← All pages

1. What the document is: OpenAI's GDPR-style Data Processing Addendum (DPA) for API and ChatGPT Enterprise business customers — a standard processor/controller contract, not a license or AI-training document.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

Independent reviews, where they had something to say

ChatGPT – Data Processor Agreement

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/ChatGPT/Data Processor Agreement/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2025-12-01

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: OpenAI’s GDPR-style Data Processing Addendum (DPA) for API and ChatGPT Enterprise business customers — a standard processor/controller contract, not a license or AI-training document.

2. Input rights: Out of scope for this document type. It governs OpenAI’s role as Data Processor, acting on the instructions of the Customer (the Data Controller) — not content licensing.

3. Output restrictions: None — not applicable to a DPA.

4. Non-explicit predatory clauses: None found. The document is built around limiting OpenAI’s processing to the Customer’s instructions, sub-processor transparency (with a 30-day objection window), and breach notification.

5. Regulatory references: Extensive and explicit. Defines “GDPR” verbatim (“Regulation (EU) 2016/679”), names Standard Contractual Clauses (SCCs), the UK Addendum (under the UK Data Protection Act 2018), and the US CCPA, with dedicated sections on international data transfers and US privacy law. The most regulation-dense document in this dataset so far. No EU AI Act reference.

6. Regional variation: Yes, explicitly. The contracting entity and applicable safeguards differ by region: EEA/Swiss Data (OpenAI Ireland Ltd., SCCs or adequacy decisions), UK Data (OpenAI’s US entity, SCCs plus the UK Addendum), and US Data (CCPA-specific obligations in §5).

7. Key risk to users: Low — this is a protective, compliance-oriented contract for business customers, not a consumer-facing or AI-training document. The main thing worth tracking is §2.9’s sub-processor list, which lets OpenAI add sub-processors without the Customer’s affirmative consent — just notice plus a 30-day objection window.

Flagged Keywords & Risks (LLM-assigned)

Regulatory & Research Context

Davidson et al. (2026), who include OpenAI among the providers they studied, note that Terms can “override their legal jurisdictions regardless of user location” through contracting-entity structuring; this DPA’s EEA/Swiss-vs-UK-vs-US entity split (OpenAI Ireland Ltd. for EEA/Switzerland Data, SCCs plus UK Addendum for UK Data, CCPA-specific terms for US Data) is the kind of jurisdictional architecture their analysis examines, here made unusually explicit and regulation-dense compared to OpenAI’s consumer-facing documents. The §2.9 sub-processor notice-and-objection mechanism (30 days, no affirmative consent required) is consistent with the discretionary-control pattern Edwards et al. (2025) associate with the “platformisation paradigm,” in which providers retain operational latitude while presenting compliance-oriented terms to business customers.


Changes Summary

DateWhat changed
2025-11-11Baseline version (first capture in this dataset; “Updated: February 15, 2024,” titled “Data processing addendum”).
2025-12-01Substantial redraft: retitled “OpenAI Data Processing Addendum,” restructured from a single long-form contract into the current Details/OpenAI Obligations/Customer Obligations/International Transfers/Further Requirements/Definitions/Schedule 1 structure; added explicit UK Addendum and US Privacy Laws (CCPA) sections not present in the 2025-11-11 version; contracting entity renamed “OpenAI, LLC” → “OpenAI OpCo, LLC.” Core Processor obligations (process only on instruction, confidentiality, breach notice, sub-processor transparency, audit rights) are substantively preserved, just reorganized and extended with US-specific terms.

Version History

2025-11-11

Clause: gdpr

In connection with the Agreement, Customer is the person that determines the purposes and means for which Customer Data (as defined below) is processed (a “Data Controller”), whereas OpenAI processes Customer Data in accordance with the Data Controller’s instructions and on behalf of the Data Controller (as a “Data Processor”). “Data Controller” and “Data Processor” also mean the equivalent concepts under Data Protection Laws. For the purposes of the Agreement and this DPA, (i) “Personal Data” has the meaning assigned to the term “personal data” or “personal information” under applicable Data Protection Laws; and (ii) “Customer Data” means Personal Data that Customer provides to OpenAI that OpenAI processes on behalf of Customer to provide the Services. OpenAI will process Customer Data as Customer’s Data Processor to provide or maintain the Services and for the purposes set forth in this DPA, the Agreement and/or in any other applicable agreements between Customer and OpenAI.


2025-12-01

Clause: gdpr (wording updated — redrafted into the new Details/Obligations structure, with UK Addendum and CCPA provisions added)

1.1 Scope and Roles. As part of providing the Services to the Customer under the Agreement, OpenAI may Process Customer Data on behalf of Customer. OpenAI acts as a Data Processor on the Customer’s behalf, and this DPA governs such Processing. […] “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. […] 4.1 EEA and Swiss Data. […] Customer hereby instructs OpenAI Ireland Limited to process any EEA and Swiss Data in compliance with this DPA. […] it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.