OpenRouter · OpenRouter Privacy Policy · View original document ↗

EEA and UK User Rights Under GDPR

Medium severity Medium confidence Explicitdocumentlanguage Rare · 2 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for OpenRouter Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Users in the EU, EEA, and UK have rights under GDPR and UK GDPR to access, correct, delete, restrict processing of, and obtain a portable copy of their personal data held by OpenRouter.

This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy acknowledges GDPR and UK GDPR rights for EEA and UK users but does not specify the lawful basis for processing under GDPR Article 6, which may be material for users or regulators assessing the adequacy of OpenRouter's data processing compliance.

Interpretive note: The policy does not specify the GDPR lawful basis for processing or international data transfer mechanisms, creating uncertainty about the completeness of GDPR compliance as disclosed.

Consumer impact (what this means for users)

EEA and UK users can contact OpenRouter to exercise data subject rights including access, rectification, erasure, and portability, and the policy states users may lodge complaints with their local data protection authority if they believe their rights have been violated.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EEA and UK users can email privacy@openrouter.ai to submit a GDPR data subject access, rectification, erasure, or portability request. Identify your account and specify the right you are exercising. If OpenRouter does not respond within one month, you may lodge a complaint with your national data protection authority.

Cross-platform context

See how other platforms handle EEA and UK User Rights Under GDPR and similar clauses.

Compare across platforms →

Monitoring

OpenRouter has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Economic Area or the United Kingdom, you have certain rights under applicable data protection law. These may include the right to (i) request access and obtain a copy of your personal data, (ii) request rectification or erasure; (iii) object to or restrict processing of your personal data; and (iv) portability of your personal data.

— Excerpt from OpenRouter's OpenRouter Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR (Regulation 2016/679) and UK GDPR, enforced by national data protection authorities within the EEA and by the UK Information Commissioner's Office respectively. The policy does not identify OpenRouter's GDPR lawful basis for processing, its EU or UK representative, or its approach to international data transfers, which are standard disclosure elements under GDPR Articles 13 and 14. 2. GOVERNANCE EXPOSURE: High for EU and UK deployments. The absence of disclosed lawful bases, transfer mechanisms, and a named EU or UK representative creates potential compliance gaps under GDPR transparency requirements. Organizations subject to GDPR that use OpenRouter as a processor or sub-processor should request a Data Processing Agreement before deploying the service with EEA user data. 3. JURISDICTION FLAGS: All EEA member states and the UK are directly affected. Organizations headquartered or operating in Germany, France, or the Netherlands, which have active data protection enforcement environments, face heightened exposure. The policy does not specify whether OpenRouter has a lead supervisory authority within the EEA. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams in EU and UK organizations should request confirmation of Standard Contractual Clauses or an equivalent transfer mechanism for any personal data transferred to OpenRouter's US infrastructure. The absence of transfer mechanism disclosure in the published policy is a gap that should be addressed prior to onboarding. 5. COMPLIANCE CONSIDERATIONS: Legal teams should request OpenRouter's Records of Processing Activities, its Article 30 records, and any DPA template before executing enterprise agreements. A data protection impact assessment may be warranted for high-volume or sensitive-data API deployments. Users can exercise GDPR rights by contacting privacy@openrouter.ai and may escalate to their national DPA if requests are not fulfilled.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Provision details

Document information
Document
OpenRouter Privacy Policy
Entity
OpenRouter
Document last updated
May 12, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-011901
Document ID
CA-D-00811
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
91717e659c28fa47150e1b31feba15f57c09644be2eb5595585f6bac16821776
Analysis generated
May 12, 2026 16:05 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenRouter
Document: OpenRouter Privacy Policy
Record ID: CA-P-011901
Captured: 2026-05-12 16:05:01 UTC
SHA-256: 91717e659c28fa47…
URL: https://conductatlas.com/platform/openrouter/openrouter-privacy-policy/eea-and-uk-user-rights-under-gdpr/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenRouter's EEA and UK User Rights Under GDPR clause do?

The policy acknowledges GDPR and UK GDPR rights for EEA and UK users but does not specify the lawful basis for processing under GDPR Article 6, which may be material for users or regulators assessing the adequacy of OpenRouter's data processing compliance.

How does this clause affect you?

EEA and UK users can contact OpenRouter to exercise data subject rights including access, rectification, erasure, and portability, and the policy states users may lodge complaints with their local data protection authority if they believe their rights have been violated.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 2 platforms. See the full comparison.

Is ConductAtlas affiliated with OpenRouter?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.