The document states that OpenAI offers a Data Processing Addendum incorporating Standard Contractual Clauses to support GDPR compliance for customers processing EU personal data through the API or ChatGPT Enterprise.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the contractual mechanism for GDPR Article 28 processor compliance and cross-border data transfer requirements for EU/EEA customers, and is the operative instrument for organizations with EU data protection obligations using OpenAI services.
Interpretive note: The binding obligations and specific terms of the DPA are not reproduced on this page; compliance verification requires review of the current DPA document separately.
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →This new provision explicitly commits to GDPR compliance infrastructure with concrete mechanisms (DPA and SCCs), addressing EU data protection regulatory requirements.
View full change record →EU-based organizations and those processing EU personal data through OpenAI's enterprise or API tiers can execute a Data Processing Addendum that incorporates Standard Contractual Clauses, providing the contractual basis for lawful cross-border data transfers under GDPR.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"We support GDPR compliance. We offer a Data Processing Addendum (DPA) to our customers and Standard Contractual Clauses for data transfers from the EU.Excerpt from OpenAI's API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 28 (processor contracts), 46 (transfers to third countries), and Chapter V transfer mechanisms.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the contractual mechanism for GDPR Article 28 processor compliance and cross-border data transfer requirements for EU/EEA customers, and is the operative instrument for organizations with EU data protection obligations using OpenAI services.
EU-based organizations and those processing EU personal data through OpenAI's enterprise or API tiers can execute a Data Processing Addendum that incorporates Standard Contractual Clauses, providing the contractual basis for lawful cross-border data transfers under GDPR.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.