Is Claude GDPR compliant? The question is framed the wrong way. A model is not compliant or non-compliant by itself. Compliance belongs to your processing: which Claude product you use, what contract sits behind it, what personal data you send, where that data goes and what the system does with the answer.
Anthropic's own statement supports that reading. On its privacy centre, Anthropic says it approaches GDPR by "assessing worldwide privacy laws and regulations together with our customers' needs in the unique context of artificial intelligence and large language models". It adds that its Privacy Policy, Data Processing Addendum and Help Center articles explain how it handles personal data, whether directly from consumers or when it acts as a processor for its customers.
That last distinction matters most. When your business builds on Claude, Anthropic processes data on your behalf. You stay answerable for the processing under the GDPR or, in the UK, the UK GDPR.
The rest of this post is the checklist we work through before a Claude system touches personal data. It covers the plan, the contract, data location, the impact assessment, sensitive data, system design and the guidance you need to keep watching.
