The document discloses that OpenAI has obtained SOC 2 Type 2 certification, indicating that its security controls have been independently audited against the AICPA Trust Services Criteria for security, availability, and related categories.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
SOC 2 Type 2 certification is a commonly required vendor security assurance standard in enterprise procurement and is relevant to due diligence under GDPR Article 32 (appropriate technical and organizational measures) and HIPAA security rule requirements. Enterprise customers may request OpenAI's SOC 2 report as part of their vendor risk assessment.
The updated terms state that workspace admins 'can control' data retention rather than directly controlling it. This conditional phrasing may suggest that retention control is optional or contingent rather than a guaranteed capability. Enterprise customers relying on admin-driven data retention policies should clarify with OpenAI whether this change affects their ability to set specific retention timelines for workspace data.
View change record →The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.
View change record →The removal of SOC 2 Type 2 certification disclosure eliminates a specific security compliance credential that previously assured customers of regular audits and maintained security controls.
View full change record →Changed from 'maintain' to 'achieved', added specificity about regular audits and security control maintenance, and clarified the purpose as data protection.
View full change record →This provision discloses that OpenAI's platform has undergone independent security auditing under the SOC 2 Type 2 framework, which is a standard enterprise security assurance certification. Enterprise customers can reference this certification in their vendor risk assessments and may request the audit report to verify scope and findings.
How other platforms handle this
To opt out of the offline disclosure of your information to third parties for these purposes, please email us at privacy@makenotion.com.
We may provide an option for users to opt into the disclosure of their demographic data in a manner and to an extent that may lead to loss of their anonymity.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
"OpenAI has achieved SOC 2 Type 2 compliance, and our systems are audited regularly to ensure we maintain the security controls necessary to protect your data.Excerpt from OpenAI's Enterprise Privacy
(1) REGULATORY LANDSCAPE: SOC 2 Type 2 certification is relevant to GDPR Article 32 requirements for appropriate technical and organizational security measures, HIPAA Security Rule requirements for safeguards, and contractual vendor security requirements common in …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
SOC 2 Type 2 certification is a commonly required vendor security assurance standard in enterprise procurement and is relevant to due diligence under GDPR Article 32 (appropriate technical and organizational measures) and HIPAA security rule requirements. Enterprise customers may request OpenAI's SOC 2 report as part of their vendor risk assessment.
This provision discloses that OpenAI's platform has undergone independent security auditing under the SOC 2 Type 2 framework, which is a standard enterprise security assurance certification. Enterprise customers can reference this certification in their vendor risk assessments and may request the audit report to verify scope and findings.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.