SAN FRANCISCO — OpenAI has introduced data residency in Europe for its ChatGPT Enterprise, ChatGPT Edu, and API Platform offerings, providing an added layer of security and compliance for businesses operating within the region. This new feature is designed to help organizations meet local data sovereignty requirements when leveraging OpenAI’s AI tools and developing AI-powered solutions. It further strengthens the company’s enterprise-level commitment to data privacy, security, and regulatory compliance.
Data Residency for API, ChatGPT Enterprise, and ChatGPT Edu With this announcement, customers of the API Platform, ChatGPT Enterprise, and ChatGPT Edu can now select Europe as the region for processing their data. This option provides greater flexibility and control over where data is stored and processed, ensuring that it complies with European regulations.
API Platform Eligible API users can now opt to process data within Europe by setting up a new project on the API Platform dashboard and choosing Europe as the region. Requests initiated through these projects will be processed locally, with no data retention. This means that model requests and responses are not stored on OpenAI servers. Note that European data residency can only be enabled for newly created projects—existing projects cannot be switched to this option after they have been set up.
ChatGPT Enterprise and Edu For new ChatGPT Enterprise and Edu customers, data residency in Europe is now available. This allows organizations to store customer content locally within Europe, ensuring that all interactions, including user prompts, uploaded files, and content spanning text, image, and vision modalities, remain in compliance with local regulations.
Enterprise-Grade Privacy, Security, and Compliance Data residency builds on OpenAI’s robust security, privacy, and compliance protocols, which already support a diverse range of organizations across Europe, including major companies and institutions like Booking.com, BBVA, Zalando, Oxford University, Estée Lauder, Spotify, and Santander. These features include:
- Advanced encryption: OpenAI utilizes AES-256 encryption for data at rest and TLS 1.2+ for data in transit, ensuring the confidentiality and integrity of data during storage and transmission.
- No training on customer data: OpenAI’s models are not trained using data from the API or business plans by default, unless customers opt-in to share their data for this purpose.
- Comprehensive data protection: OpenAI’s data protection practices align with GDPR, CCPA, and other privacy laws and adhere to the CSA STAR and SOC 2 Type 2 standards.
- Data Processing Addendum (DPA): OpenAI offers a DPA to clarify roles and responsibilities under GDPR and other privacy regulations, assisting organizations with their compliance obligations.
For both API and ChatGPT business products, customer data remains confidential, secure, and entirely under the organization’s control. The new data residency feature adds an extra layer of protection for companies based in Europe.
For more information on data residency eligibility and supported data, visit the help pages for the API Platform and ChatGPT, or contact OpenAI’s support team for assistance with using their products in accordance with European data residency standards.
With this expansion, OpenAI is excited to continue supporting organizations across Europe and globally in their AI endeavors while maintaining the highest standards of privacy, security, and compliance.