Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is OpenAI's Enterprise Privacy disclosure page, covering data handling practices for ChatGPT Enterprise, ChatGPT Teams (Business), and the API Platform. The document states that for these enterprise and API tiers, customer inputs, outputs, and uploaded files are not used to train OpenAI models by default, and that enterprise customers own their conversation data. The document also discloses that OpenAI offers a Data Processing Addendum for GDPR compliance and can enter into Business Associate Agreements for customers with HIPAA-relevant use cases.
This document is OpenAI's Enterprise Privacy page, a marketing and disclosure resource governing data handling practices for ChatGPT Enterprise, ChatGPT Business (Teams), and the API Platform, with contractual obligations grounded in OpenAI's Data Processing Addendum and Terms of Service. The document states that API and ChatGPT Enterprise customers' inputs and outputs are not used to train OpenAI models by default, that enterprise customers retain ownership of their inputs and outputs, and that OpenAI acts as a data processor under customer instructions for these tiers. The document discloses that OpenAI maintains SOC 2 Type 2 certification and encryption at rest and in transit, and asserts GDPR compliance through Standard Contractual Clauses for EU data transfers, though the document is a marketing page rather than a binding legal instrument, and specific contractual terms are governed by separate agreements referenced but not reproduced here. The policy engages GDPR, CCPA, and HIPAA-adjacent considerations, and references a Data Processing Addendum as the primary mechanism for compliance obligations; EU and California users face the most operationally significant compliance dependencies. Enterprise customers operating under BAA or DPA agreements should note that the page references but does not reproduce those instruments, and compliance verification requires review of those underlying contracts.
Institutional analysis available with Compliance
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.
Start Compliance free trial4 important changes detected
5 versions captured · Last updated: May 2026
OpenAI made minor formatting adjustments to three hyperlinks in their API Data Usage Policies on May 24, 2026. The changes affected the Data Processing Agreement link, the Student Data Privacy …
View change record →OpenAI modified a single hyperlink in its API Data Usage Policies on May 19, 2026. The phrase 'Learn more about ChatGPT Business' previously linked directly to that resource; the updated …
View change record →Monitoring
OpenAI has updated this document before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Compliance Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Compliance free trialCross-platform context
See how other platforms handle Data Processing Addendum Availability and similar clauses.
Compare across platforms →OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…
872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.