PuppyIP Resource Center
AI Security Updates 10 min Published 2026-08-21 Updated 2026-08-22

OpenAI ZDR and regional processing: limits on per-request US/EU selection

For API teams handling financial, medical, internal-code or customer data, the new capability lets Global projects choose US or European processing for individual requests. A domain prefix does not automatically grant ZDR, change retention rules or bypass model and endpoint support boundaries.

OpenAI ZDR Zero Data Retention Regional processing Private Safety Processing API compliance

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • On August 19, 2026, OpenAI said eligible API customers’ ZDR prompts and model responses are not retained after request processing, and enterprise data is not used for training by default.
  • The August 21 OpenAI API changelog added per-request regional processing: a Global-geography project’s API key can send individual requests through regional domain prefixes, with existing eligibility and retention controls still applying.
  • Private Safety Processing extends automated safety judgments from individual interactions to related interactions, aiming to keep underlying prompts and responses inaccessible to OpenAI personnel.
  • The capability is currently being tested with early customers, with gradual rollout and a technical white paper planned from September. It must not be described as already generally available.
  • Customer-controlled infrastructure and future OpenAI-hosted encrypted storage are different paths. The latter uses customer-controlled keys; they must not be conflated as current options for every ZDR deployment.
  • ZDR has exceptions: suspected CSAM images may still be retained for human review and legally required reporting.

First identify who is affected

This update primarily affects enterprise security, privacy, legal and platform teams already using or evaluating the OpenAI API, especially organizations handling financial records, health data, undisclosed business plans, internal code or research material. Ordinary ChatGPT users cannot infer from this announcement that their consumer conversations receive the same ZDR terms.

The team’s task is to turn product commitments into auditable controls: whether the customer qualifies for ZDR, which endpoints and features are approved, where content resides, who holds decryption keys, what automated safety signals contain, what people can see, and how evidence is obtained for enforcement or appeals.

What ZDR promises, and what it does not

OpenAI’s August 19 announcement describes ZDR as a commitment to eligible API customers: prompts and model responses are not retained after processing, and customer content is not available for review by OpenAI personnel. Enterprise customer data is not used to train models unless customers explicitly opt in. The key phrase is “eligible API customers”; it does not automatically apply to all accounts, plans and features.

Do not save only a news headline before procurement or launch. Check the current organization’s approval scope, exceptional features, data residency and retention configuration with the contract or account owner, and record the confirmation date in the data-flow diagram. If using a relay endpoint, separately verify the relay’s logging policy; upstream ZDR does not automatically erase requests stored by intermediaries.

What changes with per-request US/EU regional processing

Previously, fixing storage and processing to a region usually required choosing the corresponding geography when creating a project. Now a Global-geography project can be retained while its API key uses a different domain for individual requests: default requests impose no processing constraint, `https://us.api.openai.com/v1` selects US processing and storage, and `https://eu.api.openai.com/v1` selects European processing and storage. This changes request routing, not the Global project permanently into a regional project.

Before launch, verify four layers together: the project geography is Global; the organization satisfies eligibility and retention requirements for the target region; the endpoint supports regional processing; and the model or snapshot appears in that endpoint’s regional matrix. Non-US regions such as Europe may also require approved MAM or ZDR and a signed Modified Retention amendment. Replacing the base URL alone cannot bypass these conditions.

How Private Safety Processing handles cross-interaction judgments

Existing ZDR-compatible safety systems mainly evaluate individual interactions, while more complex abuse patterns may emerge only across several requests. Private Safety Processing aims to let automated systems identify patterns across related interactions and return only narrowly scoped activity-type signals to OpenAI, without giving underlying prompts or responses to OpenAI personnel. The announcement says personnel still do not receive customer content even if a signal triggers an enforcement decision.

This does not mean “no processing.” More precisely, automated systems still use customer content for safety judgments, but human visibility and returned signals are constrained. Enterprises should separate “automated processing,” “human access,” “customer investigation” and “voluntary sharing of appeal material with OpenAI” into four columns, rather than summarizing every data path with a single retention switch.

Two storage paths and customer-controlled keys

The announcement says customer content in ZDR deployments can remain on customer-controlled infrastructure. OpenAI is also developing an alternative that stores content on OpenAI infrastructure encrypted with customer-controlled keys. OpenAI personnel have no key copy and therefore cannot read the underlying content. The latter is an option under development, not something already available to every customer.

Build a six-column evaluation table: content location, key owner, automated-system inputs, safety signals received by OpenAI, human visibility and current availability stage. Assign owners for key rotation, revocation, backup, audit logs and incident response. Stating “the customer holds the keys” without lifecycle and failure procedures is still insufficient for production launch.

Availability stage: preview is not GA

At the time of the announcement, Private Safety Processing was being tested with early customers. OpenAI planned a gradual rollout and technical white paper from September 2026, but did not promise same-day availability for every region, customer, model or interface. Procurement schedules must not treat a planned date as an availability SLA.

Before formal approval, retain existing data classification and fallback paths. Validate with low-sensitivity samples, keep a service option that does not use the capability, and wait for account-level eligibility, the technical white paper, contractual text and control evidence. Record the model, interface, region, data category and actual feature state for every canary test.

The CSAM legal exception must be recorded separately

OpenAI explicitly notes in the announcement’s footnote that images suspected of containing child sexual abuse material will continue to be retained for human review and legally required reporting, even in ZDR deployments. “Zero Data Retention” therefore cannot mean that no content is ever retained under any circumstances.

Security and legal teams should include this exception in data-processing notices and internal escalation procedures and establish whether their business handles images. Do not test, upload or distribute illegal content to verify the exception. Audits should use official documentation, contractual explanations and controlled compliance evidence.

Pre-launch checklist and network troubleshooting boundaries

Before launch, confirm in order: the organization has the eligibility required for ZDR or MAM; the Global project matches the regional domain; the target model, snapshot, endpoint and tools are in the regional matrix; the data-flow diagram distinguishes customer infrastructure from hosted storage; logs, relays and observability systems do not additionally retain sensitive bodies; the CSAM exception is included in policy; and preview capabilities have rollback and review thresholds.

If a regional request fails, first check project geography, eligibility, base URL, model snapshot, endpoint and configuration. Then check restrictions such as the European Responses API not supporting `background=true` and non-US Chat Completions not supporting `store=true`. Only with DNS, connection timeout, TLS or proxy authentication evidence should you follow the proxy connection failure checklist to isolate the network layer; compare API fields with the AI API configuration guide. A proxy cannot grant ZDR eligibility or change regional-processing and retention terms.

Sources

Frequently Asked Questions

Does OpenAI ZDR mean no data is ever retained?

No. It applies to eligible API customers and has explicit legal exceptions. The announcement says suspected CSAM images may be retained for human review and reporting even in ZDR deployments.

Can Global projects select US or European processing per request?

Yes, using a Global-geography project’s API key and the corresponding regional domain prefix, while still satisfying eligibility, retention controls and endpoint and model support requirements. This does not permanently turn the project into a regional project.

Is Private Safety Processing generally available?

No. As of August 19, 2026 it was still being tested with early customers, with gradual rollout and a technical white paper planned from September.

Can OpenAI personnel see prompts flagged by the safety system?

Under the design in this announcement, OpenAI receives only narrowly scoped activity-type signals, and personnel do not receive underlying customer content even after a signal is triggered. Final controls should still be checked against organizational contracts and actual configuration.

Is OpenAI-hosted storage with customer-controlled keys available now?

The announcement says the option is still in development. Current evaluations must not describe a future option as the default storage already available to all ZDR customers.

Does upstream ZDR protect all logs when an AI relay is used?

It does not automatically guarantee that. Relay services, application logs, monitoring and local databases may store content separately. Verify their retention and access policies individually.

Can changing proxies grant ZDR access when the API will not connect?

No. ZDR concerns account eligibility and data controls. Network egress can affect only the connection path, not organizational approval scope, contracts or product availability stage.