OpenAI · OpenAI Data Processing Addendum · View original document ↗

Processor Instruction Requirement

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 5 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for OpenAI Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

OpenAI will only process personal data in the way the business customer tells it to, unless a law requires otherwise. The business customer is responsible for making sure those instructions are lawful.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision places primary legal responsibility on the operator for the lawfulness of data processing instructions, meaning that if a business submits personal data to the API without a valid legal basis, the compliance burden rests with that business rather than OpenAI.

Consumer impact (what this means for users)

Individuals whose personal data is processed through an OpenAI-powered product are protected by the requirement that the business operating that product must give OpenAI documented, lawful instructions. If the business customer's instructions are unlawful, the DPA assigns that liability to the business customer, not OpenAI.

How other platforms handle this

Egnyte Medium

Egnyte is a data controller with respect to personal data it collects from visitors to its website and through its marketing activities. Egnyte acts as a data processor with respect to the content and data that customers store within the Egnyte platform. In that capacity, Egnyte processes data on be...

Workday Medium

At Workday, we believe privacy is a fundamental right, regardless of where you live. When you connect with Workday, we understand you are trusting us to handle your personal information appropriately. That is why we are committed to transparency about how we collect, use, and share that information.

Auth0 Medium

When Okta provides its products and services to its customers (e.g., organizations that use Okta to manage their workforce or Auth0 to manage their customer identity), Okta processes personal data on behalf of those customers as a data processor. In those cases, the customer is the data controller a...

See all platforms with this clause type →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
OpenAI will process Customer Personal Data only on Customer's documented instructions, unless required to do so by applicable law. Customer instructs OpenAI to process Customer Personal Data to provide, maintain, and improve the Services, and as further specified in the Agreement and this DPA.

— Excerpt from OpenAI's OpenAI Data Processing Addendum

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision directly implements GDPR Article 28(3)(a), which requires that a processor act only on documented instructions from the controller. The relevant enforcement authorities are EU supervisory authorities, the UK ICO, and the Swiss FDPIC. Where a business customer's instructions lack a lawful basis under GDPR Article 6, the controller bears primary regulatory exposure. GOVERNANCE EXPOSURE: Medium. The provision creates a compliance obligation for operators to document their processing instructions and ensure those instructions are grounded in a lawful basis. Operators who deploy OpenAI's API without a formal records-of-processing-activities entry referencing OpenAI as a processor may face audit findings under GDPR Article 30. JURISDICTION FLAGS: EU/EEA and UK operators face the most direct exposure under GDPR and UK GDPR Article 28 requirements. Swiss operators are similarly affected under the nFADT. US-based operators without international data flows face lower immediate regulatory exposure but should still maintain documented instructions for CCPA service provider compliance. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm that internal data processing records reference OpenAI as a sub-processor or processor and that the scope of permitted instructions is documented. Any expansion of use cases (e.g. adding new data types to API calls) should trigger a review of whether the documented instructions remain current. COMPLIANCE CONSIDERATIONS: Operators should maintain a written record of the instructions provided to OpenAI, conduct a lawful basis assessment for each category of personal data submitted via the API, and update data protection impact assessments where high-risk processing occurs.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive data practices by US-based API operators who fail to process personal data in accordance with their stated privacy commitments.
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
UK GDPR
United Kingdom

Provision details

Document information
Document
OpenAI Data Processing Addendum
Entity
OpenAI
Document last updated
May 11, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 12, 2026
Record ID
CA-P-010993
Document ID
CA-D-00757
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8ae5b556815e67cd00740a6c1b656c2b56a01dfecbb0b039a8fa2625f2c769ba
Analysis generated
May 11, 2026 13:05 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Data Processing Addendum
Record ID: CA-P-010993
Captured: 2026-05-11 13:05:56 UTC
SHA-256: 8ae5b556815e67cd…
URL: https://conductatlas.com/platform/openai/openai-data-processing-addendum/processor-instruction-requirement/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenAI's Processor Instruction Requirement clause do?

This provision places primary legal responsibility on the operator for the lawfulness of data processing instructions, meaning that if a business submits personal data to the API without a valid legal basis, the compliance burden rests with that business rather than OpenAI.

How does this clause affect you?

Individuals whose personal data is processed through an OpenAI-powered product are protected by the requirement that the business operating that product must give OpenAI documented, lawful instructions. If the business customer's instructions are unlawful, the DPA assigns that liability to the business customer, not OpenAI.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.