The enterprise privacy page is specifically scoped to ChatGPT Business, ChatGPT Enterprise, and the OpenAI API Platform, and the privacy commitments described do not apply to standard consumer ChatGPT accounts.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The distinction between enterprise and consumer data handling terms is operationally significant: organizations that use both consumer and enterprise OpenAI products may be subject to different data handling practices depending on which product their employees or users access.
Interpretive note: The specific scope language distinguishing enterprise and consumer data handling was not available in the provided HTML; this provision is inferred from the document's stated subject matter and OpenAI's publicly known product structure.
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →This provision clarifying differences between enterprise and consumer privacy protections was removed, though its substance may be implicitly addressed by enterprise-specific provisions.
View full change record →Organizations that allow employees to use standard consumer ChatGPT accounts rather than ChatGPT Enterprise or the API should be aware that the stronger data handling commitments described in this enterprise privacy page do not apply to consumer accounts, where different terms govern data use including potential use for model training.
How other platforms handle this
When you use them, we'll validate your request by verifying your identity (for example, by confirming that you're signed in to your Google Account).
Not be Discriminated Against by us for exercising your privacy rights.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
(1) REGULATORY LANDSCAPE: This scope distinction has implications under GDPR's accountability principle: if employees use consumer ChatGPT for work purposes, the organization may lack documentation of a lawful basis for that processing and may not …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The distinction between enterprise and consumer data handling terms is operationally significant: organizations that use both consumer and enterprise OpenAI products may be subject to different data handling practices depending on which product their employees or users access.
Organizations that allow employees to use standard consumer ChatGPT accounts rather than ChatGPT Enterprise or the API should be aware that the stronger data handling commitments described in this enterprise privacy page do not apply to consumer accounts, where different terms govern data use including potential use for model training.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.