Svennis AI
9 min read

Is Claude GDPR compliant? What European businesses should check before deploying it

Whether Claude is GDPR compliant depends less on the model than on your plan, your contract and your system design. This checklist covers what European businesses should verify first.

Abstract layered planes and small particles passing through a narrow filter, suggesting data moving under controls

Is Claude GDPR compliant? The short answer

Is Claude GDPR compliant? The question is framed the wrong way. A model is not compliant or non-compliant by itself. Compliance belongs to your processing: which Claude product you use, what contract sits behind it, what personal data you send, where that data goes and what the system does with the answer.

Anthropic's own statement supports that reading. On its privacy centre, Anthropic says it approaches GDPR by "assessing worldwide privacy laws and regulations together with our customers' needs in the unique context of artificial intelligence and large language models". It adds that its Privacy Policy, Data Processing Addendum and Help Center articles explain how it handles personal data, whether directly from consumers or when it acts as a processor for its customers.

That last distinction matters most. When your business builds on Claude, Anthropic processes data on your behalf. You stay answerable for the processing under the GDPR or, in the UK, the UK GDPR.

The rest of this post is the checklist we work through before a Claude system touches personal data. It covers the plan, the contract, data location, the impact assessment, sensitive data, system design and the guidance you need to keep watching.

Check which Claude plan you are on

The first check is the simplest and the one most often missed. Claude comes as consumer plans and commercial plans, and only the commercial ones carry a data processing contract. According to Compound Law's guide to Claude Team, Anthropic provides a Data Processing Agreement under Article 28 GDPR for its commercial products: Team, Enterprise and the API. The Free and Pro plans do not include one.

In practice, a member of staff pasting customer emails into a personal Pro account is working outside any processing contract. Claude Team is the commercial group plan, with a minimum of five users. Claude Enterprise adds SSO and audit logs. According to Compound Law's guide, EU data residency and zero data retention are not available on Team. Regional processing is available when you reach Claude through AWS Bedrock or Google Vertex AI under those providers' terms, which is a separate route from Anthropic's own plans. Zero data retention depends on your agreement with Anthropic.

The table below sets out the differences that matter for data protection, as Compound Law reports them. Check Anthropic's current terms before relying on this table. If your people already use Claude, find out which accounts they use before you decide anything else. Our guide to putting Claude inside the tools you already use shows what a managed setup looks like once you move that usage off personal accounts.

Claude plans on data protection controls, as reported by Compound Law
ProTeamEnterprise
Data Processing AgreementNot includedIncludedIncluded
Zero data retentionNot offeredNot availableDepends on your agreement with Anthropic
SSO and audit logsNoNoYes
Regional processingNot offeredNot offeredOnly via Bedrock or Vertex AI, a separate route
Article 9 special category dataNo DPA in placeNeeds an Article 9 condition and legal reviewArticle 9 condition needed; legal review advised

Read the Data Processing Agreement, not a summary of it

Once you are on a commercial plan, the DPA applies without extra paperwork. Compound Law notes that it is incorporated into the Anthropic Commercial Terms and needs no separate signature or negotiation for standard deployments. The contract is in place when your organisation accepts those terms.

Anthropic's DPA forms part of its Commercial Terms. Save a dated copy of the version that applies to you and keep it with your record of processing. That gives procurement teams the document they expect for their files.

When you read it, compare it against how you actually intend to use Claude. Check at least these points:

  • the processing it covers and the roles it gives each party;
  • how international transfers are handled, including the Standard Contractual Clauses incorporated into the Commercial Terms and, if you are a UK business, the UK Addendum or an IDTA;
  • which sub-processors are involved and how you will hear about changes;
  • what happens to data when you close the account.

If anything in it does not match your use case, raise it with your data protection lead before go-live, not after the first complaint.

Establish where the data is processed

Data location is the question European buyers ask most, and the answer depends on the route you take to the model. Compound Law states that Anthropic does not process data only within the EEA and that Standard Contractual Clauses are built into the Commercial Terms. If you are a UK business, the EU clauses do not cover your transfers on their own, so check that the terms include the UK Addendum or an IDTA, and complete a transfer risk assessment. Compound Law also confirms that EU data residency is not available on Claude Team.

Compound Law describes configurable data location for Claude Enterprise via AWS Bedrock or Vertex AI. That regional processing runs under those providers' terms, so check them for the route you choose. If regional processing is a hard requirement, whether from a customer contract, a sector rule or your own risk appetite, that is the route to price and test. Write the region requirement into the project brief at the start, because it shapes the architecture and cannot be bolted on later.

Buying Claude through another vendor does not settle the question for you. A small business in Europe, posting on Reddit while evaluating Claude inside the Microsoft Copilot ecosystem, asked whether prompts and data are stored on EU servers when used through Microsoft or Azure. It also raised data residency, DLP and Microsoft tenant isolation as concerns.

Those are the right questions. Put them to every vendor in the chain, including the one that resells or hosts the model, and get the answers in writing before you sign.

Decide whether you need a DPIA

The Data Protection Impact Assessment is where most Claude projects either gain confidence or stall. The ICO explains that under Article 35(1) you must do a DPIA where processing is likely to result in a high risk to the rights and freedoms of individuals. Article 35(3) lists three types that always require one: systematic and extensive profiling with significant effects, large scale processing of special category or criminal offence data, and systematic monitoring of publicly accessible places on a large scale. In the UK, the ICO has published a list under Article 35(4) setting out ten more. If you are in the EU, check the equivalent list from your national data protection authority.

For AI, one entry on that list does most of the work. Processing that involves innovative technologies, including AI, requires a DPIA where it is combined with any of the criteria from the European guidelines. Those WP29 guidelines set out nine criteria that may indicate high risk. In most cases a combination of two indicates a DPIA is needed, though the ICO says this is not a strict rule.

The ICO names artificial intelligence, machine learning and deep learning as examples of innovative technology. A Claude deployment therefore starts with one factor already present. The ICO's advice for borderline cases is direct: if in any doubt, do a DPIA. Its AI guidance also adds content on what to consider as part of one. The figures below summarise the thresholds.

DPIA thresholds from the ICO at a glance
Indicatorcount
Types that always need a DPIA under Article 35(3)3
Further operations on the ICO Article 35(4) list10
WP29 criteria that may indicate high risk9
Criteria that in most cases together indicate a DPIA2
Source: ico.org.uk

Treat special category data and staff data with extra care

Two kinds of data change the picture quickly. The first is special category data under Article 9 GDPR. Compound Law's view is that Article 9 data, strict confidentiality requirements or audit log obligations require Claude Enterprise or individual legal review. Whichever plan you use, you also need an Article 9 condition before you process that data. If your use case involves patient records, HR case notes or similar material, plan for legal review from the outset.

The ICO's AI guidance has added content on AI and inferences, affinity groups and special category data to its lawfulness chapter. That matters because the risk can sit in what a system infers, not only in what you feed it. Review sample outputs as well as inputs when you assess the risk.

The second is employee data. The ICO notes that employees could be considered vulnerable data subjects where a power imbalance means they cannot easily consent or object to processing by their employer. An internal assistant that reads staff tickets or messages is not low risk just because it is internal.

For both categories, document why you need the data at all. Often the task can be done with less, and the safest data is the data you never send.

Design the system so compliance holds in production

Contracts and assessments set the frame. The design of the system decides whether you stay inside it day to day. In the Claude systems we build, the questions below are settled before any code is written.

  • What goes to the model. Send the fields the task needs, not whole records. Classifying a request rarely needs a customer's full history.
  • What the model decides. The ICO's fairness chapter covers how solely automated decision-making and its safeguards link to fairness. In the UK those rules are now in Articles 22A to 22D of the UK GDPR, and in the EU in Article 22 GDPR. Keep a person in the loop where an output significantly affects someone.
  • Where the answer lands. Write outputs back into your system of record, so they fall under the access controls and retention rules you already run.
  • Who can use it. Tie access to your identity setup, and note that on Anthropic's own plans SSO and audit logs come with Enterprise.

A narrow, well-scoped task is also where Claude performs best. The IT service desk we built for Asset Services Group on Claude inside Microsoft Teams, fronting Zoho Desk, reached 99.7% first-time-right routing, as their Head of Technology stated in the published case study. Our write-up of a Teams service desk in practice explains how that kind of system fits together.

Keep track of guidance that is still moving

The rules around AI and data protection are not settled. The ICO states that, due to changes made by the Data (Use and Access) Act, its Guidance on AI and data protection is under review and may be subject to change. The guidance was updated on 15 March 2023, after requests from UK industry to clarify requirements for fairness in AI.

For transparency and explainability, the ICO points to its separate Explaining Decisions Made with AI product as the main guidance. Annex A of the AI guidance covers fairness across the whole AI lifecycle, from problem formulation to decommissioning. That lifecycle is a useful structure for your own review cycle, because it forces you to plan for switching the system off as well as launching it.

The practical response is to set review dates rather than treat compliance as a one-off sign-off. The ICO's Plans for new and updated guidance page tells you which guidance will be updated and when. Our overview of AI law that applies to your business tracks the wider picture as it changes.

Use the ICO toolkit to structure your risk review

You do not need to invent a risk method. The ICO's AI and data protection risk toolkit is designed to give practical support to organisations to reduce the risks to individuals' rights and freedoms caused by their own AI systems. It is a downloadable file that opens in Microsoft Excel or another spreadsheet program.

Note the wording. The toolkit addresses risks caused by your own AI systems, a reminder that choosing a reputable model provider does not move the responsibility to them.

Use the toolkit alongside your DPIA, not instead of it. Work through it with the people who will run the system day to day, not only your data protection lead, because many risks sit in configuration and daily use. Keep the completed spreadsheet, the DPIA and the saved DPA together as one evidence pack you can hand to an auditor or a customer.

Practical next steps

If you are deciding whether to deploy Claude on personal data, work through these steps in order. Each one produces a document you can keep.

  1. Audit current use. Find every Claude account in the business and the plan it sits on. Move any work involving personal data off Free and Pro accounts, which carry no DPA.
  2. Choose the route. Match the plan to your data. Team covers general commercial use; Enterprise is the option where you need SSO or audit logs. If you need regional processing, check the Bedrock or Vertex AI terms, and confirm zero data retention in your agreement with Anthropic.
  3. Save the DPA. Keep a dated copy of the version that applies to you and add the processing to your records.
  4. Check transfers. Confirm how data leaves the UK or EEA. If you are a UK business, make sure the terms include the UK Addendum or an IDTA and complete a transfer risk assessment.
  5. Screen for a DPIA. Treat the AI factor as present, check the remaining criteria, and do the DPIA if you have any doubt.
  6. Confirm the basis and tell people. Record your lawful basis for each use and update your privacy notice to explain the Claude processing before you go live.
  7. Scope the design. Limit the fields sent to the model, keep a person in the loop for significant decisions, and write outputs back to your system of record.
  8. Set a review date. Recheck the ICO guidance and your vendor terms on a date you fix now, not when something goes wrong.

Start with the audit. It usually takes a day and tells you how much of the rest is urgent.

Sources

  1. 1. Anthropic Privacy Center: What is your approach to GDPR or related issues?
  2. 2. ICO: Guidance on AI and data protection
  3. 3. ICO: When do we need to do a DPIA?
  4. 4. ICO: AI and data protection risk toolkit
  5. 5. Compound Law: Claude Team Plan DPA and GDPR Compliance Guide
  6. 6. Reddit r/microsoft_365_copilot: Is Claude for Copilot safe to use for SMBs

Related articles