OpenAI updated its privacy request procedures on May 14, 2026. Previously, the policy stated users could exercise privacy rights by submitting requests through privacy.openai.com or dsar@openai.com. The updated language now describes the four substantive privacy rights themselves—access, deletion, correction, and freedom from retaliation—rather than the submission mechanism. This shifts the policy from procedural instruction to rights enumeration, establishing explicit recognition of these privacy protections.
The updated policy now explicitly states four privacy rights that apply depending on your location and subject to applicable exceptions: the right to know about and access your personal data in portable format, the right to request deletion, the right to correct inaccurate data, and the right to be free from retaliation for exercising these rights. Previously, the policy referenced these rights only through procedural language about how to submit requests. The explicit enumeration establishes clearer notice of what protections the policy recognizes. You can exercise these rights by submitting a request through privacy.openai.com or dsar@openai.com.
→ Review the four privacy rights now explicitly stated in the policy to understand what protections apply to you based on your jurisdiction
→ Submit a privacy rights request through privacy.openai.com or dsar@openai.com if you wish to exercise any of these rights
This is the 4th significant Transparency Removal change OpenAI has made since ConductAtlas began monitoring.
ConductAtlas has recorded 6 material changes to this document over 64 days of monitoring (since March 2026). An additional minor or cosmetic changes were excluded.
3 of OpenAI's significant changes have been classified as negative for consumers.
Policy now explicitly lists four privacy rights (access, deletion, correction, anti-retaliation) subject to applicable exceptions and jurisdiction, replacing prior procedural-only language
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
OpenAI's privacy policy now explicitly enumerates four substantive privacy rights (access, deletion, correction, anti-retaliation) that apply depending on jurisdiction and subject to applicable exceptions. This change shifts from procedural language to explicit rights statement, which …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002058.
OpenAI's GPT-5.5 System Card title was reformatted in an update detected on September 10, 2026. The document header changed from …
OpenAI's GPT-5 System Card was reformatted to include the document title 'GPT-5 System Card | OpenAI' at the beginning. The …
OpenAI's Frontier Governance Framework page was modified in an update detected on September 10, 2026. A loading indicator was removed …
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.