OpenAI · OpenAI Privacy Policy · View original document ↗

Business Transfer and Transaction Disclosure

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time OpenAI changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 24 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for OpenAI Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes disclosure of personal data to counterparties and advisors during due diligence for a transaction, and transfer of personal data to a successor entity as an asset in the event of a strategic transaction, reorganization, bankruptcy, receivership, or service transition.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision is a standard commercial clause that authorizes personal data transfer as a business asset in corporate transactions. The disclosure to counterparties during due diligence is noted as occurring before any transaction is completed, which means personal data may be shared with third parties in connection with a transaction that does not ultimately close.

Recent Activity

This document changed recently

Medium Jun 12, 2026

The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.

View change record →
Medium Jun 7, 2026

The updated privacy policy now explicitly states that OpenAI receives information from advertisers and other data partners, which is used to personalize ads shown to Free and Go users and to measure the effectiveness of those ads. For example, the policy notes that OpenAI could receive information about purchases users make from advertisers. The policy now includes a dedicated section on ad personalization and measurement as a primary use of personal data for these user tiers. You can manage what data OpenAI uses for ad personalization by accessing the advertising controls in your account settings or by using the Data Controls option.

View change record →
Medium May 1, 2026

The updated policy now explicitly authorizes OpenAI to promote products and services to users through direct marketing on third-party properties and to share limited information with select marketing partners (who are not service providers) to support these efforts. The policy states that some marketing partners may receive information through cookies and similar technologies. The revised terms establish that these marketing practices are subject to user choices and controls, with additional information and opt-out options available. You can make choices about the use of your information for third-party product promotion purposes through controls referenced in the policy.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, personal data collected from users may be disclosed to third-party counterparties and advisors during the due diligence phase of a corporate transaction, and transferred to a successor entity as part of a completed transaction. Users would be subject to the successor entity's privacy practices following any such transfer.

Cross-platform context

See how other platforms handle Business Transfer and Transaction Disclosure and similar clauses.

Compare across platforms →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a "Transaction"), your Personal Data may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.

Excerpt from OpenAI's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Business transfer provisions engage FTC guidance on privacy policy compliance during corporate transactions, which requires that successor entities honor the original privacy commitments or provide users with notice and choice. CCPA requires notification to California residents when personal information is transferred in a business transaction. GDPR (for EEA users) imposes requirements on transfers of personal data in the context of business transactions, addressed through the separate regional policy. 2) GOVERNANCE EXPOSURE: Low. This is a standard commercial provision. The due diligence disclosure component (pre-transaction sharing with counterparties) is the element most likely to result in personal data being shared without a completed transaction completing, which may be subject to confidentiality agreements but is disclosed in the policy. 3) JURISDICTION FLAGS: California residents may have notification rights under CCPA in the event of a business transfer. The FTC has published guidance on privacy policy compliance obligations in the context of corporate transactions that applies to US-based operations. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations that rely on OpenAI services for business-critical functions should assess whether a change of control or service transition event would trigger contract review or termination rights under applicable vendor agreements. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should monitor for announced transactions and assess whether the personal data transfer would be consistent with applicable regulatory requirements, including any state-level notification obligations.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has published guidance on privacy policy compliance obligations during corporate transactions involving consumer data
    File a complaint →

Provision details

Document information
Document
OpenAI Privacy Policy
Entity
OpenAI
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013574
Document ID
CA-D-00010
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c0c49f013e1bb2dd1fa883d161d2b79a60a5914fddbd230bcaa0df5e2cfaa86e
Analysis generated
July 9, 2026 03:28 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Privacy Policy
Record ID: CA-P-013574
Captured: 2026-07-09 03:28:49 UTC
SHA-256: c0c49f013e1bb2dd…
URL: https://conductatlas.com/platform/openai/openai-privacy-policy/provision/CA-P-013574/business-transfer-and-transaction-disclosure/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenAI's Business Transfer and Transaction Disclosure clause do?

This provision is a standard commercial clause that authorizes personal data transfer as a business asset in corporate transactions. The disclosure to counterparties during due diligence is noted as occurring before any transaction is completed, which means personal data may be shared with third parties in connection with a transaction that does not ultimately close.

How does this clause affect you?

Under this clause, personal data collected from users may be disclosed to third-party counterparties and advisors during the due diligence phase of a corporate transaction, and transferred to a successor entity as part of a completed transaction. Users would be subject to the successor entity's privacy practices following any such transfer.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.