OpenAI makes a Data Processing Addendum available to enterprise and API customers, which establishes the contractual terms under which OpenAI processes personal data on behalf of business customers.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
A signed DPA is the primary contractual instrument establishing GDPR Article 28 compliance and CCPA service provider status; without it, enterprise customers may lack documented legal basis for processing personal data through OpenAI services.
Interpretive note: The DPA availability is inferred from the document's stated enterprise privacy scope and OpenAI's publicly known practices; verbatim clause language was not available in the provided HTML.
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →Current version specifies DPA availability for three specific products (ChatGPT Business, ChatGPT Enterprise, API), references other privacy laws beyond GDPR, and provides a process link to request execution.
View full change record →This high-severity provision with no excerpt was replaced by more detailed GDPR and DPA-specific language, reducing emphasis on generic DPA availability.
View full change record →Enterprise and API customers who process personal data of employees or end users through OpenAI products should confirm that a DPA is executed, as this document governs OpenAI's data processing obligations and the customer's controller responsibilities.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
(1) REGULATORY LANDSCAPE: GDPR Article 28 requires that processing by a processor be governed by a binding contract setting out the subject matter, duration, nature, and purpose of processing, along with processor obligations.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
A signed DPA is the primary contractual instrument establishing GDPR Article 28 compliance and CCPA service provider status; without it, enterprise customers may lack documented legal basis for processing personal data through OpenAI services.
Enterprise and API customers who process personal data of employees or end users through OpenAI products should confirm that a DPA is executed, as this document governs OpenAI's data processing obligations and the customer's controller responsibilities.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.