If you use OpenAI services from outside the US, your personal data is transferred to and stored in the United States, with EU and UK transfers covered by Standard Contractual Clauses.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause establishes the jurisdictional framework and legal mechanism for international data flows, clarifying that personal data collected from non-U.S. users will be subject to U.S. law and processed in U.S. infrastructure. This addresses regulatory requirements under EU and UK data protection frameworks for lawful cross-border data transfers.
The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.
View change record →The updated privacy policy now explicitly states that OpenAI receives information from advertisers and other data partners, which is used to personalize ads shown to Free and Go users and to measure the effectiveness of those ads. For example, the policy notes that OpenAI could receive information about purchases users make from advertisers. The policy now includes a dedicated section on ad personalization and measurement as a primary use of personal data for these user tiers. You can manage what data OpenAI uses for ad personalization by accessing the advertising controls in your account settings or by using the Data Controls option.
View change record →The updated policy now explicitly authorizes OpenAI to promote products and services to users through direct marketing on third-party properties and to share limited information with select marketing partners (who are not service providers) to support these efforts. The policy states that some marketing partners may receive information through cookies and similar technologies. The revised terms establish that these marketing practices are subject to user choices and controls, with additional information and opt-out options available. You can make choices about the use of your information for third-party product promotion purposes through controls referenced in the policy.
View change record →Your personal data, regardless of where you are located, is stored in the US and subject to US law; EEA and UK users are covered by Standard Contractual Clauses as the transfer safeguard, though the adequacy of US surveillance law protections remains a subject of ongoing regulatory evaluation.
How other platforms handle this
we also transfer personal information to all other countries in which Adobe or its affiliates, providers, and partners operate. We carry out these transfers in compliance with applicable laws – for example, by putting data transfer agreements in place...
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Whenever we transfer personal data internationally, we use tools and transfer agreements to: make sure the data transfer complies with applicable law; and help to give your data the same level of protection as it has in the EU...
"OpenAI is based in the United States and the information we collect is governed by U.S. law. If you are accessing our services from outside of the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities in the United States and by those third parties with whom we may share your information as described in this Privacy Policy. We use Standard Contractual Clauses approved by the European Commission for transfers of personal data from the EEA or UK to the United States.Excerpt from OpenAI's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V (international transfers), specifically the use of Standard Contractual Clauses (SCCs) as a transfer mechanism following the Schrems II ruling, which invalidated the EU-US Privacy Shield.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause establishes the jurisdictional framework and legal mechanism for international data flows, clarifying that personal data collected from non-U.S. users will be subject to U.S. law and processed in U.S. infrastructure. This addresses regulatory requirements under EU and UK data protection frameworks for lawful cross-border data transfers.
Your personal data, regardless of where you are located, is stored in the US and subject to US law; EEA and UK users are covered by Standard Contractual Clauses as the transfer safeguard, though the adequacy of US surveillance law protections remains a subject of ongoing regulatory evaluation.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.