# OpenAI DPA v.010126 review worksheet

Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.

Published clause positions are paraphrased from the official PDF. Operational consequences and escalation questions apply them to a fictional ChatGPT Enterprise procurement case.

| Clause | Published position | Operational consequence | Escalation question |
| --- | --- | --- | --- |
| 1.1–1.2; Schedule 1 | Processor scope and processing details tied to the Services Agreement. | Identify the actual service, data and customer role. | Does this DPA version govern the workspace/order form? |
| 2.1; 3.3 | Contract and supported configurations form instructions; customer has configuration duties. | Record settings, task scope and a change owner. | Which settings implement our retention and deletion choices? |
| 2.3; 2.5 | Confidentiality commitments and reasonable, appropriate security measures. | Review the Agreement’s security detail. | Which measures apply to the exact service and feature? |
| 2.4; 2.6 | Qualified rights-request and reasonable compliance assistance. | Define the customer/provider handoff. | How do we request assistance and track completion? |
| 2.7 | Breach notice without undue delay after awareness. | Keep vendor notice separate from our legal deadlines. | Which contact receives notice and escalates it? |
| 2.8 | Annual limits, confidentiality, customer expense and possible report-summary substitution. | Plan evidence requests and audit needs. | Do the available reports and audit conditions meet our requirements? |
| 2.9–2.10 | General authorisation, 30-day objection process and comparable subprocessor obligations. | Monitor notices; assess alternatives and Agreement liability limits. | Who subscribes, objects and assesses any exit consequence? |
| 2.11 | Post-termination return/deletion on instruction, with legal-retention conditions. | Plan export, instruction and confirmation. | Which copies and exceptions need evidence at exit? |
| 4; Schedule 1 | EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input. | Review geography, transfer analysis and planned data categories. | Does the intended use require different terms or additional safeguards? |

## Review steps

- Match the applicable version: Retain the DPA, Services Agreement and order form; check precedence and negotiated differences.
- Resolve service and data scope: Review Schedule 1, the actual features and any planned sensitive-data use instead of treating the DPA as a universal approval.
- Assign the operational handoffs: Name owners for rights requests, breach notices, subprocessor changes, audits and exit instructions.

## Source identity

Official PDF: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf
Footer version: v.010126
Retrieved: 21 September 2026
SHA-256: 42309abe1e586665980ff45a83c813f5d6117c6f4ee0cf28f6cecb56c8426393

The footer is a version identifier. This worksheet does not infer the web page’s publication or update date.

## Illustrative review scope

Candidate: ChatGPT Enterprise workspace for customer-support wording.
Data approach: reduced context, with unnecessary customer details omitted.
Customer agreement: not represented by the exercise.
Decision owner: to be established by the real organisation.

Clause positions above describe the public PDF, not a legal opinion that it satisfies every obligation or authorises PHI. Review the applicable Agreement, Order Form, service eligibility and actual customer configuration.

## Source and scope

Guide: https://aona.ai/resources/guides/chatgpt-dpa-review-checklist/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- EU GDPR: Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- OpenAI Data Processing Addendum, v.010126: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf
- OpenAI: ChatGPT Work Cloud data handling and retention: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security#data-handling-and-retention
