StackLégal

AI models

GDPR OpenAI

In an indie stack, OpenAI is used for Model inference via the API. Entity cited: OpenAI Ireland Ltd for a customer established in the EEA or Switzerland; OpenAI OpCo, LLC otherwise. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA OpenAI

Yes. Public Data Processing Addendum.

Read the DPA

Stated role

For the business services, OpenAI acts as processor of Customer Data. For the personal data described in the policy, OpenAI Ireland Limited is controller for persons in the EEA or in Switzerland, and OpenAI OpCo, LLC is controller elsewhere.

Personal data

Name, contact details, account identifiers, date of birth, payment, transaction history, user content (prompts, files, images, audio, video, data from connected services), exchanges, device contacts, logs including the IP address, usage, device information, location inferred from the IP or from GPS, cookies. The DPA states that Customer Data may include names, contact details, demographic data, or other information provided by end users in unstructured data.

Sub-processors of OpenAI

Public list.

List published by the vendor

Transfers outside the EU

Hosting / location

Personal data is processed and stored in the United States and in other countries where affiliates, partners, or providers are located. The list of cloud sub-processors of customer content cites the United States and other named countries.

EU–United States Data Privacy Framework

Official search for “OpenAI”, “OpenAI OpCo”, “OpenAI LLC”, and “OpenAI, L.L.C.”: no participant. Not registered.

Cookies

OpenAI's Cookie Policy publishes a table of names on its domains (chatgpt.com, openai.com, platform.openai.com), not on an API customer's site. Examples read: _puid, _uasid, and _account (operation, chatgpt.com), oai-did and oai-sc (operation and security), oai_consent_analytics and oai_consent_marketing (consent, chatgpt.com), analytics_consent and marketing_consent (openai.com). The page lists other cookies, including third-party ones.

Typical use, written by StackLégal and not by the vendor: Model inference via the API.

History

Last update: October 4, 2026.

  1. Cookies: names from the OpenAI Cookie Policy, in place of the reference without a table.

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is OpenAI a processor within the meaning of the GDPR?

For the business services, OpenAI acts as processor of Customer Data. For the personal data described in the policy, OpenAI Ireland Limited is controller for persons in the EEA or in Switzerland, and OpenAI OpCo, LLC is controller elsewhere.

What DPA does OpenAI publish?

Yes. Public Data Processing Addendum. https://openai.com/policies/data-processing-addendum/

Which further sub-processors does OpenAI publish?

Public list. https://openai.com/policies/sub-processor-list/

Where does OpenAI state that it processes data, including outside the EU?

Personal data is processed and stored in the United States and in other countries where affiliates, partners, or providers are located. The list of cloud sub-processors of customer content cites the United States and other named countries.

Is OpenAI registered under the EU–United States Data Privacy Framework?

Official search for “OpenAI”, “OpenAI OpCo”, “OpenAI LLC”, and “OpenAI, L.L.C.”: no participant. Not registered.

Which personal data does OpenAI mention?

Name, contact details, account identifiers, date of birth, payment, transaction history, user content (prompts, files, images, audio, video, data from connected services), exchanges, device contacts, logs including the IP address, usage, device information, location inferred from the IP or from GPS, cookies. The DPA states that Customer Data may include names, contact details, demographic data, or other information provided by end users in unstructured data.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets ai models

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.