Monitor OpenAI compliance pages

Creator of GPT and o-series models โ€” API access to GPT-4, GPT-4o, o1, o3 reasoning models, Whisper, DALL-E, and ChatGPT Enterprise.

OpenAI publishes several compliance and legal pages that change over time. Under GDPR Article 28, data controllers using OpenAI as a processor must continuously verify that "sufficient guarantees" remain in place โ€” which means tracking changes to these pages as they happen. Below are the 4 most relevant pages, what typically changes on each, and ready-to-paste monitoring prompts.

Monitor all 4 pages automatically

Choose the pages that matter most and get an alert when something meaningful changes. The free plan covers 3 monitors.

Start with 3 free monitors โ†’

Pages to monitor

Sub-processor list

https://openai.com/policies/sub-processor-list/ โ†—

Typical change frequency: quarterly

What to monitor

  • Azure as primary compute sub-processor (stability important)
  • Support and moderation sub-processors (content review partners)
  • New sub-processors added for specific products (Sora video, Operator, Codex)
  • Billing and payment sub-processor changes

Suggested monitoring prompt

Alert me when OpenAI adds, removes, or changes sub-processors. Report name, product area, and purpose. Changes to Azure compute and moderation partners are particularly important.

Data Processing Agreement

https://openai.com/policies/data-processing-addendum/ โ†—

Typical change frequency: yearly

What to monitor

  • Changes to default training opt-out for API/Enterprise data (currently enterprise/API is not trained on)
  • Updates to Zero Data Retention availability and scope
  • Modifications to EU data residency commitments
  • Changes to human review provisions for safety

Suggested monitoring prompt

Monitor the OpenAI DPA for changes to API/Enterprise training defaults, Zero Data Retention, EU residency, or human review provisions. These are high-sensitivity changes.

Privacy policy

https://openai.com/policies/privacy-policy/ โ†—

Typical change frequency: yearly

What to monitor

  • Changes to training data policies for consumer ChatGPT vs API vs Enterprise
  • Updates to how user input and output are used
  • New data sharing arrangements
  • Changes to voice data handling (Advanced Voice, Realtime API)
  • Memory and personalization feature data retention

Suggested monitoring prompt

Alert me when OpenAI changes training data policies, data sharing, voice data handling, or memory/personalization retention. Report product tier (ChatGPT / API / Enterprise) the change applies to.

Status page

https://status.openai.com/ โ†—

Typical change frequency: weekly

What to monitor

  • API rate limiting or capacity issues
  • Specific model outages (GPT-4, o1, etc.)
  • ChatGPT availability
  • Incidents affecting data residency regions

Suggested monitoring prompt

Alert me on OpenAI incidents affecting the API, specific models, or ChatGPT availability. Ignore minor documentation or dashboard issues.

Compliance certifications

SOC 2 Type IIGDPRHIPAA (via BAA, API/Enterprise)CSA STAR

Data location

Hosting locations: United States (Azure), European Union (via Azure, for Enterprise)

EU-US Data Privacy Framework: Certified

Related

Ready to start monitoring OpenAI?

Set up monitoring free โ†’