Change record
CA-C-002395
OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Entity
Date detected
May 28, 2026
Effective date
May 28, 2026
Severity
Direction
Negative
Affected users
business accounts enterprise customers workplace users workspace admins
Taxonomy
Data processing change
Changes
7 sentences modified
Get alerted the next time OpenAI changes these terms. Follow OpenAI →
Share 𝕏 Share in Share 🔒 PDF
OpenAI: get same-day alerts

We email you the diff and what it means, the day it happens.

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Event Summary

OpenAI updated its API Data Usage Policies on May 28, 2026 to clarify workspace admin authority and data retention rules. Previously, the terms stated that end users controlled whether their conversations were retained and could view their own conversations. The updated language now establishes that workspace admins control data retention duration and can view, access, export, and delete end user conversations within their workspace. Additionally, the policy now permits OpenAI to retain deleted or unsaved conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.

MEDIUM

Consumer Impact

The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.

Governance Analysis

The updated terms transfer control over conversation data retention from individual users to workspace admins and expand OpenAI's authority to retain deleted data beyond the standard 30-day window. Organizations using ChatGPT Business need to clarify how admins will exercise this new authority and may need to update privacy notices or vendor agreements if they previously represented that users controlled retention or that data would be deleted after 30 days.

Available Actions

If you are an end user in a workspace environment, review your organization's data governance policies or ask your workspace admin about how they will exercise access and retention authority over conversations.

If you are a compliance officer or workspace admin, document your organization's policies governing admin access to conversations and retention duration.

If No Action Is Taken

Workspace admins will have authority to access, view, export, and delete your conversations as stated in the updated terms.

Your organization's admins, rather than you, will control how long your conversations are retained in the system.

Historical Context

Across all monitored documents, OpenAI has made 8 significant changes.

5 of OpenAI's significant changes have been classified as negative for consumers.

Key Clauses Affected

workspace admin conversation access authority

Admins now explicitly permitted to view, access, export, and delete end user conversations within their workspace.

workspace admin retention control

Retention duration is now controlled by workspace admins rather than individual end users.

expanded data retention grounds

OpenAI now reserves the right to retain deleted conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.

Full clause-by-clause analysis available with Insight.
Get alerted on what happens next

These clauses may change again. Monitor gets you a same-day alert with the diff.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
694a813c3880cd986d5603525b163c07256efa613212c14bfd28669773650667
May 24, 2026 00:02 UTC
✓ Verified
Current Version
b5e7bcba16cf57f2a8599b1e4a023d606e0273acda921b5e411c9a7ad6293642
May 28, 2026 00:01 UTC
✓ Verified
Change Detected
May 28, 2026 00:01 UTC
Analysis Methodology
Citation Record
Entity: OpenAI
Document: OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Record ID: CA-C-002395
Captured: 2026-05-28 00:01:30 UTC
URL: https://conductatlas.com/change/2026-05-28-openai-openai-api-data-usage-policies-retired-redirects-to-enterprise-privacy-ca-d-000825-2395/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
New obligations
2
Expanded
1
Protection removed
Organizations using ChatGPT Business Added

The expanded admin authority creates a need for organizations to define clear internal policies about who can access user conversations and when.

End users in workspace environments Removed

Employees or users no longer have control over how long their conversations are kept; that decision now belongs to their organization's admins.

Organizations with existing DPAs or privacy representations Expanded

Organizations may need to update their privacy statements or contracts to reflect that OpenAI can keep conversation data longer than 30 days if it claims this is necessary for service protection.

For legal and compliance teams

Institutional Analysis

Assessment

OpenAI clarified and expanded workspace admin authority over end user conversation data on May 28, 2026. The change shifts data retention control from individual users to workspace admins and explicitly authorizes admins to view, access, export, and delete conversations. Additionally, OpenAI reserved an expanded ground for retaining deleted conversations beyond 30 days, now including retention 'reasonably necessary to protect our services or any third party from harm' in addition to legal requirements. Organizations deploying ChatGPT Business should evaluate whether this expanded admin authority aligns with their internal data governance frameworks and employee privacy expectations. The change engages data protection compliance considerations if the organization operates in jurisdictions with employee privacy or workplace monitoring regulations.

Full institutional analysis

Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002395.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Entity
OpenAI
Captured
May 28, 2026
Source URL
https://openai.com/policies/api-data-usage-policies/
Other changes to OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Previous change May 24, 2026
OpenAI made minor formatting adjustments to three hyperlinks in their API Data Usage Policies on May 24, 2026. The changes …
Low Neutral
Next change May 29, 2026
OpenAI updated its API Data Usage Policies on May 29, 2026 by modifying three hyperlinked references within the document. The …
Low Neutral
View full version history →
More from OpenAI
Jul 26, 2026 Low
OpenAI Enterprise Privacy

No material change detected. The sentence describing data usage for model training remains identical in both versions. The policy continues …

Jul 26, 2026 Low
OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]

In an update detected on July 26, 2026, OpenAI's API Data Usage Policy retained its existing language stating that data …

Jul 26, 2026 Low
OpenAI EU Terms of Use

This change appears to be a no-op: the BEFORE and AFTER text are identical. The sentence about Apple integrations and …

Related Analysis
Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Track OpenAI policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All OpenAI changes →