Claude (Anthropic)
Anthropic
Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.
Pricing / Contract Route
Official pricing varies by plan, seat type, cadence and cloud provider
Enterprise Features
Commercial Terms, DPA, admin controls, eligible ZDR, and partner-cloud regional deployment options
Last Updated
September 10, 2026
Version: 10 September 2026 - prepared by WAIMAKERS B.V.
1 Purpose
This overview explains how Claude consumer plans, Claude for Work, the direct Anthropic API and partner-cloud routes handle data for European organisations.
Claude can support a GDPR-compliant business deployment under commercial terms, but compliance is not automatic. Direct Claude, the Anthropic API and partner-cloud deployments have different storage, inference, retention and contractual boundaries.
2 Comparison of Claude routes (EU focus)
| Route | Intended use | Privacy position | EU data residency | Training | Retention and practical assessment |
|---|---|---|---|---|---|
| Free / Pro / Max | Individual consumer use | ⚠️ Consumer terms | ❌ No organisational EU-residency commitment | Users choose whether new or resumed chats and coding sessions may be used for model improvement. | If enabled, affected data is retained for five years. If disabled, Anthropic states 30 days. Feedback-associated data is retained for five years. Deleting a chat stops future training use but cannot reverse training already performed. Avoid sensitive organisational data unless the exact route and setting have been assessed. |
| Claude for Work: Team / Enterprise | Managed organisational use | ✅ Anthropic acts as processor for customer-submitted data and a DPA is available | ❌ Anthropic does not document EU storage for the first-party product | Customer Content is not used for training unless the customer joins the Development Partner Program. | Saved chats and coding sessions persist for product continuity. Deleted conversations leave history immediately and are removed from back-end systems within 30 days, subject to exceptions. Complete a transfer assessment and configure retention and approved features. |
| Direct Anthropic API | Custom applications and integrations | ✅ Commercial terms and no training by default, unless the customer joins the Development Partner Program | ❌ Current first-party controls offer global or US-only inference. The only workspace geo is the US. |
No training by default under commercial terms. | Inputs and outputs are normally deleted within 30 days, with endpoint, contract, policy-enforcement and legal exceptions. Eligible customers can agree ZDR, but covered-model rules can still require retention. Do not describe this route as EU resident. |
| AWS, Google Cloud or Microsoft partner route | Cloud-managed Claude deployment | ⚠️ Provider, contract, endpoint and model specific | ✅ Regional routes can be available for supported services, including EU regions. Model availability alone does not prove that every log, tool or subprocessor flow remains there. | Governed by the selected provider and commercial terms. | Verify endpoint, region, logging, abuse controls, subprocessors, DPA and feature support before use. |
Public prices vary by market, tax, seat type, billing cadence and provider route. Verify the live pricing page and order form before purchase.
Notes for Europe
- Commercial no-training default: Anthropic says it does not train on commercial Customer Content unless the customer joins the Development Partner Program.
- DPA available: Anthropic acts as processor for covered commercial Customer Content. Verify the contracting entity and transfer annex for the exact agreement.
- No first-party EU residency: the direct API currently offers
globalor US-only inference and US workspace storage. - Partner-cloud regions are route-specific: AWS Bedrock, Google Vertex AI and Microsoft routes can offer regional options, but each endpoint, log, feature and contract still needs verification.
- ZDR is not automatic: it is an eligible contractual arrangement. Designated covered models can require retention despite the default.
3 EU data residency through cloud providers
AWS Bedrock regional route
AWS documents regional endpoints and EU inference profiles for supported Claude models. Use the current AWS model and region matrix rather than copying a model ID from an older article.
- Select a supported EU endpoint or inference profile.
- Confirm which AWS service logs and abuse controls receive prompts or outputs.
- Confirm the AWS DPA and subprocessor scope.
- Do not infer full EU residency from the presence of a model in one EU region.
Google Cloud Vertex AI regional route
Vertex AI publishes regional model availability. The supported model, endpoint and region must be checked together.
- Select the regional endpoint explicitly.
- Confirm the Google Cloud DPA and the project's storage and logging settings.
- Global endpoints, preview features and connected services can have different location rules.
Direct Anthropic API
The direct route does not currently provide EU data residency. global inference may execute in different locations and does not guarantee Europe. Workspace storage is US-only.
4 Retention and deletion details
Anthropic's commercial retention cannot be summarised as "30 days" without context:
- Direct API inputs and outputs are normally deleted within 30 days.
- Files and other stateful features can retain data under customer control.
- Deleted and Incognito Claude for Work chats are removed from back-end storage within 30 days, subject to exceptions; saved chats remain available until deletion.
- Inputs and outputs flagged for a Usage Policy violation can be retained for up to two years.
- Trust-and-safety classification scores can be retained for up to seven years.
- Feedback-associated data can be retained for five years.
- Legal requirements, policy enforcement, ZDR terms and covered-model rules can change the default.
Consumer Free, Pro and Max accounts have a separate model-improvement choice. Anthropic documents five-year retention when enabled, 30-day retention when disabled and five-year feedback retention. These consumer rules do not apply to services under the Commercial Terms.
5 Recommendations (GDPR-first)
- Use commercial terms and accept or execute the current DPA. Document controller and processor roles.
- Record whether the route is claude.ai, direct API, Claude Platform on AWS, Bedrock, Google Cloud or Microsoft Foundry.
- Verify storage geo and inference geo separately. For the direct API, record that workspace storage is US-only.
- Map Files, saved chats, feedback, connectors, tools and covered-model exceptions into the retention schedule.
- Restrict membership and tool access. Use SSO, SCIM, audit and custom retention where available.
- Complete the lawful-basis, transparency, DPIA and international-transfer work required by the use case.
6 Primary sources
- Anthropic processor/controller explanation
- Commercial data retention
- First-party Claude Platform data residency
- Anthropic DPA information
- Commercial Terms
- Anthropic pricing
- Claude on Amazon Bedrock regional endpoints
- Vertex AI locations
- Consumer model-improvement choice and retention
7 Disclaimer
This overview is an informational procurement aid, not legal advice or certification of a deployment. Verify current terms, model, region, endpoint and feature settings before production use. The customer remains responsible for its GDPR obligations.
Prepared and issued by WAIMAKERS B.V. - 10 September 2026.