Skip to content

Commit 1668acc

Browse files
authored
Merge pull request #3653 from bright/openai-rafal-2
Open AI blog post 2 - team & etrp
2 parents 85bb286 + 636b091 commit 1668acc

File tree

1 file changed

+120
-0
lines changed

1 file changed

+120
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,120 @@
1+
---
2+
author: rafal h
3+
tags:
4+
- AI
5+
- ChatGPT
6+
- OpenAI
7+
- LLM
8+
- privacy
9+
- security
10+
- enterprise
11+
- team
12+
date: 2024-01-25T13:56:15.196Z
13+
meaningfullyUpdatedAt: 2024-01-25T13:56:16.383Z
14+
title: OpenAI ChatGPT Team & Enterprise Privacy Terms Explained
15+
layout: post
16+
image: /images/open_ai_privacy.png
17+
hidden: true
18+
comments: true
19+
published: true
20+
language: en
21+
---
22+
**Recently OpenAI introduced new business plans: ChatGPT Team and Enterprise. Which plan gives you more control over data retention? Which one might comply with the security regulations in your company? Let’s delve into the OpenAI privacy terms to find answers!**
23+
24+
<div className="image">![OpenAI privacy](../../static/images/openai-chatgpt-free-plus-privacy-policies-explained/open_ai_privacy.png "")</div>
25+
26+
27+
In my last [blog post](/blog/openai-chatgpt-free-plus-privacy-policies-explained/) we have been tackling privacy terms when using basic, individual ChatGPT Free & Plus subscriptions. The control of the privacy there is quite limited but taking several precautions, as mentioned in the blog post, might be enough for you.
28+
29+
## OpenAI Trust Portal
30+
I have already mentioned it in the last post but it’s worth reminding. **[OpenAI Trust portal](https://trust.openai.com/) is your go-to place for privacy and security when it comes to OpenAI.** Upon this page, we can see that OpenAI is CCPA, GDPR, SOC2, and SOC3 compliant (OpenAI, not ChatGPT - note the difference). Here you can download or request security papers from OpenAI. You can see the status of their infrastructure, all privacy policies, PII usage, data processing agreement, or terms of service. Highly recommended to start your privacy journey here!
31+
## OpenAI Enterprise Privacy
32+
Another interesting place to visit is **[Enterprise Privacy portal](https://openai.com/enterprise-privacy)**. It gives you more **insight into how your data is used if you choose an enterprise/business way of interacting with ChatGPT**.
33+
34+
## ChatGPT Team Privacy and Data Security
35+
36+
It’s a recently introduced ChatGPT solution for small businesses. It is slightly **more pricey than ChatGPT Plus** and it requires at least two licenses. **It adds extra features like higher message caps and the possibility to create and share custom GPTs with the rest of the workspace.**
37+
38+
From a privacy point of view, the most important thing is that **OpenAI doesn’t train on our data with this plan:**
39+
<blockquote>
40+
<div>We do not train on your business data (data from ChatGPT Team, ChatGPT Enterprise, or our API Platform)</div>
41+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
42+
</blockquote>
43+
44+
<blockquote>
45+
<div>We do not use your ChatGPT Team, ChatGPT Enterprise, or API data, inputs, and outputs for training our models.</div>
46+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
47+
</blockquote>
48+
49+
That means that Team data is excluded from training by default. As opposed to individual subscriptions for ChatGPT we have an opt-in model here.
50+
51+
Also, when using the Team plan, **we have Admin console and Admin roles**. As we can read in the policy:
52+
<blockquote>
53+
<div>Workspace admins have control over workspaces and access</div>
54+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
55+
</blockquote>
56+
57+
**Data is stored for 30 days after deleting from the system**. End users from our team are in control of how long conversations are retained:
58+
<blockquote>
59+
<div>Each of your end users controls whether their conversations are retained. Any deleted or unsaved conversations are removed from our systems within 30 days, unless we are legally required to retain them. Note that retention enables features like conversation history, and shorter retention periods may compromise product experience.</div>
60+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
61+
</blockquote>
62+
63+
**Now, when our data is stored, who can see it?** Here’s an OpenAI explanation:
64+
<blockquote>
65+
<div>Within your organization, only end users can view their conversations. Workspace admins have control over workspaces and access. Our access to conversations stored on our systems is limited to (1) authorized employees that require access for engineering support, investigating potential platform abuse, and legal compliance and (2) specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse</div>
66+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
67+
</blockquote>
68+
69+
When it comes to **compliance with the product**, we can see it's still **a working process**:
70+
<blockquote>
71+
<div>SOC 2 compliance coming soon</div>
72+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
73+
</blockquote>
74+
For GDPR
75+
<blockquote>
76+
<div>we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Team, ChatGPT Enterprise, and the API in support of their compliance with GDPR and other privacy laws. Please complete our DPA form to execute a DPA with OpenAI.</div>
77+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
78+
</blockquote>
79+
80+
## ChatGPT Enterprise Privacy and Data Security
81+
82+
ChatGPT Enterprise is designed with larger organizations in mind for utilizing ChatGPT.
83+
84+
You have to ask support to get individual quota about the pricing and you are obliged to buy multiple licenses. Apart from extra functionalities like **unlimited GPT-4 queries**, there are also some additional privacy features to discuss. Apart from what is available in the Team plan, the **workspace admins have control of data retention**:
85+
<blockquote>
86+
<div>You control how long your data is retained (ChatGPT Enterprise)</div>
87+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
88+
</blockquote>
89+
<blockquote>
90+
<div>Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them. Note that retention enables features like conversation history, and shorter retention periods may compromise product experience</div>
91+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
92+
</blockquote>
93+
Having the admin’s control over data retention is a huge difference compared to the Team plan where
94+
<blockquote>
95+
<div>Each of your end users controls whether their conversations are retained.</div>
96+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
97+
</blockquote>
98+
99+
For compliance, same as the Team plan we are **eligible for GDPR compliance but it is already SOC 2 compliant:**
100+
<blockquote>
101+
<div>ChatGPT Enterprise has been audited and certified for SOC 2 Type 1 compliance (Type 2 coming soon).</div>
102+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
103+
</blockquote>
104+
105+
Also, we have a **SAML SSO authentication option:**
106+
<blockquote>
107+
<div>Enterprise-level authentication through SAML SSO (ChatGPT Enterprise and API)</div>
108+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
109+
</blockquote>
110+
111+
For both enterprise plans, there is information that
112+
<blockquote>
113+
<div>Data encryption at rest (AES-256) and in transit (TLS 1.2+)</div>
114+
<footer>[Enterprise Privacy portal](https://openai.com/enterprise-privacy)</footer>
115+
</blockquote>
116+
117+
Hopefully, this post has given you some insights into privacy in ChatGPT Team and Enterprise and its opt-in model. We’ve analyzed services designed for business. **In the next blog post, I will dive into the last enterprise solution proposed by OpenAI**. This will be OpenAI API which grants the best possibilities when it comes to data control & privacy. We will **compare it with Azure OpenAI** service which is a common alternative when using API. Stay tuned!
118+
119+
120+

0 commit comments

Comments
 (0)