The document states OpenAI offers a Data Processing Agreement incorporating EU Standard Contractual Clauses for enterprise and API customers, enabling international transfers of personal data from the EU/EEA to OpenAI's US-based infrastructure.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the mechanism by which EU-based enterprise customers can lawfully transfer personal data to OpenAI for processing. Under GDPR, a valid transfer mechanism is required for any transfer of EU personal data to a third country; the availability of SCCs via an executed DPA is the operative compliance step for EU customers.
Interpretive note: The document discloses DPA availability but does not specify whether the DPA is pre-signed or requires negotiation, or whether it addresses all GDPR Article 28 requirements in full; actual compliance depends on the executed agreement.
The updated terms state that workspace admins 'can control' data retention rather than directly controlling it. This conditional phrasing may suggest that retention control is optional or contingent rather than a guaranteed capability. Enterprise customers relying on admin-driven data retention policies should clarify with OpenAI whether this change affects their ability to set specific retention timelines for workspace data.
View change record →The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.
View change record →Changed 'DPA' terminology from 'Addendum' to 'Agreement', added explicit customer scope (API and ChatGPT Enterprise), and clarified SCCs are EC-approved for international transfers rather than just for GDPR compliance.
View full change record →This provision establishes that EU enterprise customers can enter into a GDPR-compliant DPA with OpenAI, which includes SCCs as the legal basis for international data transfers. The DPA must be separately requested and executed; it does not apply automatically upon account creation.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"For our API and ChatGPT Enterprise customers, we offer a Data Processing Agreement (DPA) that includes the Standard Contractual Clauses (SCCs) approved by the European Commission for international data transfers.Excerpt from OpenAI's Enterprise Privacy
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V (international transfers), GDPR Article 28 (processor obligations), and the European Commission's 2021 SCCs.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the mechanism by which EU-based enterprise customers can lawfully transfer personal data to OpenAI for processing. Under GDPR, a valid transfer mechanism is required for any transfer of EU personal data to a third country; the availability of SCCs via an executed DPA is the operative compliance step for EU customers.
This provision establishes that EU enterprise customers can enter into a GDPR-compliant DPA with OpenAI, which includes SCCs as the legal basis for international data transfers. The DPA must be separately requested and executed; it does not apply automatically upon account creation.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.