Glossary
Zero data retention
Zero data retention is a contractual commitment by an AI provider not to permanently store incoming requests and their content after processing. Prompts, documents, and responses are used only to produce the answer and are not kept afterwards. For small and medium-sized businesses this matters because confidential company data does not remain in the AI provider's systems.
Last updated: 2026-08-03
By default, many AI services keep incoming requests for a limited period – for abuse detection or quality assurance, for example. Zero data retention is the contractually agreed departure from that default: the provider processes the request, returns the answer, and does not permanently store the content. The term is distinct from a training exclusion – that governs whether data may be used to train AI models, while zero data retention governs whether it is kept at all. In practice, the two commitments are often combined.
In everyday business, confidential content quickly ends up in AI requests: customer emails, draft contracts, internal documents. Without zero data retention, every request adds to a growing pool of such data at the AI provider – a point data protection officers regularly probe when reviewing an AI tool. With zero data retention, data flows through processing instead of accumulating with the provider. That shrinks the attack surface and simplifies the answer to the question of where company data actually ends up.
Processing region, storage and training use depend on the approved model endpoints and applicable agreements. Review these terms for your installation. Roles and permissions control access to company knowledge.
Zero data retention is one building block, not the whole package: the commitment covers the AI provider, not automatically every other party in the processing chain. When reviewing an AI tool, also look for a data processing agreement under Art. 28 GDPR, a transparent sub-processor list, and an enforced permission model.
