# OpenAI DPA v.010126 review worksheet

Published clause positions are paraphrased from the official PDF. Operational consequences and escalation questions apply them to a fictional ChatGPT Enterprise procurement case.

Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.

Source: https://aona.ai/resources/guides/chatgpt-dpa-review-checklist/
Sources checked: 2026-09-21

## From clause to action

### 2.1 + 3.3

Instructions and configuration

Note: Record the settings and their owner.

### 2.9

Subprocessor notice and objection

Note: Track the 30-day objection window.

### 2.11

Return or deletion at exit

Note: Keep the instruction and evidence.

| Clause | Published position | Operational consequence | Escalation question |
| --- | --- | --- | --- |
| 1.1–1.2; Schedule 1 | Processor scope and processing details tied to the Services Agreement. | Identify the actual service, data and customer role. | Does this DPA version govern the workspace/order form? |
| 2.1; 3.3 | Contract and supported configurations form instructions; customer has configuration duties. | Record settings, task scope and a change owner. | Which settings implement our retention and deletion choices? |
| 2.3; 2.5 | Confidentiality commitments and reasonable, appropriate security measures. | Review the Agreement’s security detail. | Which measures apply to the exact service and feature? |
| 2.4; 2.6 | Qualified rights-request and reasonable compliance assistance. | Define the customer/provider handoff. | How do we request assistance and track completion? |
| 2.7 | Breach notice without undue delay after awareness. | Keep vendor notice separate from our legal deadlines. | Which contact receives notice and escalates it? |
| 2.8 | Annual limits, confidentiality, customer expense and possible report-summary substitution. | Plan evidence requests and audit needs. | Do the available reports and audit conditions meet our requirements? |
| 2.9–2.10 | General authorisation, 30-day objection process and comparable subprocessor obligations. | Monitor notices; assess alternatives and Agreement liability limits. | Who subscribes, objects and assesses any exit consequence? |
| 2.11 | Post-termination return/deletion on instruction, with legal-retention conditions. | Plan export, instruction and confirmation. | Which copies and exceptions need evidence at exit? |
| 4; Schedule 1 | EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input. | Review geography, transfer analysis and planned data categories. | Does the intended use require different terms or additional safeguards? |

## Review checklist

- [ ] Match the applicable version
  Retain the DPA, Services Agreement and order form; check precedence and negotiated differences.
- [ ] Resolve service and data scope
  Review Schedule 1, the actual features and any planned sensitive-data use instead of treating the DPA as a universal approval.
- [ ] Assign the operational handoffs
  Name owners for rights requests, breach notices, subprocessor changes, audits and exit instructions.

## Included example files

- chatgpt-dpa-v010126-review.md
- chatgpt-dpa-v010126-review.csv

## Source references

- EU GDPR: Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (2026-09-21)
- OpenAI Data Processing Addendum, v.010126: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf (2026-09-21)
- OpenAI: ChatGPT Work Cloud data handling and retention: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security#data-handling-and-retention (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
