CA-C-002397 Top 5%
OpenAI — OpenAI Enterprise Privacy
Entity
Date detected
May 28, 2026
Effective date
May 28, 2026
Severity
Direction
Negative
Affected users
enterprise customers workspace administrators end users in enterprise accounts
Taxonomy
Retention change
Changes
4 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Get same-day alerts when OpenAI changes We email you the diff and what it means, the day it happens.
Get same-day alerts →

Get the weekly digest

Every policy change across 844 tracked documents, once a week. No account needed.

Event Summary

OpenAI updated its Enterprise Privacy terms on May 28, 2026 to expand workspace admin authority over end user conversations. Previously, only end users could view their own conversations, and end users controlled retention decisions. The updated terms state that workspace admins can now view, access, export, and delete end user conversations, and admins control retention duration. Additionally, OpenAI broadened its deletion exception to permit longer retention not only when legally required, but also when reasonably necessary to protect its services or third parties from harm.

HIGH

Consumer Impact

The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.

Governance Analysis

The updated terms establish that workspace administrators, not individual employees, control access to conversations and data retention periods within enterprise accounts. This represents a material shift in data governance authority that affects how enterprise customers must document employee monitoring practices and may create compliance implications under privacy regulations. The expanded retention exception also permits OpenAI to retain deleted conversations longer than previously stated, creating operational discretion that may complicate data deletion commitments.

Available Actions

Review your enterprise account's workspace admin policies to understand who has access to your conversations.

Update internal privacy notices and employee policies to disclose that workspace admins can view, export, and delete conversations.

Evaluate your Data Processing Agreement with OpenAI to ensure it reflects the expanded admin monitoring authority and retention exceptions.

If No Action Is Taken

Workspace admins will have authority to access, export, and delete your conversations as stated in the updated terms.

Your conversations may be retained beyond 30 days if OpenAI determines retention is reasonably necessary to protect its services or third parties from harm.

If your organization has not updated its own privacy policies or employee agreements, discrepancies may emerge between what employees expect and what the OpenAI terms permit.

Historical Context

Across all monitored documents, OpenAI has made 9 significant changes.

6 of OpenAI's significant changes have been classified as negative for consumers.

Key Clauses Affected

workspace admin access authority

Admins now gain explicit authority to view, access, export, and delete all end user conversations in their workspace.

retention control transfer

Retention duration shifts from end user control to workspace admin control.

expanded deletion exception

Deleted conversations can now be retained beyond 30 days if retention is reasonably necessary to protect OpenAI's services or any third party from harm, not just for legal requirements.

Full clause-by-clause analysis available with Analyst.
These clauses may change again. Get alerted when they do. Get same-day alerts →

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
694a813c3880cd986d5603525b163c07256efa613212c14bfd28669773650667
May 22, 2026 00:08 UTC
✓ Verified
Current Version
1ae7d9fa2dca070b64ed5b07ad1ec3806fc650d1cfbfeddb552af548e6be6663
May 28, 2026 00:01 UTC
✓ Verified
Change Detected
May 28, 2026 00:01 UTC
Analysis Methodology
✓ Verified
Source Document
https://openai.com/enterprise-privacy/
Citation Record
Entity: OpenAI
Document: OpenAI Enterprise Privacy
Record ID: CA-C-002397
Captured: 2026-05-28 00:01:39 UTC
URL: https://conductatlas.com/change/2026-05-28-openai-openai-enterprise-privacy-2397/
Accessed: July 21, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

2
New obligations
2
Expanded
1
Protection removed
Enterprise customers Added

Businesses using OpenAI Enterprise must update their own privacy policies and employee notices to disclose that workspace admins can access, export, and delete user conversations.

Enterprise customers Expanded

OpenAI can now justify keeping deleted conversations longer than 30 days if it claims retention is necessary to protect its systems or other parties, not just when the law requires it.

End users in enterprise accounts Removed

Employees in enterprise accounts no longer decide how long their conversations are kept; workspace admins make that decision.

Enterprise customers Expanded

The reasons OpenAI can keep conversations longer are now broader and less specific, making it harder to predict when deletion will actually occur.

For legal and compliance teams

Institutional Analysis

Assessment

This change materially expands the data processing authority OpenAI asserts over enterprise customer workspaces. Workspace admins gain direct access to monitor, export, and delete end user conversations, and control retention periods. For enterprise customers operating under data protection frameworks (GDPR, CCPA, or equivalent), this shift in control authority may affect documentation of processing purposes, lawful basis determinations, and data subject rights fulfillment. The expanded retention exception now permits longer retention when reasonably necessary to protect OpenAI's services or third parties from harm, creating operational discretion that may complicate deletion timelines and data minimization commitments. Organizations with enterprise OpenAI accounts should evaluate whether this change aligns with their internal data governance policies, employee privacy expectations, and applicable regulatory obligations around employee communications monitoring and retention.

Full institutional analysis

Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.

Analyst $49/mo

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002397.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenAI Enterprise Privacy
Entity
OpenAI
Captured
May 28, 2026
Source URL
https://openai.com/enterprise-privacy/
Other changes to OpenAI Enterprise Privacy
Previous change May 22, 2026
OpenAI updated formatting in its Enterprise Privacy document on May 22, 2026 by modifying spacing around hyperlinks in three sentences. …
Low Neutral
Next change Jun 1, 2026
OpenAI updated three sentences in their Enterprise Privacy policy on June 1, 2026, removing spacing characters around hyperlinks in language …
Low Neutral
View full version history →
More from OpenAI
Jul 21, 2026 Low
OpenAI GPT-5.5 System Card

OpenAI's GPT-5.5 System Card was updated in an update detected on July 21, 2026. The document removed a reference to …

Jul 21, 2026 Low
OpenAI GPT-5 System Card

OpenAI updated the related-content section in its GPT-5 System Card detected on July 21, 2026. The previous version linked to …

Jul 21, 2026 Low
OpenAI Frontier Governance Framework

OpenAI updated its Frontier Governance Framework on July 21, 2026, modifying a single sentence within the document's reference section. The …

Related Analysis
Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Track OpenAI policy changes

Get alerted when this policy changes again — including what changed and why it matters.