When a DPA request is filed, it is will be assigned a unique alphanumeric ID. To ensure all DPA requests are filed and correctly processed within statutory time limits (which we will seek to monitor as well in the future), it would make sense to enforce RemovePII to require the request ID be provided to validate the request has been filed.
This would also be useful as if validation can be introduced when an API for TSPortal is added, it would be a safeguard as RemovePII can ensure the old username matches the requesting username within TSPortal.