OpenAI parks customer data in Europe to ease sovereignty fears
Curated by the Inblix editorial team
OpenAI finally made a move that European enterprises have been demanding for years. The company announced it will let customers pin their data processing and storage within Europe, a direct response to the continent’s stringent data sovereignty rules. The offering covers ChatGPT Enterprise, ChatGPT Edu, and the API Platform, and it’s not just lip service—the company is promising zero data retention for API requests processed in-region.
Here’s how the plumbing works. For the API, developers create a new Project and select Europe as their region. Once that’s set, model requests and responses are handled locally and aren’t stored on OpenAI’s servers. There’s a catch, though: you can’t flip the switch on existing Projects. This is a greenfield-only setup, which means teams with existing infrastructure will need to migrate to new Projects if they want the residency guarantees. For ChatGPT Enterprise and Edu workspaces, customer content—conversations, prompts, uploaded files, and content across text, vision, and image modalities—gets stored at rest in Europe.
This isn’t happening in a vacuum. OpenAI name-dropped a roster of European heavyweights already on board: Booking.com, BBVA, Zalando, Klarna, Spotify, and Santander, along with Oxford University and Estée Lauder. The company is clearly signaling that it’s open for serious business on the continent. The technical underpinnings are what you’d expect from an enterprise push—AES-256 encryption at rest, TLS 1.2+ in transit, SOC 2 Type 2 compliance, and a Data Processing Addendum that clarifies roles under GDPR. OpenAI also reiterated its default policy of not training models on business customer data.
What’s genuinely new here is the combination of in-region processing and zero retention. That’s a meaningful architectural commitment, not just a checkbox on a compliance form. But the restriction to new Projects feels like a transitional limitation that will frustrate engineering teams with established deployments. The question is how quickly OpenAI closes that gap, because competitors aren’t standing still. Google Cloud and AWS have been offering granular data residency controls for years. OpenAI is playing catch-up in enterprise procurement conversations where data locality is non-negotiable, and this update, while significant, still leaves some customers waiting.
💡 Key Takeaways
- OpenAI now allows API and ChatGPT Enterprise customers to pin data processing and storage to Europe, with a zero-retention policy for in-region API requests.
- European data residency can only be configured for new API Projects, not existing ones, creating migration friction for teams with established infrastructure.
- The company cited enterprise customers like Spotify, Klarna, and BBVA as proof of traction, signaling deeper commitment to regulated European markets.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.