← All tool briefs

Tool brief · August 21, 2026

OpenAI's Zero Data Retention for frontier models: does it actually change how Legal uses ChatGPT?

LegalFor Legal

The tool

OpenAI Zero Data Retention (ZDR)

Visit OpenAI Zero Data Retention (ZDR)

What it is

Zero Data Retention (ZDR) is an OpenAI API control that stops prompts and responses from being stored after a request runs. OpenAI reaffirms Zero Data Retention for eligible API customers and previews Private Safety Processing for advanced AI safety without compromising data privacy. Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed.

It's an API-side setting, not a ChatGPT setting. That distinction matters for the rest of this piece.

The next-work-session test

Scenario: you're marking up a draft M&A indemnification clause and you want a frontier model to stress-test the survival period language and carve-outs. The text is privileged, client-confidential, and referenced in a live matter.

Without ZDR, the paste sits in abuse-monitoring logs for a window. With ZDR on an approved API endpoint, it doesn't. What actually changes in your next session: your engineering or ops team wires the redlining workflow (or a vendor's) through a ZDR-approved endpoint, and you stop having to route around ChatGPT for privileged text. You still can't paste it into chatgpt.com — the control lives at the API layer.

Pricing

Pricing: unverified. OpenAI does not publish a line-item cost for ZDR. It is gated by contract, not by SKU. Eligible customers may have their customer content excluded from these abuse monitoring logs, subject to the limitations below, by getting approved for the Zero Data Retention or Modified Abuse Monitoring controls. Third-party write-ups describe it as an enterprise-agreement feature: OpenAI grants ZDR on prior approval for customers with a qualifying use case, generally on an enterprise API agreement, and it applies only to eligible endpoints, not to free-tier or standard pay-as-you-go accounts. One 2026 pricing roundup put it bluntly — zero data retention and HIPAA BAA compliance require enterprise agreements, which carry undisclosed pricing (that's the writer's framing, not OpenAI's). Assume: sales-led, negotiated, commit-based.

What we'd actually use it for

Narrower than the vendor pitch. Realistically, Legal teams will use ZDR for:

  • Clause-level redline suggestions on privileged drafts fed through an approved API workflow.
  • Definition consistency checks across a signed NDA plus a new SOW.
  • Summarising a long indemnity schedule for internal memo prep, where the underlying doc can't leave a controlled environment.

Not "run the whole matter through GPT." One task, one paste, one output, no persisted copy.

Limits

This is where the marketing and the reality separate.

It's not ChatGPT. OpenAI's ZDR policy applies specifically to eligible enterprise API endpoints, not to ChatGPT browser sessions, Team plans, or consumer accounts, which operate under separate data handling terms. If your associates are pasting clauses into chatgpt.com, ZDR does nothing for you.

It's not automatic. It's not automatic. OpenAI grants ZDR on prior approval for customers with a qualifying use case. Expect a sales call, a use-case questionnaire, and a contract amendment before anything flips on.

Endpoint behaviour changes. Zero Data Retention excludes customer content from abuse monitoring logs in the same way as Modified Abuse Monitoring. Additionally, Zero Data Retention changes some endpoint behavior: the store parameter for /v1/responses and v1/chat/completions gets forced off — which also means features that depend on server-side history (like stored responses) won't work. Your dev team needs to know this before they build.

Legal duty carve-outs still exist. Like other frontier model providers, OpenAI is required by law⁠(opens in a new window) to report apparent child sexual abuse material. Practically irrelevant for a redlines workflow, but worth flagging when GC asks "does 'zero' mean zero."

Training opt-out is a separate control. On OpenAI, excluding your data from model training is a setting available on all enterprise accounts, independent of ZDR. Don't conflate the two in your DPIA.

Privilege is not resolved by ZDR alone. No US court has cleanly ruled on whether pasting privileged text into a third-party frontier model, even a non-retaining one, waives privilege. ZDR removes one factual predicate for a waiver argument (the vendor holds the text). It doesn't remove the argument.

Try it if

  • You have (or can justify) an enterprise API agreement and an engineering resource to wire the endpoint into a review tool.
  • Your matter mix regularly involves privileged or regulated text that currently gets scrubbed or paraphrased before any AI touches it.
  • You need a defensible answer to "where does the text go?" for opposing counsel or a client's InfoSec review.

Skip it if

  • Your team's actual usage is browser ChatGPT — fix that first; ZDR won't apply.
  • You need to demonstrate zero third-party processing at all. ZDR reduces retention, not processing.
  • You were hoping for a checkbox in the ChatGPT admin panel. It's an API control with a sales cycle attached.

Read the OpenAI data controls guide before your next InfoSec conversation, and the original announcement for the framing your vendor will quote at you.

---

This content is for informational purposes only and is not legal advice. Confirm confidentiality, privilege, and jurisdictional rules before using any AI tool with client matters.

Source: openai.com

More for Legal professionals →

Get the next one in your inbox

One daily brief. Every story gets a hype verdict.

No spam. Unsubscribe anytime.

No sponsored verdicts · We have no paid relationship with featured vendors