Vendor comparison
OpenAI vs Anthropic DPA: side-by-side compliance read for buyers
Independent compliance comparison from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-10-04. Not legal advice.
TL;DR. Both vendors run protective commercial defaults: no training on customer data through the API and Enterprise tiers by default, and zero data retention available on approval. They match on the API retention default of 30 days. Anthropic's DPA incorporates the EU SCCs, the UK Addendum and a Swiss addendum, whereas OpenAI's DPA deems the SCCs entered into only for UK data and relies on OpenAI Ireland's onward-transfer arrangements for EEA and Swiss data. OpenAI offers EU data residency on its own API to approved customers, which Anthropic's own API does not, and OpenAI's subprocessor objection terms are stronger. Consumer-tier defaults at both vendors are not protective and need their own policy.
How the two compare on the eight clauses that decide the risk
This comparison is the buyer's-side read against the eight DPA clauses set out in the DPA for AI vendors hub. Full vendor-by-vendor detail lives in the OpenAI profile and the Anthropic profile.
1. Commercial training default
| | OpenAI | Anthropic | |---|---|---| | API | No training on customer data by default | No training on customer data by default | | Enterprise / Team | No training | No training | | Contract location of commitment | Services Agreement, section 4.2 | Commercial Terms, section B | | How training can be enabled | An organisation owner opts in to data sharing in the organisation settings | User feedback reports, or the opt-in Development Partner Program |
Both vendors are aligned. The commitment is set out in the main commercial agreement rather than on a marketing page, and the default favours the buyer.
2. Consumer training default
| | OpenAI | Anthropic | |---|---|---| | Free / consumer Plus | Opt-out (training default on; user has to disable) | Opt-in (training default off; user has to enable) since 2025-10-08 | | Retention on consumer plans | Conversation history retention up to 30 days by default; longer with memory enabled | Up to 5 years for users who opted in to training |
The consumer-tier default is the area where the two vendors diverge most. Anthropic's flip to opt-in on 2025-10-08 made consumer claude.ai the more protective consumer default, though the 5-year retention horizon for opted-in users is longer than OpenAI's consumer retention. Neither default is good enough to support PHI, special-category GDPR data, or anything subject to a procurement gate.
3. API retention default
| | OpenAI | Anthropic | |---|---|---| | Default API retention | 30 days | 30 days | | ZDR available | Yes, approval-gated | Yes, approval-gated | | What ZDR does not cover | Application state on ineligible endpoints (including Assistants, files, vector stores and batches); images flagged as potential CSAM | Content flagged by trust and safety systems (up to 2 years); safety classifier results; Covered Models; features such as Batch, the Files API and code execution |
Neither vendor's default is shorter than the other's. Anthropic's privacy centre, in an article dated 1 July 2026, puts commercial deletion at 30 days, and OpenAI retains API abuse-monitoring logs for up to 30 days. Buyers who need shorter than that go through the ZDR approval process at both vendors.
4. Subprocessor depth
| | OpenAI | Anthropic | |---|---|---| | Published subprocessor list | Yes (last updated 9 July 2026) | Yes (20 entries on 4 October 2026) | | Notice of additions | By blog post, in the service, or by email to subscribers | "Reasonable notice" before the new subprocessor gets access | | Objection mechanism | Customer may object within 30 days; if unresolved within 30 days, either party may terminate the affected services | Customer may object within 15 days, otherwise deemed to consent; the parties work in good faith, with no express termination right | | Cloud infrastructure at time of review | Microsoft, CoreWeave, Oracle Cloud Infrastructure, Google Cloud Platform, Amazon Web Services and Cerebras | Google Cloud Platform, Amazon Web Services and Microsoft Azure, none designated as primary | | Cross-vendor subprocessor relationship | Microsoft is one of six cloud infrastructure providers | Anthropic became a Microsoft 365 Copilot subprocessor on 2026-01-07 |
Both vendors now use several of the same clouds, so a buyer cannot assume that either vendor's processing stays within one cloud provider's regional commitments. Data-flow diagrams and transfer impact assessments should be drawn from the current subprocessor lists.
5. EU/UK transfer mechanism
| | OpenAI | Anthropic | |---|---|---| | EU SCCs between customer and vendor | Not for EEA or Swiss data; OpenAI Ireland's onward transfers rest on agreements containing the SCCs or an adequacy decision | 2021 Module 2 and Module 3, incorporated by reference | | UK | SCCs (Module 2 and Module 3) as amended by the UK Addendum, deemed entered into with OpenAI OpCo, LLC | UK Addendum to the SCCs | | Swiss addendum | None in the DPA | Yes | | Transfer Impact Assessment | Buyer responsible | Buyer responsible; Anthropic undertakes to provide the information reasonably necessary to complete one | | Data residency on the vendor's own API | Europe (EEA and Switzerland) for approved customers who hold abuse-monitoring controls and sign a Modified Retention amendment; the UK region stores data but does not process it there | None: inference is global by default or US on request, and data at rest is in the US | | Other routes | Azure OpenAI for buyers on Microsoft | Claude on Amazon Bedrock or Google Cloud, where European processing depends on the model; the Microsoft 365 Copilot route is out of EU Data Boundary scope as of 2026-01-07 |
A buyer that needs EU-only processing can get it on OpenAI's own API once approved, whereas with Anthropic it means moving to a cloud platform and choosing a model that is offered in-Region there.
6. Security commitments
| | OpenAI | Anthropic | |---|---|---| | SOC 2 Type II | Yes | Yes | | ISO 27001 | Yes | Yes | | ISO 27701 | Yes | Not listed on Anthropic's trust centre | | ISO 42001 (AI management system) | OpenAI states that it maintains an ISO/IEC 42001:2023 management system; certificate not confirmed | Certified; a 2025 ISO 42001 certificate is listed on Anthropic's trust centre | | HIPAA BAA available | Yes, on Enterprise / API Enterprise / Azure OpenAI | Yes, on Enterprise; sales-channel gated | | GDPR Article 28 commitments | In DPA | In DPA |
Both vendors meet the usual floor of SOC 2 and ISO 27001. On ISO 42001, Anthropic lists a certificate, while OpenAI describes a management system it maintains without saying it is certified. The HIPAA BAA picture matters for US healthcare buyers - see the HIPAA hub for the procurement workflow.
7. Deletion and contract end
Both vendors delete customer data within 30 days of the end of the contract: OpenAI under section 11.3 of its Services Agreement, unless it is legally required to retain the data or the customer has agreed otherwise, and Anthropic under section H.1 of its DPA. For buyers who fine-tuned a model on customer data, the practical question is whether deletion extends to the fine-tuned model, which should be confirmed in writing with either vendor.
8. Breach notification
OpenAI's DPA commits to notify the customer "without undue delay after becoming aware of any Personal Data Breach", with no fixed number of hours. Anthropic's DPA commits to notify "without undue delay, but in any event within 48 hours". A controller still has its own 72-hour deadline under Article 33 GDPR, so the vendor's commitment needs to leave time for that.
Picking between them
The decision usually turns on two factors that lie outside the DPA itself.
Pick OpenAI when:
- The buyer needs EU data residency on the vendor's own API
- The buyer is already on Azure and wants the Azure OpenAI route for region-locked deployment
- The buyer needs the breadth of HIPAA-eligible products (Enterprise, Edu, API on Enterprise, Azure OpenAI)
- The buyer's app stack is built against the OpenAI API surface
Pick Anthropic when:
- The buyer's procurement gate requires the consumer-tier default to be opt-in for training, not opt-out
- The buyer is already using Claude through the Claude API and wants to consolidate
Consider both alongside each other when:
- The buyer's deployment is a multi-model pipeline (common in legal, financial-services, and clinical-summarisation work)
- The buyer needs a fallback model provider for resilience, bearing in mind that both vendors now list Microsoft, Amazon Web Services and Google Cloud among their infrastructure subprocessors
The consumer-tier exposure is the trap
The single biggest procurement risk with either vendor is not the commercial DPA - both are protective. It is the consumer-tier exposure when staff use the free or personal product alongside the contracted enterprise one.
A staff member who pastes a draft procurement contract into free ChatGPT or free claude.ai is operating under that vendor's consumer default. The enterprise DPA does not apply. The buyer's procurement policy has to address this directly, either by blocking the consumer products at the network or by writing an explicit usage policy that staff have signed.
Related reading
- The hub on the eight DPA clauses: DPA for AI vendors
- The EU AI Act deployer-side read for both vendors: EU AI Act for AI buyers
- The US healthcare-specific read: HIPAA for AI tools
- Cross-comparison: OpenAI vs Copilot enterprise compliance
- Cross-comparison: Perplexity vs ChatGPT for regulated industries
Talk to Michael about OpenAI or Anthropic - or your AI vendor governance more broadly
CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.
Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
For ongoing AI compliance support, work with Janus DPO-as-a-Service. Browse the vendor index, other vendor comparisons, or the AI Agent Incident Register.