Provision record
OpenAI · OpenAI Data Processing Addendum · View original document ↗

OpenAI must maintain reasonable security measures for Customer Data

High severity Explicit document language Common · 275 of 352 platforms
Stay ahead of the changes
Track OpenAI and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

How other platforms handle this

Synthesia Medium

Customer will be permitted to export Customer Data via the Services; provided, that Customer acknowledges and agrees that such ability to export may be limited by the applicable Services plan in effect and the data retention settings enabled by Customer.

Google Ads Medium

Google will keep appropriate documentation of its processing activities as required by Applicable Data Protection Legislation.

Squarespace Medium

if you're a Customer, we may not immediately delete your information when your trial expires or you cancel all your paid Services. Instead, we keep your information for a reasonable period of time, so it will be there for you if you come back.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
OpenAI will implement and maintain reasonable and appropriate organizational and technical security measures to protect Customer Data, as set forth in the Agreement.

Excerpt from OpenAI's Data Processing Addendum

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
UK GDPR
United Kingdom

Provision details

Document information
Document
OpenAI Data Processing Addendum
Entity
OpenAI
Document last updated
May 11, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-061486
Document ID
CA-D-00757
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3a1b6bc316e690b84874f1ab6de51ac037a8084441b88c58ba8dec245e06e17d
Analysis generated
July 9, 2026 03:35 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Data Processing Addendum
Record ID: CA-P-061486
Captured: 2026-07-09 03:35:12 UTC
SHA-256: 3a1b6bc316e690b8…
URL: https://conductatlas.com/platform/openai/openai-data-processing-addendum/provision/CA-P-061486/openai-must-maintain-reasonable-security-measures-for-customer-data/
Accessed: Aug. 3, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does OpenAI's OpenAI must maintain reasonable security measures for Customer Data clause do?

The clause states: “OpenAI will implement and maintain reasonable and appropriate organizational and technical security measures to protect Customer Data, as set forth in the Agreement.”

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 275 platforms. See the full comparison.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.