OpenAI · OpenAI Data Processing Addendum · View original document ↗

Data Deletion and Return on Termination

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 15 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for OpenAI Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

When the API service agreement ends, OpenAI will either return or delete the business customer's personal data, unless a law requires it to keep certain data.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the operator's right to data deletion or return at contract end, which is a standard GDPR Article 28(3)(g) requirement. Operators should confirm what process applies and what data categories are covered, including any data that may have been used in fine-tuning or logged for safety purposes.

Consumer impact (what this means for users)

Personal data processed through an operator's API integration is subject to deletion or return when the operator ends its agreement with OpenAI. Individuals whose data was processed benefit from this commitment, though the practical scope depends on the operator requesting deletion and on any legal exceptions that may apply.

How other platforms handle this

Threads Medium

We keep information for as long as we need it to provide our products, comply with legal obligations, or for other legitimate purposes, such as to maintain safety, security, and integrity.

Hinge Medium

After your account is deleted, we keep data about interactions you've had on our service to prevent abuse, ban evaders and others in an effort to protect and ensure the safety and security of our service and our members.

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

See all platforms with this clause type →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Upon termination or expiry of the Agreement, OpenAI will, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless applicable law requires storage of the Customer Personal Data.

— Excerpt from OpenAI's OpenAI Data Processing Addendum

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: GDPR Article 28(3)(g) requires processor contracts to include deletion or return of personal data at the end of services. The UK GDPR and Swiss nFADT impose equivalent requirements. CCPA/CPRA does not impose a specific contract-end deletion obligation but service provider contract requirements may include data deletion commitments. GOVERNANCE EXPOSURE: Medium. Operators must actively request deletion or return; the provision is not automatic absent an operator instruction. Operators who allow agreements to lapse without making a deletion or return request may lose the ability to confirm data disposition. JURISDICTION FLAGS: EU/EEA and UK operators have the clearest legal basis for enforcing this provision under GDPR Article 28. US operators may rely on this provision for CCPA service provider contract purposes. Legal exceptions for data retention (e.g. financial records, law enforcement holds) may limit the scope of deletion in specific cases. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should include a data deletion request step in offboarding checklists when terminating API agreements. The provision should be reviewed for any conditions on what data is covered, particularly where data has been processed in ways that may make complete deletion technically complex (e.g. data used in inference logs retained for safety monitoring). COMPLIANCE CONSIDERATIONS: Operators should document the deletion or return request made to OpenAI at contract termination, obtain confirmation of completion, and update their records-of-processing-activities to reflect that personal data is no longer being processed by OpenAI following termination.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
OpenAI Data Processing Addendum
Entity
OpenAI
Document last updated
May 11, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 12, 2026
Record ID
CA-P-010998
Document ID
CA-D-00757
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8ae5b556815e67cd00740a6c1b656c2b56a01dfecbb0b039a8fa2625f2c769ba
Analysis generated
May 11, 2026 13:05 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Data Processing Addendum
Record ID: CA-P-010998
Captured: 2026-05-11 13:05:56 UTC
SHA-256: 8ae5b556815e67cd…
URL: https://conductatlas.com/platform/openai/openai-data-processing-addendum/data-deletion-and-return-on-termination/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenAI's Data Deletion and Return on Termination clause do?

This provision establishes the operator's right to data deletion or return at contract end, which is a standard GDPR Article 28(3)(g) requirement. Operators should confirm what process applies and what data categories are covered, including any data that may have been used in fine-tuning or logged for safety purposes.

How does this clause affect you?

Personal data processed through an operator's API integration is subject to deletion or return when the operator ends its agreement with OpenAI. Individuals whose data was processed benefit from this commitment, though the practical scope depends on the operator requesting deletion and on any legal exceptions that may apply.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.