VendorScore · AI assistant · Data-access posture

Can OpenAI read your ChatGPT Enterprise data?

A plain-language answer from OpenAI's public enterprise-privacy page, DPA, Trust Portal and Help Center. EKM gives you key custody and revocation, not zero access.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, by design (with controls): OpenAI's models process chats in plaintext and authorized staff can access them for incidents or legal reasons; EKM adds custody and revoke, not zero access.

66 / 100 overall

Scored configuration: ChatGPT Enterprise with Enterprise Key Management (customer AWS/GCP/Azure KMS), admin-set retention, SSO, Compliance API, and EU data residency where eligible.

Default setup without EKM scores lower: OpenAI-managed keys. Don't apply this score to ChatGPT Business, which allows broader contractor review.

Report confidence: Medium. OpenAI's sub-processor list, EKM and data-residency pages blocked automated fetches and were checked via a search index only.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in ChatGPT Enterprise's public documentation:

  • OpenAI's sub-processor list, EKM help articles and data-residency article block automated fetches; their content was checked via a search index only.
  • No public statement on customer-visible logging of OpenAI staff access.
  • Zero data retention is documented for eligible API endpoints only, not ChatGPT Enterprise chat.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: ChatGPT Enterprise data access, AI training, GDPR and residency

Can OpenAI read your ChatGPT Enterprise data?

Yes, by design (with controls): OpenAI's models process chats in plaintext and authorized staff can access them for incidents or legal reasons; EKM adds custody and revoke, not zero access. VendorScore rates ChatGPT Enterprise 66/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: ChatGPT Enterprise with Enterprise Key Management (customer AWS/GCP/Azure KMS), admin-set retention, SSO, Compliance API, and EU data residency where eligible.

Is ChatGPT Enterprise encrypted? Does EKM stop OpenAI reading my chats?

No. OpenAI encrypts data at rest with AES-256 and in transit with TLS 1.2+. With Enterprise Key Management, content is encrypted with keys from your own KMS (AWS KMS, Google Cloud or Azure Key Vault) and OpenAI says it "never sees or stores the KEKs", but OpenAI still needs decrypt permission on your key to serve the product, and losing the key makes the data permanently unreadable. EKM is custody and revocation, not a zero-access guarantee, and OpenAI makes no E2EE claim. We could check the EKM help articles only through a search index.

Can OpenAI employees read my ChatGPT Enterprise conversations?

In limited cases. OpenAI says: "Authorized OpenAI employees will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law." Business data may also pass through automated content classifiers. We found no customer-visible log of OpenAI staff access and no Lockbox-style approval control.

Does OpenAI train on ChatGPT Enterprise data?

No, not by default. OpenAI says: "By default, we do not use your business data for training our models." The same applies to data accessed through apps and connectors. If you explicitly opt in to share data, for example through feedback mechanisms, OpenAI may use that shared data to train its models. Admins set retention; deleted conversations are removed within 30 days unless OpenAI must keep them by law.

Is ChatGPT Enterprise GDPR compliant? Where is the OpenAI DPA?

VendorScore doesn't certify compliance; OpenAI publishes a DPA at https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf. The DPA gives a 30-day objection window for new subprocessors, with a termination right, and allows customer audits or inspections at the customer's expense.

Who are OpenAI's subprocessors for ChatGPT Enterprise?

OpenAI publishes its sub-processor list at https://openai.com/policies/sub-processor-list/. That page blocks automated fetches, so we couldn't read the list content directly and don't repeat names from it here. OpenAI's DPA describes the process: change notices by blog, in-product notice or email subscription, and a 30-day objection window.

Can I keep ChatGPT Enterprise data in the EU (data residency)?

Yes, for eligible new Enterprise and Edu workspaces: in-scope content can be stored at rest in Europe (EEA + Switzerland), with optional in-region GPU inference in Europe at no extra cost. We could check OpenAI's data-residency article only through a search index.

Compare ChatGPT Enterprise

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (chatgpt-enterprise.md), evidence dated 2026-10-07.