CA-C-003663 Top 5%
OpenAI Privacy Policy
Entity
Date detected
March 10, 2026
Effective date
March 10, 2026
Severity
Direction
Negative
Affected users
all users US users EU users UK users EEA users Switzerland users Korea residents minors
Taxonomy
Transparency removal
Changes
+2 sentences added · −20 sentences removed · 74 sentences modified
Get alerted the next time OpenAI changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Get same-day alerts when OpenAI changes We email you the diff and what it means, the day it happens.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Event Summary

OpenAI's privacy policy underwent substantial restructuring in an update detected on March 10, 2026. The policy removed multiple standalone sections including 'Disclosure of Personal Data', 'Retention', 'Data controls', 'Your rights', 'Children', 'Security', 'Additional U.S. state disclosures', and 'Changes to the privacy policy', consolidating or relocating their content. The policy added explicit links to jurisdiction-specific versions for EU/EEA/UK/Switzerland and Korea residents, and modified language describing how training data is collected from publicly available internet sources, removing prior references to advertiser data partnerships and replacing them with broader sourcing disclosures.

HIGH

Consumer Impact

OpenAI removed multiple dedicated policy sections including those addressing data retention timelines, consumer rights, security measures, and protections for minors. The policy now consolidates or relocates these disclosures, and directs users in different jurisdictions to separate policy documents rather than maintaining unified disclosure. The updated language modifies how training data sourcing is described, removing references to advertiser data partnerships and expanding description of publicly available internet sources. Under the revised structure, key protections and disclosures that were previously in clearly marked sections may now be scattered across the consolidated policy or accessible only through separate jurisdiction-specific documents.

Governance Analysis

The removal of seven dedicated policy sections, including those addressing data retention, consumer rights, security, and child protections, reduces the transparency and accessibility of core privacy disclosures previously consolidated in standalone form. The reorganization and jurisdiction-specific fragmentation may create compliance documentation challenges and may obscure consumer remedies and protections that were previously clearly delineated.

Available Actions

Review the jurisdiction-specific version of the policy applicable to your location (EU/EEA/UK/Switzerland, Korea, or US version) to locate relocated disclosures on data retention, rights, and security.

Request clarification from OpenAI support regarding the location of specific disclosures previously contained in removed sections if you cannot locate them in the reorganized policy.

If No Action Is Taken

Without reviewing the reorganized policy, you may be unable to locate specific information about how long OpenAI retains your data, as the dedicated 'Retention' section was removed.

Information about your data rights (access, deletion, correction, portability) may be harder to find, as the dedicated 'Your rights' section no longer exists in standalone form.

Security disclosures previously available in a dedicated section are no longer presented in that consolidated location, requiring navigation across the reorganized policy to understand data protection measures.

Key Clauses Affected

Removal of 'Retention' section

Data retention timelines are no longer disclosed in a dedicated section, creating ambiguity about how long OpenAI stores personal data.

Removal of 'Your rights' section

Consumer data rights (access, deletion, correction, portability) are no longer consolidated in one location, potentially obscuring remedies and mechanisms.

Removal of 'Children' section

Protections and disclosures specific to minors are no longer separately stated, raising COPPA compliance concerns.

Full clause-by-clause analysis available with Analyst.
These clauses may change again. Get alerted when they do. Get same-day alerts →

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
65969d4b3896bcb061d05a5a1fdcbdd8c2779510513f6eeb8676ac81bb99572e
April 22, 2026 06:01 UTC
✓ Verified
Current Version
987debc442ac3a58ce7f5b9c309aed808b854eac06e006f87e8d0d48ea25be94
March 10, 2026 03:21 UTC
✓ Verified
Change Detected
March 10, 2026 03:21 UTC
Analysis Methodology
✓ Verified
Source Document
https://openai.com/policies/privacy-policy
Citation Record
Entity: OpenAI
Document: OpenAI Privacy Policy
Record ID: CA-C-003663
Captured: 2026-03-10 03:21:21 UTC
URL: https://conductatlas.com/change/2026-03-10-openai-openai-privacy-policy-3663/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

7
Protections removed
Consumers Removed

Previously users could find specific information about how long OpenAI keeps their data in one clear section; that section no longer exists as a standalone disclosure.

Consumers Removed

Users can no longer find a clear summary of their data rights in a dedicated policy section.

Consumers Removed

Information about how OpenAI protects user data from unauthorized access or breach is no longer in a dedicated section.

Consumers Removed

Special protections or notices for children and parents are no longer presented in their own dedicated section.

Consumers Removed

Users can no longer easily find a complete list of third parties with whom OpenAI shares personal data.

Consumers Removed

Information about user controls over data collection and processing is no longer in a dedicated section.

Consumers Removed

State-specific privacy disclosures required under California and other state laws are no longer grouped in a dedicated section.

For legal and compliance teams

Institutional Analysis

Assessment

This change involves substantial restructuring of OpenAI's privacy policy architecture. Multiple material sections addressing data retention, consumer rights, security, and child protection were removed or consolidated. The policy now directs users to jurisdiction-specific versions for EU/EEA/UK/Switzerland and Korea residents. Training data sourcing disclosures were modified to remove advertiser partnership language and emphasize public internet sources. Organizations using OpenAI services should evaluate whether the reorganization adequately maintains required disclosures under applicable privacy regulations, particularly GDPR for EEA users and COPPA for child-directed services. The fragmentation across jurisdiction-specific documents may create compliance documentation and tracking challenges.

Full institutional analysis

Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.

Analyst $49/mo

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-003663.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenAI Privacy Policy
Entity
OpenAI
Captured
March 10, 2026
Source URL
https://openai.com/policies/privacy-policy
Other changes to OpenAI Privacy Policy
Previous change Mar 6, 2026
OpenAI's privacy policy was updated on March 6, 2026, with changes to how it describes data uses and disclosures. The …
Low Neutral
Next change Apr 22, 2026
OpenAI removed language describing a separate category of marketing partners and the cookie-based data sharing practices used with those partners. …
Medium Negative
View full version history →
More from OpenAI
Jul 21, 2026 Low
OpenAI GPT-5.5 System Card

OpenAI's GPT-5.5 System Card was updated in an update detected on July 21, 2026. The document removed a reference to …

Jul 21, 2026 Low
OpenAI GPT-5 System Card

OpenAI updated the related-content section in its GPT-5 System Card detected on July 21, 2026. The previous version linked to …

Jul 21, 2026 Low
OpenAI Frontier Governance Framework

OpenAI updated its Frontier Governance Framework on July 21, 2026, modifying a single sentence within the document's reference section. The …

Related Analysis
Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Track OpenAI policy changes

Get alerted when this policy changes again, including what changed and why it matters.