Upon agreement expiry or termination, OpenAI will return or delete Customer Data and all copies upon the Customer's instruction, unless legal retention obligations require otherwise, in which case the retained data will be isolated and protected from further processing.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision implements the processor obligation under GDPR Article 28(3)(g) to delete or return personal data at the end of processing and to delete existing copies unless Union or Member State law requires storage. The requirement that return or deletion occurs at Customer's instruction means the Customer must actively issue that instruction rather than deletion occurring automatically.
This provision establishes that personal data submitted to OpenAI through the Services will be returned or deleted upon agreement termination at the Customer's instruction, with continued protection of any data required to be retained by law. End users whose data is processed through a business customer's use of OpenAI have an indirect interest in this provision being properly invoked by the business customer upon termination.
Cross-platform context
See how other platforms handle Data Return or Deletion on Termination and similar clauses.
Compare across platforms →"Following expiry or termination of the Agreement, OpenAI will, at Customer's instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.Excerpt from OpenAI's Data Processing Addendum
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision implements the processor obligation under GDPR Article 28(3)(g) to delete or return personal data at the end of processing and to delete existing copies unless Union or Member State law requires storage. The requirement that return or deletion occurs at Customer's instruction means the Customer must actively issue that instruction rather than deletion occurring automatically.
This provision establishes that personal data submitted to OpenAI through the Services will be returned or deleted upon agreement termination at the Customer's instruction, with continued protection of any data required to be retained by law. End users whose data is processed through a business customer's use of OpenAI have an indirect interest in this provision being properly invoked by …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.