OpenAI · OpenAI Data Processing Addendum · View original document ↗

Data Return or Deletion on Termination

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time OpenAI changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 24 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for OpenAI Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Upon agreement expiry or termination, OpenAI will return or delete Customer Data and all copies upon the Customer's instruction, unless legal retention obligations require otherwise, in which case the retained data will be isolated and protected from further processing.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision implements the processor obligation under GDPR Article 28(3)(g) to delete or return personal data at the end of processing and to delete existing copies unless Union or Member State law requires storage. The requirement that return or deletion occurs at Customer's instruction means the Customer must actively issue that instruction rather than deletion occurring automatically.

Consumer impact (what this means for users)

This provision establishes that personal data submitted to OpenAI through the Services will be returned or deleted upon agreement termination at the Customer's instruction, with continued protection of any data required to be retained by law. End users whose data is processed through a business customer's use of OpenAI have an indirect interest in this provision being properly invoked by the business customer upon termination.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Upon termination or expiry of the OpenAI Services Agreement, issue a written instruction to OpenAI at privacy@openai.com specifying whether Customer Data should be returned or deleted, and request confirmation of completion.

Cross-platform context

See how other platforms handle Data Return or Deletion on Termination and similar clauses.

Compare across platforms →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Following expiry or termination of the Agreement, OpenAI will, at Customer's instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.

Excerpt from OpenAI's Data Processing Addendum

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Article 28(3)(g) and the storage limitation principle under GDPR Article 5(1)(e), as well as analogous UK GDPR provisions. The relevant enforcement authorities are competent EU supervisory authorities and the UK ICO. The condition that return or deletion requires a Customer instruction rather than occurring automatically interacts with the Customer's controller obligations to give effect to data subject deletion rights. 2. GOVERNANCE EXPOSURE: Medium. The instruction-dependent mechanism means that absent an active Customer instruction, Customer Data and existing copies may remain in OpenAI's systems following termination. Organizations with automated offboarding workflows should ensure that a data return or deletion instruction to OpenAI is part of the standard termination procedure. 3. JURISDICTION FLAGS: EU and UK organizations must ensure that post-termination data deletion aligns with their own retention schedules and data subject rights obligations. Regulated industries may have legal retention requirements that interact with this provision, including financial services record-keeping obligations or healthcare record retention requirements. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should include data return or deletion procedures in their standard contract termination checklists for OpenAI engagements. The provision's isolation mechanism for legally retained data provides a contractual safeguard but should be verified against the organization's own retention policy to ensure alignment. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should establish documented offboarding procedures for OpenAI service terminations that include issuing a written data return or deletion instruction to OpenAI, confirming receipt, and obtaining a deletion certificate or equivalent confirmation where required by organizational policy or applicable regulation.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Provision details

Document information
Document
OpenAI Data Processing Addendum
Entity
OpenAI
Document last updated
May 11, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013623
Document ID
CA-D-00757
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3a1b6bc316e690b84874f1ab6de51ac037a8084441b88c58ba8dec245e06e17d
Analysis generated
July 9, 2026 03:35 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Data Processing Addendum
Record ID: CA-P-013623
Captured: 2026-07-09 03:35:12 UTC
SHA-256: 3a1b6bc316e690b8…
URL: https://conductatlas.com/platform/openai/openai-data-processing-addendum/provision/CA-P-013623/data-return-or-deletion-on-termination/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does OpenAI's Data Return or Deletion on Termination clause do?

This provision implements the processor obligation under GDPR Article 28(3)(g) to delete or return personal data at the end of processing and to delete existing copies unless Union or Member State law requires storage. The requirement that return or deletion occurs at Customer's instruction means the Customer must actively issue that instruction rather than deletion occurring automatically.

How does this clause affect you?

This provision establishes that personal data submitted to OpenAI through the Services will be returned or deleted upon agreement termination at the Customer's instruction, with continued protection of any data required to be retained by law. End users whose data is processed through a business customer's use of OpenAI have an indirect interest in this provision being properly invoked by …

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.