CompanyScope
by Janus Compliance

General-purpose AI / LLM API

OpenAI compliance: GDPR, AI Act, DPA, training, transfers

Independent compliance research from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-10-04. Not legal advice.

Share this OpenAI profile:Share on XBluesky

TL;DR. API and ChatGPT business products: contractually no training by default since 2023-03-01. ChatGPT Plus consumer: trains on conversations unless the user opts out - the dominant unmanaged risk for any organisation with knowledge workers. Default API processing is not EU-resident; EU residency is available to approved customers who also hold abuse-monitoring controls, and the UK region stores data without processing it there. ZDR is approval-gated through sales. OpenAI maintains an ISO/IEC 42001:2023 AI management system.

DPO action: map staff use of consumer ChatGPT, configure EU residency for any EU-subject processing, apply for ZDR if data sensitivity warrants, and sign a BAA before any PHI (available on the API, ChatGPT Enterprise, and ChatGPT for Healthcare).

Primary-source evidence. For the ChatGPT Business plan specifically, the ChatGPT Business Data Protection File records what OpenAI's own Business Terms, DPA, enterprise-privacy FAQ and privacy policy say, every answer a dated verbatim quote, with the documented gaps flagged. This profile is the analysis; that File is the receipts.

What the tool does

OpenAI runs ChatGPT (consumer and business products) and the API behind it. Most enterprise buyers will be looking at one of three things: the API (for building your own apps), ChatGPT Team / Business / Enterprise (for staff use), or ChatGPT Edu (for education). The terms, training defaults and data residency position differ for each, so an answer for one cannot be assumed to apply to another.

Data processed

You will typically pass through some or all of:

Special-category likelihood: High if your use case touches health, legal, HR, or any sector where staff might paste sensitive content. Article 9 (UK GDPR) processing is a real risk and most buyers underestimate how often it happens in practice. A DPIA is rarely optional.

Default geographic processing: OpenAI's pages do not state where a project without data residency is processed. EU residency is not the default and has to be set up for each project, as described below.

DPA availability

OpenAI's Data Processing Addendum, updated 1 December 2025 and effective 1 January 2026, "supplements, and is incorporated into, the OpenAI Services Agreement", which covers the API and the ChatGPT business products. Section 5.3 of the Services Agreement provides that "If Customer uses the Services to process Personal Data, OpenAI and Customer will comply with the DPA, which is incorporated by this reference into the Agreement." No separate signature is needed, although the DPA page also offers a link for customers who want to execute a copy.

If a buyer is using ChatGPT free/Plus consumer tier, the consumer terms apply, which are not equivalent to a DPA - this is an extremely common mistake in SME deployments.

Subprocessor list

OpenAI publishes its subprocessor list at https://platform.openai.com/subprocessors, which is the address the DPA uses and which shows the same list as https://openai.com/policies/sub-processor-list/. It was last updated on 9 July 2026. For the API, the cloud infrastructure entries are Microsoft, CoreWeave, Oracle Cloud Infrastructure, Google Cloud Platform, Amazon Web Services and Cerebras, alongside Cloudflare, and the list also names support, data and security providers. Snowflake, Confluent and Cinder are used "Except where Zero Data Retention (ZDR) is used".

Under the DPA, OpenAI notifies changes by blog post, in the service, or by email to customers who subscribe, and a customer "may object to the use of such additional Sub-processor within 30 days of receiving notice of the change". If the objection is not resolved within 30 days, either party may terminate the affected services.

Training-on-customer-data position

API and business products: not used for training by default. OpenAI states (verbatim from openai.com/business-data/):

"By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform — including inputs or outputs — for training or improving our models."

This default has applied to API customers since 2023-03-01.

Consumer ChatGPT (free / Plus): conversations may be used to improve models unless the user opts out via settings. Most enterprises have staff using ChatGPT Plus on personal accounts - assume this is happening unless you've actively prevented it.

Default abuse monitoring retention: "By default, abuse monitoring logs are generated for all API feature usage and retained for up to 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm." Eligible customers can apply through OpenAI's sales team for Modified Abuse Monitoring or Zero Data Retention (ZDR), both of which are subject to prior approval. Each keeps customer content out of the abuse-monitoring logs, and ZDR also forces the store parameter to false. Neither stops application state from being stored on endpoints OpenAI lists as not eligible, which include Assistants, threads, vector stores, files, batches, fine-tuning, evals and conversations. Separately, "the Responses API has a 30 day Application State retention period by default", and Assistants objects that are not deleted are "retained indefinitely".

The no-training default is well established for the paid API and business tiers, although the 30-day abuse-monitoring window and the application state kept by some endpoints are retention periods that a DPIA needs to record. - My read

EU / UK transfer position

The DPA treats EEA and Swiss data differently from UK data. For EEA and Swiss data, the customer instructs OpenAI Ireland Limited to process it, and OpenAI Ireland's onward transfers outside the EEA or Switzerland run "on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR". The DPA does not enter into SCCs between the customer and OpenAI for that data, and it contains no Swiss addendum. For UK data, the customer instructs OpenAI OpCo, LLC to process it under "the SCCs as amended by the UK Addendum, which are deemed entered into", using Module Two where the customer is a controller and Module Three where it is a processor, governed by the law of England and Wales with the ICO as supervisory authority.

OpenAI holds no Data Privacy Framework certification. The official participant registry at dataprivacyframework.gov was searched again on 4 October 2026, active list and inactive list, with a control query that returned Microsoft, and returned nothing for OpenAI. The alphabetical enumeration was checked too, not only the search box (98 active and 102 inactive organisations file under O, and OpenAI is not among them). Its own privacy policy carries no mention of the framework either. Annex I of the adequacy decision would require that disclosure of a participant.

A record of processing activities that names the DPF against OpenAI is therefore inaccurate. For UK data the transfer rests on the SCCs as amended by the UK Addendum, and for EEA and Swiss data on OpenAI Ireland's onward-transfer arrangements, so a transfer impact assessment is required.

API data residency. OpenAI asks customers to contact sales to confirm eligibility, and "To use data residency with any region other than the United States, you must be approved for abuse monitoring controls, and execute a Modified Retention amendment." Residency endpoints carry a 10% uplift for eligible models released on or after 5 March 2026, and residency is set for each new project or for an individual request through the regional domain. The Europe region (EEA and Switzerland, eu.api.openai.com) offers regional storage and regional processing, whereas the United Kingdom region (gb.api.openai.com) offers regional storage only, and where a region does not support regional processing OpenAI "may also process and temporarily store Customer Content outside of the Region to deliver the services." Residency does not apply to system data such as billing information and structured output schemas, or to products offered by third parties through the service, and files and vector stores are stored in Europe without regional processing. Default API processing is not EU-resident, which is the point buyers most often miss.

Security documentation

OpenAI's security and privacy page and its product compliance status page (version 1.1, updated 4 August 2026) state:

HIPAA & BAA position

US healthcare buyers ask this first, so to be direct: OpenAI will sign a HIPAA Business Associate Agreement (BAA), and it covers more surfaces than buyers expect.

Azure OpenAI is the other route US healthcare buyers take. The same OpenAI models run on Microsoft Azure as a HIPAA-eligible service, and Microsoft's BAA is included by default through the Microsoft Online Services Data Processing Addendum for eligible agreements (Enterprise Agreement or CSP), with no separate BAA to sign. Text inputs are covered; image and audio modalities can need explicit inclusion, so confirm scope for any multimodal use.

The BAA is the contractual piece. HIPAA's Security Rule (risk analysis, minimum-necessary, workforce training, audit controls, breach notification) still falls on the covered entity. See HIPAA for AI tools for the full BAA-and-Security-Rule walkthrough across vendors.

AI Act role + risk classification

OpenAI publishes an AI Act readiness position, but it does not relieve your deployer obligations.

DPIA prompts (for your use case)

Answer these before deploying OpenAI in production:

  1. Are users likely to enter Article 9 special-category data (health, biometric, criminal, religion, etc.) into the prompt? If yes, your lawful basis and safeguards must cover that - UI controls and staff training matter.
  2. Are you using the API or a consumer ChatGPT account? If staff are using personal ChatGPT Plus, conversations may be retained and used for training. Your data governance must address shadow AI use.
  3. Is your use case in AI Act Annex III (recruitment, credit, education, law enforcement, migration, justice, critical infrastructure)? If yes, you are a deployer of a high-risk system regardless of the underlying model. Conformity assessment, fundamental rights impact assessment, registration in the EU AI database - all apply.
  4. Have you configured EU residency if you have EU subjects? Default API processing is not EU-resident, residency requires approval for abuse-monitoring controls, and the UK region does not process data in the UK.
  5. Have you applied for Zero Data Retention if your data sensitivity warrants it? The 30-day default abuse-monitoring window is a real retention period.

Unresolved questions / red flags

Related profiles

Sources checked

Related reading


Share this OpenAI profile:Share on XBluesky

Talk to Michael about OpenAI - or your AI vendor governance more broadly

CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.

A sentence or two is plenty.

Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe - free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

For ongoing AI compliance support, work with Janus DPO-as-a-Service. For other vendors, browse the full index, or see real agent failures analysed legally in the AI Agent Incident Register.