Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document states that all business data submitted to OpenAI services may be processed through automated content classifiers and safety tools, producing metadata about the data without retaining the underlying business data content in the classification output.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →This new provision discloses a significant processing activity on business data beyond model training, establishing automated monitoring practices and distinguishing between metadata creation and data retention.
View full change record →Under this provision, any inputs submitted to OpenAI enterprise services may be analyzed by automated classifiers and safety tools, generating metadata about the content. The agreement states this metadata does not contain the business data itself, but the retention period and access controls applicable to this metadata are not specified in this document.
How other platforms handle this
If other Instacart Services account owners invite you to place orders or request other services through their accounts, such as Family Accounts or Instacart Business Accounts, we collect information about your activities...
You may give us your Identity Data, Contact Data, Financial Data, Profile Data, and other information by filling in forms or by corresponding with us by post, phone, e-mail or otherwise.
telemetry information collected includes: (i) microservice settings, (ii) usage data and (iii) hardware environment.
Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may run any business data submitted to OpenAI's services through automated content classifiers and safety tools, including to better understand how our services are used.Excerpt from OpenAI's API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
(1) REGULATORY LANDSCAPE: This provision implicates GDPR requirements regarding automated processing of personal data, including Article 22 considerations if classifications could be used to make decisions affecting individuals. The FTC Act's unfair and deceptive practices authority is relevant to the accuracy of representations about metadata not containing business data. Applicable enforcement authorities include the Irish Data Protection Commission for EU operations and the FTC for US operations. (2) GOVERNANCE EXPOSURE: Medium. The provision does not specify retention periods for metadata classifications, the categories of classifications generated, or whether metadata could be used to inform model behavior or service decisions. These gaps create ambiguity for data mapping and GDPR Article 30 record of processing activities. (3) JURISDICTION FLAGS: EU and EEA customers should assess whether automated classification of inputs containing personal data constitutes processing requiring disclosure in privacy notices provided to data subjects. Organizations in regulated industries including healthcare and financial services should assess whether automated classification of submitted data creates additional compliance obligations under HIPAA or sector-specific regulations. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should verify whether executed DPAs address the automated classification process as a distinct processing activity, including the legal basis for that processing. Vendor assessments should clarify the categories of classifiers applied, the retention period for metadata, and whether metadata is shared with third parties. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should update data processing records to reflect automated classification as a processing activity separate from service delivery. Organizations should assess whether employee inputs that may contain personal data of third parties are subject to this classification and whether existing privacy notices disclose this processing to data subjects.
Regulatory citations, enforcement risk, and due diligence action items.
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
The document states that all business data submitted to OpenAI services may be processed through automated content classifiers and safety tools, producing metadata about the data without retaining the underlying business data content in the classification output.
Under this provision, any inputs submitted to OpenAI enterprise services may be analyzed by automated classifiers and safety tools, generating metadata about the content. The agreement states this metadata does not contain the business data itself, but the retention period and access controls applicable to this metadata are not specified in this document.
ConductAtlas has identified this type of provision across 296 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.