Get the weekly digest
Every policy change across 844 tracked documents, once a week. No account needed.
OpenAI updated its Enterprise Privacy terms on May 28, 2026 to expand workspace admin authority over end user conversations. Previously, only end users could view their own conversations, and end users controlled retention decisions. The updated terms state that workspace admins can now view, access, export, and delete end user conversations, and admins control retention duration. Additionally, OpenAI broadened its deletion exception to permit longer retention not only when legally required, but also when reasonably necessary to protect its services or third parties from harm.
The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.
The updated terms establish that workspace administrators, not individual employees, control access to conversations and data retention periods within enterprise accounts. This represents a material shift in data governance authority that affects how enterprise customers must document employee monitoring practices and may create compliance implications under privacy regulations. The expanded retention exception also permits OpenAI to retain deleted conversations longer than previously stated, creating operational discretion that may complicate data deletion commitments.
→ Review your enterprise account's workspace admin policies to understand who has access to your conversations.
→ Update internal privacy notices and employee policies to disclose that workspace admins can view, export, and delete conversations.
→ Evaluate your Data Processing Agreement with OpenAI to ensure it reflects the expanded admin monitoring authority and retention exceptions.
→ Workspace admins will have authority to access, export, and delete your conversations as stated in the updated terms.
→ Your conversations may be retained beyond 30 days if OpenAI determines retention is reasonably necessary to protect its services or third parties from harm.
→ If your organization has not updated its own privacy policies or employee agreements, discrepancies may emerge between what employees expect and what the OpenAI terms permit.
Across all monitored documents, OpenAI has made 9 significant changes.
6 of OpenAI's significant changes have been classified as negative for consumers.
Admins now gain explicit authority to view, access, export, and delete all end user conversations in their workspace.
Retention duration shifts from end user control to workspace admin control.
Deleted conversations can now be retained beyond 30 days if retention is reasonably necessary to protect OpenAI's services or any third party from harm, not just for legal requirements.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Businesses using OpenAI Enterprise must update their own privacy policies and employee notices to disclose that workspace admins can access, export, and delete user conversations.
OpenAI can now justify keeping deleted conversations longer than 30 days if it claims retention is necessary to protect its systems or other parties, not just when the law requires it.
Employees in enterprise accounts no longer decide how long their conversations are kept; workspace admins make that decision.
The reasons OpenAI can keep conversations longer are now broader and less specific, making it harder to predict when deletion will actually occur.
This change materially expands the data processing authority OpenAI asserts over enterprise customer workspaces. Workspace admins gain direct access to monitor, export, and delete end user conversations, and control retention periods. For enterprise customers operating under data protection frameworks (GDPR, CCPA, or equivalent), this shift in control authority may affect documentation of processing purposes, lawful basis determinations, and data subject rights fulfillment. The expanded retention exception now permits longer retention when reasonably necessary to protect OpenAI's services or third parties from harm, creating operational discretion that may complicate deletion timelines and data minimization commitments. Organizations with enterprise OpenAI accounts should evaluate whether this change aligns with their internal data governance policies, employee privacy expectations, and applicable regulatory obligations around employee communications monitoring and retention.
Full institutional analysis
Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.
Analyst $49/moConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002397.
OpenAI's GPT-5.5 System Card was updated in an update detected on July 21, 2026. The document removed a reference to …
OpenAI updated the related-content section in its GPT-5 System Card detected on July 21, 2026. The previous version linked to …
OpenAI updated its Frontier Governance Framework on July 21, 2026, modifying a single sentence within the document's reference section. The …
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get alerted when this policy changes again — including what changed and why it matters.