifier of the entity (organization group, user, etc.)
    - `name` string — Display name of the entity (organization name or user's full name)
    - `nameKey` string — Translation key for the name, used for internationalization
  - `deadline` string, date-time — Deadline for completing the assessment
  - `submittedOn` string, date-time — Date when the assessment was submitted for review
  - `completedOn` string, date-time — Date when the assessment was completed
  - `result` string — Result of the assessment (deprecated, use resultName instead)
  - `resultId` string, uuid — Unique identifier of the assessment result
  - `resultName` string — Name of the assessment result
  - `lowRisk` integer — Count of low risk findings in the assessment
  - `mediumRisk` integer — Count of medium risk findings in the assessment
  - `highRisk` integer — Count of high risk findings in the assessment
  - `veryHighRisk` integer — Count of very high risk findings in the assessment
  - `totalRiskCount` integer — Total count of all risk findings in the assessment
  - `riskLevel` string — Overall risk level of the assessment
  - `residualRiskScore` number — Residual risk score after mitigations
  - `openRiskCount` integer — Count of open risks in the assessment
  - `inherentRiskScore` number — Inherent risk score before mitigations
  - `targetRiskScore` number — Target risk score to achieve
  - `lastUpdated` string, date-time — Date and time when the assessment was last updated (in UTC)
  - `primaryEntityDetails` PrivacyAutomationAssessmentAutomationAssessableEntityDetail[] — Details of the primary entities associated with the assessment
    - `id` string, uuid — ID of the assessable entity
    - `name` string — Name of the assessable entity
    - `number` integer — Number of the assessable entity
    - `relationshipResponseDetails` PrivacyAutomationAssessmentAutomationRelationshipResponseDetailsDto[]
      - `relationshipNodeType` string — Type of the relationship node
      - `entityId` string, uuid, required — Unique identifier of the related entity
      - `entityDisplayName` string — Display name of the related entity
      - `entityType` PrivacyAutomationAssessmentAutomationEntityTypeInformation, required
        - `id` string, uuid — Unique identifier of the entity type
        - `name` string — Name of the entity type
        - `nameKey` string — Translation key for the entity type name
        - `moduleName` string — Module name that owns this entity type
        - `schemaName` string — Schema name for this entity type
        - `seeded` boolean — Whether this entity type is seeded
        - `validEntityType` boolean
    - `displayName` string — Display name of the entity
    - `entityBusinessKey` string — Business Key of the entity
  - `primaryRecordType` string — Type of the primary record associated with the assessment
  - `tags` string[] — List of tags associated with the assessment
  - `profileScoreInformationList` PrivacyAutomationAssessmentAutomationProfileScoreInformation[] — List of profile scores for the assessment, containing profile name and calculated score
    - `scoreProfileName` string
    - `profileScore` number

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `429` — Too Many Requests. For more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview).
- `500` — Internal Server Error

---

[API](https://skmtc.net/onetrust/apis/platform-access-management.md) · [All operations](https://skmtc.net/onetrust/apis/platform-access-management/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/onetrust/platform-access-management/versions/21de3aa0b170/schema)
