People reviewing and signing documents at a table
OpenAI Data Privacy

OpenAI enterprise data privacy terms. The nine clauses your contract needs.

What OpenAI commits to by default on training, retention and residency, which documents govern your data, and the nine clauses to negotiate into the order form.

Contact Us GenAI Advisory
500+Enterprise clients
$2B+Under advisory
PublishedMay 9, 2026UpdatedSeptember 25, 2026
ContentsKey takeawaysOpenAI data defaultsThe three governing documentsThe nine clausesChatGPT versus the APINegotiating without delayWhat our reviews showedChecking your positionWhat to do nextFAQ

OpenAI's defaults are stronger than most procurement teams assume, because business data is not used for training. The gap is everything the defaults do not cover, from retention to exit deletion, and all of it is set by contract.

Key takeaways
  • Training is excluded by default. OpenAI does not train on ChatGPT Enterprise, Business or API data unless you opt in, so there is no reason to pay extra for that assurance.
  • A policy page is not a contract term. OpenAI can change its published pages, and even its business terms on notice, so every commitment you rely on belongs in the order form.
  • Three documents govern. The business terms, the signed DPA and the trust portal evidence each cover a different part of your privacy position.
  • Retention needs a name. API content can be held for abuse monitoring unless zero data retention is approved for your use case, and that approval is decided on the use case.
  • Terms move below seven figures. Restated commitments on retention, subprocessor notice and deletion were accepted at mid six figure spend in our reviews.
  • Start privacy early. Sending the addendum and security questionnaire with the commercial terms avoids a delay at signature.

OpenAI does not train its models on ChatGPT Enterprise, ChatGPT Business or API data by default, and it says so in writing. For most privacy reviews that is the first question, and it is the easiest one to close.

The harder work is everything the default leaves open: how long content is kept, when you hear about a new subprocessor or a breach, where data is stored and what happens to it when you leave. Those points are set by the documents you sign. A policy page can change with a web edit, and an order form term cannot.

What happens to OpenAI enterprise data by default?

By default, OpenAI does not use enterprise or API data to train its models. The commitment appears in the published privacy commitments, and the business terms repeat it: OpenAI will not use customer content to develop or improve its services unless the customer explicitly agrees.

Training and retention rules differ by channel. Consumer tiers train on conversations unless the user opts out. On the API, OpenAI may keep inputs and outputs for up to 30 days for abuse monitoring, and zero data retention is available for eligible endpoints only after approval.

OpenAI data defaults by channel
ChannelTrains on your dataDefault retentionZero retention available
Consumer tiers (Free, Plus, Pro)Yes, unless opted outProvider discretionNo
ChatGPT Business (formerly Team)NoWorkspace controlledNo
ChatGPT EnterpriseNoAdmin controlled; deleted conversations removed within 30 daysNo
API, standardNoUp to 30 days for abuse monitoringBy approval
API with zero data retentionNoNone at rest on eligible endpointsYes

Zero data retention has limits that engineering teams often miss. Even with it switched on, the Assistants API, the Conversations API, vector stores, file uploads and fine tuning jobs keep what you give them until you delete it. A narrower option, Modified Abuse Monitoring, keeps your content out of the abuse logs; both need approval from OpenAI's sales team.

Why is a published policy weaker than a contract term?

OpenAI controls its own pages and can edit them. Even the business terms carry their own update clause, so the commitments you rely on belong in the order form.

  • Material changes. At least 30 days notice, and continued use after the effective date counts as acceptance.
  • Changes to comply with law. Only as much notice as OpenAI can reasonably give.
  • Your remedy. Terminate if you reject the update, which is rarely practical halfway through a rollout.

The 2025 litigation hold is the clearest recent example. A court preservation order in the New York Times copyright case required OpenAI to keep content from consumer ChatGPT, ChatGPT Team and standard API use that it would otherwise have deleted, until the obligation ended on September 26, 2025.

  • Outside the order. ChatGPT Enterprise, ChatGPT Edu and API traffic under zero data retention.
  • What decided it. The channel each customer bought and the retention terms it had signed, since no contract overrides a court.

Which OpenAI documents govern enterprise data privacy?

Three documents govern, and a privacy review that reads only one of them is incomplete. The business terms set ownership and liability, the addendum sets processor obligations, and the trust portal holds the evidence that the controls exist.

  • Business terms. The business terms govern API and enterprise use. Read data ownership and indemnity first: you keep ownership of your input, OpenAI assigns you its rights in the output, and each party's liability is capped at the fees paid in the 12 months before the event that gave rise to the liability.
  • The addendum. The DPA carries the processor commitments. It must be executed; a link in the online terms is not the same as a signed copy in your contract file.
  • Trust portal. Audit reports and subprocessor lists live on the trust portal. Pull them before signature, while what they say can still change what you sign.

What should you pull from the trust portal before signature?

Download the current SOC 2 Type 2 report and read two parts closely: the exceptions the auditor found, and the complementary user entity controls, which are the controls OpenAI expects you to run yourself. Then save a dated copy of the subprocessor list.

File both next to the signed DPA. Check the answers to your security questionnaire against the report, and every future subprocessor notice against the saved list.

Free white paper

OpenAI Negotiation Guide

The nine privacy clauses, zero data retention eligibility and the commercial terms to settle before signature.

Get the white paper →

Which nine privacy clauses should an OpenAI enterprise agreement carry?

Nine clauses separate a negotiated agreement from a signed marketing page. Each one has a concrete position you can write into a redline, and the table after the lists shows what OpenAI's own documents already say on each.

Clauses one to five: data handling

  • Training exclusion in the order form. Restate the no training default as a contract term so it survives policy edits.
  • Retention window. Name the abuse monitoring window and require written notice if it changes.
  • Zero data retention. If your workload qualifies, get approval in writing and reference it in the agreement, with the endpoints it covers.
  • Subprocessor notice. 30 days advance notice before a new subprocessor handles your data, with a right to object.
  • Breach notice. 72 hours, in place of the open "without undue delay" wording in the published addendum.

Clauses six to nine: control and exit

  • Audit rights. Annual delivery of the audit report plus a right to send a written security questionnaire.
  • Data residency. If you need regional processing, name the region. Silence means provider discretion.
  • Deletion on exit. Certified deletion within 30 days of termination, including backups on a defined cycle.
  • Indemnity scope. Confirm the output indemnity covers your usage tier and is not voided by your own fine tuning data.
What OpenAI's published documents say today on each clause
ClausePublished position
TrainingNo use of customer content to improve services without explicit agreement
RetentionUp to 30 days of API content for abuse monitoring
Zero data retentionEligible endpoints only, after approval
SubprocessorsNotice by blog post, in product or by email; 30 days to object; either party may end the affected service
BreachNotice without undue delay
AuditCompliance documents on request, at most once a year; any audit at your cost
ResidencyOffered for ChatGPT Enterprise, Edu and approved API customers
DeletionReturn or delete at your instruction, with no deadline
IndemnityExcludes claims arising from your content, combinations and modifications; sits outside the liability cap

What wording should the order form carry?

Put your specific commitments in the order form and make it the controlling document. Precedence wording does more work than any single clause, because it stops a later web edit from overriding what you negotiated.

Order form wording to request
  • Precedence. "If this Order Form conflicts with the Business Terms, the Data Processing Addendum or any policy they reference, this Order Form prevails."
  • No reduction. "No update to those documents during the term reduces the commitments in this Order Form."
  • Training. "OpenAI will not use Customer Content to develop or improve its models or services."
  • Retention change. "OpenAI will give Customer 30 days written notice before changing the retention period for Customer Content."

How do OpenAI privacy terms differ between ChatGPT and the API?

The product you buy decides which defaults apply before any negotiation starts. Spend then decides how much of the rest you can change, which the next section covers.

Which OpenAI channel are you actually buying?

  • ChatGPT Enterprise. Admins set the retention period, and data residency is offered for new workspaces.
  • ChatGPT Business. Sold on standard terms to smaller teams, with no data residency option. Use it for personal data only once the DPA is signed and you accept workspace level controls.
  • API platform. Zero data retention and Modified Abuse Monitoring need approval. Regional storage needs approval for advanced data controls and a new project, and OpenAI charges extra for it on eligible models.
  • Azure OpenAI. The same models under Microsoft's product terms and DPA, which changes the answer to every clause above. Our Azure OpenAI and direct OpenAI comparison sets the two side by side.

If you run OpenAI and Anthropic side by side, the same clause list applies to both. Our notes on negotiating with Anthropic and our GenAI licensing practice cover the differences, and episode three of the negotiation series walks through the signature stage.

How do you negotiate OpenAI privacy clauses without stalling the deal?

Tie every ask to something OpenAI has already published, because the fastest redlines are the ones the vendor has conceded elsewhere. The privacy page, the addendum and the trust portal give you a published basis for seven of the nine clauses.

Sequence matters as much as wording. Send the addendum and your security questionnaire in week one, in parallel with the commercial terms. Teams that treat privacy as a closing formality lose two to four weeks at signature.

What will the OpenAI account team push back on?

  • Zero retention eligibility. It is granted through a use case review, and negotiating pressure does not change the outcome, so submit the use case early.
  • Custom breach windows. Smaller deals get the standard terms, and below roughly $250,000 a year you should expect limited movement.
  • Audit beyond the standard report. On site audits are reserved for the largest commitments, so the report plus questionnaire route is the realistic position.

What will OpenAI say, and how should you answer?

  • "Our privacy commitments already cover training." Agree, and ask for that sentence in the order form. If it is already policy, writing it into the contract costs OpenAI nothing.
  • "We do not redline the DPA." Leave the DPA as published and put your specific terms in the order form, under a precedence clause that makes the order form win.
  • "Without undue delay is the market standard for breach notice." Article 33 of the GDPR gives you, as controller, 72 hours from awareness to notify your regulator. Open wording on the processor side makes that clock hard to plan around, so ask for a fixed number of hours.
  • "Zero data retention is a product decision." Accept that, request the review now, and write the approval into the agreement once it is granted, with the endpoints it covers.

What have we seen in recent OpenAI contract reviews?

We reviewed roughly 25 to 35 GenAI vendor contracts between 2024 and 2025. OpenAI paper was the one most often signed without a single privacy redline, more than any other vendor in that set.

Which patterns came up again and again?

  • Training defaults misread. Teams assumed API traffic trains models by default, then paid for assurances OpenAI had already given in writing.
  • Retention left unmanaged. In 60 to 70 percent of agreements, the buyer kept the standard abuse monitoring window where zero data retention was available for its use case.
  • Addendum never executed. Roughly 1 in 4 enterprise buyers had no signed DPA, despite processing personal data through the API.

The first and third patterns point in opposite directions. One is paying for protection you already have; the other is operating without protection you assumed you had.

Why we disagree that OpenAI's terms are fixed below seven figures

The usual advice is that OpenAI's terms cannot be negotiated below seven figures, so you should sign the standard paper and get on with deployment. Our files say otherwise. In roughly 12 of the 30 reviews we ran in 2024 to 2025, named retention, subprocessor notice and deletion clauses were accepted at mid six figure spend.

They were accepted because each ask restated a published commitment as a contract term instead of inventing a new obligation. A restatement adds no risk for the vendor's legal team to price, so it clears review quickly, while a new obligation goes into a queue.

Most privacy clauses are conceded fastest when the redline quotes the published commitment it restates.

Converting policy into contract is cheaper than any assurance you could buy, and we would make that change to almost every OpenAI agreement we see.

Aisle of server racks in a data center
OpenAI's residency option covers where content is stored at rest. For API projects with residency, model requests and responses are not stored at rest, so the region clause matters most for ChatGPT workspaces and stateful API features.

How do you check your current OpenAI privacy position?

Start with the documents and settings you already have. Work through this list with your security lead before any renewal or expansion talk.

  1. Find the signed DPA. You want the executed version naming your legal entity, filed with the order form.
  2. Check the API data sharing settings. Confirm in the organization settings of the API dashboard that the organization has not opted in to share inputs and outputs with OpenAI.
  3. List projects and endpoints. Flag every project that uses stateful endpoints such as assistants, vector stores or files, whatever your retention approval says.
  4. Look for written approvals. If zero data retention or Modified Abuse Monitoring was approved only in an email thread, get the approval referenced in the agreement.
  5. Review ChatGPT Enterprise retention. Check the retention setting in the admin console and who has the rights to change it.
  6. Compare subprocessor lists. Set the current list on the trust portal against the last copy in your file.

Which mistakes cost buyers the most?

  • Treating the privacy page as the contract. It explains OpenAI's intent, yet it is not a signed term and it can change.
  • Signing for one entity only. If several subsidiaries use the same OpenAI organization or workspace, the DPA has to cover each of them as a controller.
  • Choosing a region too late. ChatGPT workspaces and API projects take their region at creation, so a residency clause signed after rollout can mean moving to a new workspace or project.
  • Leaving deletion open. "Return or delete at your instruction" gives you no date to hold OpenAI to after termination.

For the commercial clauses that sit alongside these, see the seven OpenAI clauses to push back on and our guide to data governance terms in AI agreements.

What to do next

  1. Execute the DPA first. Get the processing addendum signed before anything else, because it is the gap that exposes you most once personal data runs through the API.
  2. Restate the training default. Put the no training commitment in the order form, so it survives a policy page edit.
  3. Submit the retention review early. Check whether your use case qualifies for zero data retention and file the request now, since approval depends on the use case.
  4. Name the numbers. Write the retention window, the subprocessor notice period, the breach notice hours and the deletion timeline into the contract, under a precedence clause.
  5. Start privacy in week one. Send the addendum and security questionnaire alongside the commercial terms, so privacy review runs in parallel with pricing.
  6. Keep dated copies. File the business terms, DPA and subprocessor list as signed, and compare them with each update notice. Our OpenAI contract risk review covers this if you want a second reader.

Frequently asked questions

Does OpenAI train its models on enterprise data by default?

No. ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu and API data are excluded from training unless your organization explicitly opts in. Check your API organization's data sharing settings anyway, because an opt in made there overrides the default.

If training is excluded, what is actually at risk?

Everything the default does not cover: retention length, subprocessor changes, breach notice timing, storage region and deletion after exit. Each is a contract variable that can be fixed in the order form at little cost to OpenAI.

How many enterprise buyers lacked a signed processing addendum?

Roughly 1 in 4 of the enterprise buyers in our reviews had none executed, despite processing personal data through the API. Under the GDPR, Article 28 expects a written processor contract, and a signed copy is the simplest proof one exists.

Which OpenAI documents govern enterprise data privacy?

Three: the business terms for ownership and liability, the DPA for processor obligations, and the trust portal for evidence of controls. When one conflicts with your order form, the precedence clause decides which wins.

What is the most common wasted spend in OpenAI privacy negotiations?

Buying a training assurance OpenAI already gives in its business terms. Teams that assume API traffic trains models by default spend negotiating capital on a clause they already have. Read the business terms first, then put that time into retention, notice and deletion.

How often is OpenAI data retention left unmanaged?

In 60 to 70 percent of the agreements we reviewed. Those buyers stayed on the default abuse monitoring retention of up to 30 days even though their use case qualified for zero data retention. File the eligibility review before commercial talks begin.

Are OpenAI privacy terms negotiable below seven figures?

Yes. In roughly 12 of 30 reviews, named retention, subprocessor and deletion clauses were accepted at mid six figure spend. Smaller deals have less room on breach windows and audits, but restating published defaults is almost always possible.

Why does OpenAI accept those clauses?

Because they restate published commitments as contract terms instead of creating new obligations. OpenAI's legal team is agreeing to substance it already offers, and quoting the published sentence in the redline shortens their review.

What will the OpenAI account team resist?

Zero data retention outside a use case review, custom breach windows on smaller deals, and audit rights beyond the standard report. Trade on those three late, and settle everything else in the first weeks.

Why is OpenAI's published privacy page not enough?

Because a web page can be edited and a signed order form term cannot. Treating the two as equivalent is the most common GenAI procurement error we see, and the 2025 preservation order showed retention can change while the policy text stays the same.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the OpenAI negotiation guide.

Commercial terms, the nine privacy clauses, zero data retention eligibility and the redlines that pass OpenAI legal review without stalling the deal.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

AI platform licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.