Skip to content
Back to blog
GDPROperational checks for a Claude deployment

Claude and GDPR: what the deployment team must verify

Anthropic offers commercial data terms and a DPA, but a Claude deployment still needs a documented route, purpose, retention policy, access model and review by the organisation responsible for processing.

A provider contract is one input to a GDPR review. The company still chooses the account, data route, purpose, retention, permissions and safeguards for its process.

Author

Syntalith

Published Updated 8 min read

“Is Claude GDPR compliant?” is too broad for a deployment decision. Anthropic's commercial material describes a customer organisation as controller and Anthropic as processor for commercial services, and Anthropic publishes a data processing addendum with standard contractual clauses. The company still has to document its own purpose, data, product route, retention and access model.

The official Anthropic Privacy Center and the DPA guidance should be read for the account and service selected. The GDPR text remains the source for the organisation's obligations.

Resolve the account and role first

Record whether the workflow uses a commercial Claude organisation, the API or a consumer account. An employee's personal account does not give the company the same administrator controls, contract or export path as an organisation-owned service.

For a commercial service, record:

  • the company acting as controller;
  • Anthropic and any cloud provider involved in the route;
  • the purpose and categories of data sent;
  • the groups of users and data subjects involved;
  • the service terms and DPA version;
  • the administrator who can change privacy settings.

Anthropic's commercial data guidance says commercial inputs and outputs are not used to train models by default. The same guidance describes exceptions such as explicit feedback or an opt-in programme. Save the applicable terms and account setting with the processing record.

Match the route to the data policy

The API, a first-party work product and a cloud marketplace route may differ in processing location, administrator controls, retention and contract chain. Ask the supplier and cloud provider:

  1. Where is the request processed and stored?
  2. Which party operates each step?
  3. Which subprocessors can receive the data?
  4. What transfer safeguards apply outside the EEA?
  5. Can the organisation restrict regions or retention?
  6. What happens when a route or model changes?

Do not infer the route from the model name. Save the exact product, organisation, region and feature configuration in the record of processing activities. A cloud service can change the processing chain even when the model family remains the same.

Set retention and deletion deliberately

Anthropic's retention guidance distinguishes API handling from products that retain conversations for continued use. It also describes deletion controls and exceptions. Compare those terms with the company's retention schedule.

On the company side, decide:

  • whether prompts and outputs enter an application log;
  • how long source documents and model responses remain;
  • which users can export or delete conversations;
  • how a deletion request reaches backups and downstream systems;
  • which data must be redacted before a model call;
  • how an incident freezes or shortens retention.

Model output should not become a second uncontrolled archive. Keep only the records needed for the process, its audit trail and the organisation's documented purpose.

Review access, security and subprocessors

Map the minimum permission for each user, service and integration. A support classifier may read a limited queue and write a review item. It need not send an external message or reach an unrelated customer system.

The technical review should cover authentication, credential rotation, encryption, network route, logging, incident notification, backup access and test data. The contractual review should cover the DPA, subprocessors, audit information, deletion and transfer safeguards. GDPR Article 28 requires a processor contract with defined processing details; Article 32 requires measures appropriate to the processing risk.

Turn findings into a deployment record

Use one page that a process owner, security lead and counsel can inspect:

Process:                 ................................
Purpose:                 ................................
Data categories:         ................................
Controller:              ................................
Processor and route:     ................................
Subprocessors:           ................................
Processing location:     ................................
Retention on our side:   ................................
Access roles:            ................................
Deletion path:           ................................
Security controls:       ................................
Review owner and date:   ................................

Link the record to the exact Anthropic product documentation and contract version. Revisit it when the product route, feature set, model, data class or retention policy changes.

Decide whether Claude fits the process

Claude may fit when the company can define the purpose, minimise data, document the route and retain a responsible owner. Delay the integration when the account is personal, the source data has no lawful purpose, retention is unknown, or the process owner cannot explain who may access the output.

Syntalith can map the data route, access controls, retention and audit trail in an Implementation Specification starting from €1,200 net. For the earlier question of whether the process is worth automating, use a free process scan. This page supplies an operational checklist; the organisation's counsel decides how its processing meets applicable law.

Frequently asked questions

Does Claude come with commercial data terms?
Anthropic's commercial documentation describes the customer as controller and Anthropic as processor for commercial services, with a DPA incorporated into the commercial terms. Confirm the terms and route that apply to the organisation's account.
Is commercial Claude data used for model training?
Anthropic's Privacy Center says inputs and outputs from commercial products are not used to train models by default, subject to feedback, opt-in and contract conditions. Record the applicable setting and terms for the account you use.
What should a GDPR review cover before deployment?
Document the purpose, data categories, controller and processor roles, route and hosting, retention, access, deletion, security, subprocessors and transfer safeguards. The organisation's counsel and security owner should approve the final record.
Does an EU data centre answer the whole GDPR question?
No. Location is one part of the processing record. Purpose, minimisation, access, retention, security, contractual terms and the actual product configuration also require review.

Free process scan

Start with a free process scan.

  • A 30-minute call with the engineer who would lead the work.
  • A review of the processes that cost you the most time and money.
  • A written summary of what to automate first and the likely cost range.

The scan chooses one process to assess, and within 2 business days you receive a recommendation, including when a simpler route is the better fit.

€0

30 minutes · written takeaway within 2 business days

Book a free process scan (30 min)

Times are shown in your own time zone. We work with clients across time zones.

Describe the process in the form