Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document states that OpenAI does not use business customer data for model training by default, but reserves the right to train on data if the customer has explicitly opted in through available opt-in mechanisms.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a default data protection posture for enterprise customers, but the opt-in mechanism and what constitutes valid opt-in consent are not fully detailed within this document, requiring review of supplemental terms and the specific opt-in interface presented to customers.
Interpretive note: The document does not specify the format, location, or revocability conditions of the opt-in mechanism, creating ambiguity about whether consent captured meets GDPR or other jurisdiction-specific standards.
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →Current version provides more specific examples of opt-in mechanisms (feedback mechanisms) and clarifies the purpose is to 'improve our services'.
View full change record →Under this provision, business data submitted through covered products is not used for model training unless the customer actively opts in. The agreement does not specify in this document the precise mechanism or interface through which opt-in consent is recorded, which may require independent verification by enterprise customers.
Cross-platform context
See how other platforms handle Default No-Training Commitment with Opt-In Exception and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"By default, we do not use your business data for training our models. If you have explicitly opted in to share your data with us (for example, through our opt-in feedback mechanisms) to improve our services, then we may use the shared data to train our models.Excerpt from OpenAI's API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 6 lawful basis requirements and GDPR Article 7 consent standards, particularly regarding the specificity and freely given nature of opt-in consent for data processing beyond the original service purpose. The FTC's authority over deceptive data practices is relevant if opt-in mechanisms are not clearly disclosed. The relevant enforcement authority for EU operations is the Irish Data Protection Commission, as OpenAI's EU establishment is in Ireland. (2) GOVERNANCE EXPOSURE: Medium. The provision creates a clear default protection but the document does not specify the format, location, or revocability conditions of the opt-in mechanism, creating ambiguity about whether opt-in consent meets GDPR Article 7 standards. Organizations that have interacted with any opt-in feedback mechanism should audit whether employees have consented to training use. (3) JURISDICTION FLAGS: EU and EEA customers face heightened exposure because GDPR requires that consent for secondary processing purposes such as model training be specific, informed, and freely given. California customers may evaluate this provision under CPRA's restrictions on use of personal information beyond the disclosed purpose. Healthcare organizations should assess whether any opt-in inadvertently authorizes training use of data that may constitute PHI. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm that executed DPAs address the opt-in training exception explicitly, including whether the DPA overrides or supplements this default commitment. Vendor assessments should include review of any opt-in feedback mechanisms accessible to end users within enterprise workspaces to assess whether workspace admin controls prevent unintended opt-in. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit workspace configurations to confirm that opt-in feedback mechanisms are disabled or controlled at the admin level. Policy updates may be needed to address employee use of opt-in feedback functions within enterprise ChatGPT deployments. Organizations in regulated industries should document this default protection as part of their AI vendor risk management records.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes a default data protection posture for enterprise customers, but the opt-in mechanism and what constitutes valid opt-in consent are not fully detailed within this document, requiring review of supplemental terms and the specific opt-in interface presented to customers.
Under this provision, business data submitted through covered products is not used for model training unless the customer actively opts in. The agreement does not specify in this document the precise mechanism or interface through which opt-in consent is recorded, which may require independent verification by enterprise customers.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.