Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Upon agreement expiry or termination, OpenAI will return or delete Customer Data and all copies upon the Customer's instruction, unless legal retention obligations require otherwise, in which case the retained data will be isolated and protected from further processing.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision implements the processor obligation under GDPR Article 28(3)(g) to delete or return personal data at the end of processing and to delete existing copies unless Union or Member State law requires storage. The requirement that return or deletion occurs at Customer's instruction means the Customer must actively issue that instruction rather than deletion occurring automatically.
This provision establishes that personal data submitted to OpenAI through the Services will be returned or deleted upon agreement termination at the Customer's instruction, with continued protection of any data required to be retained by law. End users whose data is processed through a business customer's use of OpenAI have an indirect interest in this provision being properly invoked by the business customer upon termination.
Cross-platform context
See how other platforms handle Data Return or Deletion on Termination and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Following expiry or termination of the Agreement, OpenAI will, at Customer's instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.Excerpt from OpenAI's Data Processing Addendum
1. REGULATORY LANDSCAPE: This provision engages GDPR Article 28(3)(g) and the storage limitation principle under GDPR Article 5(1)(e), as well as analogous UK GDPR provisions. The relevant enforcement authorities are competent EU supervisory authorities and the UK ICO. The condition that return or deletion requires a Customer instruction rather than occurring automatically interacts with the Customer's controller obligations to give effect to data subject deletion rights. 2. GOVERNANCE EXPOSURE: Medium. The instruction-dependent mechanism means that absent an active Customer instruction, Customer Data and existing copies may remain in OpenAI's systems following termination. Organizations with automated offboarding workflows should ensure that a data return or deletion instruction to OpenAI is part of the standard termination procedure. 3. JURISDICTION FLAGS: EU and UK organizations must ensure that post-termination data deletion aligns with their own retention schedules and data subject rights obligations. Regulated industries may have legal retention requirements that interact with this provision, including financial services record-keeping obligations or healthcare record retention requirements. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should include data return or deletion procedures in their standard contract termination checklists for OpenAI engagements. The provision's isolation mechanism for legally retained data provides a contractual safeguard but should be verified against the organization's own retention policy to ensure alignment. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should establish documented offboarding procedures for OpenAI service terminations that include issuing a written data return or deletion instruction to OpenAI, confirming receipt, and obtaining a deletion certificate or equivalent confirmation where required by organizational policy or applicable regulation.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision implements the processor obligation under GDPR Article 28(3)(g) to delete or return personal data at the end of processing and to delete existing copies unless Union or Member State law requires storage. The requirement that return or deletion occurs at Customer's instruction means the Customer must actively issue that instruction rather than deletion occurring automatically.
This provision establishes that personal data submitted to OpenAI through the Services will be returned or deleted upon agreement termination at the Customer's instruction, with continued protection of any data required to be retained by law. End users whose data is processed through a business customer's use of OpenAI have an indirect interest in this provision being properly invoked by …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.