The document states that inputs and outputs submitted through the OpenAI API or ChatGPT Enterprise are not used to train OpenAI models by default, and that training use requires explicit customer opt-in.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the primary data use boundary for enterprise and API customers, directly affecting purpose limitation and data minimization compliance under GDPR and equivalent frameworks. The default exclusion from model training is a material operational distinction from consumer-tier ChatGPT accounts, where different terms may apply.
Interpretive note: The binding obligations are contained in the referenced Data Processing Addendum and Terms of Service, not this disclosure page; the enforceability of this commitment depends on those underlying instruments.
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →Previous version had no excerpt; current version adds explicit language clarifying opt-in model training default and covers both API and ChatGPT Enterprise.
View full change record →Under this provision, organizations using the API or ChatGPT Enterprise can operate with the assurance that their submitted data is not used for model training unless they affirmatively opt in. This provision applies specifically to enterprise and API tiers and does not govern standard consumer ChatGPT accounts.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"We do not train on your business data by default. Data submitted via the API or ChatGPT Enterprise is not used to train our models unless you explicitly opt in.Excerpt from OpenAI's API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
1) REGULATORY LANDSCAPE: This provision engages GDPR Articles on purpose limitation and data minimization, as well as CCPA restrictions on secondary use of personal information submitted under a service provider relationship.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the primary data use boundary for enterprise and API customers, directly affecting purpose limitation and data minimization compliance under GDPR and equivalent frameworks. The default exclusion from model training is a material operational distinction from consumer-tier ChatGPT accounts, where different terms may apply.
Under this provision, organizations using the API or ChatGPT Enterprise can operate with the assurance that their submitted data is not used for model training unless they affirmatively opt in. This provision applies specifically to enterprise and API tiers and does not govern standard consumer ChatGPT accounts.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.