6 Total
0 High severity
5 Medium severity
1 Low severity
Summary

This is OpenAI's Enterprise Privacy disclosure page, covering data handling practices for ChatGPT Enterprise, ChatGPT Teams (Business), and the API Platform. The document states that for these enterprise and API tiers, customer inputs, outputs, and uploaded files are not used to train OpenAI models by default, and that enterprise customers own their conversation data. The document also discloses that OpenAI offers a Data Processing Addendum for GDPR compliance and can enter into Business Associate Agreements for customers with HIPAA-relevant use cases.

Technical / Legal Breakdown

This document is OpenAI's Enterprise Privacy page, a marketing and disclosure resource governing data handling practices for ChatGPT Enterprise, ChatGPT Business (Teams), and the API Platform, with contractual obligations grounded in OpenAI's Data Processing Addendum and Terms of Service. The document states that API and ChatGPT Enterprise customers' inputs and outputs are not used to train OpenAI models by default, that enterprise customers retain ownership of their inputs and outputs, and that OpenAI acts as a data processor under customer instructions for these tiers. The document discloses that OpenAI maintains SOC 2 Type 2 certification and encryption at rest and in transit, and asserts GDPR compliance through Standard Contractual Clauses for EU data transfers, though the document is a marketing page rather than a binding legal instrument, and specific contractual terms are governed by separate agreements referenced but not reproduced here. The policy engages GDPR, CCPA, and HIPAA-adjacent considerations, and references a Data Processing Addendum as the primary mechanism for compliance obligations; EU and California users face the most operationally significant compliance dependencies. Enterprise customers operating under BAA or DPA agreements should note that the page references but does not reproduce those instruments, and compliance verification requires review of those underlying contracts.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

4 important changes detected

5 versions captured · Last updated: May 2026

What changed OpenAI updated its API Data Usage Policies on May 29, 2026 by modifying three hyperlinked references within the document. The changes involved adjusting whitespace and link formatting around the Data Processing Agreement form, the Student Data Privacy Agreement for educational users, and the ChatGPT Business information page. These are formatting and structural edits with no change to the substantive content, procedures, or rights described in the policy.
Why this matters These changes are formatting and hyperlink adjustments with no impact on how OpenAI collects, uses, or protects user data. The substantive content of the Data Processing Agreement, Student Data Privacy Agreement, and ChatGPT Business terms remains unchanged. No action is required in response to these edits.
View full change record →

May 28, 2026

unknown
What changed OpenAI updated their OpenAI API Data Usage Policies on May 28, 2026. Change detected: 7 sentence(s) modified. Document contained 107 sentences after update.
View full change record →

May 24, 2026 low

OpenAI made minor formatting adjustments to three hyperlinks in their API Data Usage Policies on May 24, 2026. The changes affected the Data Processing Agreement link, the Student Data Privacy …

View change record →
May 19, 2026 low

OpenAI modified a single hyperlink in its API Data Usage Policies on May 19, 2026. The phrase 'Learn more about ChatGPT Business' previously linked directly to that resource; the updated …

View change record →

Recent Provision Changes May 29, 2026

6 provisions unchanged.

View full change record →
Medium — 5 provisions
Low — 1 provision

Monitoring

OpenAI has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Data Processing Addendum Availability and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

DMCA
United States Federal
View official text ↗

Related Analysis

Privacy · May 3, 2026
OpenAI Privacy Policy Update May 2026: New Terms Authorize Advertiser Data Sharing

OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…

Dependency Governance · June 11, 2026
AI Dependency Governance: How API Terms Govern Every App Built on OpenAI, Anthropic, and Google

872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Archival ProvenanceSource & Archival Record
Last Captured May 29, 2026 04:51 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000789
Version ID CA-V-003131
SHA-256 1ae7d9fa2dca070b64ed5b07ad1ec3806fc650d1cfbfeddb552af548e6be6663
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans