Between 13 May and 26 September 2025 the difference between ChatGPT Team and ChatGPT Enterprise was not a feature list. It was whether your deleted chats were being kept for the New York Times. A magistrate judge’s preservation order covered “ChatGPT Free, Plus, Pro, and Team” users and non-ZDR API customers; it “does not impact ChatGPT Enterprise or ChatGPT Edu customers” (OpenAI’s response to the NYT data demands). Team has since been renamed Business. The lesson has not changed.

That is the sharpest way to see the ChatGPT Business vs Enterprise question for law firms. Both plans carry the same no-training default. The difference is who controls retention, where the data sits, what an auditor can see, and what happens when a court gets involved. Below: what Business already gives a firm, the four things Enterprise adds, the narrower-than-advertised truth about zero data retention, the Claude equivalents, and a recommendation by firm size. Everything here is drawn from the vendors’ own pages as of September 2026; the broader picture is in the confidentiality cluster.

The rename: Team became Business

On 29 August 2025 OpenAI wrote: “We’ve renamed the ChatGPT Team plan to ChatGPT Business to better reflect how customers use ChatGPT today.” A name change only; the plan, the terms and the workspace were the same. So when a bar opinion, a court order or an older vendor comparison refers to “Team”, read “Business”. The preservation order is the case in point: the tier it covered still exists and still sits outside Enterprise.

Business: what you get for $20 to $25 a seat

ChatGPT Business costs $20 per seat billed annually or $25 monthly; a Premium seat is $100 annual or $125 monthly (OpenAI, what is ChatGPT Business). For that a firm gets the commercial data terms most lawyers assume they already have on Plus and do not:

  • No training by default. “By default, we do not use your business data for training our models”, a commitment that applies to Business, Enterprise, Edu and the API (OpenAI, enterprise privacy).
  • Thirty-day deletion. “Any deleted or unsaved conversations are removed from our systems within 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm.”
  • Admin visibility. Workspace admins “can view, access, export, and delete end user conversations”. That is a governance feature and a warning: the managing partner can read what the associates typed.
  • A DPA and a SOC 2 Type 2 report. Both are available for Business.
  • Limited OpenAI access. Authorised employees and “specialized third-party contractors… solely to review for abuse and misuse”.

What OpenAI’s pages do not offer Business: a retention period you set, an audit log, SAML single sign-on, EU data residency or a BAA; and nothing in the plan exempts it from a future litigation hold. For a firm whose client material is anonymised before it goes in, that list is tolerable. For a firm that wants to say to a client or a regulator “here is the log and here is where the data lives”, it is not.

Enterprise: retention controls, audit log, SSO, residency

ChatGPT Enterprise is priced on request. The four additions that matter to a law firm are these.

  1. Retention you set. “Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.” Files not saved to a Library “expire after 48 hours” on Enterprise.
  2. An audit log. The Enterprise Compliance API gives admins a record of conversations and GPTs, which is what an insurer’s renewal questionnaire, an outside-counsel guideline or a protective order increasingly asks for.
  3. Tighter access. “Authorized OpenAI employees will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law.” Compare the Business wording, which includes third-party contractors reviewing for abuse.
  4. Identity and residency. SAML SSO ties access to your directory. New Enterprise and Edu workspaces can be created with data residency at rest in Europe (and, since 27 October 2025, in the UK, Japan, Canada, Australia and other regions), and since 16 January 2026 eligible Enterprise customers can choose in-region GPU inference in Europe (OpenAI, data residency). Residency is offered for new workspaces, so it is a decision to make at creation.

The fifth addition is the one you cannot see in the console: when a court ordered OpenAI to keep everything, Enterprise was carved out.

Extract what a plan's terms actually say
Here are the current terms, privacy page and DPA for [ChatGPT Business / ChatGPT Enterprise / Claude Team / Claude Enterprise]: <terms>[paste]</terms>. For each of these points, quote the exact sentence and give the section: training on inputs, outputs and uploaded files; retention of deleted conversations and files; who at the vendor may access content and why; audit or compliance logging; single sign-on; data residency at rest and for inference; zero data retention (which products, what is excluded); HIPAA BAA availability; what happens on termination. Where the documents are silent, write NOT ADDRESSED. Do not infer or soften.

Zero data retention: API only, and not for everything

Lawyers hear “zero data retention” and assume it is an Enterprise toggle. It is not. OpenAI’s own wording: “OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse… You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case.” ZDR and “Modified Abuse Monitoring” are “subject to prior approval by OpenAI and acceptance of additional requirements” (OpenAI, API data guide).

Three limits follow from that page. First, ZDR is an API arrangement, so it applies to software your firm or its vendor builds on the API, not to the ChatGPT app your associates open in a browser; ChatGPT Enterprise relies on 30-day deletion and admin-set retention instead. Second, it is not universal even on the API: endpoints such as conversations, assistants, threads, vector stores and files are not ZDR-eligible, and MCP servers you connect are third parties with their own retention. Third, some retention survives ZDR by design: “If the classifier detects potential CSAM content, the image will be retained for manual review, even if Zero Data Retention… is enabled.”

The practical reading for a firm: ZDR is what your legal-AI vendor should have with OpenAI (Harvey says it “requires Zero Data Retention (ZDR) by model providers”), not what you will get from buying ChatGPT Enterprise. Brad Lightcap’s line during the preservation order is the reason it matters: “If you are a business customer that uses our Zero Data Retention (ZDR) API, we never retain the prompts you send or the answers we return. Because it is not stored, this court order doesn’t affect that data.”

Claude Team, Premium seats and Enterprise compared

Anthropic’s tiers mirror OpenAI’s almost exactly on price and differ on two points of substance. Claude Team is $20 a seat annual or $25 monthly; Team Premium seats are $100 or $125; Enterprise is custom, with SCIM provisioning, audit logs and custom retention (claude.com/pricing). All commercial plans carry the no-training default: “By default, we will not use your inputs or outputs from our commercial products… to train our models” (Anthropic, model training).

Feature (September 2026) ChatGPT Business ChatGPT Enterprise Claude Team Claude Enterprise
Price per seat $20 annual / $25 monthly; Premium $100 / $125 On request $20 annual / $25 monthly; Premium $100 / $125 On request
Trains on your data by default No No No No
Deleted-chat retention 30 days Admin-set; 30 days after deletion 30 days Custom, minimum 30 days; default indefinite until set
Audit log Not listed Compliance API Not listed Yes
SSO / provisioning Not listed SAML SSO Not listed SCIM
EU data at rest No New workspaces, at creation No (US only) No (US only; EU via Bedrock or Vertex)
Zero data retention API only, on approval API only, on approval API and Claude Code for Enterprise, on approval Same, and “covered models” keep 30 days regardless
HIPAA BAA No ChatGPT for Healthcare and API customers Not listed HIPAA Type 1 reports; BAA excludes web search
Feedback retention Sent to OpenAI Sent to OpenAI Five years unless “Rate chats” off Five years unless “Rate chats” off

The two differences of substance. On residency, OpenAI can store a new Enterprise workspace in Europe and run inference there; Anthropic’s own platform stores workspaces in the US only, with inference in “global” or “us” regions, so EU processing of Claude means AWS Bedrock or Google Vertex, where the hyperscaler is the processor. On retention, Claude Enterprise’s default is “retained indefinitely unless a custom retention period is set”, minimum 30 days, changes tracked in audit logs; set it on day one (Anthropic, retention controls). And one Anthropic-specific wrinkle: from 9 June 2026 its “covered models” retain prompts for 30 days “on every platform where these models are offered”, even for ZDR customers. The Claude guide covers Projects, Cowork and the Word beta.

HIPAA and the BAA: a gate for PI and healthcare firms

Personal injury firms live on medical records, and medical records are protected health information. OpenAI’s business-data page says a BAA is “offered to ChatGPT for Healthcare and API healthcare customers” (OpenAI, business data). Guidance for legal professionals published by Supio puts it more bluntly: Free, Plus, Team and Business do not qualify, and a BAA requires a sales-managed Enterprise or Edu account with the agreement signed. Read together, the rule for a firm is simple. If PHI is going in, either sign a BAA at the Enterprise level, or use a PI platform or wrapper that operates under one; and remember, as the same guidance notes, that uploading medical records without safeguards is a Model Rule 1.6 problem before it is a HIPAA one.

Two adjacent facts. Anthropic publishes HIPAA Type 1 reports for Claude Enterprise and its first-party API, but its BAA “would not apply to use of the web search functionality”. And Google’s Gemini Notebook “is not covered by the Google Business Associate Agreement” even on Workspace. The personal injury guide works through the medical-chronology workflow with those constraints.

EU residency: Enterprise, Edu and the API

For a German, Austrian or UK firm this is often the deciding factor, and it points to Enterprise. OpenAI’s residency pages describe at-rest storage in Europe for new Enterprise and Edu workspaces (conversations, custom GPTs, prompts, uploaded files), in-region handling with zero data retention for API projects created with the Europe region, and, from 16 January 2026, in-region GPU inference for eligible Enterprise, Edu and Healthcare customers. Data-residency API endpoints carry a 10% price uplift for models released on or after 5 March 2026, and non-US residency requires approval for abuse-monitoring controls and a “Modified Retention amendment”.

Business offers none of this. Nor, on its own platform, does Anthropic. And Microsoft’s note that “Anthropic models are currently excluded from the EU Data Boundary” inside Copilot is a reminder that residency follows the model, not the brand on the login screen. Germany’s BRAK recommends preferring providers with servers in Germany or Europe and reads § 203 StGB so that the provider’s mere possibility of access counts; the EU residency guide compares OpenAI, Anthropic, Google and Microsoft in detail.

Litigation holds apply to Business too

Return to where this started. The preservation order in the New York Times case ran from 13 May to 26 September 2025. It covered Free, Plus, Pro and Team (now Business) and API customers without a ZDR agreement; it excluded Enterprise, Edu and ZDR-API customers. OpenAI was reported to have told European users it was temporarily suspending GDPR erasure rights because of the order; its October 2025 update confirmed that conversations from the EEA, Switzerland and the UK were carved out. On 5 January 2026 Judge Sidney Stein affirmed an order that 20 million de-identified logs be produced, reasoning that users had “voluntarily submitted their communications” to OpenAI.

A hold is a promise the vendor cannot keep to you when a court says otherwise. The best a firm can do is choose the tier with the fewest hostages: admin-set retention, EU residency where the carve-outs applied, and ZDR where the work runs through the API.

Write the internal note on which tier we bought and what goes in it
Draft a one-page internal note for a [12-lawyer firm] that has moved from personal ChatGPT Plus accounts to a [ChatGPT Business / Claude Team] workspace. Cover: what the workspace does and does not do (no training by default; 30-day deletion; admin visibility of conversations; no EU residency; no BAA); the three data classes (public, anonymised client material, privileged or health data) and which may go in; the anonymisation rule with placeholders and a key table kept offline; feedback buttons off; Temporary Chat not treated as zero retention; what to do if a client asks; and who approves exceptions. Plain English, no jargon, headed "Read before you paste". Under 500 words.

Recommendation by firm size

There is no verified survey of which tier firms of a given size buy, so what follows is a recommendation, not a statistic. It rests on the vendor terms above, ABA Formal Opinion 512’s instruction to read the terms before client information goes in, and the protective-order language courts now use.

Firm Buy Why Conditions
Solo or small firm, mostly domestic clients ChatGPT Business or Claude Team Same no-training default as Enterprise at $20 to $25 a seat; DPA; 30-day deletion Anonymise everything; feedback off; nothing privileged or health-related; consent language in the engagement letter
Small firm with PHI (personal injury, healthcare) Enterprise with a BAA, or a BAA-covered platform Business cannot give you a BAA Records never touch a plan without one
Firm with EU or UK clients or regulators ChatGPT Enterprise with EU residency, or a legal platform with EU hosting Business and Anthropic’s own platform store data in the US Create the workspace with residency from the start; check model routing
Mid-size firm with an IT function Enterprise (either vendor) Retention you set, audit log, SSO, tighter vendor access; outside the 2025 hold Set retention on day one; disable feedback; log who reviewed what
Any firm building tools on the API API with ZDR and Modified Abuse Monitoring The only way to get zero retention Prior approval; check endpoint eligibility

Whichever row you are in, one test settles most edge cases. Morgan v. V2X (D. Colo., 30 March 2026) amended a protective order to bar AI platforms unless the provider is contractually prohibited from “(1) storing or using inputs to train or improve its model; and (2) disclosing inputs to third parties except where essential”. Business and Team pass the first limb. Whether they pass the second depends on how you read abuse review by contractors, which is exactly why a court-facing matter belongs on Enterprise or a platform. The wider pricing guide puts these seat prices next to Harvey, Legora and CoCounsel.

Reply to a client who asks which ChatGPT plan we use
A client has asked, in writing, whether our firm uses ChatGPT and whether their information is safe. We use a [ChatGPT Business / ChatGPT Enterprise] workspace. Draft a reply of under 200 words that: states the plan and that OpenAI does not train on our workspace data by default; explains our anonymisation practice and that privileged strategy is kept off the tool; states the retention position honestly (30-day deletion; [admin-set retention]; no EU residency unless applicable); invites them to instruct us otherwise; and avoids any claim of "privilege" or "guaranteed" security. Warm, plain, no marketing language. Tag anything I should verify against the current terms [VERIFY].

Where to go next: the tier-by-tier confidentiality guide covers all five vendors, the ChatGPT guide covers Projects, custom GPTs and Deep Research once the workspace is set up, and the vendor due diligence checklist turns the questions above into a scoring sheet. In AI Lab for Lawyers we open the admin console of a Business and a Team workspace on screen, setting by setting, so that the plan decision is made on what the console actually shows rather than on the brochure.

Frequently asked questions

Is ChatGPT Business safe for law firms?

Safer than any consumer plan, and adequate for most anonymised client work. OpenAI does not train on Business workspace data by default, offers a DPA, deletes removed conversations within 30 days unless the law requires longer, and lets admins view, export and delete conversations. What Business lacks is admin-set retention, an audit log, EU data residency and a BAA, and its predecessor Team was covered by the 2025 New York Times preservation order while Enterprise was not.

What does ChatGPT Enterprise add for lawyers?

Four things that matter: workspace admins set how long conversations are retained; a Compliance API gives an audit log of conversations and GPTs; SAML single sign-on ties access to your identity system; and new workspaces can store data at rest in Europe, with in-region inference available since January 2026. Enterprise access by OpenAI staff is limited to incident resolution, recovery with your permission or legal requirement, and Enterprise was excluded from the 2025 preservation order.

Does ChatGPT offer zero data retention?

Only on the API. OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, and customers with a qualifying use case can request zero data retention for eligible endpoints, subject to prior approval. Endpoints such as files, vector stores, assistants and conversations are not eligible, and images flagged by the CSAM classifier are retained even under ZDR. ChatGPT Business and Enterprise instead rely on 30-day deletion and, for Enterprise, admin-configured retention.

Can a law firm get a BAA from OpenAI?

Not on Free, Plus or Business. OpenAI's business-data page says a BAA is offered to ChatGPT for Healthcare and API healthcare customers; guidance for legal professionals published by Supio reports that only sales-managed Enterprise or Edu accounts with a signed BAA qualify. A firm handling medical records in personal injury or healthcare matters should treat the BAA as a gate, or use a wrapper that operates under one, and remember that Model Rule 1.6 applies regardless of HIPAA.

Should a small firm buy ChatGPT Business or Claude Team?

Either, and the price is identical: $20 a seat billed annually or $25 monthly, with no training on your data by default and 30-day deletion. Choose on workflow, not privacy. Claude Team adds Projects and the Claude for Word beta, which writes native tracked changes; ChatGPT Business adds custom GPTs and Projects. Whichever you pick, switch off feedback buttons, anonymise client material, and move to Enterprise if you need EU residency or retention controls.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.