SurfingBear ToolsSurfingBearTools
Skip to content

HomeAI News › Tool & Product Updates

Tool & Product UpdatesPublished 2026.08.24Source · OpenAI

OpenAI reaffirms zero data retention (ZDR) — the ‘where does our data live’ question changes shape

Announced 19 August. OpenAI keeps its policy of not retaining prompts and responses, while previewing a new approach to safety checking.

On 19 August OpenAI reaffirmed its Zero Data Retention (ZDR) policy, and alongside it previewed a new approach to safety checking called Private Safety Processing.

What ZDR promises eligible API customers is clear enough.

  • Once a request has been processed, prompts and model responses are not retained.
  • Customer content cannot be reviewed by OpenAI staff.
  • Enterprise customer data is not used for model training unless the customer explicitly opts in.

Why the announcement came now

The background OpenAI gave is a structural limitation in safety checking. As models take on longer and more complex tasks, some serious risks only become visible when several interactions are viewed together. The examples offered were repeated probing of safety guardrails, activity spread across multiple accounts, and agents that keep operating after being told to stop. The problem is that existing ZDR-compatible safety systems evaluate interactions only one at a time.

OpenAI also noted that some recent frontier model deployments have required customers to permit retention of sensitive content for safety monitoring. For many organisations that requirement conflicts with their own security obligations. Private Safety Processing is described as designed to let ZDR continue to be offered in exactly that situation.

How Private Safety Processing works

  • In ZDR deployments, content stays on infrastructure the customer controls.
  • An option to store on OpenAI infrastructure is also in development, in which case it is encrypted with a customer-managed key. OpenAI staff do not hold a copy of that key.
  • When a risk is detected, OpenAI receives only a narrowly defined signal indicating the type of activity. Even for flagged cases, staff do not access the content.
  • Customers can investigate alerts and actions themselves using information from their own systems, and choose whether to share information to contest a finding or assist an investigation.

It is currently in testing with a set of early customers, with the rollout and technical white paper scheduled for September.

One exception is stated explicitly. Like other frontier model providers, OpenAI has a legal obligation to report suspected child sexual abuse material (CSAM), and images flagged as potential CSAM are retained even in ZDR deployments for manual review and reporting.

Glean chief information security officer Sunil Agrawal said enterprise AI adoption “depends entirely on customers controlling their data”, and that OpenAI’s no-training commitment together with ZDR gives the confidence to build on OpenAI.

What this means for Korean teams — SurfingBear editorial

The item that most often stalls an evaluation of an international AI product is ‘where does the data end up’. What this announcement changes is not the answer but the precision of the question.

“Do you store data?” is now too blunt to be useful. In practice what you need to confirm narrows to three things.

Is the contract type we are on actually covered by ZDR? ZDR applies to ‘eligible API customers’. It is not a condition that automatically extends to ordinary subscription plans or consumer products. ② Is training use opt-in? Check that this wording is in the contract. ③ What are the retention exceptions? As the CSAM case above shows, statutory exceptions exist independently of policy.

And this is not only about OpenAI. The same three questions apply to every international SaaS product with AI features in it. It is also why SurfingBear product pages keep data location as its own line item under ‘what to check before adopting in Korea’.

If you need the data-handling terms of an international AI product pinned down — AI product sourcing runs candidate selection, domestic contracting and data-terms verification through a single point of contact. If your shortlist is already set, each product page in the product library lists what to check first.

Sources

  1. OpenAI, “Offering Zero Data Retention for frontier models”, 2026.08.19 — read the original

The policy details and quotations above are summarised and translated from the official OpenAI announcement cited. The ‘What this means for Korean teams’ section is SurfingBear editorial interpretation, not a claim made by OpenAI. Private Safety Processing was at an early-customer testing stage as of the announcement, and the conditions under which it actually applies vary by contract and deployment type. Always confirm contractual data-handling terms against the vendor’s current agreement.

We handle the data-terms check too

Candidate selection, comparative validation, data-handling verification, domestic contracting and tax invoicing, and Korean-language onboarding for international AI products — through one point of contact.

Talk to us about sourcing See what the service covers →

Considering AI for your team?

What does this trend actually mean for your company — where to start, and which tools and products fit? A PM reviews your case directly and replies within 24 hours. Early-stage questions are welcome.