Provision record
OpenAI · OpenAI Privacy Policy · View original document ↗

Business Transfer and Transaction Disclosure

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time OpenAI changes these terms. Follow OpenAI →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 27 documented changes in the last 30 days.
Follow OpenAI →
Monitor governance changes for OpenAI Monitor emails you the same day this changes. The archive stays free.
Follow OpenAI →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes disclosure of personal data to counterparties and advisors during due diligence for a transaction, and transfer of personal data to a successor entity as an asset in the event of a strategic transaction, reorganization, bankruptcy, receivership, or service transition.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision is a standard commercial clause that authorizes personal data transfer as a business asset in corporate transactions. The disclosure to counterparties during due diligence is noted as occurring before any transaction is completed, which means personal data may be shared with third parties in connection with a transaction that does not ultimately close.

Recent Activity

This document changed recently

Medium Jun 12, 2026

The updated policy removes language describing how OpenAI uses advertiser and data partner information to personalize ads and measure ad effectiveness. The policy also removes the specific mechanism Free and Go users previously had to control ad personalization through account settings. In exchange, the policy adds explicit authorization for OpenAI to identify which of a user's contacts use OpenAI services and to monitor all content submitted on the platform for fraud and misuse detection. The authorization to monitor content and identify contacts now appears in the main policy purposes section rather than in supplementary documentation. You can review the Korea Addendum if you are located in South Korea to understand region-specific privacy rules.

View change record →
Medium Jun 12, 2026

The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.

View change record →
Medium Jun 9, 2026

The updated policy removes language that previously described ad personalization controls available to Free and Go users through account settings, though the policy continues to authorize OpenAI to personalize ads and measure their effectiveness for these user tiers. Previously, the policy explicitly stated that 'For Free and Go users, you can use the advertising controls in your account settings to control what data we use to personalize the ads we show you on our Services.' This language is no longer present in the updated version. The policy still lists ad personalization as an authorized use of personal data for Free and Go users, but no longer explicitly describes how users can access controls to manage this practice. You should verify whether advertising controls remain functional in your OpenAI account settings, as the policy no longer explicitly references them.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Change history

removed Jul 17, 2026

Removal of explicit disclosure about data handling during business transactions, bankruptcies, and ownership changes reduces transparency about potential data transfer scenarios.

View full change record →

Consumer impact (what this means for users)

Under this clause, personal data collected from users may be disclosed to third-party counterparties and advisors during the due diligence phase of a corporate transaction, and transferred to a successor entity as part of a completed transaction. Users would be subject to the successor entity's privacy practices following any such transfer.

Cross-platform context

See how other platforms handle Business Transfer and Transaction Disclosure and similar clauses.

Compare across platforms →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow OpenAI → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a "Transaction"), your Personal Data may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.

Excerpt from OpenAI's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Business transfer provisions engage FTC guidance on privacy policy compliance during corporate transactions, which requires that successor entities honor the original privacy commitments or provide users with notice and choice. CCPA requires notification to California residents when personal information is transferred in a business transaction. GDPR (for EEA users) imposes requirements on transfers of personal data in the context of business transactions, addressed through the separate regional policy. 2) GOVERNANCE EXPOSURE: Low. This is a standard commercial provision. The due diligence disclosure component (pre-transaction sharing with counterparties) is the element most likely to result in personal data being shared without a completed transaction completing, which may be subject to confidentiality agreements but is disclosed in the policy. 3) JURISDICTION FLAGS: California residents may have notification rights under CCPA in the event of a business transfer. The FTC has published guidance on privacy policy compliance obligations in the context of corporate transactions that applies to US-based operations. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations that rely on OpenAI services for business-critical functions should assess whether a change of control or service transition event would trigger contract review or termination rights under applicable vendor agreements. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should monitor for announced transactions and assess whether the personal data transfer would be consistent with applicable regulatory requirements, including any state-level notification obligations.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has published guidance on privacy policy compliance obligations during corporate transactions involving consumer data
    File a complaint →

Provision details

Document information
Document
OpenAI Privacy Policy
Entity
OpenAI
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-013574
Document ID
CA-D-00010
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c0c49f013e1bb2dd1fa883d161d2b79a60a5914fddbd230bcaa0df5e2cfaa86e
Analysis generated
July 9, 2026 03:28 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Privacy Policy
Record ID: CA-P-013574
Captured: 2026-07-09 03:28:49 UTC
SHA-256: c0c49f013e1bb2dd…
URL: https://conductatlas.com/platform/openai/openai-privacy-policy/provision/CA-P-013574/business-transfer-and-transaction-disclosure/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does OpenAI's Business Transfer and Transaction Disclosure clause do?

This provision is a standard commercial clause that authorizes personal data transfer as a business asset in corporate transactions. The disclosure to counterparties during due diligence is noted as occurring before any transaction is completed, which means personal data may be shared with third parties in connection with a transaction that does not ultimately close.

How does this clause affect you?

Under this clause, personal data collected from users may be disclosed to third-party counterparties and advisors during the due diligence phase of a corporate transaction, and transferred to a successor entity as part of a completed transaction. Users would be subject to the successor entity's privacy practices following any such transfer.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.