The document states that OpenAI provides Standard Contractual Clauses as the legal mechanism for cross-border personal data transfers from the EU to the United States and other non-adequate countries.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Under GDPR Chapter V, cross-border transfers of personal data to non-adequate third countries require an approved transfer mechanism; this provision discloses that OpenAI uses Standard Contractual Clauses as that mechanism for EU-originating enterprise and API data.
Interpretive note: The document does not specify which SCC module or version is in use, nor whether a Transfer Impact Assessment has been conducted; these details must be verified with OpenAI directly.
The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View change record →The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
View change record →This provision was consolidated into the updated GDPR DPA provision, which now references Standard Contractual Clauses implicitly as part of broader DPA execution rather than as a standalone offering.
View full change record →This new provision explicitly commits to SCCs as a lawful mechanism for transatlantic data transfers, addressing post-Schrems II regulatory requirements.
View full change record →EU-based enterprise and API customers can rely on Standard Contractual Clauses as the disclosed transfer mechanism for their data processed in the US, though organizations must verify that the current EU Commission-approved SCC form is in use and that a Transfer Impact Assessment has been conducted.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"We offer Standard Contractual Clauses for data transfers from the EU to the US and other countries.Excerpt from OpenAI's API Data Usage Policies [RETIRED: redirects to /enterprise-privacy/ (CA-D-000825)]
1) REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V and the EU Commission's Standard Contractual Clauses decisions.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Under GDPR Chapter V, cross-border transfers of personal data to non-adequate third countries require an approved transfer mechanism; this provision discloses that OpenAI uses Standard Contractual Clauses as that mechanism for EU-originating enterprise and API data.
EU-based enterprise and API customers can rely on Standard Contractual Clauses as the disclosed transfer mechanism for their data processed in the US, though organizations must verify that the current EU Commission-approved SCC form is in use and that a Transfer Impact Assessment has been conducted.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.