CA-C-002395
OpenAI, OpenAI API Data Usage Policies
Entity
Date detected
May 28, 2026
Effective date
May 28, 2026
Severity
Direction
Negative
Affected users
business accounts enterprise customers workplace users workspace admins
Taxonomy
Data processing change
Changes
7 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Get same-day alerts when OpenAI changes We email you the diff and what it means, the day it happens.
Get same-day alerts →

Get the weekly research letter

What the week's governance changes actually mean, read against a corpus of 844 tracked documents. Grounded analysis of the changes that matter, not a feed of every change. Email only, no account.

Event Summary

OpenAI updated its API Data Usage Policies on May 28, 2026 to clarify workspace admin authority and data retention rules. Previously, the terms stated that end users controlled whether their conversations were retained and could view their own conversations. The updated language now establishes that workspace admins control data retention duration and can view, access, export, and delete end user conversations within their workspace. Additionally, the policy now permits OpenAI to retain deleted or unsaved conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.

MEDIUM

Consumer Impact

The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.

Governance Analysis

The updated terms transfer control over conversation data retention from individual users to workspace admins and expand OpenAI's authority to retain deleted data beyond the standard 30-day window. Organizations using ChatGPT Business need to clarify how admins will exercise this new authority and may need to update privacy notices or vendor agreements if they previously represented that users controlled retention or that data would be deleted after 30 days.

Available Actions

If you are an end user in a workspace environment, review your organization's data governance policies or ask your workspace admin about how they will exercise access and retention authority over conversations.

If you are a compliance officer or workspace admin, document your organization's policies governing admin access to conversations and retention duration.

If No Action Is Taken

Workspace admins will have authority to access, view, export, and delete your conversations as stated in the updated terms.

Your organization's admins, rather than you, will control how long your conversations are retained in the system.

Historical Context

Across all monitored documents, OpenAI has made 8 significant changes.

5 of OpenAI's significant changes have been classified as negative for consumers.

Key Clauses Affected

workspace admin conversation access authority

Admins now explicitly permitted to view, access, export, and delete end user conversations within their workspace.

workspace admin retention control

Retention duration is now controlled by workspace admins rather than individual end users.

expanded data retention grounds

OpenAI now reserves the right to retain deleted conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.

Full clause-by-clause analysis available with Analyst.
These clauses may change again. Get alerted when they do. Get same-day alerts →

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
694a813c3880cd986d5603525b163c07256efa613212c14bfd28669773650667
May 24, 2026 00:02 UTC
✓ Verified
Current Version
b5e7bcba16cf57f2a8599b1e4a023d606e0273acda921b5e411c9a7ad6293642
May 28, 2026 00:01 UTC
✓ Verified
Change Detected
May 28, 2026 00:01 UTC
Analysis Methodology
Citation Record
Entity: OpenAI
Document: OpenAI API Data Usage Policies
Record ID: CA-C-002395
Captured: 2026-05-28 00:01:30 UTC
URL: https://conductatlas.com/change/2026-05-28-openai-openai-api-data-usage-policies-2395/
Accessed: July 21, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
New obligations
2
Expanded
1
Protection removed
Organizations using ChatGPT Business Added

The expanded admin authority creates a need for organizations to define clear internal policies about who can access user conversations and when.

End users in workspace environments Removed

Employees or users no longer have control over how long their conversations are kept; that decision now belongs to their organization's admins.

Organizations with existing DPAs or privacy representations Expanded

Organizations may need to update their privacy statements or contracts to reflect that OpenAI can keep conversation data longer than 30 days if it claims this is necessary for service protection.

For legal and compliance teams

Institutional Analysis

Assessment

OpenAI clarified and expanded workspace admin authority over end user conversation data on May 28, 2026. The change shifts data retention control from individual users to workspace admins and explicitly authorizes admins to view, access, export, and delete conversations. Additionally, OpenAI reserved an expanded ground for retaining deleted conversations beyond 30 days, now including retention 'reasonably necessary to protect our services or any third party from harm' in addition to legal requirements. Organizations deploying ChatGPT Business should evaluate whether this expanded admin authority aligns with their internal data governance frameworks and employee privacy expectations. The change engages data protection compliance considerations if the organization operates in jurisdictions with employee privacy or workplace monitoring regulations.

Full institutional analysis

Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.

Analyst $49/mo

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002395.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenAI API Data Usage Policies
Entity
OpenAI
Captured
May 28, 2026
Source URL
https://openai.com/policies/api-data-usage-policies/
Other changes to OpenAI API Data Usage Policies
Previous change May 24, 2026
OpenAI made minor formatting adjustments to three hyperlinks in their API Data Usage Policies on May 24, 2026. The changes …
Low Neutral
Next change May 29, 2026
OpenAI updated its API Data Usage Policies on May 29, 2026 by modifying three hyperlinked references within the document. The …
Low Neutral
View full version history →
More from OpenAI
Jul 21, 2026 Low
OpenAI GPT-5.5 System Card

OpenAI's GPT-5.5 System Card was updated in an update detected on July 21, 2026. The document removed a reference to …

Jul 21, 2026 Low
OpenAI GPT-5 System Card

OpenAI updated the related-content section in its GPT-5 System Card detected on July 21, 2026. The previous version linked to …

Jul 21, 2026 Low
OpenAI Frontier Governance Framework

OpenAI updated its Frontier Governance Framework on July 21, 2026, modifying a single sentence within the document's reference section. The …

Related Analysis
Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Track OpenAI policy changes

Get alerted when this policy changes again, including what changed and why it matters.