OpenAI Expands Global Data Residency for Business Customers

OpenAI has expanded the availability of data residency, enabling eligible business customers using ChatGPT Enterprise, ChatGPT Edu, and the API Platform to store their data at rest within specific geographic regions. This expansion allows organizations to better meet local regulatory and data protection requirements.

Data Residency Availability and Scope

OpenAI now offers data residency in the following regions:

  • Europe
  • United Kingdom
  • United States
  • Canada
  • Japan
  • South Korea
  • Singapore
  • India
  • Australia
  • United Arab Emirates

OpenAI plans to expand these options to additional regions over time.

Implementation for ChatGPT Enterprise and ChatGPT Edu

For ChatGPT Enterprise and ChatGPT Edu customers, data residency is implemented through the creation of new ChatGPT workspaces. These workspaces can be configured to store customer content at rest in a selected region. Covered content includes:

  • Conversations
  • Uploaded files
  • Cusom GPTs
  • Image generation artifacts

Data Residency for the API Platform

Enterprise customers approved for advanced data controls can enable regional data residency by creating a new Project within the API Platform dashboard and selecting a preferred region. For requests made through these Projects, model requests and responses are not stored at rest on OpenAI's servers, and requests are handled in-region.

Privacy, Security, and Compliance Framework

OpenAI employs several technical and legal frameworks to ensure data confidentiality and integrity:

Encryption and Key Management

OpenAI uses AES-256 for data at rest and TLS 1.2+ for data in transit. To provide additional security, Enterprise Key Management (EKM) allows customers to bring their own encryption keys for content stored at rest.

Data Usage and Training

By default, OpenAI models are not trained on data from the API or ChatGPT business plans unless a customer explicitly opts in to share that data.

Compliance and Certifications

OpenAI's data protection practices are designed to support compliance with GDPR, CCPA, and other privacy laws. The organization maintains the following certifications:

  • CSA STAR
  • SOC 2 Type 2
  • ISO/IEC 27001, 27017, 27018, and 27701

Additionally, OpenAI provides a Data Processing Addendum (DPA) to clarify roles and responsibilities under GDPR and other privacy regulations.

Sources