Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document states that ChatGPT for Teachers is available exclusively to verified educators at accredited U.S. K-12 institutions and is designed to support use with classroom materials and student data under education-grade protections.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that ChatGPT for Teachers is designed for a product category that may involve student data subject to FERPA, COPPA, and applicable state student privacy laws, with compliance supported through a Student Data Privacy Agreement referenced elsewhere in the document rather than a DPA.
Interpretive note: The document references a Student Data Privacy Agreement governing this product but does not reproduce or summarize its terms, requiring separate review to assess the specific data protection obligations applicable to student data processing.
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →This new provision introduces a specialized education product with student data protections, verification requirements, and administrative controls for K-12 institutions.
View full change record →Under this provision, ChatGPT for Teachers is positioned for use with student data in K-12 contexts, with access restricted to verified educators. The agreement states that data processing for this product is governed by a Student Data Privacy Agreement rather than the GDPR DPA, and that the no-training default and authorized access limitations applicable to other enterprise products also apply.
Cross-platform context
See how other platforms handle ChatGPT for Teachers K-12 Scope and Student Data Protections and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"ChatGPT for Teachers is a secure, self-serve workspace for U.S. K-12 educators, enabling teachers to use ChatGPT with classroom materials and student data, along with education-grade protections, admin controls, teacher-specific onboarding, and suggested prompts. It is available to verified teachers, staff, school leaders, and district administrators who work for an accredited U.S. K-12 school or district.Excerpt from OpenAI's API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
(1) REGULATORY LANDSCAPE: This provision engages FERPA, which governs the privacy of student education records at institutions receiving federal funding, and COPPA, which applies to collection of personal information from children under 13. Applicable enforcement authorities include the U.S. Department of Education for FERPA and the FTC for COPPA. State student privacy laws, including the California Student Privacy Act and New York Education Law Section 2-d, may impose additional obligations. The Student Data Privacy Agreement referenced in this document should be reviewed for alignment with applicable federal and state student privacy frameworks. (2) GOVERNANCE EXPOSURE: Medium. The product's explicit positioning for use with student data creates direct FERPA and potentially COPPA exposure for school districts deploying it. Districts should confirm that the Student Data Privacy Agreement addresses their specific FERPA obligations as educational agencies and that student data is not used for any purpose beyond the educational service. (3) JURISDICTION FLAGS: California school districts should assess the California Student Privacy Act requirements. New York school districts should assess compliance with New York Education Law Section 2-d. Districts in states with enacted student data privacy legislation should confirm that the Student Data Privacy Agreement satisfies applicable state-specific vendor contract requirements. (4) CONTRACT AND VENDOR IMPLICATIONS: School districts and university procurement teams should review the Student Data Privacy Agreement in full before deployment, assessing whether it satisfies applicable FERPA, COPPA, and state student privacy law requirements. Vendor assessments should confirm that the no-training default and access limitations described in this document are reflected in the Student Data Privacy Agreement as binding contractual obligations. (5) COMPLIANCE CONSIDERATIONS: Educational institutions should confirm that parental consent or appropriate school official authority under FERPA supports the deployment of ChatGPT for Teachers with student data. Acceptable use policies for K-12 teachers should address the scope of permissible student data input into the platform. Districts should maintain records of the Student Data Privacy Agreement execution and scope as part of their FERPA vendor management documentation.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that ChatGPT for Teachers is designed for a product category that may involve student data subject to FERPA, COPPA, and applicable state student privacy laws, with compliance supported through a Student Data Privacy Agreement referenced elsewhere in the document rather than a DPA.
Under this provision, ChatGPT for Teachers is positioned for use with student data in K-12 contexts, with access restricted to verified educators. The agreement states that data processing for this product is governed by a Student Data Privacy Agreement rather than the GDPR DPA, and that the no-training default and authorized access limitations applicable to other enterprise products also apply.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.