Change record
CA-C-002397 Top 5%
OpenAI Enterprise Privacy
Entity
Date detected
May 28, 2026
Effective date
May 28, 2026
Severity
Direction
Negative
Taxonomy
Retention change
Changes
4 sentences modified

Impact Summary

High Negative for users
Affected users
Enterprise customers Workspace administrators End users in enterprise accounts

OpenAI updated its Enterprise Privacy terms on May 28, 2026 to expand workspace admin authority over end user conversations. Previously, only end users could view their own conversations, and end users controlled retention decisions. The updated terms state that workspace admins can now view, access, export, and delete end user conversations, and admins control retention duration. Additionally, OpenAI broadened its deletion exception to permit longer retention not only when legally required, but also when reasonably necessary to protect its services or third parties from harm.

2 new obligations 2 obligations expanded 1 protection removed

Enterprise customers: Businesses using OpenAI Enterprise must update their own privacy policies and employee notices to disclose that workspace admins can access, export, and delete user conversations.

Enterprise customers: OpenAI can now justify keeping deleted conversations longer than 30 days if it claims retention is necessary to protect its systems or other parties, not just when the law requires it.

End users in enterprise accounts: Employees in enterprise accounts no longer decide how long their conversations are kept; workspace admins make that decision.

Enterprise customers: The reasons OpenAI can keep conversations longer are now broader and less specific, making it harder to predict when deletion will actually occur.

Stay ahead of the changes
Track OpenAI and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.

What you can do

Review your enterprise account's workspace admin policies to understand who has access to your conversations.

Update internal privacy notices and employee policies to disclose that workspace admins can view, export, and delete conversations.

Evaluate your Data Processing Agreement with OpenAI to ensure it reflects the expanded admin monitoring authority and retention exceptions.

Historical Context

Across all monitored documents, OpenAI has made 5 significant changes.

4 of OpenAI's significant changes have been classified as negative for consumers.

Key Clauses Affected

workspace admin access authority

Admins now gain explicit authority to view, access, export, and delete all end user conversations in their workspace.

retention control transfer

Retention duration shifts from end user control to workspace admin control.

expanded deletion exception

Deleted conversations can now be retained beyond 30 days if retention is reasonably necessary to protect OpenAI's services or any third party from harm, not just for legal requirements.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
694a813c3880cd986d5603525b163c07256efa613212c14bfd28669773650667
May 22, 2026 00:08 UTC
✓ Verified
Current Version
1ae7d9fa2dca070b64ed5b07ad1ec3806fc650d1cfbfeddb552af548e6be6663
May 28, 2026 00:01 UTC
✓ Verified
Change Detected
May 28, 2026 00:01 UTC
Analysis Methodology
✓ Verified
Source Document
https://openai.com/enterprise-privacy/
Citation Record
Entity: OpenAI
Document: OpenAI Enterprise Privacy
Record ID: CA-C-002397
Captured: 2026-05-28 00:01:39 UTC
URL: https://conductatlas.com/change/2026-05-28-openai-openai-enterprise-privacy-2397/
Accessed: Aug. 16, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

This change materially expands the data processing authority OpenAI asserts over enterprise customer workspaces. Workspace admins gain direct access to monitor, export, and delete end user conversations, and control retention periods. For enterprise customers operating …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002397.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenAI Enterprise Privacy
Entity
OpenAI
Captured
May 28, 2026
Source URL
https://openai.com/enterprise-privacy/
Other changes to OpenAI Enterprise Privacy
Previous change May 22, 2026
OpenAI updated formatting in its Enterprise Privacy document on May 22, 2026 by modifying spacing around hyperlinks in three sentences. …
Low Neutral
Next change Jun 1, 2026
OpenAI updated three sentences in their Enterprise Privacy policy on June 1, 2026, removing spacing characters around hyperlinks in language …
Low Neutral
View full version history →
More from OpenAI
Aug 11, 2026 Low
OpenAI GPT-5.5 System Card

OpenAI's GPT-5.5 System Card, last substantively updated on April 24, 2026, was modified on August 11, 2026. The change replaced …

Aug 11, 2026 Low
OpenAI GPT-5 System Card

OpenAI's GPT-5 System Card was updated in an update detected on August 11, 2026. The change involved replacing one featured …

Aug 11, 2026 Low
OpenAI Frontier Governance Framework

OpenAI's Frontier Governance Framework was updated in an update detected on August 11, 2026, adding a new featured article titled …

Related Analysis
Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track OpenAI policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All OpenAI changes →