Is Anthropic GDPR Compliant? A Guide for Businesses
Anthropic GDPR Compliance Overview
Anthropic provides contracts and security controls that can support GDPR-compliant use of Claude. These measures do not make every deployment compliant. Your organisation must assess its legal basis, data flows, retention settings, and risks. The applicable terms and controls depend on the product and how you access it.
- Anthropic's DPA is incorporated into its commercial terms; third-party platforms have their own terms.
- Current public documentation states that data is stored in the US. An Enterprise plan does not establish EU-only processing.
- ZDR depends on the service, model, feature, and agreement. Retention exceptions can apply.
- Assess international transfers and screen for a DPIA before processing personal data.
Anthropic provides contractual and security measures that can support GDPR-compliant use of Claude. These measures do not make every deployment compliant. Your organisation must assess its purpose, legal basis, data flows, retention settings, and risks. The applicable terms and controls depend on the product and how you access it.
Last reviewed: 22 September 2026. This guide addresses business use in Germany under the GDPR. It uses public documentation; a negotiated contract can have different terms. This page provides general information and is not legal advice for a specific situation.
| Assessment area | What to check |
|---|---|
| Article 28 — Processor contract | Applicable DPA and each party’s role |
| Chapter V — International transfers | Transfer mechanism, recipient, destination, and required assessment |
| Article 32 — Security | Relevant audit reports, certifications, and actual controls |
| Data minimisation and retention | Data needed for the task, deletion periods, and any ZDR exceptions |
| Data location | Storage, inference, support access, and safety review |
| Article 35 — High-risk processing | Whether a DPIA is required before use |
Is Anthropic GDPR Compliant?
A vendor’s contracts and security credentials are evidence for an assessment. They do not establish that a specific use of AI is lawful. Your organisation must decide which personal data it can send, for what purpose, and under which legal basis. It must also implement suitable access controls, retention rules, and procedures for data subject requests.
Document the assessment for the actual workflow. For example, a deployment that handles employee records needs a different assessment from one that uses only public, non-personal text. Reassess the workflow when its purpose, data, model, or connected services change.
Anthropic as Data Processor: The Key Distinction
For customer data covered by its commercial DPA, Anthropic describes itself as a processor. Its role for that data should not be extended to all account, billing, or other processing. See Anthropic’s explanation of its role.
Identify the roles for your workflow:
- Controller: determines the purposes and means of processing.
- Processor: processes personal data on a controller’s behalf.
- Subprocessor: is engaged by a processor to carry out processing for the controller.
A business using Claude can itself be a processor for its clients. Record Anthropic as processor or subprocessor as applicable, and check the relevant instructions and authorisations. Do not call it a subprocessor merely because it is a vendor.
For access through Amazon Bedrock or Microsoft Foundry, review the selected platform’s contract and data flows. These routes do not all create the same contractual chain. Anthropic expressly notes that third-party platform terms govern such use. Microsoft’s Claude integration is part of Microsoft Foundry. See Anthropic’s platform terms note and Microsoft’s service documentation.
Data Processing Addendum (DPA)
Anthropic incorporates its DPA into its commercial terms. You can read it publicly; access to a customer portal is not required. Save the version that applies to your agreement and document your review. See Anthropic’s DPA acceptance guidance.
The DPA addresses processing instructions, security measures, subprocessors, assistance, and transfers. Review it against Article 28 and your intended use. Contract terms must match the data and operations you plan to entrust to the provider.
For further context, see our Anthropic DPA guide and Data Processing Addendum analysis.
Claude Free, Pro, and Max are consumer plans. Do not assume that a paid consumer plan supplies a commercial processor arrangement. Check the applicable terms before using it for business processing that requires one. See Anthropic’s consumer product categories.
Standard Contractual Clauses (SCCs) for International Transfers
Anthropic’s DPA incorporates the 2021 EU SCCs where required: Module 2 for controller-to-processor transfers and Module 3 for processor-to-processor transfers. It also includes UK and Swiss provisions. Select the module by the parties’ roles, not simply by whether an intermediary is involved. See DPA section I and Schedule 3.
For each transfer, identify the exporter, recipient, data, purpose, and destination. Confirm which mechanism applies. A claim about EU storage does not resolve separate questions about access or processing outside the EEA.
The EU-US Data Privacy Framework (DPF) can support transfers within the scope of the relevant adequacy decision to covered US recipients. Verify the legal entity, active status, and data coverage in the official DPF register. This guide does not establish DPF coverage for Anthropic. A cloud provider’s entry does not establish coverage for a separate company. See the EDPB’s DPF guidance for businesses.
EU Data Residency: Storage and Inference Are Separate
Anthropic’s current server-location documentation states that data is stored in the US. It also describes global traffic routing and processing for support, safety review, and incident response in countries where it or its affiliates operate.
The API data-residency documentation distinguishes inference location from workspace storage and endpoint processing. At the review date, it lists US or global inference and only a US workspace location. These controls do not establish an EU-only service.
If your organisation requires EU-only storage or processing, obtain written confirmation for the selected service. Check inference, stored content, logs, backups, support access, and connected tools. Assess third-party cloud deployments separately; their model availability and regional settings can differ.
Zero Data Retention (ZDR)
ZDR is an agreed arrangement for eligible services. It is not an automatic property of every Enterprise feature. Anthropic’s ZDR scope guidance describes exceptions for legal obligations and misuse or harm. It also states that safety-classifier results are retained.
Check the API retention and feature-eligibility documentation for your exact configuration. Some features retain technical artifacts or have their own storage rules. The ordinary Team and Enterprise chat interfaces are not ZDR-eligible; eligible Claude Code use has separate rules. Do not describe ZDR as a guarantee that nothing is ever written to disk.
Anthropic’s Covered Models policy generally requires 30-day retention and describes limited authorised exceptions. Check the current model policy and your written agreement before relying on ZDR.
Outside a special arrangement, Anthropic states that standard API inputs and outputs are deleted within 30 days, subject to exceptions. Saved chats and files can have different retention periods. See the commercial retention policy.
Retention controls do not supply a legal basis or remove professional confidentiality duties. Send only the data needed for the task, even when ZDR applies.
Certifications and Audits
Anthropic’s published credentials include ISO 27001:2022 certification and SOC 2 Type I and Type II reports. A SOC 2 report is an audit report. Request the current documents and check their service scope, period, exclusions, and any controls that customers must implement.
These documents can support an Article 32 security assessment. They do not certify the lawfulness of your processing.
GDPR certification schemes exist. The EDPB approved Europrivacy criteria as a European Data Protection Seal under Article 42(5) in October 2022. Article 43 concerns certification bodies. We have not verified an applicable GDPR certificate for Anthropic. See EDPB Opinion 28/2022.
Transfer Impact Assessment (TIA)
Where you rely on SCCs, assess the destination country’s laws and practices and any supplementary measures needed to protect the data. Where a valid adequacy decision covers the transfer, verify that the decision remains in force and covers the recipient and data. A separate SCC-style TIA is not required merely because the destination is the US. See EDPB Opinion 22/2024, paragraphs 93–96.
Anthropic commits to reasonable TIA support in DPA section I.4. Request the information needed for your assessment, including locations, safeguards, and relevant government-access information. Record any evidence gaps. Review the assessment when the service, transfer chain, or legal position changes.
What Your Organisation Still Needs to Do
-
Assess the vendor and contract. Record the selected product, each party’s role, applicable terms, security evidence, and data flows. Use our GDPR AI Vendor Assessment Checklist to organise the review.
-
Document the legal basis and safeguards. Identify a suitable basis for each purpose. Where special-category data is involved, identify the applicable Article 9 condition as well. Address transparency, data subject rights, confidentiality, and any rules specific to the use case.
-
Check transfers and retention. Verify the transfer mechanism, complete the assessment it requires, and set suitable deletion periods. Check that model, feature, and tool settings match the contract.
-
Maintain processing records. Where Article 30 applies, update the relevant records with the actual purposes, data categories, recipients, transfers, and retention arrangements. Use the correct processor or subprocessor role.
-
Screen for a DPIA. Complete a Data Protection Impact Assessment before processing that is likely to create a high risk to individuals’ rights and freedoms. A legal review does not replace a required DPIA. See the EDPB’s DPIA guidance.
Compound Law advises companies in Germany on AI tool GDPR compliance. We assess the intended use, review the contracts and data flows, and help prepare the documentation needed for deployment.