Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
OpenAI's privacy policy underwent substantial restructuring in an update detected on March 10, 2026. The policy removed multiple standalone sections including 'Disclosure of Personal Data', 'Retention', 'Data controls', 'Your rights', 'Children', 'Security', 'Additional U.S. state disclosures', and 'Changes to the privacy policy', consolidating or relocating their content. The policy added explicit links to jurisdiction-specific versions for EU/EEA/UK/Switzerland and Korea residents, and modified language describing how training data is collected from publicly available internet sources, removing prior references to advertiser data partnerships and replacing them with broader sourcing disclosures.
OpenAI removed multiple dedicated policy sections including those addressing data retention timelines, consumer rights, security measures, and protections for minors. The policy now consolidates or relocates these disclosures, and directs users in different jurisdictions to separate policy documents rather than maintaining unified disclosure. The updated language modifies how training data sourcing is described, removing references to advertiser data partnerships and expanding description of publicly available internet sources. Under the revised structure, key protections and disclosures that were previously in clearly marked sections may now be scattered across the consolidated policy or accessible only through separate jurisdiction-specific documents.
The removal of seven dedicated policy sections, including those addressing data retention, consumer rights, security, and child protections, reduces the transparency and accessibility of core privacy disclosures previously consolidated in standalone form. The reorganization and jurisdiction-specific fragmentation may create compliance documentation challenges and may obscure consumer remedies and protections that were previously clearly delineated.
→ Review the jurisdiction-specific version of the policy applicable to your location (EU/EEA/UK/Switzerland, Korea, or US version) to locate relocated disclosures on data retention, rights, and security.
→ Request clarification from OpenAI support regarding the location of specific disclosures previously contained in removed sections if you cannot locate them in the reorganized policy.
→ Without reviewing the reorganized policy, you may be unable to locate specific information about how long OpenAI retains your data, as the dedicated 'Retention' section was removed.
→ Information about your data rights (access, deletion, correction, portability) may be harder to find, as the dedicated 'Your rights' section no longer exists in standalone form.
→ Security disclosures previously available in a dedicated section are no longer presented in that consolidated location, requiring navigation across the reorganized policy to understand data protection measures.
Data retention timelines are no longer disclosed in a dedicated section, creating ambiguity about how long OpenAI stores personal data.
Consumer data rights (access, deletion, correction, portability) are no longer consolidated in one location, potentially obscuring remedies and mechanisms.
Protections and disclosures specific to minors are no longer separately stated, raising COPPA compliance concerns.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Previously users could find specific information about how long OpenAI keeps their data in one clear section; that section no longer exists as a standalone disclosure.
Users can no longer find a clear summary of their data rights in a dedicated policy section.
Information about how OpenAI protects user data from unauthorized access or breach is no longer in a dedicated section.
Special protections or notices for children and parents are no longer presented in their own dedicated section.
Users can no longer easily find a complete list of third parties with whom OpenAI shares personal data.
Information about user controls over data collection and processing is no longer in a dedicated section.
State-specific privacy disclosures required under California and other state laws are no longer grouped in a dedicated section.
This change involves substantial restructuring of OpenAI's privacy policy architecture. Multiple material sections addressing data retention, consumer rights, security, and child protection were removed or consolidated. The policy now directs users to jurisdiction-specific versions for EU/EEA/UK/Switzerland and Korea residents. Training data sourcing disclosures were modified to remove advertiser partnership language and emphasize public internet sources. Organizations using OpenAI services should evaluate whether the reorganization adequately maintains required disclosures under applicable privacy regulations, particularly GDPR for EEA users and COPPA for child-directed services. The fragmentation across jurisdiction-specific documents may create compliance documentation and tracking challenges.
Full institutional analysis
Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.
Analyst $49/moConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-003663.
OpenAI's GPT-5.5 System Card was updated in an update detected on July 21, 2026. The document removed a reference to …
OpenAI updated the related-content section in its GPT-5 System Card detected on July 21, 2026. The previous version linked to …
OpenAI updated its Frontier Governance Framework on July 21, 2026, modifying a single sentence within the document's reference section. The …
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get alerted when this policy changes again, including what changed and why it matters.