49 Total
23 High severity
19 Medium severity
7 Low severity

Key Facts

What authorization does Customer grant OpenAI?
Customer grants OpenAI a general authorization to engage the Sub-Processors listed in the Sub-Processor List to process Customer Data in connection with the Services.
What does OpenAI prohibit Customer from taking?
OpenAI prohibits Customer from taking actions that would render OpenAI not a 'service provider' under the CCPA or 'processor' under U.S. Privacy Laws.
What does Customer represent, warrant, and covenant regarding necessary notices?
Customer represents, warrants, and covenants that it has provided all necessary notices and has and will maintain throughout the Term all necessary rights, consents, and authorizations for Customer Data.
What must Customer maintain throughout the Term?
Customer represents, warrants, and covenants that it has provided all necessary notices and has and will maintain throughout the Term all necessary rights, consents, and authorizations for Customer Data.
What does OpenAI Ireland Limited transfer outside the European Economic Area or Switzerland on the basis of?
OpenAI Ireland Limited transfers EEA and Swiss Data outside the European Economic Area or Switzerland on the basis of agreements containing SCCs or, where applicable, an adequacy decision.
When may either party terminate the Agreement or any Order Forms?
Either party may terminate the Agreement or any Order Forms or usage regarding Services that cannot be provided without the use of a new Sub-Processor if an objection to that Sub-Processor is unresolved.
Will OpenAI inform Customer if OpenAI receives a legally binding request for disclosure of Customer Data by a law enforcement authority?
OpenAI will, to the extent legally permitted, inform Customer if OpenAI receives a legally binding request for disclosure of Customer Data by a law enforcement authority.
To what extent will OpenAI inform Customer?
OpenAI will, to the extent legally permitted, inform Customer if OpenAI receives a legally binding request for disclosure of Customer Data by a law enforcement authority.
What will OpenAI do with Customer Data following expiry or termination of the Agreement?
Following expiry or termination of the Agreement, OpenAI will, at Customer's instruction, return or delete Customer Data and existing copies, unless retention is required under applicable laws.
When will OpenAI notify Customer after becoming aware of any Personal Data Breach?
OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach.
Stay ahead of the changes
Track OpenAI and get the diff the day its terms change.
Summary

This document sets the rules for how OpenAI handles data that business customers provide when using its services. OpenAI can only use that data as the customer instructs, and cannot sell or share it under applicable privacy law definitions. If there is a security breach, OpenAI must notify the customer without undue delay, and after the agreement ends, OpenAI will return or delete the customer's data upon instruction.

Analysis

This Data Processing Addendum establishes the terms under which OpenAI processes Customer Data on behalf of customers, grounding the relationship in a processor/service-provider model. OpenAI is obligated to process Customer Data only in accordance with Customer Instructions, unless applicable law requires otherwise, and is prohibited from selling or sharing Personal Data as defined under U.S. Privacy Laws and the CCPA. The DPA sets out Sub-Processor authorization on a general basis, with termination rights available to either party if a new Sub-Processor objection is unresolved. International transfers of EEA and Swiss Data by OpenAI Ireland Limited are conducted under Standard Contractual Clauses or applicable adequacy decisions. Customer-side obligations include maintaining all necessary consents and authorizations for Customer Data throughout the Term, and customers must not take actions that would cause OpenAI to lose its service-provider or processor status under applicable law.

What this means for you

For a business customer, this document means OpenAI is bound to process their data only as directed, must promptly notify them of any Personal Data Breach, and must return or delete their data after the agreement ends when instructed to do so. Customers bear responsibility for ensuring they have all necessary consents and rights for the data they provide to OpenAI throughout the entire duration of the agreement. Customers who object to a newly added Sub-Processor and cannot reach resolution have the right to terminate the Agreement or the specific services requiring that Sub-Processor. Audit rights to verify OpenAI's data handling practices are limited to once per year and are conducted at the customer's sole expense.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: June 2026

What changed OpenAI removed the full language selector list from the header of their Data Processing Addendum on June 6, 2026, replacing it with a collapsed menu indicator ('...'). The document substance, effective date (January 1, 2026), and legal definitions remain unchanged. This is a formatting change to how the document is presented, not a modification of the data processing terms, rights, or obligations themselves.
Why this matters This change does not affect the substance of OpenAI's Data Processing Addendum or the terms governing data processing practices. The document language, legal definitions, obligations, and effective date remain identical. The change is limited to how the language selection interface is displayed on the webpage.
View full change record →
What changed OpenAI updated the language selection interface in their Data Processing Addendum on May 23, 2026. The change added five additional language options to the language selector menu (Armenian, Georgian, Icelandic, Maltese, and Somali) while keeping all substantive terms identical. This is a formatting and localization update with no change to the underlying data processing rights, obligations, or protections.
Why this matters This change does not alter any substantive terms of the Data Processing Addendum. The updated document now offers the agreement in five additional languages: Armenian, Georgian, Icelandic, Maltese, and Somali. The rights, obligations, and data processing authorizations remain identical across all language versions.
View full change record →

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

49 provisions
12 featured
13 clause types
23 high severity
Stay ahead of the changes

Monitoring

OpenAI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Customer grants general authorization to listed Sub-Processors and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗

Related Analysis

Privacy · May 3, 2026
OpenAI Privacy Policy Update May 2026: New Terms Authorize Advertiser Data Sharing

OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…

Dependency Governance · June 11, 2026
AI Dependency Governance: How API Terms Govern Every App Built on OpenAI, Anthropic, and Google

872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Archival ProvenanceSource & Archival Record
Last Captured June 6, 2026 00:06 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000757
Version ID CA-V-003482
SHA-256 a140b365afe4e3f2cfbea8fef1de46df25c7e28eabe33308405f9a4a629de32a
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans