Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document discloses that all business data submitted to OpenAI services may be processed through automated content classifiers and safety tools for purposes including usage understanding, with resulting classifications described as metadata that does not contain the underlying business data.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that automated processing of business data is a universal baseline across all covered services, regardless of service tier. Compliance teams should assess whether this automated processing is addressed in their DPAs and whether it triggers obligations under applicable data protection law.
The updated terms state that workspace admins 'can control' data retention rather than directly controlling it. This conditional phrasing may suggest that retention control is optional or contingent rather than a guaranteed capability. Enterprise customers relying on admin-driven data retention policies should clarify with OpenAI whether this change affects their ability to set specific retention timelines for workspace data.
View change record →The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.
View change record →This provision discloses automated processing of business data for safety and service improvement while explicitly distinguishing metadata from actual data content and limiting human review to service-specific bases.
View full change record →This provision establishes that all business data submitted to OpenAI services may be processed through automated classifiers, with metadata outputs generated from that processing. The document states that the metadata classifications do not contain the underlying business data itself.
Cross-platform context
See how other platforms handle Automated Content Classification of Business Data and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may run any business data submitted to OpenAI's services through automated content classifiers and safety tools, including to better understand how our services are used. The classifications created are metadata about the business data but do not contain any of the business data itself. Business data is only subject to human review as described below on a service-by-service basis.Excerpt from OpenAI's Enterprise Privacy
(1) REGULATORY LANDSCAPE: Automated processing of data submitted by enterprise customers may engage GDPR Article 22 if the processing involves solely automated decision-making with legal or similarly significant effects, though the provision as described appears to be analytical rather than decisional. GDPR Articles 13 and 14 require disclosure of automated processing to data subjects; this provision constitutes a disclosure but its adequacy for GDPR notice purposes depends on whether it is incorporated into customer-facing privacy notices and DPAs. The FTC Act is relevant to the accuracy of the claim that metadata does not contain underlying business data. (2) GOVERNANCE EXPOSURE: Medium. The breadth of the provision ('any business data submitted to OpenAI's services') and the stated purpose ('including to better understand how our services are used') are broad. The characterization of outputs as metadata that does not contain business data reduces some exposure, but the automated processing itself may constitute a data processing activity requiring documentation in GDPR records of processing activities. (3) JURISDICTION FLAGS: EU and UK organizations should assess whether this automated processing is adequately described in their DPA and whether it requires disclosure in their own privacy notices to data subjects whose personal data may be included in submitted business data. California organizations should evaluate whether the classifier processing constitutes a use of personal information requiring disclosure under CCPA. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm that executed DPAs address this automated processing as a distinct processing activity. The distinction between classifier metadata and underlying business data should be verified technically and contractually, as the adequacy of this separation may be relevant to data minimization assessments. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should update data processing inventories to include automated classifier processing as a distinct activity. Privacy impact assessments for enterprise AI deployments should address this processing. Organizations in regulated sectors should assess whether classifier processing of sector-specific data triggers additional obligations.
This provision establishes that automated processing of business data is a universal baseline across all covered services, regardless of service tier. Compliance teams should assess whether this automated processing is addressed in their DPAs and whether it triggers obligations under applicable data protection law.
This provision establishes that all business data submitted to OpenAI services may be processed through automated classifiers, with metadata outputs generated from that processing. The document states that the metadata classifications do not contain the underlying business data itself.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.