7 Total
2 High severity
4 Medium severity
1 Low severity
Summary

This is OpenAI's enterprise privacy information page covering ChatGPT Enterprise, ChatGPT Teams (Business), and the API Platform. The document states that by default, inputs, outputs, and conversation data from enterprise and API customers are not used to train OpenAI models, and that OpenAI offers GDPR-compliant data processing agreements including standard contractual clauses for EU data transfers. For customers handling health information, the document states that OpenAI can sign a Business Associate Agreement for applicable API deployments, enabling use under HIPAA-relevant contexts.

Technical / Legal Breakdown

This document is OpenAI's enterprise privacy disclosure page, governing data handling practices for ChatGPT Enterprise, ChatGPT Business (Teams), and the API Platform, operating under OpenAI's Terms of Use and applicable data processing agreements. The terms state that API and ChatGPT Enterprise customers' inputs and outputs are not used to train OpenAI models by default, that enterprise conversation data is not retained beyond the immediate session by default, and that OpenAI acts as a data processor on behalf of enterprise customers for purposes of applicable data protection law. The document asserts GDPR-compliant data processing terms including standard contractual clauses for international data transfers, SOC 2 Type 2 certification, and CCPA service provider status, though the operational scope of these commitments depends on the specific contract executed and product tier in use. The document engages GDPR, CCPA, and HIPAA-adjacent considerations, noting that OpenAI offers a Business Associate Agreement for applicable API use cases, with regulatory applicability varying by jurisdiction, industry, and product configuration. Material compliance considerations include verifying that executed DPAs align with the disclosures on this page, confirming BAA availability and scope for health-related deployments, and ensuring that enterprise administrators have configured data retention and training opt-out settings correctly.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

4 important changes detected

5 versions captured · Last updated: June 2026

What changed OpenAI updated three sentences in their Enterprise Privacy policy on June 1, 2026, removing spacing characters around hyperlinks in language describing Data Processing Agreements, Student Data Privacy Agreements for ChatGPT Edu and Teachers, and ChatGPT Business information. The changes are formatting adjustments to how hyperlinked references appear in the document text. No changes to substantive privacy terms, rights, obligations, or data handling practices were made.
Why this matters This change involves formatting adjustments to hyperlinks in OpenAI's Enterprise Privacy policy and does not modify any substantive privacy terms, data handling practices, or user rights. The updated language maintains identical language for Data Processing Agreements, Student Data Privacy Agreements, and ChatGPT Business references; only spacing around hyperlinks was adjusted. No action is required by users or organizations.
View full change record →

May 28, 2026

unknown
What changed OpenAI updated their OpenAI Enterprise Privacy on May 28, 2026. Change detected: 4 sentence(s) modified. Document contained 107 sentences after update.
View full change record →

May 22, 2026 low

OpenAI updated formatting in its Enterprise Privacy document on May 22, 2026 by modifying spacing around hyperlinks in three sentences. The changes involve adjusting whitespace before the opening parentheses in …

View change record →
May 19, 2026 low

OpenAI updated a hyperlink in its Enterprise Privacy document on May 19, 2026. The previous link text 'Learn more about ChatGPT Business' was modified to 'Learn more about ChatGPT Business …

View change record →

Recent Provision Changes Jun 1, 2026

7 provisions unchanged.

View full change record →
High — 2 provisions
Medium — 4 provisions
Low — 1 provision

Monitoring

OpenAI has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle GDPR Data Processing Addendum and Standard Contractual Clauses and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗

Related Analysis

Privacy · May 3, 2026
OpenAI Privacy Policy Update May 2026: New Terms Authorize Advertiser Data Sharing

OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…

Dependency Governance · June 11, 2026
AI Dependency Governance: How API Terms Govern Every App Built on OpenAI, Anthropic, and Google

872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.

Archival ProvenanceSource & Archival Record
Last Captured June 1, 2026 00:05 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000825
Version ID CA-V-003227
SHA-256 b5e7bcba16cf57f2a8599b1e4a023d606e0273acda921b5e411c9a7ad6293642
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans