Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document sets the rules for how OpenAI handles data that business customers provide when using its services. OpenAI can only use that data as the customer instructs, and cannot sell or share it under applicable privacy law definitions. If there is a security breach, OpenAI must notify the customer without undue delay, and after the agreement ends, OpenAI will return or delete the customer's data upon instruction.
This Data Processing Addendum establishes the terms under which OpenAI processes Customer Data on behalf of customers, grounding the relationship in a processor/service-provider model. OpenAI is obligated to process Customer Data only in accordance with Customer Instructions, unless applicable law requires otherwise, and is prohibited from selling or sharing Personal Data as defined under U.S. Privacy Laws and the CCPA. The DPA sets out Sub-Processor authorization on a general basis, with termination rights available to either party if a new Sub-Processor objection is unresolved. International transfers of EEA and Swiss Data by OpenAI Ireland Limited are conducted under Standard Contractual Clauses or applicable adequacy decisions. Customer-side obligations include maintaining all necessary consents and authorizations for Customer Data throughout the Term, and customers must not take actions that would cause OpenAI to lose its service-provider or processor status under applicable law.
For a business customer, this document means OpenAI is bound to process their data only as directed, must promptly notify them of any Personal Data Breach, and must return or delete their data after the agreement ends when instructed to do so. Customers bear responsibility for ensuring they have all necessary consents and rights for the data they provide to OpenAI throughout the entire duration of the agreement. Customers who object to a newly added Sub-Processor and cannot reach resolution have the right to terminate the Agreement or the specific services requiring that Sub-Processor. Audit rights to verify OpenAI's data handling practices are limited to once per year and are conducted at the customer's sole expense.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
2 important changes detected
3 versions captured · Last updated: June 2026
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
OpenAI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Customer grants general authorization to listed Sub-Processors and similar clauses.
Compare across platforms →OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…
872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.