Compliance decisions
ChatGPT
ChatGPT DPA: a clause-by-clause review
OpenAI’s published DPA v.010126 covers processor instructions, assistance, security, subprocessors, return or deletion and transfers. Review it with the Services Agreement and your order form. The customer still owns lawful disclosure and relevant configuration decisions; the DPA alone does not approve every plan, feature or data type.
For Privacy counsel, procurement and AI workspace owners
Retrieved 21 September 2026. Match the public text to your applicable agreement.
Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.01
Match the public DPA to your service
This review uses the four-page official PDF labelled v.010126, retrieved on 21 September 2026. It supplements the OpenAI Services Agreement. Sections 1.1 and 1.2 describe OpenAI as processor for Customer Data and refer to Schedule 1 for processing details. Confirm the applicable agreement and order form for your ChatGPT Enterprise workspace.
Schedule 1 describes customer-selected data and purposes, but says sensitive data is not intended to be transferred unless unexpectedly included in unstructured data. Resolve any planned sensitive-data use against the actual service terms and required legal grounds. This DPA is not a HIPAA BAA.
Source context: OpenAI Data Processing Addendum, v.010126 · EU GDPR: Regulation (EU) 2016/679
02
Treat configuration as part of the instructions
Section 2.1 includes the DPA, Agreement, order form and supported configuration/tool instructions in Customer Instructions. Section 3.3 assigns the customer responsibility for relevant design and configuration choices, such as retention and deletion, without displacing OpenAI’s section 2.5 security obligations.
Keep the agreed task, workspace settings and change owner with the contract review. The fictional use here is customer-support wording with reduced context, not an assertion that a customer agreement or live configuration has been approved.
Source context: OpenAI Data Processing Addendum, v.010126
03
Understand assistance and incident wording
Sections 2.4 and 2.6 describe rights-request and reasonable compliance assistance, subject to their stated qualifications. Section 2.7 provides for customer notice without undue delay after OpenAI becomes aware of a Personal Data Breach. It does not state a fixed 72-hour vendor notice promise.
Identify the customer’s contact and response procedure rather than assuming the provider completes every rights request or DPIA. Your regulatory clocks, decisions and notices need separate ownership.
Source context: OpenAI Data Processing Addendum, v.010126 · EU GDPR: Regulation (EU) 2016/679
04
Read the audit and subprocessor conditions
Section 2.8 contains annual-frequency limits, confidentiality and customer-expense conditions for information and audits. Where data-protection law permits, OpenAI may instead provide a relevant audit-report summary. Review those conditions against the evidence your organisation needs.
Section 2.9 provides general subprocessor authorisation and a 30-day objection period after notice. Email notification depends on subscription; other reasonable notification methods are listed. It also describes alternatives and potential termination when objections cannot be resolved. Assign someone to monitor changes and evaluate operational consequences.
Source context: OpenAI Data Processing Addendum, v.010126
05
Separate exit terms from everyday deletion
Section 2.11 addresses return or deletion at the customer’s instruction following expiry or termination, with a legal-retention exception and protection of retained data. Section 4 distinguishes EEA/Swiss and UK transfer arrangements. Neither provision promises universal in-region processing or immediate deletion of every copy.
Check the service lifecycle separately. OpenAI’s Work Cloud documentation distinguishes conversation, Library and project-file controls. Use the worksheet’s clause references and questions to connect the public contract to your actual process, then retain any negotiated differences.
Source context: OpenAI Data Processing Addendum, v.010126 · OpenAI: ChatGPT Work Cloud data handling and retention
Put it into practice
OpenAI DPA v.010126 review worksheet
Published clause positions are paraphrased from the official PDF. Operational consequences and escalation questions apply them to a fictional ChatGPT Enterprise procurement case.
Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.
2.1 + 3.3
Instructions and configuration
Record the settings and their owner.
2.9
Subprocessor notice and objection
Track the 30-day objection window.
2.11
Return or deletion at exit
Keep the instruction and evidence.
| Clause | Published position | Operational consequence | Escalation question |
|---|---|---|---|
| 1.1–1.2; Schedule 1 | Processor scope and processing details tied to the Services Agreement. | Identify the actual service, data and customer role. | Does this DPA version govern the workspace/order form? |
| 2.1; 3.3 | Contract and supported configurations form instructions; customer has configuration duties. | Record settings, task scope and a change owner. | Which settings implement our retention and deletion choices? |
| 2.3; 2.5 | Confidentiality commitments and reasonable, appropriate security measures. | Review the Agreement’s security detail. | Which measures apply to the exact service and feature? |
| 2.4; 2.6 | Qualified rights-request and reasonable compliance assistance. | Define the customer/provider handoff. | How do we request assistance and track completion? |
| 2.7 | Breach notice without undue delay after awareness. | Keep vendor notice separate from our legal deadlines. | Which contact receives notice and escalates it? |
| 2.8 | Annual limits, confidentiality, customer expense and possible report-summary substitution. | Plan evidence requests and audit needs. | Do the available reports and audit conditions meet our requirements? |
| 2.9–2.10 | General authorisation, 30-day objection process and comparable subprocessor obligations. | Monitor notices; assess alternatives and Agreement liability limits. | Who subscribes, objects and assesses any exit consequence? |
| 2.11 | Post-termination return/deletion on instruction, with legal-retention conditions. | Plan export, instruction and confirmation. | Which copies and exceptions need evidence at exit? |
| 4; Schedule 1 | EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input. | Review geography, transfer analysis and planned data categories. | Does the intended use require different terms or additional safeguards? |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
chatgpt-dpa-v010126-review.mdInspect
# OpenAI DPA v.010126 review worksheet
Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.
Published clause positions are paraphrased from the official PDF. Operational consequences and escalation questions apply them to a fictional ChatGPT Enterprise procurement case.
| Clause | Published position | Operational consequence | Escalation question |
| --- | --- | --- | --- |
| 1.1–1.2; Schedule 1 | Processor scope and processing details tied to the Services Agreement. | Identify the actual service, data and customer role. | Does this DPA version govern the workspace/order form? |
| 2.1; 3.3 | Contract and supported configurations form instructions; customer has configuration duties. | Record settings, task scope and a change owner. | Which settings implement our retention and deletion choices? |
| 2.3; 2.5 | Confidentiality commitments and reasonable, appropriate security measures. | Review the Agreement’s security detail. | Which measures apply to the exact service and feature? |
| 2.4; 2.6 | Qualified rights-request and reasonable compliance assistance. | Define the customer/provider handoff. | How do we request assistance and track completion? |
| 2.7 | Breach notice without undue delay after awareness. | Keep vendor notice separate from our legal deadlines. | Which contact receives notice and escalates it? |
| 2.8 | Annual limits, confidentiality, customer expense and possible report-summary substitution. | Plan evidence requests and audit needs. | Do the available reports and audit conditions meet our requirements? |
| 2.9–2.10 | General authorisation, 30-day objection process and comparable subprocessor obligations. | Monitor notices; assess alternatives and Agreement liability limits. | Who subscribes, objects and assesses any exit consequence? |
| 2.11 | Post-termination return/deletion on instruction, with legal-retention conditions. | Plan export, instruction and confirmation. | Which copies and exceptions need evidence at exit? |
| 4; Schedule 1 | EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input. | Review geography, transfer analysis and planned data categories. | Does the intended use require different terms or additional safeguards? |
## Review steps
- Match the applicable version: Retain the DPA, Services Agreement and order form; check precedence and negotiated differences.
- Resolve service and data scope: Review Schedule 1, the actual features and any planned sensitive-data use instead of treating the DPA as a universal approval.
- Assign the operational handoffs: Name owners for rights requests, breach notices, subprocessor changes, audits and exit instructions.
## Source identity
Official PDF: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf
Footer version: v.010126
Retrieved: 21 September 2026
SHA-256: 42309abe1e586665980ff45a83c813f5d6117c6f4ee0cf28f6cecb56c8426393
The footer is a version identifier. This worksheet does not infer the web page’s publication or update date.
## Illustrative review scope
Candidate: ChatGPT Enterprise workspace for customer-support wording.
Data approach: reduced context, with unnecessary customer details omitted.
Customer agreement: not represented by the exercise.
Decision owner: to be established by the real organisation.
Clause positions above describe the public PDF, not a legal opinion that it satisfies every obligation or authorises PHI. Review the applicable Agreement, Order Form, service eligibility and actual customer configuration.
## Source and scope
Guide: https://aona.ai/resources/guides/chatgpt-dpa-review-checklist/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- EU GDPR: Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- OpenAI Data Processing Addendum, v.010126: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf
- OpenAI: ChatGPT Work Cloud data handling and retention: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security#data-handling-and-retention
Download chatgpt-dpa-v010126-review.mdchatgpt-dpa-v010126-review.csvInspect
Clause,Published position,Operational consequence,Escalation question
1.1–1.2; Schedule 1,Processor scope and processing details tied to the Services Agreement.,"Identify the actual service, data and customer role.",Does this DPA version govern the workspace/order form?
2.1; 3.3,Contract and supported configurations form instructions; customer has configuration duties.,"Record settings, task scope and a change owner.",Which settings implement our retention and deletion choices?
2.3; 2.5,"Confidentiality commitments and reasonable, appropriate security measures.",Review the Agreement’s security detail.,Which measures apply to the exact service and feature?
2.4; 2.6,Qualified rights-request and reasonable compliance assistance.,Define the customer/provider handoff.,How do we request assistance and track completion?
2.7,Breach notice without undue delay after awareness.,Keep vendor notice separate from our legal deadlines.,Which contact receives notice and escalates it?
2.8,"Annual limits, confidentiality, customer expense and possible report-summary substitution.",Plan evidence requests and audit needs.,Do the available reports and audit conditions meet our requirements?
2.9–2.10,"General authorisation, 30-day objection process and comparable subprocessor obligations.",Monitor notices; assess alternatives and Agreement liability limits.,"Who subscribes, objects and assesses any exit consequence?"
2.11,"Post-termination return/deletion on instruction, with legal-retention conditions.","Plan export, instruction and confirmation.",Which copies and exceptions need evidence at exit?
4; Schedule 1,EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input.,"Review geography, transfer analysis and planned data categories.",Does the intended use require different terms or additional safeguards?
Download chatgpt-dpa-v010126-review.csvBefore you proceed
Keep these distinctions clear
- The DPA is not a BAA
- Its processing schedule does not approve every planned sensitive-data or PHI use.
- A contract clause is not a completed action
- Rights assistance, configuration and exit still need customer-owned procedures.
Apply it to employee AI use
Bring your actual data path.
Aona can help evaluate employee-AI visibility and sensitive-input policies within a supported installed scope.
It does not negotiate or approve an OpenAI DPA. Aona’s own role, processing and terms need separate review where it handles personal data.
Use a synthetic support prompt to check the intended input boundary while privacy and procurement complete the contract review.
Review your use caseFAQ
Questions for this decision
Which version was reviewed?
Does the DPA promise breach notification within 72 hours?
Can we object to a new subprocessor?
Does the DPA authorise planned PHI or special-category uploads?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- EU GDPR: Regulation (EU) 2016/679
Articles 5, 6, 9, 12, 17, 19, 28, 32, 35 and 36 establish the relevant processing, rights, processor and risk-assessment requirements.
law · checked 2026-09-21 - OpenAI Data Processing Addendum, v.010126
Official four-page contract PDF: processor scope, sections 2.1–2.11, customer obligations in section 3, transfer provisions in section 4 and Schedule 1; version verified from footer.
vendor · checked 2026-09-21 - OpenAI: ChatGPT Work Cloud data handling and retention
Distinct operational lifecycles for conversations, Library files, project files, memories and exported records; separate from post-termination contract instructions.
vendor · checked 2026-09-21