General-purpose AI / LLM API
Anthropic compliance: GDPR, AI Act, DPA, training, transfers
Independent compliance research from Janus Compliance. Reviewed by Michael K. Onyekwere, CIPP/E. Last reviewed 2026-10-04. Not legal advice.
TL;DR. Commercial products (API, Team, Enterprise): contractually no training by default. Anthropic deletes API inputs and outputs within 30 days of receipt or generation, which is the same default window OpenAI runs. Consumer products (claude.ai free, Pro, Max): training default flipped to opt-in on 2025-10-08, with up to 5-year retention. Anthropic became a Microsoft 365 Copilot subprocessor on 2026-01-07 and is explicitly out of EU Data Boundary scope for that route.
DPO action: map staff use of consumer claude.ai (defaults are no longer protective); decide whether to allow Anthropic models in Copilot tenants; apply for ZDR if data sensitivity warrants; sign a BAA before any PHI (API or Enterprise; covered models use 30-day retention, not ZDR).
Primary-source evidence. For the Claude Team plan specifically, the Claude Team Data Protection File records what Anthropic's own Commercial Terms, DPA, Service Specific Terms and privacy-centre articles say - every answer a dated verbatim quote, with the documented gaps flagged. This profile is the analysis; that File is the receipts.
What the tool does
Anthropic runs Claude - both the consumer-facing chat product (claude.ai) and the API behind it. Buyers will be looking at one of three things: the API (for embedded apps), Claude Team / Enterprise (for staff use), or claude.ai consumer plans. As with OpenAI, the terms, training defaults and retention defaults differ between commercial and consumer products, so each has to be assessed on its own terms.
Data processed
- Text input from users / apps
- Documents you upload for analysis
- Image content (Claude vision)
- Tool-use / function-call results
- Embeddings (Anthropic's first-party embeddings story has shifted through 2025-2026 via the Voyage AI acquisition; if your use case relies on embeddings, confirm the current API surface and terms)
Special-category likelihood: High for the same reasons as OpenAI - if staff or end users can type freely, sensitive content gets in. DPIA needed for any public-facing or HR-adjacent deployment.
Default geographic processing: inference runs in the "global" geography by default, which Anthropic describes as "Inference may run in any available geography for optimal performance and availability." A customer can restrict inference to the United States per request, at 1.1 times the standard price, and data at rest is stored in the US, because "Currently, "us" is the only available workspace geo." (Anthropic data residency documentation, checked 4 October 2026.)
DPA availability
Anthropic publishes its DPA at anthropic.com/legal/data-processing-addendum, and the Privacy Center article below links to it. The DPA is headed Effective February 24, 2025 and is automatically incorporated into the Commercial Terms of Service - when a customer accepts the Commercial Terms, they accept the DPA without a separate signature flow.
- Pointer (Help Center):
https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa- short article that links the actual DPA document - The DPA itself covers SCCs Module 2 / Module 3 for international transfers, the UK International Data Transfer Addendum, and a Swiss addendum
- Establishes the customer as data controller, Anthropic as processor
- For customers in the EEA, Switzerland and the UK, the Commercial Terms are governed by Irish law, and disputes go to "a sole arbitrator in Dublin, Ireland pursuant the UNCITRAL Arbitration Rules". The SCCs are governed by Irish law with the Irish courts as forum, and the Swiss addendum applies Swiss law to transfers governed by Swiss data protection law. Customers elsewhere contract with Anthropic, PBC under California law.
- Effective date on the document: 2025-02-24
This auto-incorporation model is buyer-friendly compared to OpenAI's account-gated DPA flow, but the implication is the same: read the terms before signing the commercial contract. Note that the SCC modules, UK Addendum, and Irish governing-law provisions are stated in the DPA document itself, not in the Help Center pointer article.
Subprocessor list
Anthropic publishes its subprocessor list at trust.anthropic.com/subprocessors, which held 20 entries when checked on 4 October 2026. Google Cloud Platform, Amazon Web Services and Microsoft Azure each appear as cloud infrastructure, worldwide, for all products, and the list does not designate any of them as the primary provider. The other entries include Cloudflare, Stripe, WorkOS, Intercom, Twilio, Sentry and ElevenLabs.
Because all three clouds can process data for all products, a buyer should not assume that one cloud's regional commitments apply. Under the DPA, Anthropic gives "reasonable notice" of a new subprocessor, and a customer may object on reasonable data privacy or security grounds "within fifteen (15) days of the date of such notice, or Customer is deemed to consent to the new Subprocessor." The DPA provides for the parties to work together in good faith on an objection and gives no express right to terminate.
Training-on-customer-data position
Commercial products (API, Team, Enterprise): not used for model training by default, and contractually restricted. The Commercial Terms state that "Anthropic may not train models on Customer Content from Services." Two routes lead to training on commercial data: feedback a user reports explicitly, which the Privacy Center says may be used to train models, and the Development Partner Program, under which a customer that enables the permissive data setting allows Anthropic to use its data "including to train models" (Service Specific Terms, effective 31 August 2026).
Consumer products (claude.ai free, Pro, Max): default changed 2025-10-08. Consumer plans now default to opt-in for model training, with data potentially retained for up to 5 years for training purposes unless the user opts out. This is a material change that many enterprise buyers have not registered. Staff using personal claude.ai accounts are now in a training-eligible flow by default.
API log retention: Anthropic's privacy centre, in an article dated 1 July 2026, states that for API users it automatically deletes inputs and outputs on its backend within 30 days of receipt or generation. It lists four exceptions: services with longer retention under the customer's control such as the Files API, a separate agreement such as zero data retention, retention needed to enforce the Usage Policy, and retention required by law. Anthropic's developer documentation describes the default differently, stating that conversation content "is not retained by default; the exception is Covered Models, which require 30-day retention." Because the two documents differ, a retention schedule should record the 30-day window from the Privacy Center. Where a chat or session is flagged by Anthropic's trust and safety systems, inputs and outputs may be kept for up to 2 years, and this applies even under zero data retention. Zero Data Retention (ZDR) is subject to Anthropic's approval, is requested through the sales team and is enabled per organisation. Under ZDR Anthropic "does not store customer prompts or responses at rest after the API response is returned", although it still retains safety classifier results, and features such as the Batch API, the Files API and code execution are outside it.
Covered Models. Anthropic designates Claude Mythos 5.1, Claude Fable 5.1, Claude Mythos 5 and Claude Fable 5 as Covered Models. Their prompts and completions are retained for at least 30 days, the policy applies "wherever Covered Models are offered, including third-party cloud platforms", and the Service Specific Terms state that Anthropic's right to retain and review that data "supersedes any modified retention commitments (e.g., ZDR)". Anthropic has offered eligible customers time-limited ZDR for Fable 5 and Fable 5.1 as a transition to its Enterprise Frontier Safeguards programme.
Anthropic's commercial defaults match OpenAI's on retention, since both delete API inputs and outputs within 30 days and gate anything shorter behind ZDR approval. The consumer-tier shift to default-opt-in for training is a real risk that mirrors OpenAI's shadow-use problem. - My read
EU / UK transfer position
Anthropic relies on Standard Contractual Clauses (SCCs) (Module Two and Module Three) for EU transfers, incorporated through the DPA. The DPA explicitly adapts the SCCs for the UK International Data Transfer Addendum (the addendum laid before UK Parliament on 2 February 2022) and includes an addendum for transfers subject to Swiss data protection law. The SCCs are governed by Irish law, with the Irish courts as forum, and Anthropic undertakes to provide the information reasonably necessary for a customer to complete a transfer impact assessment.
Anthropic holds no Data Privacy Framework certification. The participant registry at dataprivacyframework.gov was searched again on 4 October 2026, active and inactive, with a control query that returned Microsoft, and returned nothing for Anthropic (317 active and 341 inactive organisations file under A, and it is not among them). Neither the DPA nor the privacy policy now in force, effective 10 September 2026, mentions the framework, and OpenAI is in the same position. The SCCs and the Swiss and UK addenda in the DPA carry the transfer on their own, so a transfer impact assessment is required.
EU data residency. Anthropic's own API offers no EU option: inference geography can be "global" or "us", and the US is the only location for data at rest. Anthropic lists European processing as included for Claude on Amazon Bedrock and on Google Cloud, and as coming soon on Microsoft Foundry. On Bedrock, Claude Opus 5 and Sonnet 5 can run in-Region in Ireland (eu-west-1) and Stockholm (eu-north-1), and Sonnet 5 also in London (eu-west-2), whereas Claude Fable 5, Fable 5.1 and Mythos 5.1 are available in every EU Region through global routing only, which AWS describes as having no geographic restrictions (AWS model and Region compatibility table, checked 4 October 2026). Where processing must stay in Europe, the model has to be chosen with this in mind.
Significant warning: when Anthropic models are accessed via Microsoft 365 Copilot (default-enabled for most commercial tenants from 2026-01-07), Anthropic processing is out of scope for the Microsoft EU Data Boundary. EU buyers using Copilot's Anthropic features need to know this and decide actively whether to allow it.
Security documentation
Anthropic's trust center at trust.anthropic.com lists:
- SOC 2 Type 2 (the 2025 report, with a bridge letter dated August 2026)
- ISO 27001:2022
- ISO/IEC 42001:2023
- CSA STAR, through the combined SOC 2 and CSA STAR Level 2 report
- HIPAA Business Associate Agreement (BAA): available for qualifying healthcare customers
HIPAA & BAA position
Anthropic will sign a HIPAA Business Associate Agreement (BAA), covering the first-party Claude API and Enterprise plans.
- Enterprise: eligible organisations enable a click-to-accept BAA directly in organisation settings; clicking "Accept and Enable HIPAA" constitutes acceptance, with no separate document to sign and return.
- API: covered under the BAA for first-party API use.
- HIPAA readiness is an alternative to ZDR. Anthropic's documentation describes HIPAA readiness as applying "a broader set of privacy and security safeguards than ZDR (encryption, access controls, and audit logging that protect PHI throughout its lifecycle) rather than requiring immediate deletion", and states that an organisation handling PHI does not also need ZDR. Once enabled, the configuration is permanent and is enforced at organisation level, so an organisation that needs both HIPAA-ready and general-purpose access should use separate organisations.
- Not covered by HIPAA readiness on the API: consumer plans, processing PHI through the Claude Console, Amazon Bedrock and Google Cloud (which have their own compliance documentation), Claude Platform on AWS and Microsoft Foundry (where it is not available), third-party integrations, Claude Code, and beta features unless listed as eligible (Anthropic developer documentation, checked 4 October 2026). For the Team tier and the Enterprise click-to-accept route described above, the position was last verified in June 2026.
The BAA is the contractual piece. HIPAA's Security Rule (risk analysis, minimum-necessary, workforce training, audit controls, breach notification) stays on the covered entity. See HIPAA for AI tools for the full walkthrough across vendors.
AI Act role + risk classification
- Role: Anthropic is a provider of general-purpose AI models. GPAI obligations under Articles 51-55 apply to Anthropic.
- Your role as a buyer: deployer, with separate obligations.
- Risk tier: same logic as OpenAI - most uses fall at limited or minimal risk; Annex III triggers high-risk obligations regardless of which model you use.
Anthropic publishes a Responsible Scaling Policy and AI Safety Level (ASL) framework, which is more substantive than most peers. Useful evidence of provider-side governance in your audit file.
DPIA prompts (for your use case)
- Are you using the API/Team/Enterprise tier or claude.ai consumer? Consumer-tier defaults changed in October 2025 - staff accounts may now be in a training-eligible flow by default.
- Are you accessing Claude via Microsoft 365 Copilot? If yes, processing falls outside the EU Data Boundary; EU subjects' data is leaving the boundary unless you actively block it.
- Special-category data: same Article 9 question as OpenAI. Staff can paste anything; UI controls and training matter.
- AI Act Annex III applicability: if your use case is in recruitment, credit, education, law enforcement, migration, or justice, deployer obligations apply.
- API log retention: record the 30-day window from the Privacy Center in your retention schedule, together with the two-year period that applies to flagged content. If you need shorter retention, ZDR is approval-gated and requested through Anthropic's sales team, and it is not available for Covered Models except under the time-limited arrangement described above.
Unresolved questions / red flags
- Consumer-tier training default flipped 2025-10-08. Many enterprise DPOs are still operating on the assumption that claude.ai consumer is "no training by default." That is no longer true.
- Microsoft 365 Copilot integration moves Anthropic processing out of the EU Data Boundary for those Copilot tenants. This is not obvious and is being missed.
- Anthropic's own API has no EU residency option. European processing depends on the cloud platform and on the model, and the newest models run on global routing only on Bedrock.
- Buyer records frequently name the wrong transfer mechanism. Anthropic is regularly recorded as DPF-certified in records of processing. It is not on the participant list. The SCCs and the UK Addendum in the DPA are what the transfer runs on, and they require a transfer impact assessment.
- Embeddings story has shifted through the Voyage acquisition. If your stack relies on Anthropic embeddings, confirm the current product / term shape.
Related profiles
- OpenAI - same general-purpose LLM category, different defaults
- Microsoft 365 Copilot - embeds Anthropic models out of EU Data Boundary scope
- Perplexity - routes to Anthropic models, applying Anthropic's terms transitively
Sources checked
https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa- corroborated 2026-04-29https://trust.anthropic.com/andhttps://trust.anthropic.com/subprocessors- certifications, documents and the 20-entry subprocessor list - checked 2026-10-04https://www.anthropic.com/legal/data-processing-addendum(effective 24 February 2025),https://www.anthropic.com/legal/commercial-terms(effective 17 June 2025) andhttps://www.anthropic.com/legal/service-specific-terms(effective 31 August 2026) - checked 2026-10-04https://platform.claude.com/docs/en/manage-claude/data-residencyandhttps://platform.claude.com/docs/en/manage-claude/api-and-data-retention- inference geography, workspace geography, ZDR and HIPAA readiness - checked 2026-10-04https://support.claude.com/en/articles/15425695-covered-models(dated 1 September 2026) andhttps://claude.com/regional-compliance- checked 2026-10-04https://docs.aws.amazon.com/bedrock/latest/userguide/models-region-compatibility.html- in-Region, geographic and global availability of Claude models in EU Regions - checked 2026-10-04- dataprivacyframework.gov participant registry, active and inactive, with a control query - checked 2026-10-04
https://privacy.claude.com/en/articles/7996866("How long do you store my organization's data?", article dated 2026-07-01) - the 30-day commercial deletion window and its exceptions - checked 2026-09-17- Microsoft Foundry documentation on Anthropic as subprocessor and EU Data Boundary scope - 2026-04-29
- Public reports of consumer-tier training default change 2025-10-08
- Anthropic-in-Copilot default-enable announcement 2026-01-07
Related reading
- DPA for AI vendors - the eight clauses to check on any AI vendor DPA, with Anthropic's 30-day retention default put in context
- EU AI Act for AI buyers - deployer-side obligations for UK and EU buyers running Claude through the API or Enterprise tier
- HIPAA for AI tools - BAA gate and Security Rule checklist for US healthcare buyers using Claude
- OpenAI vs Anthropic DPA - head-to-head on the two most-asked-about API vendors
- Copilot 365 vs Google Workspace AI compliance - relevant because Anthropic became a Copilot subprocessor on 2026-01-07
- Practitioner how-to (Janus Compliance): Is the Claude API GDPR compliant? - configuring the GDPR-compliant path step by step (DPA, residency, DPIA, transfers)
Talk to Michael about Anthropic - or your AI vendor governance more broadly
CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.
Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
For ongoing AI compliance support, work with Janus DPO-as-a-Service. For other vendors, browse the full index, or see real agent failures analysed legally in the AI Agent Incident Register.