GDPR-gated: requires allowContactPersonalData capability.
Access is audited to the PII access log (6-year retention).
OAuth 2.0 client_credentials grant via Keycloak service account.
Clients are provisioned per IntegrationOrganization in the
nt24-idp realm.
Optional purpose justification for PII-bearing endpoints (Phase 3+ may become mandatory for sensitive data).
UUID of the seller trade partner (must be in caller's authorized list).
UUID of the buyer trade partner.