Change record
CA-C-002395
OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Entity
Date detected
May 28, 2026
Effective date
May 28, 2026
Severity
Direction
Negative
Taxonomy
Data processing change
Changes
7 sentences modified

Impact Summary

Medium Negative for users
Affected users
Business accounts Enterprise customers Workplace users Workspace admins

OpenAI updated its API Data Usage Policies on May 28, 2026 to clarify workspace admin authority and data retention rules. Previously, the terms stated that end users controlled whether their conversations were retained and could view their own conversations. The updated language now establishes that workspace admins control data retention duration and can view, access, export, and delete end user conversations within their workspace. Additionally, the policy now permits OpenAI to retain deleted or unsaved conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.

1 new obligation 2 obligations expanded 1 protection removed

Organizations using ChatGPT Business: The expanded admin authority creates a need for organizations to define clear internal policies about who can access user conversations and when.

End users in workspace environments: Employees or users no longer have control over how long their conversations are kept; that decision now belongs to their organization's admins.

Organizations with existing DPAs or privacy representations: Organizations may need to update their privacy statements or contracts to reflect that OpenAI can keep conversation data longer than 30 days if it claims this is necessary for service protection.

Stay ahead of the changes
Track OpenAI and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.

What you can do

If you are an end user in a workspace environment, review your organization's data governance policies or ask your workspace admin about how they will exercise access and retention authority over conversations.

If you are a compliance officer or workspace admin, document your organization's policies governing admin access to conversations and retention duration.

Historical Context

Across all monitored documents, OpenAI has made 4 significant changes.

3 of OpenAI's significant changes have been classified as negative for consumers.

Key Clauses Affected

workspace admin conversation access authority

Admins now explicitly permitted to view, access, export, and delete end user conversations within their workspace.

workspace admin retention control

Retention duration is now controlled by workspace admins rather than individual end users.

expanded data retention grounds

OpenAI now reserves the right to retain deleted conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
694a813c3880cd986d5603525b163c07256efa613212c14bfd28669773650667
May 24, 2026 00:02 UTC
✓ Verified
Current Version
b5e7bcba16cf57f2a8599b1e4a023d606e0273acda921b5e411c9a7ad6293642
May 28, 2026 00:01 UTC
✓ Verified
Change Detected
May 28, 2026 00:01 UTC
Analysis Methodology
Citation Record
Entity: OpenAI
Document: OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Record ID: CA-C-002395
Captured: 2026-05-28 00:01:30 UTC
URL: https://conductatlas.com/change/2026-05-28-openai-openai-api-data-usage-policies-retired-redirects-to-enterprise-privacy-ca-d-000825-2395/
Accessed: Sept. 9, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

OpenAI clarified and expanded workspace admin authority over end user conversation data on May 28, 2026. The change shifts data retention control from individual users to workspace admins and explicitly authorizes admins to view, access, …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002395.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Entity
OpenAI
Captured
May 28, 2026
Source URL
https://openai.com/policies/api-data-usage-policies/
Other changes to OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Previous change May 24, 2026
OpenAI made minor formatting adjustments to three hyperlinks in their API Data Usage Policies on May 24, 2026. The changes …
Low Neutral
Next change May 29, 2026
OpenAI updated its API Data Usage Policies on May 29, 2026 by modifying three hyperlinked references within the document. The …
Low Neutral
View full version history →
More from OpenAI
Sep 9, 2026 Low
OpenAI GPT-5.5 System Card

OpenAI's GPT-5.5 System Card was updated in an update detected on September 9, 2026. The change modified the metadata and …

Sep 9, 2026 Low
OpenAI GPT-5 System Card

OpenAI's GPT-5 System Card was revised in an update detected on September 9, 2026. The change removed the header 'GPT-5 …

Sep 9, 2026 Low
OpenAI Frontier Governance Framework

OpenAI's Frontier Governance Framework webpage was updated on September 9, 2026. The framework document title header was removed, a loading …

Related Analysis
Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track OpenAI policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All OpenAI changes →