AI models
GDPR OpenAI
In an indie stack, OpenAI is used for Model inference via the API. Entity cited: OpenAI Ireland Ltd for a customer established in the EEA or Switzerland; OpenAI OpCo, LLC otherwise. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA OpenAI
Yes. Public Data Processing Addendum.
Stated role
For the business services, OpenAI acts as processor of Customer Data. For the personal data described in the policy, OpenAI Ireland Limited is controller for persons in the EEA or in Switzerland, and OpenAI OpCo, LLC is controller elsewhere.
Personal data
Name, contact details, account identifiers, date of birth, payment, transaction history, user content (prompts, files, images, audio, video, data from connected services), exchanges, device contacts, logs including the IP address, usage, device information, location inferred from the IP or from GPS, cookies. The DPA states that Customer Data may include names, contact details, demographic data, or other information provided by end users in unstructured data.
Sub-processors of OpenAI
Public list.
Transfers outside the EU
Hosting / location
Personal data is processed and stored in the United States and in other countries where affiliates, partners, or providers are located. The list of cloud sub-processors of customer content cites the United States and other named countries.
EU–United States Data Privacy Framework
Official search for “OpenAI”, “OpenAI OpCo”, “OpenAI LLC”, and “OpenAI, L.L.C.”: no participant. Not registered.
Cookies
OpenAI's Cookie Policy publishes a table of names on its domains (chatgpt.com, openai.com, platform.openai.com), not on an API customer's site. Examples read: _puid, _uasid, and _account (operation, chatgpt.com), oai-did and oai-sc (operation and security), oai_consent_analytics and oai_consent_marketing (consent, chatgpt.com), analytics_consent and marketing_consent (openai.com). The page lists other cookies, including third-party ones.
Typical use, written by StackLégal and not by the vendor: Model inference via the API.
History
Last update: October 4, 2026.
Cookies: names from the OpenAI Cookie Policy, in place of the reference without a table.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is OpenAI a processor within the meaning of the GDPR?
For the business services, OpenAI acts as processor of Customer Data. For the personal data described in the policy, OpenAI Ireland Limited is controller for persons in the EEA or in Switzerland, and OpenAI OpCo, LLC is controller elsewhere.
What DPA does OpenAI publish?
Yes. Public Data Processing Addendum. https://openai.com/policies/data-processing-addendum/
Which further sub-processors does OpenAI publish?
Public list. https://openai.com/policies/sub-processor-list/
Where does OpenAI state that it processes data, including outside the EU?
Personal data is processed and stored in the United States and in other countries where affiliates, partners, or providers are located. The list of cloud sub-processors of customer content cites the United States and other named countries.
Is OpenAI registered under the EU–United States Data Privacy Framework?
Official search for “OpenAI”, “OpenAI OpCo”, “OpenAI LLC”, and “OpenAI, L.L.C.”: no participant. Not registered.
Which personal data does OpenAI mention?
Name, contact details, account identifiers, date of birth, payment, transaction history, user content (prompts, files, images, audio, video, data from connected services), exchanges, device contacts, logs including the IP address, usage, device information, location inferred from the IP or from GPS, cookies. The DPA states that Customer Data may include names, contact details, demographic data, or other information provided by end users in unstructured data.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.