Change record
CA-C-003663 Top 5%
OpenAI Privacy Policy
Entity
Date detected
March 10, 2026
Effective date
March 10, 2026
Severity
Direction
Negative
Taxonomy
Transparency removal
Changes
+2 sentences added · −20 sentences removed · 74 sentences modified

Impact Summary

High Negative for users
Affected users
All users US users EU users UK users EEA users Switzerland users Korea residents Minors

OpenAI's privacy policy underwent substantial restructuring in an update detected on March 10, 2026. The policy removed multiple standalone sections including 'Disclosure of Personal Data', 'Retention', 'Data controls', 'Your rights', 'Children', 'Security', 'Additional U.S. state disclosures', and 'Changes to the privacy policy', consolidating or relocating their content. The policy added explicit links to jurisdiction-specific versions for EU/EEA/UK/Switzerland and Korea residents, and modified language describing how training data is collected from publicly available internet sources, removing prior references to advertiser data partnerships and replacing them with broader sourcing disclosures.

7 protections removed

Consumers: Previously users could find specific information about how long OpenAI keeps their data in one clear section; that section no longer exists as a standalone disclosure.

Consumers: Users can no longer find a clear summary of their data rights in a dedicated policy section.

Consumers: Information about how OpenAI protects user data from unauthorized access or breach is no longer in a dedicated section.

Consumers: Special protections or notices for children and parents are no longer presented in their own dedicated section.

Consumers: Users can no longer easily find a complete list of third parties with whom OpenAI shares personal data.

Consumers: Information about user controls over data collection and processing is no longer in a dedicated section.

Consumers: State-specific privacy disclosures required under California and other state laws are no longer grouped in a dedicated section.

Stay ahead of the changes
Track OpenAI and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

OpenAI removed multiple dedicated policy sections including those addressing data retention timelines, consumer rights, security measures, and protections for minors. The policy now consolidates or relocates these disclosures, and directs users in different jurisdictions to separate policy documents rather than maintaining unified disclosure. The updated language modifies how training data sourcing is described, removing references to advertiser data partnerships and expanding description of publicly available internet sources. Under the revised structure, key protections and disclosures that were previously in clearly marked sections may now be scattered across the consolidated policy or accessible only through separate jurisdiction-specific documents.

What you can do

Review the jurisdiction-specific version of the policy applicable to your location (EU/EEA/UK/Switzerland, Korea, or US version) to locate relocated disclosures on data retention, rights, and security.

Request clarification from OpenAI support regarding the location of specific disclosures previously contained in removed sections if you cannot locate them in the reorganized policy.

Key Clauses Affected

Removal of 'Retention' section

Data retention timelines are no longer disclosed in a dedicated section, creating ambiguity about how long OpenAI stores personal data.

Removal of 'Your rights' section

Consumer data rights (access, deletion, correction, portability) are no longer consolidated in one location, potentially obscuring remedies and mechanisms.

Removal of 'Children' section

Protections and disclosures specific to minors are no longer separately stated, raising COPPA compliance concerns.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
65969d4b3896bcb061d05a5a1fdcbdd8c2779510513f6eeb8676ac81bb99572e
April 22, 2026 06:01 UTC
✓ Verified
Current Version
987debc442ac3a58ce7f5b9c309aed808b854eac06e006f87e8d0d48ea25be94
March 10, 2026 03:21 UTC
✓ Verified
Change Detected
March 10, 2026 03:21 UTC
Analysis Methodology
✓ Verified
Source Document
https://openai.com/policies/privacy-policy
Citation Record
Entity: OpenAI
Document: OpenAI Privacy Policy
Record ID: CA-C-003663
Captured: 2026-03-10 03:21:21 UTC
URL: https://conductatlas.com/change/2026-03-10-openai-openai-privacy-policy-3663/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

This change involves substantial restructuring of OpenAI's privacy policy architecture. Multiple material sections addressing data retention, consumer rights, security, and child protection were removed or consolidated. The policy now directs users to jurisdiction-specific versions for …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-003663.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenAI Privacy Policy
Entity
OpenAI
Captured
March 10, 2026
Source URL
https://openai.com/policies/privacy-policy
Other changes to OpenAI Privacy Policy
Previous change Mar 6, 2026
OpenAI's privacy policy was updated on March 6, 2026, with changes to how it describes data uses and disclosures. The …
Low Neutral
Next change Apr 22, 2026
OpenAI removed language describing a separate category of marketing partners and the cookie-based data sharing practices used with those partners. …
Medium Negative
View full version history →
More from OpenAI
Sep 7, 2026 Low
OpenAI GPT-5.5 System Card

OpenAI's GPT-5.5 System Card was updated on September 7, 2026, to modify the list of related safety and research content …

Sep 7, 2026 Low
OpenAI GPT-5 System Card

OpenAI removed a reference to a security incident article ('The Hugging Face incident and the road ahead') from the GPT-5 …

Sep 7, 2026 Low
OpenAI Frontier Governance Framework

In an update detected on September 7, 2026, OpenAI's Frontier Governance Framework removed a reference to 'The Hugging Face incident …

Related Analysis
Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track OpenAI policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All OpenAI changes →