1. What the document is: A privacy and trust FAQ for OpenAI's business-tier products (ChatGPT Business, Enterprise, Edu, Teachers, Healthcare, and the API Platform) — separate from the consumer ChatGPT Privacy Policy. It covers data ownership, training opt-outs, retention controls, compliance certifications (SOC 2, HIPAA, GDPR), and fine-tuning.
What this wiki found — complete, every page
Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.
ChatGPT – Business Privacy Policy
Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present
GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive
genai-euproject across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.
Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:
Source: sources/GenGA/ChatGPT/Business Privacy Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source)
Last updated: 2026-01-08
Note on methodology: No pre-computed
risk_score/keywordfields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (input license,output restriction,fine-tune,gdpr). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (seemethodology.md§4) — no page, GenGA included, computes or displays a numeric risk score.
Overview
1. What the document is: A privacy and trust FAQ for OpenAI’s business-tier products (ChatGPT Business, Enterprise, Edu, Teachers, Healthcare, and the API Platform) — separate from the consumer ChatGPT Privacy Policy. It covers data ownership, training opt-outs, retention controls, compliance certifications (SOC 2, HIPAA, GDPR), and fine-tuning.
2. Input rights: Business customers keep ownership and control of their business data, explicitly including “inputs and outputs,” across all listed products. By default, data from Business, Enterprise, Edu, Teachers, Healthcare, and the API is not used to train models — training only happens if the customer explicitly opts in (for example, through feedback mechanisms). This is a notably stronger input-rights position than what’s typical for consumer-tier products.
3. Output restrictions: None found. Outputs are described as something the customer “owns and controls,” not something OpenAI restricts downstream use of.
4. Non-explicit predatory clauses: The opt-in training language comes closest to a soft “improve our services” hook (“unless you have explicitly opted in to share your data with us to improve the services”) — but because it’s opt-in, not opt-out, it’s a notably less risky version of a clause type that’s usually riskier elsewhere in this wiki.
5. Regulatory references: GDPR is explicitly named (“in support of their compliance with GDPR and other privacy laws,” with a Data Processing Addendum offered), and so is HIPAA (Business Associate Agreements offered for healthcare compliance). Worth flagging because these are concrete, named-regulation commitments, not vague “we comply with applicable law” language. No EU AI Act reference found.
6. Regional variation: Not explicitly split by region, though offering a GDPR-specific DPA implies EU/EEA customers are treated as a distinct compliance audience from the HIPAA (US-specific) provisions.
7. Key risk to users: Low. This document is built almost entirely to reassure business customers. One line (“We also use data from versions of ChatGPT and other services for individuals”) implicitly confirms that the consumer tier (covered separately in ChatGPT_Privacy_Policy.md) doesn’t get the same by-default training exclusion — worth noting as context, though it isn’t a clause of this document itself.
Flagged Keywords & Risks (LLM-assigned)
input license,train AI/models— “By default, we do not train our models on your business data… unless you have explicitly opted in.” Why it matters: sets up opt-in, not opt-out, training on business data — the most user-protective input-rights framing found so far in this dataset.fine-tune— “You can adapt certain models to specific tasks by fine-tuning them with your own prompt-completion pairs… never… used to train other models.” Why it matters: confirms fine-tuned models stay siloed to the customer instead of feeding into OpenAI’s general training data.gdpr— GDPR and HIPAA compliance commitments (DPA/BAA). Why it matters: concrete regulatory references, useful for comparing regulatory disclosure across platforms.
Regulatory & Research Context
This page’s opt-in (not opt-out) training default — “we do not train our models on your business data… unless you have explicitly opted in” — is a notable departure from the pattern Pandit et al. (2026) describe across the six GenAI services they coded, where inputs and outputs were generally used “for other purposes beyond” the immediate service by default; here, OpenAI’s business tier requires affirmative customer action before that occurs. Davidson et al. (2026), who include OpenAI among the providers they studied directly, would situate the named GDPR/HIPAA compliance commitments (DPA, BAA) as a comparatively concrete regulatory hook, in contrast to the vaguer “applicable law” language their analysis flags elsewhere in the dataset.
Changes Summary
| Date | What changed |
|---|---|
| 2025-11-11 | Baseline version (first capture in this dataset). |
| 2025-11-24 | Added “ChatGPT for Teachers” as a covered product throughout (FAQ section, training-data list, GDPR/DPA section split out a separate Student Data Privacy Agreement reference for Edu/Teachers); link-formatting cosmetic changes throughout. |
| 2026-01-08 | Added “ChatGPT for Healthcare” as a covered product throughout (new HIPAA/BAA section, new Healthcare FAQ block); “connectors” renamed to “apps” throughout; training-data list updated to drop “business” qualifier (“data from…” instead of “business data from…”), broadening the no-default-training commitment to cover non-business data too. |
Version History
2025-11-11
- Explicit AI clause: YES
- Non-explicit predatory: NO
- Flagged keywords:
input license,train AI/models,fine-tune,gdpr
Clause: input license, train AI/models
Our commitments provide you with ownership and control over your business data (inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, and our API Platform) and support for your compliance needs.
Clause: fine-tune
Yes, you can adapt certain models to specific tasks by fine-tuning them with your own prompt-completion pairs. Your fine-tuned models are for your use alone and never served to or shared with other customers or used to train other models. Data submitted to fine-tune a model is retained until the customer deletes the files.
Clause: gdpr
Yes, we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, and the API in support of their compliance with GDPR and other privacy laws. Please complete our DPA form to execute a DPA with OpenAI.
Clause: train AI/models
OpenAI uses data from different places including public sources, licensed third-party data, and information created by human reviewers. We also use data from versions of ChatGPT and DALL·E for individuals. By default, business data from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.
2025-11-24
- Explicit AI clause: YES
- Non-explicit predatory: NO
- Flagged keywords:
input license,train AI/models,fine-tune,gdpr
fine-tune unchanged from 2025-11-11.
Clause: input license (wording updated — “ChatGPT for Teachers” added to the covered-products list)
Our commitments provide you with ownership and control over your business data (inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, ChatGPT for Teachers and our API Platform) and support for your compliance needs.
Clause: gdpr (wording updated — Edu/Teachers split out to a separate Student Data Privacy Agreement)
Yes, we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, and the API in support of their compliance with GDPR and other privacy laws. Please complete our DPA form to execute a DPA with OpenAI. For ChatGPT Edu and for Teachers, we process your data pursuant to our Student Data Privacy Agreement.
Clause: train AI/models (wording updated — “ChatGPT for Teachers” added)
OpenAI uses data from different places including public sources, licensed third-party data, and information created by human reviewers. We also use data from versions of ChatGPT and other services for individuals. By default, business data from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.
2026-01-08
- Explicit AI clause: YES
- Non-explicit predatory: NO
- Flagged keywords:
input license,train AI/models,fine-tune,gdpr
fine-tune, gdpr unchanged from 2025-11-24.
Clause: input license (wording updated — “ChatGPT for Healthcare” added to the covered-products list)
Our commitments provide you with ownership and control over your business data (inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers and our API Platform) and support for your compliance needs.
Clause: train AI/models (wording updated — “business” qualifier dropped, broadening scope; “ChatGPT for Healthcare” added)
OpenAI uses data from different places including public sources, licensed third-party data, and information created by human reviewers. We also use data from versions of ChatGPT and other services for individuals. By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.