CompanyScope
by Janus Compliance

General-purpose AI / LLM API

OpenAI compliance: GDPR, AI Act, DPA, training, transfers

Independent compliance research from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-06-25. Not legal advice.

Share this OpenAI profile:Share on XBluesky

TL;DR. API and ChatGPT business products: contractually no training by default since 2023-03-01. ChatGPT Plus consumer: trains on conversations unless the user opts out — the dominant unmanaged risk for any organisation with knowledge workers. Default API processing is not EU-resident; enterprise EU residency is configurable but not on by default. ZDR is approval-gated through sales. ISO 42001 certified — the strongest AI Act audit signal in the LLM market.

DPO action: map staff use of consumer ChatGPT, configure EU residency for any EU-subject processing, apply for ZDR if data sensitivity warrants, and sign a BAA before any PHI (available on the API, ChatGPT Enterprise, and ChatGPT for Healthcare).

What the tool does

OpenAI runs ChatGPT (consumer and business products) and the API behind it. Most enterprise buyers will be looking at one of three things: the API (for building your own apps), ChatGPT Team / Business / Enterprise (for staff use), or ChatGPT Edu (for education). The terms, training defaults, and data residency story are different for each — do not assume an answer for one applies to the other.

Data processed

You will typically pass through some or all of:

Special-category likelihood: High if your use case touches health, legal, HR, or any sector where staff might paste sensitive content. Article 9 (UK GDPR) processing is a real risk and most buyers underestimate how often it happens in practice. A DPIA is rarely optional.

Default geographic processing: Multi-region; primarily US infrastructure. EU residency is available on enterprise tiers but is not the default — it must be configured.

DPA availability

OpenAI publishes a Data Processing Addendum that customers can sign through their account portal.

If a buyer is using ChatGPT free/Plus consumer tier, the consumer terms apply, which are not equivalent to a DPA — this is an extremely common mistake in SME deployments.

Subprocessor list

OpenAI publishes a subprocessor list at https://openai.com/policies/sub-processor-list/. Last updated 2026-02-11. Notable subprocessors:

The Microsoft / Azure dependency is significant: OpenAI's processing inherits Azure's regional commitments, which means EU buyers should pay attention to which Azure regions OpenAI's enterprise tier supports. Do not assume EU residency without confirming with OpenAI sales.

Training-on-customer-data position

API and business products: not used for training by default. OpenAI states (verbatim from openai.com/business-data/):

"By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform — including inputs or outputs — for training or improving our models."

This default has applied to API customers since 2023-03-01.

Consumer ChatGPT (free / Plus): conversations may be used to improve models unless the user opts out via settings. Most enterprises have staff using ChatGPT Plus on personal accounts — assume this is happening unless you've actively prevented it.

Default abuse monitoring retention: 30 days for API content, even when not used for training. Eligible enterprise customers can apply for Zero Data Retention (ZDR) via the OpenAI sales team, which removes the abuse-monitoring retention. ZDR is opt-in and approval-gated, not automatic.

The training-by-default-no story is solid for paid API/business tiers, but the 30-day abuse-monitoring retention catches buyers off guard. Plan for it explicitly in your DPIA. — My read

EU / UK transfer position

OpenAI relies on Standard Contractual Clauses (SCCs) for EU transfers, supplemented by the UK International Data Transfer Addendum for UK transfers. OpenAI is certified under the EU-US Data Privacy Framework (listed Active, re-confirmed June 2026; the framework survived its EU General Court challenge in September 2025 with a CJEU appeal still pending, so the SCCs in the DPA remain the fallback).

EU residency option: enterprise tier offers EU data residency for ChatGPT Enterprise; API EU residency is also available but requires configuration. Default API processing is not EU-resident — this is the most-missed compliance fact in our market.

Security documentation

OpenAI's trust center at trust.openai.com lists:

The ISO 42001 certification is unusual at this scale and a strong signal for AI Act audit defensibility.

HIPAA & BAA position

US healthcare buyers ask this first, so to be direct: OpenAI will sign a HIPAA Business Associate Agreement (BAA), and it covers more surfaces than buyers expect.

Azure OpenAI is the other route US healthcare buyers take. The same OpenAI models run on Microsoft Azure as a HIPAA-eligible service, and Microsoft's BAA is included by default through the Microsoft Online Services Data Processing Addendum for eligible agreements (Enterprise Agreement or CSP), with no separate BAA to sign. Text inputs are covered; image and audio modalities can need explicit inclusion, so confirm scope for any multimodal use.

The BAA is the contractual piece. HIPAA's Security Rule (risk analysis, minimum-necessary, workforce training, audit controls, breach notification) still falls on the covered entity. See HIPAA for AI tools for the full BAA-and-Security-Rule walkthrough across vendors.

AI Act role + risk classification

OpenAI publishes an AI Act readiness position, but it does not relieve your deployer obligations.

DPIA prompts (for your use case)

Answer these before deploying OpenAI in production:

  1. Are users likely to enter Article 9 special-category data (health, biometric, criminal, religion, etc.) into the prompt? If yes, your lawful basis and safeguards must cover that — UI controls and staff training matter.
  2. Are you using the API or a consumer ChatGPT account? If staff are using personal ChatGPT Plus, conversations may be retained and used for training. Your data governance must address shadow AI use.
  3. Is your use case in AI Act Annex III (recruitment, credit, education, law enforcement, migration, justice, critical infrastructure)? If yes, you are a deployer of a high-risk system regardless of the underlying model. Conformity assessment, fundamental rights impact assessment, registration in the EU AI database — all apply.
  4. Have you configured EU residency if you have EU subjects? Default API is not EU-resident.
  5. Have you applied for Zero Data Retention if your data sensitivity warrants it? The 30-day default abuse-monitoring window is a real retention period.

Unresolved questions / red flags

Related profiles

Sources checked

Related reading

<!-- Phase C residual items resolved (browser agent run 2026-05-02). Subprocessor URL corrected (was /subprocessor-list/, now /sub-processor-list/). Training-defaults sentence quoted verbatim from openai.com/business-data/. ISO 42001 confirmed on trust.openai.com (Schellman-issued). 2026-06-25 targeted update (demand-backed, not a full re-review): added the HIPAA & BAA section (API BAA without an enterprise agreement, ChatGPT Enterprise, ChatGPT for Healthcare Jan 2026, Azure OpenAI via Microsoft Online Services DPA; facts verified June 2026); DPF line refreshed to current status (Active; EU General Court dismissal Sep 2025; CJEU appeal pending); DPO-action line gained a BAA pointer. Other facts carried from the 2026-04-29 review. -->
Share this OpenAI profile:Share on XBluesky

Talk to Michael about OpenAI — or your AI vendor governance more broadly

CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.

A sentence or two is plenty.

Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe — free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

For ongoing AI compliance support, work with Janus DPO-as-a-Service. For other vendors, browse the full index, or see real agent failures analysed legally in the AI Agent Incident Register.