Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that administrators of ChatGPT Enterprise or business accounts may access and control individual user accounts and their content, and that OpenAI may share account existence and email address with an employer if a work email is used to create a personal account.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that employer-level administrators have access to individual user content within enterprise accounts, and separately that OpenAI may disclose account existence to an employer based solely on the email domain used during registration, which may affect employee expectations regarding the separation of personal and professional account data.
The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.
View change record →The updated privacy policy now explicitly states that OpenAI receives information from advertisers and other data partners, which is used to personalize ads shown to Free and Go users and to measure the effectiveness of those ads. For example, the policy notes that OpenAI could receive information about purchases users make from advertisers. The policy now includes a dedicated section on ad personalization and measurement as a primary use of personal data for these user tiers. You can manage what data OpenAI uses for ad personalization by accessing the advertising controls in your account settings or by using the Data Controls option.
View change record →The updated policy now explicitly authorizes OpenAI to promote products and services to users through direct marketing on third-party properties and to share limited information with select marketing partners (who are not service providers) to support these efforts. The policy states that some marketing partners may receive information through cookies and similar technologies. The revised terms establish that these marketing practices are subject to user choices and controls, with additional information and opt-out options available. You can make choices about the use of your information for third-party product promotion purposes through controls referenced in the policy.
View change record →Under this provision, users on ChatGPT Enterprise or business accounts should be aware that account administrators may access their content and account controls. Additionally, users who register for any OpenAI account using a work email address may have their account existence and email address disclosed to their employer or organization without a separate notification step.
Cross-platform context
See how other platforms handle Business Account Administrator Access to User Content and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When you join a ChatGPT Enterprise or business account, the administrators of that account may access and control your OpenAI account, including being able to access your Content. In addition, if you create an account using an email address belonging to your employer or another organization, we may share the fact that you have an account and certain account information, such as your email address, with your employer or organization to, for example, enable you to be added to their business account.Excerpt from OpenAI's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR and UK GDPR requirements regarding the lawful basis for employer access to employee personal data and the adequacy of notice to data subjects, enforced by EU and UK data protection authorities. For US users, applicable state privacy statutes and employment law vary by jurisdiction. The FTC Act applies to whether disclosures about employer data sharing are sufficiently clear. In healthcare or financial services contexts, additional sector-specific regulations may apply if sensitive data appears in user content. 2) GOVERNANCE EXPOSURE: Medium. The employer disclosure triggered by work email domain registration operates without requiring a separate affirmative action by the user or the employer, which may create an unexpected data flow for employees who use work email addresses for personal AI use. Enterprise deployment teams should confirm that administrator access scope is addressed in their customer agreements with OpenAI. 3) JURISDICTION FLAGS: EU and UK jurisdictions require a lawful basis for employer access to employee personal data, which typically requires either employee consent or a legitimate interest assessment. California employees may have additional privacy rights under the California Consumer Privacy Act as applied to employee data. Jurisdictions with strong data minimization requirements may scrutinize the scope of administrator access to all user content. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations procuring ChatGPT Enterprise should confirm through their customer agreement what controls exist over administrator access to employee content, what audit logs are maintained, and whether administrator access permissions can be restricted. The policy's statement that administrators may access and control user accounts is broadly stated and the specific scope may be further defined in enterprise contractual terms. 5) COMPLIANCE CONSIDERATIONS: HR and legal teams should assess whether employees have been notified that work email registration may result in account disclosure to the employer, and whether internal policies address the use of OpenAI consumer accounts with work credentials. Enterprise deployment teams should review administrator access policies and ensure that access is limited to authorized personnel consistent with applicable employment and privacy law.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that employer-level administrators have access to individual user content within enterprise accounts, and separately that OpenAI may disclose account existence to an employer based solely on the email domain used during registration, which may affect employee expectations regarding the separation of personal and professional account data.
Under this provision, users on ChatGPT Enterprise or business accounts should be aware that account administrators may access their content and account controls. Additionally, users who register for any OpenAI account using a work email address may have their account existence and email address disclosed to their employer or organization without a separate notification step.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.