Provision record
OpenAI · OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)] · View original document ↗

Automated content classification of business data

Medium severity Explicitdocumentlanguage Common · 296 of 352 platforms
Get alerted the next time OpenAI changes these terms. Follow OpenAI →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 30 documented changes in the last 30 days.
Follow OpenAI →
Monitor governance changes for OpenAI Monitor emails you the same day this changes. The archive stays free.
Follow OpenAI →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The document states that all business data submitted to OpenAI services may be processed through automated content classifiers and safety tools, producing metadata about the data without retaining the underlying business data content in the classification output.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

Recent Activity

This document changed recently

Medium Jul 16, 2026

The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.

View change record →
Medium May 28, 2026

The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.

View change record →

Clause Stability Mostly Stable

1
Change
2
Months Monitored
Jul 9, 2026
First Seen
Jul 10, 2026
Last Seen
This clause type exists across 4187 other provisions on other platforms.
This clause has changed once in 2 months of monitoring.

Change history

added Jul 16, 2026

This new provision discloses a significant processing activity on business data beyond model training, establishing automated monitoring practices and distinguishing between metadata creation and data retention.

View full change record →

Consumer impact (what this means for users)

Under this provision, any inputs submitted to OpenAI enterprise services may be analyzed by automated classifiers and safety tools, generating metadata about the content. The agreement states this metadata does not contain the business data itself, but the retention period and access controls applicable to this metadata are not specified in this document.

How other platforms handle this

Instacart Medium

If other Instacart Services account owners invite you to place orders or request other services through their accounts, such as Family Accounts or Instacart Business Accounts, we collect information about your activities...

ZipRecruiter Medium

You may give us your Identity Data, Contact Data, Financial Data, Profile Data, and other information by filling in forms or by corresponding with us by post, phone, e-mail or otherwise.

NVIDIA NIM Medium

telemetry information collected includes: (i) microservice settings, (ii) usage data and (iii) hardware environment.

See all platforms with this clause type →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow OpenAI → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may run any business data submitted to OpenAI's services through automated content classifiers and safety tools, including to better understand how our services are used.

Excerpt from OpenAI's API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision implicates GDPR requirements regarding automated processing of personal data, including Article 22 considerations if classifications could be used to make decisions affecting individuals. The FTC Act's unfair and deceptive practices authority is relevant to the accuracy of representations about metadata not containing business data. Applicable enforcement authorities include the Irish Data Protection Commission for EU operations and the FTC for US operations. (2) GOVERNANCE EXPOSURE: Medium. The provision does not specify retention periods for metadata classifications, the categories of classifications generated, or whether metadata could be used to inform model behavior or service decisions. These gaps create ambiguity for data mapping and GDPR Article 30 record of processing activities. (3) JURISDICTION FLAGS: EU and EEA customers should assess whether automated classification of inputs containing personal data constitutes processing requiring disclosure in privacy notices provided to data subjects. Organizations in regulated industries including healthcare and financial services should assess whether automated classification of submitted data creates additional compliance obligations under HIPAA or sector-specific regulations. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should verify whether executed DPAs address the automated classification process as a distinct processing activity, including the legal basis for that processing. Vendor assessments should clarify the categories of classifiers applied, the retention period for metadata, and whether metadata is shared with third parties. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should update data processing records to reflect automated classification as a processing activity separate from service delivery. Organizations should assess whether employee inputs that may contain personal data of third parties are subject to this classification and whether existing privacy notices disclose this processing to data subjects.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority over representations about data processing practices and unfair or deceptive trade practices relevant to how business data is analyzed and what metadata is retained.
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
California AB 2013 AI Training Data Transparency
US-CA
CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Entity
OpenAI
Document last updated
May 12, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013606
Document ID
CA-D-00789
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1ae7d9fa2dca070b64ed5b07ad1ec3806fc650d1cfbfeddb552af548e6be6663
Analysis generated
July 9, 2026 03:33 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
Record ID: CA-P-013606
Captured: 2026-07-09 03:33:57 UTC
SHA-256: 1ae7d9fa2dca070b…
URL: https://conductatlas.com/platform/openai/openai-api-data-usage-policies-retired-redirects-to-enterprise-privacy-ca-d-000825/provision/CA-P-013606/automated-content-classification-of-business-data/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does OpenAI's Automated content classification of business data clause do?

The document states that all business data submitted to OpenAI services may be processed through automated content classifiers and safety tools, producing metadata about the data without retaining the underlying business data content in the classification output.

How does this clause affect you?

Under this provision, any inputs submitted to OpenAI enterprise services may be analyzed by automated classifiers and safety tools, generating metadata about the content. The agreement states this metadata does not contain the business data itself, but the retention period and access controls applicable to this metadata are not specified in this document.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 296 platforms. See the full comparison.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.