Claude ZDR zero data retention guide for Anthropic API and Claude Code enterprise use
tools

Claude ZDR: Zero Data Retention for Enterprise and Claude Code

Is Claude ZDR available?

Yes, but only on qualified enterprise paths. Claude ZDR is available for eligible Anthropic API usage and for Claude Code on Claude Enterprise when ZDR is enabled for the organization. It does not apply to standard Claude Team or Claude Enterprise chat interfaces.

  • Claude ZDR covers eligible API usage and Claude Code on qualified Enterprise organizations.
  • Standard Claude Team and Claude Enterprise product interfaces are not ZDR-eligible.
  • Commercial Claude Code defaults to 30-day retention unless your organization is separately approved for ZDR.
  • ZDR reduces storage risk, but it does not replace the DPA, SCCs, or EU hosting analysis.

Claude ZDR is available, but only on qualified enterprise paths. In plain language, Zero Data Retention means Anthropic does not store covered prompts and outputs after the response is returned, except for limited legal or misuse-prevention cases. For buyers evaluating claude zdr or anthropic zdr, the key scope answer is this: ZDR applies to eligible Anthropic API usage and to Claude Code on Claude Enterprise when ZDR is separately enabled for the organization, but it does not apply to the standard Claude Team or Claude Enterprise chat interface.

That three-part answer matters because current search intent is mixed. Some users want the definition of zdr meaning, others want to know whether Claude Enterprise chat qualifies, whether the Anthropic API itself is covered, where Anthropic documents the ZDR retention policy, and how Claude Code session and transcript retention changes under ZDR. This page keeps all of those jobs on one URL so legal, privacy, and procurement teams can use the same owner page.

This article is general information, not legal advice for a specific deployment. For the contract layer, start with our Anthropic DPA. For the location question, see Claude EU hosting. For the broader rollout analysis, see Claude Code GDPR, Claude Enterprise GDPR, and our Claude Enterprise guide.

Short answer: is Claude ZDR available?

Yes, but not across every Claude surface.

Product pathClaude ZDR available?Why the answer differs
Anthropic API with eligible commercial organization keysYesZDR applies to eligible APIs on approved organizational scope
Claude Code on Claude EnterpriseYes, if separately enabledZDR is qualified, not standard, and is enabled per organization
Claude Enterprise chat interface on claude.aiNoThe standard Enterprise product interface is not ZDR-eligible
Claude Team interfaceNoTeam is commercial, but the product interface is not covered
Claude Free, Pro, or MaxNoConsumer products are outside ZDR scope

For most buyers, this table is the practical answer they need. If your company uses the ordinary Claude chat interface, buying Enterprise does not automatically create a ZDR deployment. If your company uses Claude Code or the Anthropic API on the qualified path, ZDR may be available.

What does ZDR mean in the Anthropic / Claude context?

ZDR means Zero Data Retention. In Anthropic’s current documentation, that means covered customer data is not stored at rest after the response is returned, except where retention is still needed to comply with law or combat misuse.

That definition is useful, but incomplete if left alone. In procurement practice, zdr meaning only becomes actionable when it is paired with the scope limitation:

  • ZDR is not a universal setting for every Anthropic product.
  • ZDR is not a synonym for GDPR compliance as a whole.
  • ZDR is not the same as EU hosting, data residency, a DPA, or an AVV.

For German buyers, the most accurate short definition is this: Claude ZDR is a product-specific retention control that can reduce vendor-side storage risk for approved Claude API and Claude Code workflows, but only within a confirmed scope.

Where Anthropic ZDR applies today

The current official documentation is clearer than many older explainers. It distinguishes between the API, Claude Code, and the standard chat surfaces.

Does Claude ZDR apply to the Anthropic API?

Yes — Claude ZDR applies to the Anthropic API, but only to specific APIs on eligible commercial organizations: the Messages API and the Token Counting API. If your integration uses any other Anthropic API surface, ZDR coverage is not automatic and must be verified per feature.

Anthropic’s current API and data retention documentation says ZDR applies to certain Claude APIs, specifically the Messages API and the Token Counting API.

That matters because many searches for anthropic zero data retention official docs are not really asking for a general privacy statement. They are asking: which exact API path qualifies? For direct Anthropic API deployments, the current official page is the starting point. Procurement should not assume that every API-adjacent feature has the same retention position without checking its own feature page.

Does ZDR apply to Claude Code?

Yes — ZDR is available for Claude Code, but only for qualified Claude for Enterprise organizations, and only when Anthropic enables it separately for your organization. Without that enablement, commercial Claude Code sessions stay on standard 30-day retention and local clients keep plaintext session transcripts for 30 days.

Anthropic’s current Claude Code Zero Data Retention documentation says ZDR is available to qualified accounts on Claude for Enterprise. It also says ZDR is not included in the standard Claude for Enterprise plan, cannot be turned on from admin settings, and must be enabled separately by Anthropic.

The same page also states that ZDR is enabled per organization. That is an important procurement point. If your company has multiple Anthropic organizations, ZDR does not automatically follow across all of them.

Standard Claude Enterprise chat interface

This is the area where buyers most often over-assume. Anthropic’s current API and retention documentation says Claude Team and Claude Enterprise product interfaces are not ZDR-eligible, except for Claude Code when used through Claude Enterprise with ZDR enabled for the organization.

So if the internal plan is “we will use the Claude Enterprise web chat and rely on ZDR,” the answer is no. The ordinary chat product is not the covered path.

Claude Team and consumer plans

Claude Team is a commercial plan, but it still does not make the product interface ZDR-eligible. Consumer plans such as Free, Pro, and Max are also outside ZDR scope.

This is why the head terms claude zdr and anthropic zdr can be misleading if treated as plan labels. The decisive question is not only which contract you signed. The decisive question is which product surface your users actually touch.

Claude ZDR policy: which official Anthropic documents define retention?

Anthropic documents the Claude ZDR retention policy in two primary official sources: the API and data retention documentation and the Claude Code Zero Data Retention documentation. Sales summaries and third-party explainers are secondary. Read those pages as the policy baseline before procurement sign-off.

If you are validating anthropic zero data retention official docs, do not rely on summaries alone. Anthropic’s own docs are the primary source, and procurement should verify the current wording before rollout or renewal.

Claude Code zero-data-retention docs

If Claude Code is in scope, start with Anthropic’s Claude Code Zero Data Retention page. That page currently confirms:

  • ZDR is available to qualified accounts on Claude for Enterprise.
  • ZDR is enabled separately by Anthropic, not self-serve in admin settings.
  • ZDR is scoped per organization.
  • Standard Claude chat on claude.ai is not covered.
  • Some features are disabled under ZDR because they require storage.

For code-heavy deployments, this is the core eligibility document.

Claude Platform API and data-retention docs

For API workflows, review Anthropic’s API and data retention page. That page currently confirms:

  • ZDR applies to the Messages API and Token Counting API.
  • Console and Workbench are excluded.
  • Claude consumer products are excluded.
  • Claude Team and Claude Enterprise interfaces are excluded except for Claude Code with enabled ZDR.
  • Some models require retention and are unavailable under ZDR.

This is the main official source for the API-side scope split.

What to confirm in writing during procurement

Official documentation is necessary, but not always sufficient for internal sign-off. Procurement should still confirm in writing:

  1. Which organization IDs or workspaces are actually covered.
  2. Which models remain available under ZDR and which do not.
  3. Whether the intended workflow uses only covered APIs or also excluded surfaces.
  4. What the fallback retention rule is when ZDR is not available.
  5. Whether the deployment includes Claude Code local artifacts that still require device governance.

For German companies, this written confirmation is often what turns a marketing-level statement into a reviewable Freigabe record.

What Claude ZDR still does not cover

ZDR is useful, but it is not a blanket “problem solved” control. The practical limits matter as much as the headline.

Excluded interfaces and product surfaces

Anthropic’s current docs exclude several surfaces from ZDR, including:

  • Chat on claude.ai through the standard Claude Enterprise web interface
  • Claude Team product usage
  • Consumer plans such as Free, Pro, and Max
  • Console and Workbench
  • Third-party integrations whose own storage policies must be reviewed separately

That means a company can have a real ZDR arrangement for one part of its Claude setup while another part remains on standard retention.

Anthropic’s documentation does not present ZDR as absolute. The current wording says data may still be retained where needed to comply with law or combat misuse. The Claude Code documentation also states that if a session is flagged for a policy violation, associated inputs and outputs may be retained for up to 2 years under Anthropic’s standard ZDR policy.

That nuance matters for internal policies. A privacy team should describe ZDR as narrowing storage rather than eliminating every retention scenario.

Local client or workspace artifacts that still need governance

If your deployment includes Claude Code, the server-side ZDR answer is not the whole picture. Anthropic’s current Claude Code data usage page says commercial users otherwise have standard 30-day retention, and that Claude Code clients store local plaintext session transcripts under ~/.claude/projects/ for 30 days by default to enable session resumption.

For German companies, this changes the operational analysis:

  • ZDR may reduce vendor-side persistence.
  • Local workstation or VDI policies may still need adjustment.
  • Endpoint governance, deletion settings, and repository rules still matter.

That is why this page should be read together with our Claude Code GDPR guide when the workflow is developer-facing.

Claude ZDR vs DPA / AVV vs SCCs vs EU hosting

Companies often collapse several distinct controls into one. That leads to weak procurement analysis.

ControlWhat question it answersWhy it still matters when ZDR exists
ZDRIs covered data stored after the response?Helps with storage limitation and data minimization
DPA / AVVWhat is the Article 28 GDPR processor contract?Still required for processor use cases
SCCsWhat is the transfer mechanism for third-country processing?Still matters if data reaches US-linked infrastructure
EU hostingWhere is processing and storage geographically anchored?Still matters when EU-only architecture is required

ZDR does not replace the DPA or AVV. If Anthropic processes personal data on your behalf, the contract layer still matters. Start with our Anthropic DPA.

ZDR does not replace SCCs. If the deployment still involves international transfers, the Chapter V analysis does not disappear just because retention is narrower.

ZDR does not create EU hosting. If your organization needs EU-only architecture, review Claude EU hosting. That is a separate question from retention.

For German legal, privacy, and procurement teams, keeping these controls separate is often the difference between a workable rollout memo and an over-broad assumption.

Practical procurement checklist for German companies

If your company is evaluating claude zdr or anthropic zdr, the cleanest internal process is to run a short documented checklist:

  1. Define the target workflow. Is the use case the Anthropic API, Claude Code, or ordinary Claude Enterprise chat?
  2. Verify the official Anthropic docs. Check the API retention page and, if relevant, the Claude Code ZDR and data usage pages.
  3. Confirm organizational scope in writing. If multiple organizations or workspaces exist, document exactly which ones are covered.
  4. Confirm model and feature scope. Ask which models are unavailable under ZDR and whether any workflow relies on excluded features.
  5. Check the local artifact picture. If Claude Code is in scope, assess endpoint controls and local transcript cleanup settings.
  6. Align the contract stack. Verify the Anthropic DPA, any SCC analysis, and any internal policy updates.
  7. Separate retention from location. If EU-only handling matters, pair this review with Claude EU hosting.

This is usually enough to distinguish a real, documented ZDR setup from a vague assumption that “Enterprise must already cover it.”

Frequently asked questions

What does ZDR mean?

In the Claude and Anthropic context, ZDR means Zero Data Retention. Anthropic uses that term for a setup where covered customer data is not stored at rest after the response is returned, except where retention is still required for law or misuse prevention. It is a defined retention arrangement, not a universal privacy label for every product surface.

Is Anthropic ZDR the same as Claude ZDR?

Usually yes in buyer shorthand, but the scope still depends on the exact workflow. People often use Anthropic ZDR for the vendor-level concept and Claude ZDR for the Claude-specific path they want to deploy. In practice, the real issue is whether the exact API or Claude Code workflow is within Anthropic’s current documented ZDR scope.

Does ZDR apply to Claude Enterprise chat?

No. Anthropic’s current documentation says Claude Team and Claude Enterprise product interfaces are not ZDR-eligible, except for Claude Code when ZDR is enabled for the organization. Standard chat through the Enterprise web interface is therefore outside the ZDR path.

Does ZDR apply to Claude Code?

Yes, but only on the qualified enterprise path. Anthropic’s Claude Code documentation says ZDR is available to qualified Claude for Enterprise accounts, must be enabled separately by Anthropic, and applies per organization. Without that enablement, commercial Claude Code sessions stay on standard 30-day retention and local clients cache plaintext session transcripts for 30 days. Even under ZDR, sessions flagged for policy violations may be retained for up to 2 years.

Where does Anthropic document its Claude ZDR policy?

In two primary official sources: the API and data retention documentation on the Claude Platform docs, which defines ZDR scope for the Messages API and Token Counting API, and the Claude Code Zero Data Retention documentation, which defines the enterprise path, per-organization enablement, and the retention exception for flagged sessions. The Claude Code data usage page adds the standard 30-day retention and local transcript caching defaults that apply outside a ZDR arrangement. Treat those pages as the policy baseline and verify the current wording before procurement sign-off.

Does Claude ZDR apply to the Anthropic API?

Yes, for eligible APIs on approved commercial organizations. Anthropic’s API and data retention documentation scopes ZDR to the Messages API and the Token Counting API, while Console and Workbench are excluded and models that require retention are unavailable under ZDR. For any other Anthropic API surface, verify the feature-specific documentation before assuming ZDR coverage.

Does ZDR replace the DPA or AVV?

No. ZDR is a retention control, while the DPA or AVV is the processor contract under Article 28 GDPR. A company still needs the contract layer, transfer analysis, and internal governance for the actual workflow it plans to approve.

Is ZDR enough for GDPR compliance?

No. ZDR is helpful for storage limitation and data minimization, but GDPR compliance still depends on lawful basis, processor terms, international transfer analysis, security measures, and whether the workflow itself is appropriate. Many German buyers will need ZDR review together with DPA, SCC, and hosting analysis.

Need a Claude ZDR procurement review?

Compound Law advises companies, startups, and legal teams in Germany on AI procurement, GDPR, commercial contracts, employment law, and AI governance. If your organization needs a deployment-specific review of Claude ZDR, the Anthropic DPA, or the split between retention, transfer, and hosting controls, contact us.

Related Tool Guides

DeepL DPA and GDPR approval guide for companies in Germany
tools

DeepL DPA and GDPR in Germany: Approval Guide for Buyers

DeepL can usually be approved in Germany only on paid business plans with a signed DPA, feature review, and confidentiality checks. DeepL Free is not approved.

Cursor DPA and GDPR review for teams in Germany
tools

Cursor DPA 2026: Where to Find It and What It Covers

The Cursor DPA is public at cursor.com/terms/dpa, but German teams still need the right paid plan, Privacy Mode, and transfer review before using personal data.

DeepSeek GDPR compliance analysis for German companies
tools

Is DeepSeek GDPR Compliant? What German Companies Need to Know

Hosted DeepSeek still creates GDPR and procurement risk for German companies. Self-hosted deployments can work with EU infrastructure and proper controls.

Zapier GDPR 2026 Germany — DPA, Article 28, SCCs and EU data transfers for German companies
tools

Is Zapier GDPR Compliant? Germany Guide 2026

Is Zapier GDPR compliant for German companies? DPA, SCCs, EU data residency, and when Zapier is too risky for personal data workflows.

Claude Code GDPR compliance — DPA, data retention and EU hosting guide
tools

Claude Code Data Privacy: GDPR, DPA & No Training Policy

Claude Code's data privacy policy: no training on your code by default, GDPR DPA included via Anthropic API, zero data retention for Enterprise.

HubSpot privacy and GDPR compliance for German businesses
tools

HubSpot Privacy in Germany: GDPR, DPA, and Works Council Risks

HubSpot privacy and GDPR compliance in Germany require a DPA, transfer review, EU data hosting assessment, and works council analysis.

Tool Library

Browse More AI Tools by Topic

Compare more tools, privacy issues, and deployment scenarios in the full AI tool library.

View all AI tools

Frequently asked questions

In the Claude and Anthropic context, ZDR means Zero Data Retention. Anthropic describes this as not storing covered customer data at rest after the response is returned, except where retention is still needed to comply with law or combat misuse. It is a scope-limited retention control, not a blanket privacy guarantee for every Anthropic product.

Usually yes in practical buyer language, but the exact scope still depends on product path. Buyers often say Anthropic ZDR when they mean the vendor-level offering and Claude ZDR when they mean the Claude-specific workflow. The real question is whether the exact API or Claude Code path you plan to use is covered.

No, not to the standard Claude Enterprise web interface. Anthropic's current API and retention documentation says Claude Team and Claude Enterprise product interfaces are not ZDR-eligible, except for Claude Code when ZDR is enabled for the organization.

Yes, but only on the qualified enterprise path. Anthropic's Claude Code documentation says ZDR is available to qualified Claude for Enterprise accounts, must be enabled separately by Anthropic, and applies per organization. Without that enablement, commercial Claude Code sessions stay on standard 30-day retention and local clients cache plaintext session transcripts for 30 days. Even under ZDR, sessions flagged for policy violations may be retained for up to 2 years.

In two primary official sources: the API and data retention documentation on the Claude Platform docs, which defines ZDR scope for the Messages API and Token Counting API, and the Claude Code Zero Data Retention documentation, which defines the enterprise path, per-organization enablement, and the retention exception for flagged sessions. The Claude Code data usage page adds the standard 30-day retention and local transcript caching defaults that apply outside a ZDR arrangement. Treat those pages as the policy baseline and verify the current wording before procurement sign-off.

Yes, for eligible APIs on approved commercial organizations. Anthropic's API and data retention documentation scopes ZDR to the Messages API and the Token Counting API, while Console and Workbench are excluded and models that require retention are unavailable under ZDR. For any other Anthropic API surface, verify the feature-specific documentation before assuming ZDR coverage.

No. ZDR addresses storage after processing, while the DPA or AVV addresses the Article 28 GDPR processor contract. Companies still need the contract layer, transfer analysis, internal usage rules, and any required technical controls even when ZDR is active.

No. ZDR is helpful for storage limitation and data minimization, but GDPR compliance also depends on lawful basis, processor terms, international transfer analysis, governance, and whether the actual workflow is appropriate for the tool. Many German companies will need both ZDR analysis and separate EU hosting or AVV review.

Get a quote