30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

  • ChatGPT

ChatGPT DPA: a clause-by-clause review

OpenAI’s published DPA v.010126 covers processor instructions, assistance, security, subprocessors, return or deletion and transfers. Review it with the Services Agreement and your order form. The customer still owns lawful disclosure and relevant configuration decisions; the DPA alone does not approve every plan, feature or data type.

For Privacy counsel, procurement and AI workspace owners

Aona field notesC08
Published terms, practical consequences
DPA v.010126

Retrieved 21 September 2026. Match the public text to your applicable agreement.

Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.

01

Match the public DPA to your service

This review uses the four-page official PDF labelled v.010126, retrieved on 21 September 2026. It supplements the OpenAI Services Agreement. Sections 1.1 and 1.2 describe OpenAI as processor for Customer Data and refer to Schedule 1 for processing details. Confirm the applicable agreement and order form for your ChatGPT Enterprise workspace.

Schedule 1 describes customer-selected data and purposes, but says sensitive data is not intended to be transferred unless unexpectedly included in unstructured data. Resolve any planned sensitive-data use against the actual service terms and required legal grounds. This DPA is not a HIPAA BAA.

Source context: OpenAI Data Processing Addendum, v.010126 · EU GDPR: Regulation (EU) 2016/679

02

Treat configuration as part of the instructions

Section 2.1 includes the DPA, Agreement, order form and supported configuration/tool instructions in Customer Instructions. Section 3.3 assigns the customer responsibility for relevant design and configuration choices, such as retention and deletion, without displacing OpenAI’s section 2.5 security obligations.

Keep the agreed task, workspace settings and change owner with the contract review. The fictional use here is customer-support wording with reduced context, not an assertion that a customer agreement or live configuration has been approved.

Source context: OpenAI Data Processing Addendum, v.010126

03

Understand assistance and incident wording

Sections 2.4 and 2.6 describe rights-request and reasonable compliance assistance, subject to their stated qualifications. Section 2.7 provides for customer notice without undue delay after OpenAI becomes aware of a Personal Data Breach. It does not state a fixed 72-hour vendor notice promise.

Identify the customer’s contact and response procedure rather than assuming the provider completes every rights request or DPIA. Your regulatory clocks, decisions and notices need separate ownership.

Source context: OpenAI Data Processing Addendum, v.010126 · EU GDPR: Regulation (EU) 2016/679

04

Read the audit and subprocessor conditions

Section 2.8 contains annual-frequency limits, confidentiality and customer-expense conditions for information and audits. Where data-protection law permits, OpenAI may instead provide a relevant audit-report summary. Review those conditions against the evidence your organisation needs.

Section 2.9 provides general subprocessor authorisation and a 30-day objection period after notice. Email notification depends on subscription; other reasonable notification methods are listed. It also describes alternatives and potential termination when objections cannot be resolved. Assign someone to monitor changes and evaluate operational consequences.

Source context: OpenAI Data Processing Addendum, v.010126

05

Separate exit terms from everyday deletion

Section 2.11 addresses return or deletion at the customer’s instruction following expiry or termination, with a legal-retention exception and protection of retained data. Section 4 distinguishes EEA/Swiss and UK transfer arrangements. Neither provision promises universal in-region processing or immediate deletion of every copy.

Check the service lifecycle separately. OpenAI’s Work Cloud documentation distinguishes conversation, Library and project-file controls. Use the worksheet’s clause references and questions to connect the public contract to your actual process, then retain any negotiated differences.

Source context: OpenAI Data Processing Addendum, v.010126 · OpenAI: ChatGPT Work Cloud data handling and retention

Put it into practice

OpenAI DPA v.010126 review worksheet

Published clause positions are paraphrased from the official PDF. Operational consequences and escalation questions apply them to a fictional ChatGPT Enterprise procurement case.

Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.

From clause to action
01

2.1 + 3.3

Instructions and configuration

Record the settings and their owner.

02

2.9

Subprocessor notice and objection

Track the 30-day objection window.

03

2.11

Return or deletion at exit

Keep the instruction and evidence.

OpenAI DPA v.010126 review worksheet
ClausePublished positionOperational consequenceEscalation question
1.1–1.2; Schedule 1Processor scope and processing details tied to the Services Agreement.Identify the actual service, data and customer role.Does this DPA version govern the workspace/order form?
2.1; 3.3Contract and supported configurations form instructions; customer has configuration duties.Record settings, task scope and a change owner.Which settings implement our retention and deletion choices?
2.3; 2.5Confidentiality commitments and reasonable, appropriate security measures.Review the Agreement’s security detail.Which measures apply to the exact service and feature?
2.4; 2.6Qualified rights-request and reasonable compliance assistance.Define the customer/provider handoff.How do we request assistance and track completion?
2.7Breach notice without undue delay after awareness.Keep vendor notice separate from our legal deadlines.Which contact receives notice and escalates it?
2.8Annual limits, confidentiality, customer expense and possible report-summary substitution.Plan evidence requests and audit needs.Do the available reports and audit conditions meet our requirements?
2.9–2.10General authorisation, 30-day objection process and comparable subprocessor obligations.Monitor notices; assess alternatives and Agreement liability limits.Who subscribes, objects and assesses any exit consequence?
2.11Post-termination return/deletion on instruction, with legal-retention conditions.Plan export, instruction and confirmation.Which copies and exceptions need evidence at exit?
4; Schedule 1EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input.Review geography, transfer analysis and planned data categories.Does the intended use require different terms or additional safeguards?

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

chatgpt-dpa-v010126-review.mdInspect
# OpenAI DPA v.010126 review worksheet

Contract positions are documented; the customer, use case and follow-up questions are illustrative. No negotiated agreement or customer approval is represented.

Published clause positions are paraphrased from the official PDF. Operational consequences and escalation questions apply them to a fictional ChatGPT Enterprise procurement case.

| Clause | Published position | Operational consequence | Escalation question |
| --- | --- | --- | --- |
| 1.1–1.2; Schedule 1 | Processor scope and processing details tied to the Services Agreement. | Identify the actual service, data and customer role. | Does this DPA version govern the workspace/order form? |
| 2.1; 3.3 | Contract and supported configurations form instructions; customer has configuration duties. | Record settings, task scope and a change owner. | Which settings implement our retention and deletion choices? |
| 2.3; 2.5 | Confidentiality commitments and reasonable, appropriate security measures. | Review the Agreement’s security detail. | Which measures apply to the exact service and feature? |
| 2.4; 2.6 | Qualified rights-request and reasonable compliance assistance. | Define the customer/provider handoff. | How do we request assistance and track completion? |
| 2.7 | Breach notice without undue delay after awareness. | Keep vendor notice separate from our legal deadlines. | Which contact receives notice and escalates it? |
| 2.8 | Annual limits, confidentiality, customer expense and possible report-summary substitution. | Plan evidence requests and audit needs. | Do the available reports and audit conditions meet our requirements? |
| 2.9–2.10 | General authorisation, 30-day objection process and comparable subprocessor obligations. | Monitor notices; assess alternatives and Agreement liability limits. | Who subscribes, objects and assesses any exit consequence? |
| 2.11 | Post-termination return/deletion on instruction, with legal-retention conditions. | Plan export, instruction and confirmation. | Which copies and exceptions need evidence at exit? |
| 4; Schedule 1 | EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input. | Review geography, transfer analysis and planned data categories. | Does the intended use require different terms or additional safeguards? |

## Review steps

- Match the applicable version: Retain the DPA, Services Agreement and order form; check precedence and negotiated differences.
- Resolve service and data scope: Review Schedule 1, the actual features and any planned sensitive-data use instead of treating the DPA as a universal approval.
- Assign the operational handoffs: Name owners for rights requests, breach notices, subprocessor changes, audits and exit instructions.

## Source identity

Official PDF: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf
Footer version: v.010126
Retrieved: 21 September 2026
SHA-256: 42309abe1e586665980ff45a83c813f5d6117c6f4ee0cf28f6cecb56c8426393

The footer is a version identifier. This worksheet does not infer the web page’s publication or update date.

## Illustrative review scope

Candidate: ChatGPT Enterprise workspace for customer-support wording.
Data approach: reduced context, with unnecessary customer details omitted.
Customer agreement: not represented by the exercise.
Decision owner: to be established by the real organisation.

Clause positions above describe the public PDF, not a legal opinion that it satisfies every obligation or authorises PHI. Review the applicable Agreement, Order Form, service eligibility and actual customer configuration.

## Source and scope

Guide: https://aona.ai/resources/guides/chatgpt-dpa-review-checklist/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- EU GDPR: Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- OpenAI Data Processing Addendum, v.010126: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf
- OpenAI: ChatGPT Work Cloud data handling and retention: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security#data-handling-and-retention
Download chatgpt-dpa-v010126-review.md
chatgpt-dpa-v010126-review.csvInspect
Clause,Published position,Operational consequence,Escalation question
1.1–1.2; Schedule 1,Processor scope and processing details tied to the Services Agreement.,"Identify the actual service, data and customer role.",Does this DPA version govern the workspace/order form?
2.1; 3.3,Contract and supported configurations form instructions; customer has configuration duties.,"Record settings, task scope and a change owner.",Which settings implement our retention and deletion choices?
2.3; 2.5,"Confidentiality commitments and reasonable, appropriate security measures.",Review the Agreement’s security detail.,Which measures apply to the exact service and feature?
2.4; 2.6,Qualified rights-request and reasonable compliance assistance.,Define the customer/provider handoff.,How do we request assistance and track completion?
2.7,Breach notice without undue delay after awareness.,Keep vendor notice separate from our legal deadlines.,Which contact receives notice and escalates it?
2.8,"Annual limits, confidentiality, customer expense and possible report-summary substitution.",Plan evidence requests and audit needs.,Do the available reports and audit conditions meet our requirements?
2.9–2.10,"General authorisation, 30-day objection process and comparable subprocessor obligations.",Monitor notices; assess alternatives and Agreement liability limits.,"Who subscribes, objects and assesses any exit consequence?"
2.11,"Post-termination return/deletion on instruction, with legal-retention conditions.","Plan export, instruction and confirmation.",Which copies and exceptions need evidence at exit?
4; Schedule 1,EEA/Swiss and UK transfer mechanisms; no intended sensitive-data transfer except unexpected unstructured input.,"Review geography, transfer analysis and planned data categories.",Does the intended use require different terms or additional safeguards?
Download chatgpt-dpa-v010126-review.csv

Before you proceed

Keep these distinctions clear

The DPA is not a BAA
Its processing schedule does not approve every planned sensitive-data or PHI use.
A contract clause is not a completed action
Rights assistance, configuration and exit still need customer-owned procedures.

Apply it to employee AI use

Bring your actual data path.

Aona can help evaluate employee-AI visibility and sensitive-input policies within a supported installed scope.

It does not negotiate or approve an OpenAI DPA. Aona’s own role, processing and terms need separate review where it handles personal data.

Use a synthetic support prompt to check the intended input boundary while privacy and procurement complete the contract review.

Review your use case

FAQ

Questions for this decision

Which version was reviewed?
The official four-page PDF bearing footer v.010126, retrieved on 21 September 2026. Confirm the version incorporated into your own agreement; the footer does not establish the website’s update date.
Does the DPA promise breach notification within 72 hours?
Section 2.7 says without undue delay after awareness of a Personal Data Breach. It does not state that fixed duration. Assess your own statutory response and notification duties separately.
Can we object to a new subprocessor?
Section 2.9 describes an objection within 30 days of receiving notice, possible alternatives and termination conditions if the issue cannot be resolved. Read the full procedure and assign a notice owner.
Does the DPA authorise planned PHI or special-category uploads?
No blanket permission follows from it. Schedule 1’s sensitive-data wording, the applicable service terms, legal grounds and any required separate agreement must be resolved for the intended use.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. EU GDPR: Regulation (EU) 2016/679

    Articles 5, 6, 9, 12, 17, 19, 28, 32, 35 and 36 establish the relevant processing, rights, processor and risk-assessment requirements.

    law · checked 2026-09-21
  2. OpenAI Data Processing Addendum, v.010126

    Official four-page contract PDF: processor scope, sections 2.1–2.11, customer obligations in section 3, transfer provisions in section 4 and Schedule 1; version verified from footer.

    vendor · checked 2026-09-21
  3. OpenAI: ChatGPT Work Cloud data handling and retention

    Distinct operational lifecycles for conversations, Library files, project files, memories and exported records; separate from post-termination contract instructions.

    vendor · checked 2026-09-21
ChatGPT DPA: a clause-by-clause review | Aona