ChatGPT (OpenAI)
OpenAI
Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.
Pricing / Contract Route
Official pricing varies by plan, billing cadence, market and tax
Enterprise Features
DPA, eligible ChatGPT storage and GPU inference residency, eligible API regional processing, retention and admin controls
Last Updated
September 10, 2026
Version: 10 September 2026 - prepared by WAIMAKERS B.V.
1 Purpose
This report gives an at-a-glance view of how ChatGPT subscriptions and the OpenAI API process personal data under the European General Data Protection Regulation (GDPR).
OpenAI services can support a GDPR-compliant deployment, but no plan is automatically "GDPR compliant". The organisation remains responsible for lawful basis, transparency, data minimisation, access controls, retention, data-subject requests and, where appropriate, a DPIA and transfer assessment.
2 Comparison of versions
| Plan | Privacy position | EU data residency | Training | Retention | DPA and practical assessment |
|---|---|---|---|---|---|
| Free / Plus | ⚠️ Consumer route, without the organisational contract and controls of a business workspace | ❌ No organisational residency commitment | ChatGPT may use conversations to improve models while Improve the model for everyone is enabled. Users can disable it account-wide in Data Controls. | Turning training off does not delete ordinary chat history. Temporary Chats are deleted within 30 days, are not trained on and may be reviewed for abuse monitoring. | Do not treat this route as DPA-backed business use. Avoid client data and sensitive personal data unless the exact use has been assessed. |
| ChatGPT Business | ✅ Business-data protections, subject to the current service terms and configuration | ⚠️ Regional storage is rolling out and is not available to every customer. It does not provide inference residency. Safety and abuse-monitoring data, including a limited-time copy of prompts and responses, is stored in the US. | ✅ Business inputs and outputs are not used for training by default. An explicit opt-in can change this. | No universal 30-day period. Confirm workspace controls and current product-specific rules. | Check that the current DPA covers the customer and service. Potentially suitable for ordinary business use after plan, DPA, residency and feature checks. |
| ChatGPT Enterprise / Edu | ✅ Stronger organisational governance, still dependent on the actual use and configuration | ✅ Eligible new workspaces can select Europe for in-scope customer content at rest. Eligible workspaces can also enable European GPU inference. CPU processing, system data, external integrations and unsupported features can remain outside the region. | ✅ Business data is not used for training by default. | Admin retention controls are available to qualifying plans. Deletion, security and legal exceptions remain. | DPA and enterprise controls are available. Record the exact storage and inference settings rather than inferring them from the billing address. |
| OpenAI API | ✅ Commercial route, assessed per project, endpoint and tool | ⚠️ European storage and processing are limited to eligible projects, endpoints and models. Non-US residency requires approval for abuse-monitoring controls and a Modified Retention amendment. Supported regional processing can also be selected per request from a Global-geography project through the regional endpoint. | ✅ API inputs and outputs are not used to train OpenAI models by default unless the customer opts in. | Abuse-monitoring logs can contain customer content and are kept for up to 30 days by default. ZDR, MAM and application state are endpoint-specific. | Map every endpoint, tool, storage object and third-party integration before production use. |
Public prices change by country, currency, tax, billing route and model. Verify the official pricing page or order form immediately before purchase. Price is not evidence of privacy coverage.
Notes for Europe
- DPA and processor role: under OpenAI's DPA, OpenAI acts as processor for covered Customer Data. OpenAI Ireland Ltd. is the contracting entity for EEA and Swiss customers. SCCs or an adequacy decision can support onward transfers.
- No training by default for business data: this applies to ChatGPT Business, Enterprise, Edu and API data, unless the customer explicitly opts in.
- Residency has a defined scope: account data, billing information, high-level usage statistics, content-free logs and other system data are outside ChatGPT's customer-content residency scope.
- Inference residency is not all processing: European inference residency concerns GPU execution. Routing, authentication, CPU extraction and external integrations can still occur elsewhere. OpenAI also listed the US and UAE as supported inference regions on the review date.
- API controls differ by endpoint: unsupported endpoints or tools can store application state or process data outside the selected region. ZDR does not mean that every API feature retains nothing.
- External services require their own assessment: apps, connectors, third-party GPTs, MCP servers and web search introduce separate terms and data flows.
3 Recommendations for EU deployment
- Use an organisational Business, Enterprise, Edu or API contract and record the exact service and plan.
- Confirm that the current DPA is incorporated and identify the contracting OpenAI entity.
- Capture the selected storage and inference regions from the admin console.
- Inventory apps, connectors, GPTs, tools and API endpoints, including anything outside residency or ZDR.
- Configure and test retention and deletion, including safety, legal-hold, feedback and application-state exceptions.
- Apply least privilege, SSO/MFA where available, feature controls and an approved-data policy.
- Complete a DPIA or transfer assessment when the risks, data categories or international transfers require it.
4 Primary sources
- OpenAI business data privacy, security and compliance
- OpenAI Data Processing Addendum
- ChatGPT data and inference residency
- ChatGPT Business content location
- OpenAI API data controls and residency
- OpenAI business pricing
- ChatGPT Data Controls FAQ
5 Disclaimer
This overview is an informational procurement aid, not legal advice or a certification of a deployment. Verify the current contract, configuration and data flow before production use. The customer remains responsible for its GDPR obligations.
Prepared and issued by WAIMAKERS B.V. - 10 September 2026.