7 Total
2 High severity
4 Medium severity
1 Low severity
Summary

This is OpenAI's privacy disclosure page specifically for enterprise and business customers using ChatGPT Enterprise, ChatGPT Team, and the API. The most significant commitment the document states is that conversations and data submitted through these enterprise products are not used to train OpenAI's AI models by default, and API data is deleted within 30 days unless you opt in to longer retention. If your organization handles sensitive data, you should check whether you have an active Data Processing Addendum or Business Associate Agreement with OpenAI, as these are required to access GDPR and HIPAA-level protections.

Technical / Legal Breakdown

This document is OpenAI's Enterprise Privacy page, governing data handling practices for ChatGPT Enterprise, ChatGPT Business (Team), and the API Platform, framed as a disclosure of privacy commitments rather than a binding contractual agreement in the traditional sense. The terms state that API and ChatGPT Enterprise/Team customers' inputs and outputs are not used to train OpenAI models by default, that data submitted via the API is retained for up to 30 days for abuse monitoring before deletion unless the customer has opted into longer storage, and that enterprise customers retain ownership of their inputs and outputs. The document asserts a Data Processing Addendum (DPA) is available for enterprise customers and references SOC 2 Type 2 compliance, GDPR compliance mechanisms, and HIPAA-eligible services under a Business Associate Agreement (BAA), though the page functions as a marketing and disclosure page rather than a full contractual instrument, meaning the precise enforceability of individual commitments depends on the operative terms of service and any executed DPA or BAA. The document engages GDPR, CCPA, HIPAA, and the EU AI Act regulatory landscape; GDPR applicability is acknowledged through references to Standard Contractual Clauses (SCCs) and a DPA, while HIPAA applicability is noted as available to qualifying customers via BAA. Compliance teams should note that the privacy protections described (no training on enterprise data, 30-day retention limits) are operationally conditional on the product tier used and may not apply to free or consumer-tier users, creating a tiered data governance structure with materially different implications depending on the customer relationship.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 2 provisions
Medium — 4 provisions
Low — 1 provision

Monitoring

OpenAI has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle GDPR Data Processing Addendum and Standard Contractual Clauses and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

DMCA
United States Federal
View official text ↗

Related Analysis

Privacy · May 3, 2026
OpenAI Privacy Policy Update May 2026: New Terms Authorize Advertiser Data Sharing

OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…

Archival ProvenanceSource & Archival Record
Last Captured May 12, 2026 06:03 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000825
Version ID CA-V-002498
SHA-256 a4bbc99b03aaf2a26f3940ee860bd2b128cdad012e7dba865f794a138c7b0c7c
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans