{"id":"chatgpt-business-data-protection-file","name":"The ChatGPT Business Data Protection File","version":"1.0","vendor":"OpenAI","product":"ChatGPT Business (OpenAI’s team and small-business tier)","firstPublished":"2026-08-24","lastVerified":"2026-08-24","nextReview":"2026-09-24","slug":"chatgpt-business","vendorProfileSlug":"openai","url":"https://companyscope.io/files/chatgpt-business","jsonUrl":"https://companyscope.io/api/files/chatgpt-business","author":"Michael K. Onyekwere, CIPP/E","status":"live","license":"https://creativecommons.org/licenses/by/4.0/","license_note":"CC BY 4.0 — reuse the structured data with attribution to \"Michael K. Onyekwere, AI Vendor Data Protection Files (companyscope.io/files)\". The quotations are from the named vendor documents at their cited URLs.","retention":[{"surface":"ChatGPT Business conversations","kept":"Deleted or unsaved conversations","howLong":"Removed from OpenAI’s systems within 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm. Workspace admins can control how long data is retained.","source":{"url":"https://openai.com/enterprise-privacy/","section":"ChatGPT Business FAQ, data retention","accessed":"20 August 2026"}},{"surface":"ChatGPT Enterprise / Edu / Healthcare conversations","kept":"Deleted conversations","howLong":"Removed from OpenAI’s systems within 30 days, unless we are legally required to retain them. A narrower carve-out than the Business tier above.","source":{"url":"https://openai.com/enterprise-privacy/","section":"ChatGPT Enterprise, Edu, Healthcare FAQ, data retention","accessed":"20 August 2026"}},{"surface":"API inputs and outputs","kept":"Prompts and completions","howLong":"Retained for up to 30 days to provide the services and to identify abuse, then removed unless legally required to retain them. Zero Data Retention (ZDR) is available for eligible endpoints on request. ZDR is an API feature and is not documented for ChatGPT Business, so a buyer that needs it should look to the API tier, where it is documented.","source":{"url":"https://openai.com/enterprise-privacy/","section":"API Platform FAQ, data retention","accessed":"20 August 2026"}},{"surface":"Data submitted to fine-tune a model","kept":"Training files for a customer’s fine-tuned model","howLong":"Retained until the customer deletes it.","source":{"url":"https://openai.com/enterprise-privacy/","section":"API Platform FAQ, fine-tuning","accessed":"20 August 2026"}},{"surface":"Customer Content at contract end","kept":"Customer Content (inputs and outputs)","howLong":"Deleted from OpenAI’s systems within thirty days of termination, unless OpenAI is legally required to retain it or the customer has agreed otherwise in writing.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 11.3, effect of termination","effective":"1 January 2026","accessed":"20 August 2026"}},{"surface":"Customer Data at contract end (DPA)","kept":"Customer Data and existing copies (personal data)","howLong":"Following expiry or termination, returned or deleted at the customer’s instruction, unless retention is required under applicable laws. The DPA itself states no fixed number of days. The fixed 30-day clock is in the Business Terms above.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.11 Data Return or Deletion","effective":"1 January 2026","accessed":"20 August 2026"}}],"entries":[{"id":"governing-documents","question":"Which documents actually govern a paid ChatGPT Business subscription?","shortAnswer":"OpenAI’s Business Terms, together with the Data Processing Addendum, which the Business Terms incorporate by reference whenever the customer processes personal data, and the privacy policy that applies to the customer’s region. The concrete data-protection answers, the retention periods above all, are found in the enterprise-privacy FAQ. The Business Terms themselves do not carry them. The document at the business-terms URL titles itself the OpenAI Services Agreement.","quotes":[{"text":"If Customer uses the Services to process Personal Data, OpenAI and Customer will comply with the DPA, which is incorporated by this reference into the Agreement.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 5.3, Privacy","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"Yes, we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, and the API in support of their compliance with GDPR and other privacy laws.","source":{"url":"https://openai.com/enterprise-privacy/","section":"Data processing addendum","accessed":"20 August 2026"}},{"text":"OpenAI may update this Agreement, or OpenAI Policies, by providing Customer with reasonable notice, including by posting the update on OpenAI’s website.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 16.13, Updates","effective":"1 January 2026","accessed":"20 August 2026"}}],"commentary":["The DPA is not an optional extra a customer requests through a form. Section 5.3 of the Business Terms makes it apply by its own terms to any customer processing personal data through the Services. The FAQ line about executing a DPA is the route to a signed copy. The processor terms themselves are already switched on by the contract.","The Business Terms carry the commercial relationship but few of the concrete data-protection numbers. The retention day-counts and the sub-processor roster are published on the enterprise-privacy FAQ and a separately maintained sub-processor page, and a reader who reads only the contract will not find those. The training default is the exception: it is written into Section 4.2 of the contract, not left to the FAQ.","One accountability point on the documents themselves. Each is dated by effective date only, with a \"previous version\" link and no version number, and Section 16.13 lets OpenAI update the Agreement on notice, with at least thirty days where an update materially impacts the customer’s rights. A controller that cites a bare vendor URL in its records of processing is citing something that can move under it, so point-in-time proof depends on the customer keeping its own dated copy.","One naming point for a reader who opens the source: the document at openai.com/policies/business-terms/, effective 1 January 2026, titles itself the OpenAI Services Agreement and calls itself the Agreement throughout. This File uses the Business Terms after its URL. The section numbers cited (4.2, 5.3, 5.4, 11.3, 16.13, and the Governing Laws and Venue definitions) are the Agreement’s own."],"status":"documented"},{"id":"counterparty","question":"Who is a UK customer actually contracting with?","shortAnswer":"OpenAI OpCo, LLC, the US entity. The Business Terms route the Irish entity, OpenAI Ireland Ltd., only to customers located in the EEA or Switzerland. The United Kingdom is in neither, so for the contracting party a UK customer falls into the \"outside the EEA or Switzerland\" limb and contracts with the US company. The governing law and venue, though, group the UK back with Europe: the Laws of Ireland and the courts of Dublin.","quotes":[{"text":"“OpenAI Contracting Party” means: (a) OpenAI OpCo, LLC, for Customers located outside the EEA or Switzerland; (b) OpenAI Ireland Ltd. for Customers located in the EEA or Switzerland;","source":{"url":"https://openai.com/policies/business-terms/","section":"OpenAI Contracting Party definition","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"“Governing Laws” means: (a) for Customers in the EEA, Switzerland, or UK, the Laws of Ireland; and (b) for all other Customers, the laws of the State of California, excluding California’s conflicts of law rules or principles.","source":{"url":"https://openai.com/policies/business-terms/","section":"Definitions, Governing Laws","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"“Venue” means: (a) for Customers in the EEA, Switzerland or UK, the courts of Dublin, Ireland; and (b) for all other Customers, federal or state courts located in San Francisco County, California.","source":{"url":"https://openai.com/policies/business-terms/","section":"Definitions, Venue","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"Without prejudice to Section 15, all claims arising out of or relating to this Agreement will be brought exclusively in the Venue.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 16.3, Governing Law","effective":"1 January 2026","accessed":"20 August 2026"}}],"commentary":["This is the clearest single contrast with the Claude Team File on the counterparty question. Anthropic’s Commercial Terms group the UK with the EEA and Switzerland under its Irish entity. OpenAI’s Business Terms put the UK with everywhere else, under its US entity, for the purpose of who signs the contract.","The Business Terms then split the two questions a reader would expect to move together. The contracting party for a UK customer is the US company, while the governing law and the venue keep the UK with the EEA and Switzerland: the Laws of Ireland and the courts of Dublin. So a UK buyer contracts with the US entity, under Irish law and with venue in Dublin.","Section 15 routes claims to binding arbitration through NAM after an informal-resolution step, seated by default in San Francisco and on an individual basis only, with class actions waived. Section 16.3 then makes the Dublin-courts venue apply \"without prejudice to Section 15\", so the courts reach only the residual claims left outside arbitration. A UK buyer weighing where a dispute would actually run reads Section 15 first."],"status":"documented"},{"id":"training","question":"Is ChatGPT Business content used to train OpenAI’s models?","shortAnswer":"Not by default, and the default is contractual. The Business Terms bar OpenAI from using Customer Content to develop or improve the Services unless the customer explicitly agrees, and the enterprise-privacy FAQ restates the same opt-in in plainer terms. The prohibition is a default with a documented opt-in override, the same shape as the Claude position and, like Claude’s, written into the contract itself.","quotes":[{"text":"OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 4.2, OpenAI Obligations","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"We do not train our models on your data by default","source":{"url":"https://openai.com/enterprise-privacy/","section":"Ownership","accessed":"20 August 2026"}},{"text":"By default, we do not use your business data for training our models. If you have explicitly opted in to share your data with us (for example, through our opt-in feedback mechanisms) to improve our services, then we may use the shared data to train our models.","source":{"url":"https://openai.com/enterprise-privacy/","section":"Does OpenAI train its models on my business data?","accessed":"20 August 2026"}}],"commentary":["The override runs through the same opt-in feedback mechanism that most products carry. In practice the default stays in force until somebody inside the workspace turns sharing on."],"status":"documented"},{"id":"retention-business-carveout","question":"How long does OpenAI keep ChatGPT Business conversations?","shortAnswer":"Deleted or unsaved conversations are removed within 30 days, and admins can control the retention window. The Business tier, however, keeps a broader exception than Enterprise. OpenAI may hold data longer where it is \"reasonably necessary to protect our services or any third party from harm\", language the Enterprise answer does not carry.","quotes":[{"text":"Your workspace admins can control how long your data is retained. Any deleted or unsaved conversations are removed from our systems within 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm.","source":{"url":"https://openai.com/enterprise-privacy/","section":"ChatGPT Business FAQ, data retention","accessed":"20 August 2026"}},{"text":"Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.","source":{"url":"https://openai.com/enterprise-privacy/","section":"ChatGPT Enterprise, Edu, Healthcare FAQ, data retention","accessed":"20 August 2026"}}],"commentary":["A firm that assumes Business and Enterprise behave identically on retention would be wrong on OpenAI’s own pages. The Enterprise carve-out is bounded to a legal requirement. The Business carve-out adds retention that is \"reasonably necessary to protect our services or any third party from harm\", a broader trigger than a bare legal requirement. That harm branch states no period of its own, so content held under it has no documented deletion clock, the same open-ended carve-out the Claude File records for Anthropic.","These day-count figures for live and deleted conversations are published on the enterprise-privacy FAQ, a page OpenAI can edit without touching the contract, the same off-contract pattern the Claude File records for Anthropic. The one retention number that is contractual points the other way: Section 11.3 of the Business Terms fixes a thirty-day deletion clock for Customer Content at the end of the contract. So the contract does carry a fixed deletion deadline, though it covers content at termination. The day-to-day conversation retention is set out on the FAQ.","The two clocks cover different things. Section 11.3 speaks to \"Customer Content\", the inputs and outputs, while the DPA’s deletion clause speaks to \"Customer Data\", the personal data processed on the customer’s behalf, and states no number of its own."],"status":"documented"},{"id":"special-categories","question":"What do the documents say about special-category and sensitive data?","shortAnswer":"The DPA’s processing details record that no sensitive data is intended to be transferred unless a user includes it unexpectedly in unstructured data. The Business Terms add one narrow bar: they forbid Protected Health Information, a US concept the Agreement defines by reference to the HIPAA Privacy Rule (45 C.F.R. Section 160.103), unless a Healthcare Addendum is signed, and OpenAI runs a separate ChatGPT for Healthcare product for HIPAA-covered use. That bar does not reach UK GDPR special-category data generally. The sickness-absence, occupational-health and casework records a UK workspace routinely processes are not HIPAA PHI, so nothing in these documents bars them, and the schedule’s \"included only unexpectedly\" framing under-describes what a workspace deliberately holds.","quotes":[{"text":"No sensitive data is intended to be transferred unless the user includes it unexpectedly in unstructured data","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Schedule 1, item 5, Sensitive data transferred","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"Customer agrees not to use the Services to create, receive, maintain, transmit, or otherwise process Protected Health Information, unless it has signed the Healthcare Addendum.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 5.4, HIPAA","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"“Protected Health Information” is as defined under the HIPAA Privacy Rule (45 C.F.R. Section 160.103).","source":{"url":"https://openai.com/policies/business-terms/","section":"Definitions, Protected Health Information","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"ChatGPT for Healthcare is a secure workspace designed to support HIPAA compliance and built for healthcare organizations and their clinicians, administrators, and researchers.","source":{"url":"https://openai.com/enterprise-privacy/","section":"ChatGPT for Healthcare","accessed":"20 August 2026"}}],"commentary":["The parallel with the Anthropic Schedule 1 \"None\" finding is close, and it turns on reading the HIPAA point correctly. OpenAI’s Business Terms bar Protected Health Information, but that term is defined by the US HIPAA Privacy Rule, keyed to HIPAA covered entities and business associates, and it is much narrower than the UK GDPR category of data concerning health. So the health bar closes the HIPAA-covered route and sends that use to the separate ChatGPT for Healthcare product. It does nothing about the ordinary GDPR health data, the HR sickness records and occupational-health notes, that a UK workspace processes as routine business.","That leaves a descriptive gap, and it is the deliberate case rather than the accidental one. The DPA schedule already contemplates sensitive data the user \"includes unexpectedly in unstructured data\", so a stray mention typed into a prompt is anticipated. What the framing does not reach is routine, deliberate processing: race, religion, trade-union membership, sexual orientation, and GDPR health data that is not HIPAA PHI are carved out nowhere, and a workspace can process them on purpose, in HR, casework or monitoring. Schedule 1 is also the executed Annex for the UK Standard Contractual Clauses, so a transfer description recording that no sensitive data is intended runs alongside a customer that deliberately sends it. That is the same tension the Claude File records as unreconciled. OpenAI’s conditional \"unless unexpectedly\" softens the accidental case, not this one.","The DPA’s substantive protections are not narrowed to match, so they still apply to whatever is processed. The mismatch is descriptive, and it is easier to reconcile against a customer’s own record of processing before an incident than during one."],"status":"unreconciled"},{"id":"processor-role","question":"Is OpenAI a processor, and on what terms?","shortAnswer":"The DPA puts OpenAI in the processor role for business products, processing Customer Data only to deliver the Services. It does not itself fix the customer as controller: it names OpenAI the processor, and the SCC schedule contemplates both the customer-as-controller case (Module Two) and the customer-as-processor case where OpenAI is a sub-processor (Module Three). Measured against the Article 28(3) checklist, the required processor terms are present, each at a named section: purpose limitation (1.2), documented instructions (2.1), confidentiality (2.3), data-subject-request assistance (2.4), impact-assessment and supervisory-consultation assistance (2.6), security (2.5), breach notice (2.7), information to demonstrate compliance and audit (2.8), sub-processor flow-down (2.10), and return or deletion on termination (2.11). Three are quoted here. The rest are pinpoints to the same DPA, several quoted in their own entries below.","quotes":[{"text":"OpenAI acts as a Data Processor on the Customer’s behalf, and this DPA governs such Processing.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 1.1, Scope and Roles","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI will only Process Customer Data for the purposes of delivering the Services to Customer pursuant to the Agreement and this DPA.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 1.2, Details of Processing","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI will ensure that all persons authorized by OpenAI to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.3, Confidentiality","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI will, to the extent legally permitted, inform Customer if OpenAI receives a request to exercise data subject rights pursuant to Data Protection Laws (“Data Subject Request”) in respect of Customer Data.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.4, Data Subject Requests","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"the preparation of data protection impact assessments with respect to OpenAI’s processing of Customer Data and, where necessary, the Customer consulting with a supervisory authority","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.6, Assistance to Customer","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"Module Two (Controller to Processor) of the SCCs apply when Customer is a Data Controller and OpenAI is processing Customer Data as a Data Processor.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Schedule 1, item 8.1","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI will only use Customer Content as necessary to provide Customer with the Services, comply with applicable law, enforce the OpenAI Policies, and prevent abuse.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 4.2, OpenAI Obligations","effective":"1 January 2026","accessed":"20 August 2026"}}],"commentary":["One scope point worth reconciling, because the two contracts use different words. The DPA’s purpose limitation is narrow: OpenAI processes Customer Data, the personal data, only to deliver the Services. The Agreement’s Section 4.2 is broader for Customer Content, the inputs and outputs, and permits four uses: to provide the Services, comply with law, enforce the OpenAI Policies, and prevent abuse. The narrow DPA clause governs personal data. The broader Agreement clause is what authorises the abuse and moderation review the sub-processors and admin-controls entries describe."],"practice":"The role assignment and the assistance terms are on the page. Whether the processor performs them is a separate question, answered through the audit and security artefacts the DPA and Trust Portal provide for.","status":"documented"},{"id":"sub-processors","question":"Who else processes the data, and how are changes handled?","shortAnswer":"The customer gives a general authorisation for OpenAI to use the sub-processors on its published list. Changes are notified by blog post or in-product notice, with a window to object. The current list names cloud and infrastructure providers including Microsoft, Amazon Web Services, Google Cloud, Oracle Cloud, CoreWeave and Cloudflare.","quotes":[{"text":"Customer hereby provides a general authorization to OpenAI to engage the Sub-Processors listed in the Sub-Processor List to process Customer Data in connection with the Services.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.9 Engagement of Sub-processors","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.9 Engagement of Sub-processors","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).","source":{"url":"https://openai.com/policies/sub-processor-list/","section":"Sub-processor list, introduction","effective":"9 July 2026","accessed":"20 August 2026"}},{"text":"OpenAI shall enter into contractual arrangements with each Sub-Processor that imposes on them obligations comparable to those imposed on OpenAI under this DPA.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.10, Sub-processor obligations","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI may share samples of the flagged Customer Content with relevant Sub-processors to assist OpenAI in its review and enforcement.","source":{"url":"https://openai.com/policies/sub-processor-list/","section":"Moderation of content","effective":"9 July 2026","accessed":"20 August 2026"}}],"commentary":["The roster is maintained on a separate page and moves by notice, not by contract amendment, so a buyer who wants to track it has to watch the page or subscribe to its notifications. The objection route has some teeth: a customer can object within 30 days of the notice, OpenAI will work to address the concern and offer commercially reasonable alternatives, and where the affected Services cannot be provided without the new sub-processor either party may terminate them, with a refund of applicable pre-paid fees. Objecting is not the customer’s only protection either. Section 2.10 flows the DPA’s obligations down onto each sub-processor and keeps OpenAI liable for their acts and omissions under the Agreement.","The current list scopes each entity to the products it touches, and ChatGPT Business is named alongside Enterprise and Edu on the infrastructure rows, so the cloud providers above process Business data, not only Enterprise data.","On where the data physically goes, the location column varies by provider. Amazon Web Services and Snowflake process in the United States only; Google Cloud, Oracle and CoreWeave process across several countries including the United Kingdom; Microsoft across many; and Cloudflare routes to the data centre closest to the end user. No UK-only or EU-only residency control for ChatGPT Business is documented on the pages read.","The abuse review named in the admin-controls entry has vendors and locations behind it. Moderation of content for ChatGPT Business runs through TaskUs (Philippines) and Accenture (United States, Canada, Philippines), and OpenAI may share samples of flagged Customer Content with them. The Philippines is not a country the UK has found adequate, so content that trips a moderation flag can be a more sensitive transfer than the cloud-infrastructure rows above."],"status":"documented"},{"id":"breach-notice","question":"How quickly does OpenAI have to tell you about a breach?","shortAnswer":"Without undue delay after becoming aware of it. The DPA sets no fixed number of hours, so the commitment is to promptness rather than to a stated clock. A UK controller’s own 72-hour duty to the ICO runs from when the controller becomes aware, which depends on OpenAI’s notice arriving in time.","quotes":[{"text":"OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.7 Personal Data Breaches","effective":"1 January 2026","accessed":"20 August 2026"}}],"commentary":["Anthropic’s DPA commits to 48 hours. OpenAI’s commits to \"without undue delay\" with no number. Both are lawful drafting, though the promises differ. A customer that needs a fixed window to make its own 72-hour ICO deadline reliable gets that from Anthropic’s 48-hour clock. OpenAI’s open-ended commitment states no deadline."],"status":"documented"},{"id":"uk-representative","question":"Is a UK Article 27 representative designated?","shortAnswer":"Not established on these documents. No Article 27 representative is designated in the DPA, the Business Terms or the privacy policy. For EEA and Swiss users the DPA is entered with OpenAI’s Irish entity, which the privacy policy also names as controller, so the documents place an OpenAI establishment inside the EEA. For a UK user the privacy policy names the US entity as controller, and no UK representative is designated in any document read for this File. OpenAI does have a UK company, which raises the establishment question without settling it.","quotes":[{"text":"If you live anywhere else, OpenAI OpCo, LLC, with its registered office at 1455 Third Street, San Francisco, California 94158, United States, is the controller and is responsible for the processing of your Personal Data as described in this policy.","source":{"url":"https://openai.com/policies/eu-privacy-policy/","section":"Section 12, Data controller","effective":"4 June 2026","accessed":"20 August 2026"}},{"text":"OpenAI UK Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United Kingdom","source":{"url":"https://openai.com/policies/sub-processor-list/","section":"OpenAI entities","effective":"9 July 2026","accessed":"20 August 2026"}},{"text":"This Privacy Policy does not apply to content that we process on behalf of customers of our business offerings, such as our API.","source":{"url":"https://openai.com/policies/eu-privacy-policy/","section":"Scope","effective":"4 June 2026","accessed":"20 August 2026"}}],"commentary":["UK GDPR Article 27 requires a controller or processor established outside the UK that offers goods or services to UK data subjects to designate a UK representative in writing, unless a narrow exemption applies. The documents read for this File designate none. This File records that silence. Whether an exemption is relied on, or a representative is named somewhere not read here, is not established on these documents.","Two things complicate the picture, and both cut against reading it as a bare non-compliance. The sub-processor list names OpenAI UK Ltd. as a UK company supporting ChatGPT Business. Whether a support affiliate gives the group an establishment in the UK that takes Article 27 out of play is a real question these documents do not answer, and the Claude File leaves the identical question open for Anthropic Limited. And the privacy policy that names the US controller states on its face that it does not apply to business-offering customer content. For ChatGPT Business OpenAI’s role toward Customer Data is processor rather than controller, so that US-controller line speaks to OpenAI’s own account-holder data more than to the Business relationship. So these documents leave the Article 27 position open rather than settling it either way."],"status":"not-established"},{"id":"transfers","question":"How are international transfers handled, and who processes UK data?","shortAnswer":"Through the EU Standard Contractual Clauses, with Module Two applying where the customer is a controller and Module Three where the customer is itself a processor. For UK data the DPA goes further: whoever the contracting party is, the customer instructs OpenAI OpCo, LLC, the US entity, to process UK data on the SCCs as amended by the UK Addendum.","quotes":[{"text":"Regardless of the OpenAI applicable contracting Party under this DPA, Customer hereby instructs OpenAI OpCo, LLC to process any UK Data in compliance with this DPA and with the SCCs as amended by the UK Addendum, which are deemed entered into (and incorporated into this DPA by this reference) and completed as described in Schedule 1.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 4.2, International Data Transfers, UK Data","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"Module Two (Controller to Processor) of the SCCs apply when Customer is a Data Controller and OpenAI is processing Customer Data as a Data Processor.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Schedule 1, item 8.1","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"In Clause 17 (Option 1), the SCCs will be governed by the laws of England and Wales; (vi) In Clause 18(b), disputes will be resolved before the courts of England and Wales","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Schedule 1, item 8.2, UK Addendum","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI will, to the extent legally permitted, inform Customer if OpenAI receives a legally binding request for disclosure of Customer Data by a law enforcement authority.","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.2, Notices to Customer","effective":"1 January 2026","accessed":"20 August 2026"}}],"commentary":["The UK transfer runs on a recognised mechanism, the SCCs plus the ICO’s UK Addendum, and the UK Addendum here is governed by the laws of England and Wales with disputes before the E&W courts. That makes three governing laws across the documents: California for customers outside the EEA, Switzerland and UK; Irish law for the UK Agreement; and E&W law for the UK Addendum. The mechanism is only part of the job, though. As exporter the customer still owes its own documented assessment that the safeguard gives adequate protection for the particular data it sends, and these documents do not supply that.","Because UK data is processed in the US, lawful-access exposure is the input that assessment turns on. The DPA speaks to it once: OpenAI will tell the customer of a law-enforcement disclosure request where legally permitted. That is a partial mitigation only, since the same \"to the extent legally permitted\" qualifier means a gag order can bar the notice.","What the UK-data clause makes explicit is the counterparty point from earlier. UK data is processed by the US entity, OpenAI OpCo, LLC, regardless of who the customer contracted with. For a UK buyer the Irish establishment is not a link in the chain between them and the US company on their own data."],"status":"documented"},{"id":"security-certification","question":"What security assurance does ChatGPT Business carry?","shortAnswer":"A SOC 2 Type 2 audit, plus AES-256 encryption at rest and TLS 1.2+ in transit. SOC 2 Type 2 tests whether the controls actually operated over a period, the more demanding of the two SOC 2 forms. The Business Terms give the customer a contractual right to a copy of the report, once a year on written request, and the DPA adds a once-a-year right to the policies and information needed to demonstrate compliance.","quotes":[{"text":"ChatGPT Business successfully completed a SOC 2 Type 2 audit.","source":{"url":"https://openai.com/enterprise-privacy/","section":"ChatGPT Business FAQ, compliance standards","accessed":"20 August 2026"}},{"text":"OpenAI encrypts all data at rest (AES-256) and in transit between our customers and us and between us and our service providers (TLS 1.2+)","source":{"url":"https://openai.com/enterprise-privacy/","section":"Security","accessed":"20 August 2026"}},{"text":"Upon Customer’s written request, but no more than once per year, OpenAI will provide Customer a copy of the most recent Audit Reports","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 5.2, Audit Reports","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"no more than once per year, provide Customer with OpenAI’s privacy and security policies and other such information necessary to demonstrate compliance with OpenAI’s obligations under this DPA","source":{"url":"https://openai.com/policies/data-processing-addendum/","section":"Section 2.8, Assessing Compliance","effective":"1 January 2026","accessed":"20 August 2026"}},{"text":"OpenAI may periodically update the Security Measures.","source":{"url":"https://openai.com/policies/business-terms/","section":"Section 5.1, Security Measures","effective":"1 January 2026","accessed":"20 August 2026"}}],"commentary":["A SOC 2 Type 2 report is evidence of an audited control environment, not of GDPR compliance, and the report is held behind OpenAI’s Security Portal, away from the public documents. Obtaining it is a contractual right: Business Terms 5.2 entitles the customer to a copy of the most recent Audit Reports once a year on written request, and DPA 2.8 adds a once-a-year right to the information needed to demonstrate compliance. Section 2.8 also carries an audit-or-inspection right exercisable by or for the customer, at the customer’s sole expense, minimally disruptive, no more than once a year, with OpenAI able to make available a summary of the Audit Reports instead. Each is capped at annual and falls on the customer to invoke. A buyer that needs the assurance should exercise the right and read the scope and any exceptions before relying on the one-line claim.","The security baseline itself is off-contract and movable. The Security Measures are a separate document OpenAI may update, and the Agreement lets the customer terminate only where a change materially diminishes the security features of the Services taken as a whole. That is the same off-contract-mutability pattern the retention answer shows, applied to the security controls."],"status":"documented"},{"id":"admin-controls","question":"What can a workspace admin control, and who can see the conversations?","shortAnswer":"An admin controls the retention window and which connected apps are enabled, and can view, access, export and delete any member’s conversations in the workspace. On top of that, OpenAI’s own access to Business conversations extends to authorised employees and to specialised third-party contractors reviewing for abuse. The retention control is the one to set deliberately: the admin sets how long conversations are kept. The 30-day figure is separate. It is the default removal window once a conversation is deleted, subject to the same law and \"reasonably necessary to protect our services or any third party from harm\" carve-outs the retention entry above sets out.","quotes":[{"text":"Your workspace admins can control how long your data is retained.","source":{"url":"https://openai.com/enterprise-privacy/","section":"ChatGPT Business FAQ, data retention","accessed":"20 August 2026"}},{"text":"Your workspace admins can control which apps are enabled for your workspace.","source":{"url":"https://openai.com/enterprise-privacy/","section":"Apps and connectors","accessed":"20 August 2026"}},{"text":"Workspace admins have control over workspaces and can view, access, export, and delete end user conversations in the workspace.","source":{"url":"https://openai.com/enterprise-privacy/","section":"Who can view conversations in ChatGPT Business?","accessed":"20 August 2026"}},{"text":"Our access to conversations stored on our systems is limited to (1) authorized employees that require access for engineering support, investigating potential platform abuse, and legal compliance and (2) specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse.","source":{"url":"https://openai.com/enterprise-privacy/","section":"Who can view conversations in ChatGPT Business?","accessed":"20 August 2026"}}],"practice":"Two things a firm should note before putting confidential or client material through a shared workspace. A workspace admin can read any member’s conversations directly, where on the Enterprise tier the equivalent is an audit log through the Compliance API. And OpenAI’s abuse review can bring third-party contractors into contact with content, under confidentiality terms. Set the retention window on day one: left at the default, conversations persist for up to 30 days after deletion.","status":"documented"}]}