OpenAI
What OpenAI commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.
Governance and contractual terms
- Training use (default)
- Consumer ChatGPT (Free/Plus/Pro): yes, by default, via the 'Improve the model for everyone' setting. API, ChatGPT Business, Enterprise, Edu and Healthcare: no, off by default — OpenAI's Services Agreement states it will not use customer content to develop or improve its models unless the customer explicitly opts in.
- Retention
- Consumer: content kept until deleted; deleted data purged from systems within 30 days; Temporary Chats auto-delete after 30 days. Business/Enterprise/Edu/Healthcare: admin-controlled, deleted conversations purged within 30 days. API: inputs/outputs retained up to 30 days by default for abuse monitoring; Zero Data Retention (ZDR) available for eligible endpoints.
- Opt-out
- Yes, for consumer tiers — 'Improve the model for everyone' toggle in Settings > Data Controls. Applies to future conversations only, not retroactively.
- Data residency
- Yes. EEA data residency now covers in-region GPU inference as well as storage, for eligible ChatGPT Enterprise, Edu and Healthcare customers (expanded 16 Jan 2026 from a storage-only offering). API residency is sales-gated at project level, not retroactive to existing projects, and uses zero data retention for in-region requests.
- Sub-processor list
- Published at openai.com/policies/sub-processor-list/ — 24 named entities (including Microsoft, Cloudflare, CoreWeave, Oracle Cloud, AWS, GCP, Snowflake) with processing location and purpose per entry, last updated 9 July 2026. A subscription form exists for update notifications.
- DPA available
- Yes, self-serve for Business, Enterprise, API, and Edu/Healthcare (a separate Student Data Privacy Agreement variant applies to Edu/Teachers). Signed with OpenAI OpCo, LLC or OpenAI Ireland Ltd depending on customer location. Not applicable to individual consumer ChatGPT use.
- Contracting entity
- OpenAI OpCo, LLC (Delaware) — consumer terms outside the EEA/Switzerland/UK
- EU contracting entity
- OpenAI Ireland Ltd, for EEA and Switzerland residents. UK residents remain on OpenAI OpCo, LLC.
- Governing law
- Non-EEA/CH/UK consumer: California law, San Francisco courts. EEA/CH/UK consumer: law of the resident's own country. Business/API: Ireland law and Dublin courts for EEA/CH/UK customers, California law and San Francisco County courts for everyone else.
- Certifications
- SOC 2 Type II, SOC 3, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, ISO/IEC 42001:2023, PCI DSS v4.0.1
- AI Act Code of Practice
- yes
- Vulnerability disclosure
- Yes — public Bug Bounty Program via Bugcrowd, a separate Safety Bug Bounty Program, a Coordinated Vulnerability Disclosure Policy, and CVE Numbering Authority (CNA) status. Exact reward figures were not independently confirmed on OpenAI's own bounty page in this pass — see verification note.
- Documented incidents
- One confirmed incident: 20 March 2023, a Redis client library bug exposed some users' chat history titles and, for a subset of ChatGPT Plus subscribers active in a roughly nine-hour window, payment details (name, email, billing address, card type, last four digits, expiry — not full card numbers). Documented in OpenAI's own postmortem. No other incident specific to OpenAI's platform was found in primary sources during this pass.
Model inventory
Listed by the AI Act deadline each model falls under, which depends on when it was placed on the EU market rather than on its capability. No benchmark scores — why not.
| Model | API identifier | EU availability | AI Act deadline | Covered by DPA |
|---|---|---|---|---|
| GPT-5.6 Ships as three variants (Sol, Terra, Luna) under one release. | gpt-5.6 | 9 July 2026 (global GA; no separate EU date found) | 2 Aug 2026 | Yes — same OpenAI Services Agreement / DPA as the rest of the API platform |
| GPT-5 Unified system replacing the separate GPT-4-series and o-series naming. | gpt-5 | 7 August 2025 (announcement event held in Brussels) | 2 Aug 2026 | Yes |
| o3 OpenAI's own model page now states o3 is succeeded by GPT-5. | o3 | 16 April 2025 (widely reported API release) | 2 Aug 2027 | Yes |
| GPT-4o No longer a current flagship; still listed for specific audio pipeline use cases. | gpt-4o | 13 May 2024 | 2 Aug 2027 | Yes |
Who you are contracting with
For most consumer use, you’re contracting with OpenAI OpCo, LLC, a Delaware company — “These Terms form an agreement between you and OpenAI OpCo, LLC, a Delaware company” (Terms of Use, effective 1 Jan 2026). If you’re resident in the EEA or Switzerland, the counterparty switches to OpenAI Ireland Ltd; UK residents stay on OpenAI OpCo, LLC (EU Terms of Use, updated 16 Jan 2026). The API and business terms carry the same split, set out in the Services Agreement: Irish law and Dublin courts for EEA/Switzerland/UK customers, California law and San Francisco County courts for everyone else.
Training use and retention
The most important fact in this record is that consumer and business terms diverge. ChatGPT Free, Plus and Pro train on conversations by default — the opt-out is the “Improve the model for everyone” toggle, and OpenAI’s own support documentation is explicit that switching it off keeps your chats out of training while still leaving them in your visible history. Business, API, Enterprise, Edu and Healthcare customers get the opposite default: OpenAI’s enterprise privacy page states plainly that customer data isn’t used for training “unless you have explicitly opted in,” and the Services Agreement goes further — “OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use.”
Retention follows the same split. Consumer deletions are purged within 30 days; Temporary Chats auto-delete on the same schedule. API traffic is held up to 30 days by default for abuse monitoring, and Zero Data Retention is available on eligible endpoints for customers who don’t want that window at all.
Residency and sub-processors
OpenAI’s EEA data-residency offering originally covered storage only; as of 16 January 2026 it was expanded to include in-region GPU inference for eligible ChatGPT Enterprise, Edu and Healthcare customers. It’s opt-in at the project level and doesn’t apply retroactively to projects that predate the setting.
The sub-processor list is published and reasonably current (last updated 9 July 2026 at the time this was read), naming 24 entities with their processing location and purpose, and OpenAI offers an email subscription for change notifications.
Certifications
OpenAI’s own Trust Portal (built on SafeBase) lists SOC 2 Type II, SOC 3, ISO/IEC 27001:2022, 27017:2015, 27018:2019, 27701:2019, and 42001:2023 (the AI-management-system standard), plus PCI DSS v4.0.1. The ISO 27001 certificate has been publicly viewable there since 25 August 2025. As with any vendor-hosted trust portal, the underlying audit reports themselves sit behind a request-access gate — the certification claims are OpenAI’s own, not independently re-verified against the full reports in this pass.
AI Act posture
OpenAI announced its intention to sign in July 2025, then confirmed in a 31 July 2026 post that it had “contributed to and endorsed two Codes of Practice: the EU’s General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content.” That’s the strongest public-source basis for marking it a signatory here — see the verification note above on the possible copyright-chapter carve-out before treating this as unqualified. See the framework for why the distinction matters from 2 August 2026.
Model inventory notes
No model-specific DPA exists — the single OpenAI Services Agreement and its DPA cover everything served through the API, regardless of which model is called. The EU-market dates above are global GA dates; no separate, earlier-or-later EU rollout was found for any current model.
This record describes contractual and governance terms as read on the date shown, for the tier shown. Providers revise terms without notice — verify against the provider's own documentation before relying on any of it. Nothing here is legal advice.