Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →●
Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →●
Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →●
Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →●
GenAI Practice
OpenAI data privacy. The nine clauses that matter.
OpenAI gives stronger privacy defaults than most vendors. The risk is everything the defaults do not cover. Nine clauses close the gap.
OpenAI will not train on your enterprise data by default, but retention, subprocessors, audit rights, and exit deletion are only as strong as the clauses you sign.
Key takeaways
OpenAI does not train on ChatGPT Enterprise, Team, or API data by default; restate that default as an order form term so it survives policy edits.
The standard API retention window is 30 days for abuse monitoring; zero data retention is available by use case approval.
The DPA must be executed, not referenced. Roughly 1 in 4 enterprise buyers we reviewed had never signed it.
Ask for 30 day subprocessor notice, 72 hour breach notice, and certified deletion on exit.
Anchor every redline to a published OpenAI commitment; those clear legal fastest.
Below roughly 250 thousand dollars a year, expect the standard DPA; the leverage is in the order form, not the DPA text.
Try Vera AI · free trial
Do not send the counter until Vera has read the deal.
Percentile standing for your exact deal size and industry, from real closed transactions
Scenario simulation before the call: test alternative terms and see the financial impact of each
A negotiation playbook, talking points, and a two page executive brief on day one
What does OpenAI do with enterprise data by default?
OpenAI does not train its models on ChatGPT Enterprise, ChatGPT Team, or API data by default, and that commitment sits in the published enterprise privacy commitments. The default position is stronger than most procurement teams assume.
The gap is everything the defaults do not cover. Retention windows, subprocessor changes, breach notice timing, and audit rights are all set by the contract documents, not the marketing page.
Business terms. The OpenAI business terms govern API and enterprise use. Read the data ownership and indemnity sections first.
DPA. The Data Processing Addendum carries the GDPR and CCPA processor commitments. It must be executed, not just referenced.
Trust portal. SOC 2 reports and subprocessor lists live on the OpenAI trust portal. Pull them before signature, not after.
The three documents that actually govern
The business terms set ownership and liability, the DPA sets processor obligations, and the trust portal evidences the controls. A privacy review that reads only one of the three is incomplete.
What the defaults leave open
Retention length, subprocessor changes, breach notice timing, residency, and exit deletion are contract variables. Each defaults to provider discretion unless your order form says otherwise.
Which nine clauses should the agreement carry?
Nine clauses separate a defensible OpenAI agreement from a signed marketing page: training exclusion, retention, zero data retention eligibility, subprocessor notice, breach notice, audit rights, data residency, deletion on exit, and indemnity scope. Each one has a concrete buyer position.
Clauses one to five: data handling
Training exclusion in the order form. Restate the no training default as a contract term so it survives policy edits.
Retention window. Name the 30 day abuse monitoring window and require written notice if it changes.
Zero data retention. If your workload qualifies, get ZDR approval in writing and reference it in the agreement.
Subprocessor notice. 30 days advance notice of new subprocessors, with a right to object.
Breach notice. 72 hours to match GDPR Article 33, not the vaguer commercially reasonable standard.
Clauses six to nine: control and exit
Audit rights. Annual SOC 2 Type 2 delivery plus a written security questionnaire right.
Data residency. If you need EU processing, name the region. Silence means provider discretion.
Deletion on exit. Certified deletion within 30 days of termination, including backups on a defined cycle.
Indemnity scope. Copyright indemnity for output exists in OpenAI paper. Confirm it covers your usage tier and is not voided by your own fine tuning data.
OpenAI data commitments by channel, 2026
Channel
Trains on your data
Default retention
ZDR available
ChatGPT Free and Plus
Yes unless opted out
Provider discretion
No
ChatGPT Team
No
Workspace controlled
No
ChatGPT Enterprise
No
Admin controlled
No
API standard
No
30 days abuse monitoring
By approval
API with ZDR
No
None at rest
Yes
How do you negotiate these clauses without stalling the deal?
Anchor every ask to something OpenAI has already published, because the fastest redlines are the ones the vendor has conceded elsewhere. The enterprise privacy page, the DPA, and the trust portal give you the anchor for seven of the nine clauses.
Sequence matters. Send the DPA and the security questionnaire in week one, in parallel with commercial terms. Teams that treat privacy as a closing formality lose two to four weeks at signature.
What the account team will push back on
ZDR eligibility. Granted by use case review, not by negotiation pressure. Submit the use case early.
Custom breach windows. Smaller deals get the standard DPA terms. Below roughly 250 thousand dollars a year, expect limited movement.
Audit beyond SOC 2. On site audits are reserved for the largest commitments. The report plus questionnaire route is the realistic position.
Where the common advice on OpenAI privacy terms is wrong
The standard advisory line is that OpenAI terms are non negotiable below seven figures, so buyers should sign the standard paper and move on. We disagree. In roughly 12 of the 30 OpenAI reviews Morten Andersen ran in 2024 to 2025, named retention, subprocessor notice, and deletion clauses were accepted at mid six figure spend, because the asks restated published commitments as contract terms rather than inventing new obligations. The buyer side move is to convert policy into contract. A policy page can change with a web edit; an order form term cannot. Treating the two as equivalent is the single most common GenAI procurement error we see.
Most OpenAI privacy clauses are conceded fastest when the redline quotes the published commitment it restates.
30+
OpenAI agreements reviewed 2024 to 2025
9
Privacy clauses in the buyer checklist
1 in 4
Enterprise buyers with no executed DPA
Source: Redress Compliance advisory engagement file, 2024 to 2025.
A privacy policy is a webpage. An order form clause is a promise you can enforce. Never confuse the two when the data leaving your estate is your customers own.
Negotiating a renewal? Read the paper before you counter. Upload the contract or renewal quote to Vera AI and get a clause by clause read in plain English: which terms are off market, where the money hides, and paste ready replacement language to send back. Free, no signup needed. Decode your contract free with Vera AI →
What to do next
Map every OpenAI channel in use: ChatGPT tiers, API keys, and shadow usage through third party tools.
Pull the current business terms, DPA, and SOC 2 report from the trust portal.
Execute the DPA before the next renewal or expansion order.
Submit the zero data retention use case review if your workload qualifies.
Redline the nine clauses above into the order form, anchored to published commitments.
Set a quarterly check on the enterprise privacy page for changes to defaults.
Brief the AI governance owner on retention and residency positions agreed.
No. OpenAI states it does not train models on ChatGPT Enterprise, ChatGPT Team, or API customer data by default. Restate that commitment in your order form so a future policy change cannot weaken it.
How long does OpenAI retain API data?
The standard window is up to 30 days for abuse monitoring, after which inputs and outputs are deleted. Qualifying workloads can apply for zero data retention, which removes storage at rest.
Is the OpenAI DPA negotiable?
Mostly no at typical enterprise spend. The realistic positions are executing the standard DPA, adding order form clauses for notice and deletion, and securing ZDR approval where eligible.
What audit rights can an enterprise get from OpenAI?
Annual SOC 2 Type 2 report delivery plus a written security questionnaire right is the standard achievable position. On site audit rights are reserved for the largest commitments.
Does OpenAI offer EU data residency?
Regional processing options exist for eligible enterprise customers but only apply when named in the agreement. Silence in the contract means provider discretion on processing location.
OpenAI Negotiation Guide
The full openai negotiation guide from the GenAI Practice.
Commercial levers, the nine privacy clauses, ZDR eligibility, and the redlines that pass OpenAI legal without stalling the deal.
Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.