OpenAI Data Residency in Europe and Global Expansion

OpenAI has launched data residency in Europe for the API Platform, ChatGPT Enterprise, and ChatGPT Edu, enabling organizations to meet local data sovereignty requirements. This offering expands into global availability and adds options for in-region GPU inference for specific eligible customers.

Data Residency Capabilities by Product

OpenAI provides different data residency implementations depending on the product being used:

API Platform

Eligible API customers can process data in Europe by creating a new Project in the API Platform dashboard and selecting Europe as the region. For these Projects, OpenAI handles requests in-region with zero data retention, meaning that model requests and responses are not stored at rest on OpenAI servers.

ChatGPT Enterprise and Edu

New ChatGPT workspaces for Enterprise and Edu customers can be configured to store customer content at rest in Europe. This storage includes user prompts, uploaded files, and content across text, vision, and image modalities, as well as conversations with ChatGPT and custom GPTs within the workspace.

Global Expansion and Inference Residency

Following the initial European launch, OpenAI expanded at-rest data residency to several additional regions, including the UK, US, Japan, Canada, South Korea, Singapore, Australia, India, and the UAE for eligible API customers and new ChatGPT Enterprise and Edu workspaces.

As of January 16, 2026, OpenAI has further expanded its offering to include options for in-region GPU inference in the U.S. or Europe for eligible ChatGPT Enterprise, ChatGPT Edu, and ChatGPT for Healthcare customers.

Enterprise-Grade Privacy and Security Standards

Data residency is an addition to OpenAI's existing security and compliance framework. The following protections apply to organizations using OpenAI's business products:

  • Data Encryption: OpenAI utilizes AES-256 for data at rest and TLS 1.2+ for data in transit.
  • No Training on Customer Data: By default, OpenAI does not train its models on data from the API or ChatGPT business plans unless the customer explicitly opts in.
  • Compliance Standards: Data protection practices are designed to support compliance with GDPR, CCPA, CSA STAR, and SOC 2 Type 2 standards.
  • Data Processing Addendum (DPA): A comprehensive DPA is available to clarify roles and responsibilities under GDPR and other privacy regulations.

OpenAI states that for the API Platform and ChatGPT business products, data remains confidential, secure, and entirely owned by the customer.

Sources