Is Claude GDPR compliant? What a UK business has to check, plan by plan.
By Zain M · 24 September 2026 · 17 min read
Claude can be used in line with UK GDPR, but the plan decides how much work that takes. Anthropic’s commercial products, the Team plan, Enterprise and the API, do not use your data for training by default, contract through Anthropic Ireland under a data processing addendum that incorporates the ICO’s UK Addendum to the standard contractual clauses, and are covered by ISO 27001, ISO 42001 and SOC 2 Type II. The consumer plans, Free, Pro and Max, ask each user to allow training with the option switched on, so they need the setting changed and are a poor fit for client data. Processing happens in the United States on every first-party plan; UK or EU residency means Claude on AWS Bedrock or Google Vertex. Compliance is then yours to finish: a lawful basis, a record of processing, a DPIA where the use is high risk, and a written policy on what staff may paste in.
The honest answer is “it depends on the plan and on you”
No software is GDPR compliant on its own. Compliance is a property of a processing activity: who the controller is, what the lawful basis is, what data goes in, where it goes, how long it stays, and whether the people it is about have been told. What a vendor can do is make each of those questions easy or hard to answer. Anthropic makes them easy on its commercial plans and leaves the consumer plans to the individual user.
So the question to ask is not “is Claude GDPR compliant” but “can my firm use this plan of Claude for this task and defend it to the ICO”. For most UK SMEs on the Team plan, with a sensible policy, the answer is yes. For a firm pasting client files into a personal Pro account with training left on, the answer is no, and the fix is cheap.
Training on your data: the plan-by-plan position
Anthropic’s privacy centre states that by default it will not use inputs or outputs from its commercial products to train its models. Commercial products means Claude for Work, which is the Team and Enterprise plans, the Anthropic API, and Claude Gov. The two exceptions are explicit feedback, when a user rates a chat or reports a bug, and any case where the customer chooses to allow it. Team and Enterprise owners can switch off the feedback route under Organisation settings, Data and Privacy.
The consumer plans changed in August 2025. Free, Pro and Max users, including when they use Claude Code from those accounts, are asked to choose whether their chats and coding sessions may be used to train future models. The prompt presents the option switched on. If it stays on, retention is five years for new or resumed conversations; if it is switched off, retention falls back to 30 days. The setting can be changed at any time in Privacy Settings and applies to new chats from that point.
The practical consequence for a UK employer is that every member of staff with a personal Claude account is a data controller decision you have not made. Either put them on a Team plan, or make the training toggle part of the acceptable-use policy and check it.
| Plan | Training on your content | Retention | Who controls it |
|---|---|---|---|
| Free, Pro, Max | Yes if the user leaves the setting on | Five years on, 30 days off | Each individual user |
| Team | No by default | Workspace setting | Your admin |
| Enterprise | No | Custom, zero-retention available | Your admin and contract |
| API | No by default | Per the DPA, zero-retention available | Your developers and contract |
Anthropic privacy centre and consumer terms, read 24 September 2026.
The contract: who you are dealing with and what it says
UK customers of the commercial products contract with Anthropic Ireland, Limited, under Anthropic’s commercial terms and a data processing addendum incorporated by reference. The commercial terms state that Anthropic may not train models on customer content from the services, that the customer owns its inputs and its outputs, and that data submitted through the services is processed under the DPA. Governing law is Irish, with arbitration in Dublin, which is worth knowing before a dispute rather than during one.
The DPA is where the GDPR mechanics live. It incorporates the EU standard contractual clauses (controller to processor and processor to processor modules) and, for transfers subject to UK GDPR, the ICO’s Approved Addendum, version B.1.0. It grants general authorisation for the sub-processors listed in its schedule, with fifteen days to object to a new one on reasonable data-protection grounds. It commits to AES-256 encryption at rest and TLS 1.2 or better in transit, multi-factor authentication and role-based access, annual independent audits, and return or deletion of customer data within thirty days of termination, except where law, a live dispute or abuse prevention requires retention.
That is a stronger starting position than most SaaS vendors a UK SME already uses. The gap is not in Anthropic’s paperwork; it is in whether the firm has read it, recorded Anthropic as a processor, and can produce the DPA when a client’s procurement team asks.
Where the data goes: the residency question
On every first-party plan, consumer, Team, Enterprise and the direct API, Claude runs on infrastructure in the United States. There is no UK or EU inference region on the first-party service as of September 2026. The transfer is lawful under the UK Addendum, and for the majority of UK businesses that is the end of the analysis: the same is true of most of the American software they already run.
Some firms cannot stop there. A client contract that requires processing to stay in the UK or EU, a regulator that has asked the question, or a risk appetite that rules out US processing of special-category data all point to the same route: Claude models served through AWS Bedrock in London or an EU region, or through Google Vertex in an EU region. Anthropic’s own regional compliance page directs European customers with residency requirements to exactly those options. The trade is that you are then building on an API rather than buying seats, which is a development project rather than a subscription, and our guide to what that costs to run applies.
One caution from the same page: routing Claude through Microsoft Foundry did not, as of mid-2026, keep inference inside the Azure region you selected, and Anthropic listed EU support there as coming. Check the current position before relying on it.
Security assurance you can hand to a client
Anthropic’s privacy centre lists ISO 27001:2022 for information security management, ISO/IEC 42001:2023 for AI management systems, SOC 2 Type I and Type II, and a HIPAA-ready configuration with a business associate agreement available, all covering the commercial products. The audit reports are available through Anthropic’s trust centre, and the DPA points to the same place for the annual independent assessment.
ISO 42001 is the one to notice. It is the management-system standard for AI specifically, and most vendors a UK firm compares Claude against do not hold it. When a client’s security questionnaire asks how your AI supplier governs its own models, that certificate is the short answer.
What the ICO expects you to do, in order
The ICO’s guidance on AI and data protection does not treat a chat assistant differently from any other processor, but it does expect the controller to have done the thinking. This is the order we work through with clients, and none of it takes more than a day for a firm that has its records in order.
Staff, monitoring and the employment angle
Rolling Claude out is also an employment matter, and the two guides the ICO would point you to are the same ones that cover any workplace tool. Staff need to be told, in the staff privacy notice, that an AI assistant is in use, what it is used for, and that the workspace admin can see usage and, on Enterprise, audit logs. If the firm intends to review what individuals put into Claude, that is monitoring, and the ICO expects it to be necessary, proportionate and explained in advance, not discovered from a disciplinary. Write the acceptable-use policy so that it tells people what will be checked and why.
Consent is the wrong basis for any of this. An employee cannot freely refuse a tool their manager requires, so the lawful basis for processing staff data through Claude is legitimate interests, documented with a short balancing test, or contract where the processing is part of the job. Keep the personal data of staff out of prompts where it is not needed; a request to “draft a warning letter to J Smith about lateness” carries special-category risk the moment health is mentioned, and belongs on a plan with retention you control.
Special-category data, children and automated decisions
Three kinds of processing raise the bar regardless of plan. Special-category data, which is health, ethnicity, religion, sexual orientation, trade-union membership, biometrics and genetics, needs an Article 9 condition on top of the lawful basis, and in practice belongs on Enterprise with a retention setting or on an in-region deployment, with a DPIA. Children’s data, for a school, a tutoring firm or a youth service, brings the ICO’s Children’s Code into scope and a higher expectation of minimisation. And any use of Claude to make or materially shape a decision with legal or similarly significant effects on a person, a hiring decision, a credit decision, a benefits or housing decision, is caught by the rules on automated decision-making: the person must be told, must be able to ask for human review, and the logic must be explainable. Claude is a fine drafting tool for those workflows and a poor decision-maker for them, and the design should keep a human in the loop where the consequence lands on an individual.
Subject access requests and what is actually stored
A subject access request that mentions AI is now common, and the answer depends on what your workspace retains. On a Team plan with retention set, the conversation history is data you hold and must search. Anthropic, as processor, retains what the DPA says it retains and deletes on termination within thirty days; it does not answer your data subjects directly. Keep the retention setting short enough that the search is manageable and long enough that you can reconstruct advice given. Firms that leave retention at its longest because “it might be useful” discover the cost when the first request arrives.
One more practical point. Where a client asks whether their data was used to train an AI model, the commercial plans let you answer no and point to the terms. Where a member of staff used a personal account with training left on, you cannot, and that is the sentence to read aloud to anyone who argues the Team plan is not worth the money.
Claude Code, Cowork and connectors
The same rules apply, with one extra consideration each. Claude Code from a consumer account falls under the consumer training choice, so a developer on a personal Max plan working on your codebase should be on a Team seat or the API instead. Connectors, which let Claude read your Google Drive, email or an MCP server, do not feed connector content into training unless it is copied directly into a chat, but they do widen what the tool can see, so admin control over which connectors are enabled is the setting to use. And anything that runs unattended, an agent that reads inboxes or files, is an automated processing activity in its own right and belongs in the DPIA.
Common questions
Is Claude GDPR compliant?
Claude can be used in compliance with UK GDPR. On the Team, Enterprise and API plans Anthropic does not train on your data by default, provides a DPA with the UK Addendum to the SCCs, and holds ISO 27001, ISO 42001 and SOC 2 Type II. Compliance itself is your responsibility as controller: lawful basis, records, a DPIA where needed, and a staff policy.
Is the Claude Team plan GDPR compliant?
It is the plan most UK SMEs should use for exactly this reason. Training is off by default, retention is controlled by your admin, and the DPA applies. You still need to record Anthropic as a processor and set a policy.
Is Claude Pro GDPR compliant for business use?
It is risky. Pro is a consumer plan where the user is asked to allow training with the option switched on, and retention is five years if it stays on. Switch it off and it is usable for one person; for client data, use Team.
Is Claude allowed in the UK?
Yes. Anthropic contracts with UK businesses through Anthropic Ireland and provides the ICO’s UK Addendum for the transfer of data to the United States, which is the lawful mechanism UK GDPR requires.
Where does Claude process data?
On Anthropic’s infrastructure in the United States for all first-party plans. UK or EU residency is available by running Claude through AWS Bedrock or Google Vertex in a UK or EU region.
Does Anthropic have a data processing agreement?
Yes. The DPA is incorporated into the commercial terms and incorporates the EU standard contractual clauses and the UK Addendum. It names sub-processors, security measures and a 30-day deletion commitment on termination.
Do I need a DPIA to use Claude?
Only where the processing is likely to be high risk under the ICO’s screening criteria: systematic profiling, special-category data at scale, or automated decisions about individuals. Everyday drafting and analysis usually does not need one; candidate screening or patient triage usually does.
Is Claude safe to use with personal data?
On a commercial plan, with a lawful basis and a policy, yes for ordinary personal data. For special-category data, use Enterprise or an in-region deployment and run a DPIA first.
Is Claude Code GDPR compliant?
Claude Code inherits the plan it runs on. From a Team or Enterprise seat or the API it is covered by the commercial terms. From a personal Pro or Max account it falls under the consumer training choice.
What certifications does Anthropic hold?
ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I and Type II, and a HIPAA-ready configuration, covering Claude for Work and the API, per Anthropic’s privacy centre in March 2026.
Need the paperwork done, not just described?
We set UK firms up on Claude with the processor record, the lawful-basis map per task, the DPIA where one is needed and the one-page staff policy, at a fixed price. Every recommendation names the data, the provider, the region and the lawful basis.