CompanyScope
by Janus Compliance

AI Vendor Data Protection File · Anthropic

The Claude Team Data Protection File

Product: Claude Team (Claude for Work, Team Plan). Version 1.0. By Michael K. Onyekwere, CIPP/E. Whole-set last verified 10 August 2026; next scheduled review 10 September 2026. CC BY 4.0 — reuse with attribution. Not legal advice.

Share this Anthropic profile:Share on XBluesky

A sourced, dated record of what Anthropic's own published documents say about data protection. Each answer is a quotation with its source URL, the date the page was read, and, where the document prints one, its own effective date. Where the published documents do not settle a question, the File records that rather than filling the gap. It is the primary-source evidence layer beneath the Anthropic vendor compliance profile.

Which documents actually govern a paid Claude Team subscription?

Documented

The Commercial Terms of Service, plus the documents they incorporate by reference: the Service Specific Terms (whose Section A is titled for the Team and Enterprise plans), the Data Processing Addendum, the Usage Policy, the Supported Regions Policy, and the Model Pricing Page. There is no standalone "Claude Team terms" document.

These Terms (including the Usage Policy, Supported Regions Policy, Service Specific Terms, DPA, Model Pricing Page and other documents or terms that are incorporated by reference by these Terms) constitute the parties’ entire understanding as to the Services’ provision and use.Section M.9 · document effective 17 June 2025 · accessed 22 July 2026
A. Claude for Work (Team Plan; Enterprise Plan)Section A heading · document effective 8 June 2026 · accessed 22 July 2026

Who is the UK customer actually contracting with?

Documented

Anthropic Ireland, Limited, for a customer in the UK, the EEA or Switzerland. Anthropic, PBC contracts with customers elsewhere.

“Anthropic” means Anthropic Ireland, Limited if Customer resides in the European Economic Area (“EEA”), Switzerland or UK, and Anthropic, PBC if Customer resides anywhere else.introductory paragraph, preceding Section A · document effective 17 June 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026

Is Team content used to train Anthropic’s models?

Documented

Not by default. The Commercial Terms state the prohibition without qualification. Two documented exceptions run alongside it, and both require somebody to switch them on: deliberately submitted feedback, and Development Partner Mode, which the Service Specific Terms make an organisation-level choice the customer has to enable.

Anthropic may not train models on Customer Content from Services.Section B · document effective 17 June 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026
By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models. If you explicitly report feedback or bugs to us (e.g. via our thumbs up/down feedback button), or otherwise choose to allow us to use your data, then we may use your chats and coding sessions to train our models.https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training · accessed 22 July 2026
If Customer enables Development Partner Mode, Anthropic may use the data that Customer submits to the Services (e.g., Customer Content) in connection with Anthropic’s products and services, including to train models.Section E · document effective 8 June 2026 · accessed 22 July 2026
In the event of any conflict between the Terms and these Service Specific Terms, these Service Specific Terms control for the relevant Services.preamble · document effective 8 June 2026 · accessed 22 July 2026

The reading

The three documents pull in different directions on their face. Section B of the Commercial Terms carries no exception wording at all, while the exceptions appear in the Service Specific Terms and in the privacy centre articles. A reader who stops at the Commercial Terms will come away with a stronger prohibition than the document set actually gives.

The Service Specific Terms settle the order of precedence in their own preamble, quoted above, so the exceptions govern for the services they cover. That is why the prohibition has to be read as a default rather than an absolute.

Trust and safety flagging is a retention and review exception in the current text; no document read for this File makes it a training exception. Anything beyond the two opt-in paths above is not established on these documents.

What does the thumbs up or thumbs down button actually do?

Documented

It sends the entire related conversation, not the single message, and that conversation may be stored for up to five years and used for training. Anthropic de-links the feedback from user and customer IDs before it is used; the content of the conversation is stored regardless. An Owner can switch the button off for the whole organisation.

When you provide us feedback via our thumbs up / down button, we will store the entire related conversation, including any content, custom styles, conversation preferences, or model settings, in our secured back-end for up to 5 years.https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training · accessed 22 July 2026
We de-link your feedback from your user and customer IDs before it’s used by Anthropic.https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training · accessed 22 July 2026
As a Primary Owner or Owner of a Team or Enterprise plan, you can disable the ability for members of your organization to submit feedback to Anthropic via the thumbs up / down button using the Rate chats setting, under Organization settings > Data and PrivacyDisabling Feedback · accessed 22 July 2026

In practice. Switching Rate chats off stops this from that point on. It does not reach back to a conversation that has already been rated, and Anthropic’s documentation does not describe a self-service way to withdraw an earlier rating.

The reading

The de-linking sentence reads as more protective than it is. It operates on the identifiers held alongside the conversation, so the user and customer IDs come off. The content of the messages is stored either way. If a client name, a matter reference or the substance of somebody’s affairs was in the conversation, de-linking does not remove it.

Claude Code has its own versions of the same button, and they run on different terms from each other. The /feedback, /bug and /share commands report through the same path to a five-year store and can feed product improvement. The after-session rating prompt stores only the rating itself; a separate optional follow-up can share the session transcript, which is retained for up to six months and is expressly outside model training. Treating all of these as one thing gets the retention answer wrong by a factor of ten.

Is Anthropic a processor, and does the DPA carry what UK GDPR expects?

Documented

The DPA fixes the roles: the customer is the controller and Anthropic is the processor. Comparing the DPA against the ICO’s checklist for processor contracts, the required content is present, each at a named section: processing on documented instructions (B.2), notice of an infringing instruction (B.5), assistance with impact assessments (B.6), confidentiality (B.7), sub-processor terms (Section C), assistance with data-subject requests (D.1 and D.2), security measures (E.1 and Schedule 2), audit rights including SOC 2 reports on request (F.1 and F.2), breach notice (G.1), and return or deletion within 30 days of termination (H.1).

With respect to Customer Personal Data, Customer is the controller and Anthropic is Customer’s processor.Section B.1 · document effective 24 February 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026
Unless required by applicable law to which Anthropic is subject, Anthropic will only process Customer Personal Data to provide or maintain the Services, and in compliance with Customer’s documented instructions...Section B.2 · document effective 24 February 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026

In practice. This is a comparison of documents, which shows the required terms are present. Two of the provisions are quoted here; the rest are section pinpoints to the same document, each due the same word-for-word re-read on the File’s review dates. Whether a processor performs them in practice is a separate question, answered through the audit artefacts the DPA itself provides for.

How quickly does Anthropic have to tell you about a breach?

Documented

Within 48 hours of becoming aware of it. A UK controller’s own clock to the ICO, where a breach is notifiable, is 72 hours, so a 48-hour vendor commitment leaves that timetable workable.

Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach, and will assist Customer in complying with Customer’s obligations under Applicable Data Protection laws by reasonably cooperating with Customer’s investigation of the Security Breach.Section G.1 · document effective 24 February 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026
“Security Breach” means a breach of Anthropic’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Personal Data.Section A.7 · document effective 24 February 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026

In practice. The commitment is tied to personal data. A pure service outage that never touches personal data falls outside this clause.

Data leaves the UK. What covers that?

Documented

The DPA incorporates the EU Standard Contractual Clauses together with the UK Addendum in its approved version. That is the safeguard route this contract adopts; UK law also recognises others, including the standalone International Data Transfer Agreement and, for US importers holding a UK Extension certification, the UK-US data bridge, but none of those is what this DPA uses.

The parties agree that, to the extent required by Applicable Data Protection Laws, the terms of the SCCs Module Two (controller to processor) and/or Module Three (processor to processor), as completed as described in Schedule 3 of this DPA, are hereby incorporated by reference and will be deemed to have been executed by the parties.Section I.1 · document effective 24 February 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026
“Approved Addendum” means the template addendum, version B.1.0 issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018 and laid before the UK Parliament on 2 February 2022Schedule 3.B · document effective 24 February 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026
By default, we may route customer traffic to select countries in the US, Europe, Asia and Australia, unless otherwise agreed upon or at your instructionsfull article · accessed 22 July 2026
data is stored in the USfull article · accessed 22 July 2026
process data for internal processes (such as safety-related review, product support, or incident response) in countries where we or our affiliates operatefull article · accessed 22 July 2026

In practice. The mechanism is only half of the job; the customer, as exporter, still owes a documented assessment that the mechanism gives adequate protection for its own transfer. The contract does not supply that.

The reading

The residency article answers three separate questions that are easy to run together: how traffic is routed, where data is stored, and where internal processing happens. Routing may touch several regions. Storage is in the United States. Internal processes such as safety review and incident response happen wherever Anthropic or its affiliates operate.

The route to lawfulness is the EU Standard Contractual Clauses with the UK Addendum bolted on, rather than a standalone International Data Transfer Agreement. A drafting fault is visible on the face of the DPA: the definition at Section A.10 labels the instrument an “International Data Transfer Addendum to the SCCs” while linking an ICO file named international-data-transfer-agreement.pdf, which is a different instrument. The operative provision at Schedule 3.B is the one to read, and it pins the Approved Addendum at version B.1.0 of 2 February 2022.

Two limits follow. No residency or in-region processing control for the Team plan is documented anywhere read for this File, so a requirement that personal data stays in the UK cannot be met on Team as the documents currently stand. And the transfer instrument and the transfer risk assessment are different things. UK GDPR puts the assessment on the exporter, which is the customer, and the contract supplies the safeguard without assessing whether it is adequate for the particular data being sent.

What does Claude Code send, and what stays on the machine?

Documented

A file the tool never reads stays where it is. A file a session reads into context is transmitted to Anthropic, processed under the DPA, and held on that surface for 30 days. A plaintext transcript of each session is also written on the local machine.

Claude Code runs locally. To interact with the LLM, Claude Code sends data over the network. This data includes all user prompts and model outputs, encrypted in transit via TLS 1.2+.https://code.claude.com/docs/en/data-usage · accessed 22 July 2026
Commercial users (Team, Enterprise, and API): Standard: 30-day retention periodData retention · accessed 8 August 2026

In practice. The paths by which session content can go back to Anthropic for product improvement, the feedback command and the after-session transcript prompt, have documented off-switches. Before fetching a web page the tool sends the hostname, and only the hostname, for a safety check.

Is Claude Code included with Team seats?

Documented

Yes, on Anthropic’s published plan pages. The Team plan card lists it and the pricing FAQ states it is included in all paid plans. The Service Specific Terms, which are the contract document dealing with the Team plan, do not mention Claude Code at all.

Claude Code is included in all paid plans. It shares the same usage limits as the rest of your plan, so your work in the terminal and your chats draw from one pool.Is Claude Code included in my plan? · accessed 28 July 2026
Commercial users: (Team and Enterprise plans, API, 3rd-party platforms, and Claude Gov) maintain existing policies: Anthropic does not train generative models using code or prompts sent to Claude Code under commercial terms, unless the customer has chosen to provide their data to us for model improvement […]Data training policy · accessed 22 July 2026

In practice. The Claude Code documentation points Team users to the same commercial contract that governs the rest of the plan, so the data-protection position follows the Commercial Terms and the DPA rather than anything separate.

The reading

The text of the Service Specific Terms effective 8 June 2026 was searched for “Claude Code”. It appears only in the site’s product navigation menu, never in the terms themselves. So the inclusion is a product statement on a pricing page rather than a contractual commitment, and whether it is committed anywhere is not established on the documents read for this File.

A pricing page can be edited. If Claude Code access were withdrawn from the Team tier, the contract as drafted does not appear to be the place a customer would look for a remedy.

Who inside your organisation can see what?

Documented

A public project exposes its contents and knowledge files to everyone in the workspace. Chats inside it stay private unless a user shares one, and sharing stays inside the organisation.

Everyone in your organization can view and use the project.Understand the two project visibility options · accessed 10 August 2026
Even if a project is public, your chats within that project will be private and inaccessible to other members of your organization unless you manually share them.https://support.claude.com/en/articles/9519189-manage-project-visibility-and-sharing · accessed 22 July 2026 · re-read against the live page 28 July 2026
Archiving a project doesn’t reset its sharing permissions or remove members. All members, permission levels, and project knowledge are preserved, and everything is restored exactly as it was when you unarchive the project. To revoke someone’s access, remove them in the project’s sharing settings before or after archiving.What happens when archiving a shared project? · accessed 28 July 2026
Disabling the public project feature allows Team and Enterprise owners to restrict the creation of public projects across their organization while maintaining internal sharing capabilities.introduction · document effective 16 March 2026 · accessed 28 July 2026
All existing public projects will be converted to private projects.When you disable public projects · document effective 16 March 2026 · accessed 28 July 2026

In practice. The documentation does not describe a routine way for an administrator to browse members’ private chats. It does record that an organisation-level export run by the Primary Owner can contain conversations and uploaded files. Removing a member ends that member’s access, and ends other members’ access to that member’s own chats and private projects, but projects they had shared stay available. Removal is not a deletion event.

The reading

Archiving is not a way to withdraw access, and this is the single most likely thing for an administrator to get wrong. Archiving preserves every member and permission level exactly as they were. Access has to be removed in the sharing settings, separately.

That page changed on this point during July 2026. Any note written before then may say the opposite, which is the reason every quotation in this File carries its own read date in addition to the whole-set date at the top.

An owner can switch public projects off across the whole organisation. Doing so converts existing public projects to private and blocks new ones, while leaving person-to-person sharing intact, so it narrows the default without stopping people working together.

What does sharing a chat actually share?

Documented

A snapshot of the messages sent up to that moment, and it stays inside the organisation. Team and Enterprise plans cannot share a chat publicly. Later messages stay private unless somebody updates the snapshot. Uploaded files are excluded from it, and so is the raw data behind tool calls.

Users on Team and Enterprise plans can only share chats with other members of the same organization, not publicly.Share chats · document effective 15 June 2026 · accessed 22 July 2026
If you share a chat that contains an attached file, the file itself is not included in the shared snapshot and remains private.Attached files · document effective 15 June 2026 · accessed 8 August 2026
When sharing chats that use MCP integrations, the raw data retrieved from MCP tool calls remains hidden in the shared snapshot.MCP tool calls · document effective 15 June 2026 · accessed 8 August 2026
The chat snapshot includes all messages that were sent prior to sharing the chat, including any artifacts. All messages sent after sharing a chat will remain private by default. However, you can choose to update the shared snapshot to include new messages.Share and unshare chats · accessed 22 July 2026 · re-read against the live page 28 July 2026

In practice. Unsharing is a visibility change on the same chat, and the documented effect is on the link: the chat moves from Shared back to Private, which disables the direct link.

The reading

A snapshot is a point in time, so the question to ask about any shared chat is what had already been said when the share happened, and whether anyone has pressed update since. A chat that looked harmless when shared does not become visible again as it continues, which cuts both ways: it limits exposure, and it means the shared version can quietly stop matching the conversation people think they are reading.

Files being excluded from the snapshot is the useful part for a professional firm. A document uploaded into a chat does not travel with the share.

Who else gets the data, and what say do you have?

Documented

Anthropic publishes a sub-processor list and commits to it in the DPA. On a new appointment it gives "reasonable notice", with no fixed number of days, and a fifteen-day window to object on reasonable data-protection grounds.

Anthropic’s list of subprocessors is available at https://www.anthropic.com/subprocessors.Schedule 4 · document effective 24 February 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026
C.3. In the event that Anthropic wishes to appoint an additional Subprocessor: (a) Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data; and (b) Customer may, on the basis of reasonable data privacy or data security concerns, object to Anthropic’s use of such Subprocessor by providing Anthropic with written notice of the objection within fifteen (15) days of the date of such notice, or Customer is deemed to consent to the new Subprocessor. In the event Customer objects to Anthropic’s use of a new Subprocessor, Customer and Anthropic will work together in good faith to find a mutually acceptable resolution to address any objection raised by Customer.Section C.3 · document effective 24 February 2025 · accessed 22 July 2026

In practice. That address redirects to Anthropic’s Trust Center, which carries the current list and a subscription option for change notices. If an objection cannot be resolved, the practical backstop is the customer’s right to terminate on notice under the Commercial Terms.

The reading

Read the two periods separately. The fifteen days is the deadline for objecting. The length of the notice itself is left undefined at “reasonable notice”, so the customer does not know from the contract how much warning it will get, only how long it has to react once warned.

Silence within the fifteen days is deemed consent. Combined with an objection window that runs from the notice rather than from the appointment, the practical effect is that a customer who does not see the notice has agreed to the subprocessor without knowing it. The subprocessor list page itself carried no “last updated” date when read on 22 July 2026, so subscribing to the Trust Center change notices is the only reliable way to see them.

The DPA lists special categories of personal data as “None”. Does that mean health data cannot go through Claude?

Unreconciled

Nothing in the documents prohibits it, though the Usage Policy treats healthcare decision-making as a high-risk use that requires review by a qualified professional and disclosure that AI was involved. Schedule 1 is the standard description of the processing that the Standard Contractual Clauses require. It records the categories of data subjects and of personal data as matters the customer determines, then records special categories as “None”, which will not match a customer whose ordinary work involves health or other special-category material.

B.1. Categories of data subjects: Determined by Customer (in accordance with the Agreement). B.2. Categories of personal data: Determined by the Customer (in accordance with the Agreement). B.3. Special categories of personal data (if applicable): None.Schedule 1, Part B · document effective 24 February 2025 · accessed 22 July 2026
When using our products or services to provide advice, recommendations, or in subjective decision-making directly affecting individuals or consumers, a qualified professional in that field must review the content or decision prior to dissemination or finalization.High-Risk Use Cases · accessed 10 August 2026

In practice. The protections themselves are unaffected. The substantive obligations are drafted around “Customer Personal Data” as defined, with no special-category carve-out: processing on documented instructions at B.2, confidentiality at B.7, security at E.1 and Schedule 2, breach notice at G.1, and deletion or return at H.1. Those apply to special-category data on the same terms as any other personal data.

The reading

A customer whose own record of processing shows special-category data therefore holds a processor schedule describing something narrower than what it actually sends. For the transfer safeguard the description does more work: the Standard Contractual Clauses say the details of the transfers, including the categories of data, are specified in Annex I.B, which the DPA completes as Schedule 1 Part B, and that schedule says none is sent. A customer transferring special-category data is relying on clauses whose executed description records no such transfer, which is the strongest reason to have the schedule corrected rather than merely noted.

How to record that is a matter for the customer’s own documentation, and it is a fair question to put to Anthropic. It is also the kind of inconsistency that is easier to resolve before an incident than during one.

Do the documents say anything about legal professional privilege?

Not established

No. Privilege is not addressed in the Commercial Terms, the Service Specific Terms or the DPA. What those documents do provide is a confidentiality obligation on every person Anthropic authorises to process customer personal data.

Anthropic will ensure that each person it authorizes to process Customer Personal Data is subject to an appropriate duty of confidentiality.Section B.7 · document effective 24 February 2025 · accessed 22 July 2026

In practice. Anthropic maintains a separate article on how it handles governmental requests for user information (support.claude.com/en/articles/9519291, read 10 August 2026). A firm sending privileged material to any cloud service will want to read that page itself and reach its own view. The contract documents do not speak to it.

The reading

Silence is the finding here. Vendor contracts of this kind do not usually address privilege, and the confidentiality obligation at B.7 is the ordinary protection they give.

Privilege is not a contractual right that a supplier can grant. Whether privilege survives disclosure to a processor is a question of law, and a data processing addendum cannot answer it.

Who is Anthropic’s UK representative under Article 27 UK GDPR?

Not established

Not established from the public documents. A UK customer contracts with Anthropic Ireland, Limited, and the DPA incorporates the ICO’s Approved Addendum for UK transfers. No Article 27 representative is named in any of the legal documents reviewed, and no ICO registration number appears in them.

“Anthropic” means Anthropic Ireland, Limited if Customer resides in the European Economic Area (“EEA”), Switzerland or UK, and Anthropic, PBC if Customer resides anywhere else.introductory paragraph, preceding Section A · document effective 17 June 2025 · accessed 22 July 2026 · re-read against the live page 28 July 2026

The reading

Anthropic has a UK group company, Anthropic Limited (Companies House no. 14604577, registered in London; checked 8 August 2026). Whether that presence gives the contracting entity, Anthropic Ireland, Limited, an establishment in the UK, which would take Article 27 out of play, or whether Anthropic instead relies on a representative not named in these documents, is not stated on the public text.

For most customers this is a question about Anthropic’s own position rather than about theirs: a customer’s own Article 27 position turns on its own establishment rather than its supplier’s.

How do you prove what the terms said on the day you signed up?

Documented

With your own dated copy. No Anthropic legal document publishes a version number. Each page shows an effective date and a link to a previous version, which gives two points rather than a numbered history. Privacy centre articles are dated inconsistently: some carry a fixed date, and at least one, as read on 22 July 2026, carried only a relative timestamp such as “Updated over 3 weeks ago”.

Anthropic may update these Terms at any time, to be effective 30 days after the updates are posted by Anthropic or Customer otherwise receives Notice, except that updates made in response to changes to law or regulation take effect immediately upon posting or Notice. Changes will not apply retroactively.Section M.3, Amendment and Modification · document effective 17 June 2025 · accessed 22 July 2026

In practice. The consequence falls on the customer. Point-in-time evidence of the terms you contracted under depends on a copy you took and dated yourself, because the published page shows whatever is current when you look.

The reading

This is why every quotation in this File carries its own read date alongside any date the document prints. The printed date is the vendor’s claim about the document; the read date is the age of this record of it.

A controller relying on a vendor term in its own accountability documentation, and citing only a URL, is citing something that can change underneath it without notice or trace.

Are the retention periods contractual, or can they be changed?

Documented

Almost none of them are contractual. The Commercial Terms contain no retention or deletion timetable at all. Every row in the retention table in this File cites a page Anthropic can revise without amending the contract: privacy centre articles, the Claude Code documentation, and a support centre article. The single retention commitment written into a contractual document is the deletion-on-termination clause in the DPA, quoted below.

H.1. Within thirty (30) days of the date of termination or expiration of the Agreement, Anthropic will: [...] delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors, except to the extent (i) Applicable Data Protection Laws or other applicable legal or regulatory requirements requires storage of the Customer Data, (ii) retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.Section H.1 · document effective 24 February 2025 · accessed 22 July 2026

In practice. Anyone writing a retention schedule from these documents should record where each period comes from, because the two kinds of source behave differently. A contractual term changes by agreement. An article changes when the vendor edits the page.

The reading

A retention period quoted from a help centre article and a retention period written into a data processing addendum look identical in a compliance document, and they are different promises.

The practical consequence for a controller is that the retention entry in its record of processing rests, for most surfaces, on a page the vendor can edit. Anthropic’s published periods are clearer than most. The response is to date the entry, cite the article, and re-read it on a schedule, which is what the maintenance covenant on this File exists to do.

The third carve-out in H.1, retention necessary to combat harmful use of the Services, has no stated period attached to it.

Can a Team administrator set a retention period?

Not established

No such control is documented for Team. A custom retention period is documented as an Enterprise feature, and the documented Team controls are chat deletion, the Rate chats toggle, and an organisation export.

This feature is available to Enterprise plan customers.https://privacy.claude.com/en/articles/10440198-configure-custom-data-retention-controls-for-enterprise-plans · accessed 22 July 2026

In practice. The sentence "By default, data is retained indefinitely unless a custom retention period is set" appears in that same Enterprise article and describes the Enterprise default. It should not be quoted as a statement about Team.

What happens to rated conversations when the contract ends?

Unreconciled

Not settled on the text as written. Feedback submissions are held for five years. That five-year period is not among the stated exceptions to the DPA’s deletion-on-termination clause, and the public documents do not reconcile the two.

Where you have provided feedback to us (e.g. by submitting feedback through our thumbs up/down button or sent bug reports), we retain data associated with that submission for 5 years.https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data · accessed 22 July 2026

In practice. One more reason to keep the Rate chats switch off where client material is in play.

What is kept, and for how long

SurfaceKeptHow longSource
Claude Team saved chatsConversations, until you actNo automatic expiry is documented for Team. A custom retention period is documented as an Enterprise feature.https://privacy.claude.com/en/articles/10440198-configure-custom-data-retention-controls-for-enterprise-plans · accessed 22 July 2026
A chat you deleteRemoved from history at onceDeleted from back-end storage within 30 dayshttps://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data · accessed 22 July 2026
Claude Code (server side)Prompts, outputs, file content read into a session30 days, the standard position for commercial usersCommercial users (Team, Enterprise, and API) · accessed 22 July 2026
Claude Code (on the machine)Plaintext session transcript30 days by default, adjustable through cleanupPeriodDaysLocal caching · accessed 22 July 2026
Rated conversations (thumbs up or down)The whole related conversationUp to 5 yearshttps://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training · accessed 22 July 2026
Safety-flagged contentInputs and outputs, and classification scoresWhere a chat is flagged by the automated trust and safety systems as violating the Usage Policy: inputs and outputs up to 2 years, classification scores up to 7 yearsUsage Policy Violations · accessed 22 July 2026
Covered Models (models Anthropic designates)Prompts and completions on those modelsAt least 30 days by default, then automatic deletion, unless subject to a safety investigation or legally required. Zero data retention is not available for these models in workspaces, Claude Enterprise organizations, or third-party platforms.https://support.claude.com/en/articles/15425695-covered-models · accessed 27 July 2026 · re-read against the live page 8 August 2026

How the dates work. Accessed is when a quotation was first captured. Re-read is set only where the quotation was actually checked against the live page again on that date; its absence means it has not been re-read since it was captured. The whole-set verification date at the top is the date the entire File was checked together. It is never advanced to match a single source's later re-read, because that would claim a full sweep that did not happen.

Machine-readable version: https://companyscope.io/api/files/claude-team (JSON, CC BY 4.0).


Share this Anthropic profile:Share on XBluesky

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe — free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

For the analysis behind this record, see the Anthropic vendor compliance profile. For real agent failures analysed legally, the AI Agent Incident Register. For ongoing support, Janus DPO-as-a-Service.