What you will be able to do
- Identify who is the data controller and who is the processor on commercial Claude deployments
- Describe Anthropic's default retention commitments and where organisation retention settings live
- Choose between zero data retention and HIPAA readiness, and name what each does not cover
- Tell apart inference geo and workspace geo for data-residency requirements
- Explain why consumer and commercial terms matter for legal confidentiality
1.Who is responsible for the data
Regulations such as GDPR assign duties according to role. For commercial services, Anthropic's consumer Privacy Policy does not apply where Anthropic acts as a data processor on behalf of commercial customers. In that case the commercial customer is the controller. On the Claude API, Claude Platform on AWS and Claude in Microsoft Foundry, Anthropic is the processor. On Amazon Bedrock and Google Cloud's Agent Platform, the cloud provider is the processor, and that platform's documentation applies.
For a knowledge worker this has a practical consequence. When your team wants to analyse personal data about EU residents, the question is not 'is Claude GDPR-compliant?' It is whether your organisation, as controller, has an approved arrangement for this processing. Anthropic says its Privacy Policy, Data Processing Addendum and Help Center articles explain how it handles personal data. Those are the documents your privacy or legal team would review. The sources here don't describe the Addendum's terms, so don't guess what it guarantees.
2.What gets retained, and who sets it
On the API, Anthropic states a few default commitments. Retained data is never used for model training without express permission. Only what is technically necessary for a feature is kept. Conversation content is not retained by default, with one exception: Covered Models require 30-day retention. Retained data is purged on the shortest practical time to live.
Some data follows its own retention rules. Chat, file and project content in claude.ai follows the retention policy an organisation sets under Organization settings > Data and privacy, unless a user deletes it sooner. The Activity Feed keeps data for 6 years. Data available through the Compliance API follows its own retention model. You don't need to know how to call the Compliance API. You need to know that it exists and that admins can use it for oversight, so your organisation's retention setting may not be the only copy.
Sources2
3.Zero data retention versus HIPAA readiness
For the Claude API, Anthropic offers two arrangements. Under zero data retention (ZDR), prompts and responses are not stored at rest once the response is returned. HIPAA readiness takes a different approach. It doesn't delete data straight away. Instead it adds safeguards such as encryption, access controls and audit logging for protected health information (PHI), under a signed Business Associate Agreement (BAA). They solve different problems, and each has gaps.
| Point | Zero data retention | HIPAA readiness |
|---|---|---|
| What it does | No prompts or responses stored at rest after the API response | Broader safeguards for PHI throughout its lifecycle, not immediate deletion |
| How you get it | Request from Anthropic sales; enabled per organization | Signed BAA and a HIPAA-enabled organization, set up from the Claude Console |
| Claude Teams / Enterprise interfaces | Not ZDR-eligible (except Claude Code via Enterprise with ZDR enabled) | Not listed; HIPAA readiness applies to the Claude API for eligible features |
| Claude Code | Covered with Commercial organization API keys or Enterprise with ZDR | Not covered |
| Consumer plans (Free, Pro, Max) | Not covered | Not covered |
| Third-party integrations | Not covered | Not covered |
Two more limits catch people out. Beta features are generally outside the BAA unless the feature eligibility table lists them. Enabling HIPAA readiness from the Console is supported, but processing PHI through the Console is not covered. Before regulated data goes into any surface, check that this exact surface is covered, not just the organisation.
Sources2
4.Where data is processed and stored
Some requirements are about location rather than retention. Claude's data residency controls have two independent settings, and it is easy to confuse them.
| Setting | Controls | How it is set | Current options |
|---|---|---|---|
| Inference geo | Where model inference runs | Per request (inference_geo) or workspace default | "global" (default) or "us" |
| Workspace geo | Where data is stored at rest and where endpoint processing happens | Chosen when the workspace is created; can't be changed afterward | "us" only |
Admins can enforce a policy with allowed_inference_geos, which rejects requests for any geo outside the list. The response also records where inference actually ran, so compliance teams can check it.
{
"usage": {
"input_tokens": 25,
"output_tokens": 150,
"inference_geo": "us"
}
}A Claude.ai Pro user wants their conversations excluded from any model training data, but they've enabled the optional "model improvement" setting and use Incognito chats occasionally. What happens to their Incognito chats?
Correct answer: A — Incognito chats are excluded from model training even when the model improvement setting is enabled
- A. Correct. Incognito chats are specifically excluded from model training, even for users who have otherwise opted into the model improvement setting for their other conversations.
- B. Incorrect. The model improvement setting applies to a user's regular conversations; Incognito chats carry their own exclusion regardless of that setting.
- C. Incorrect. The 5-year rule applies to conversations retained under the model improvement setting, which does not apply to Incognito chats since they're excluded from training.
- D. Incorrect. Trust and safety flagging depends on detected policy violations in content, not on whether a chat was conducted in Incognito mode.
Sources4
5.Confidentiality and privilege: why the plan matters
Legal work shows why consumer and commercial terms matter. Anthropic presents this as its own perspective, not legal advice. In United States v. Heppner, a defendant used a consumer AI account without their lawyers' involvement, and the court held that use was not privileged work product. The court's reasoning rested on the consumer privacy terms and on the absence of direction from a lawyer.
Later decisions went the other way when confidentiality duties were in place. Morgan v. V2X approved uploading confidential information where the provider is contractually barred from training on, retaining or disclosing it beyond what the service needs. None of these are appellate decisions, and Anthropic encourages consulting your own counsel. The general lesson applies beyond law: confidential material belongs on a plan with commercial confidentiality commitments, used as your organisation directs.
Sources5
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Being on Claude Enterprise means the claude.ai chat interface runs under zero data retention.Why is that wrong?
The Teams and Enterprise product interfaces are outside ZDR. The only exception is Claude Code used through Enterprise with ZDR enabled.
Covered in Zero data retention versus HIPAA readiness
2.An organisation handling PHI needs both HIPAA readiness and ZDR to be safe.Why is that wrong?
HIPAA readiness is the arrangement for PHI on its own. It applies safeguards rather than deletion, and ZDR is not also required.
Covered in Zero data retention versus HIPAA readiness
3.Once the BAA is signed, PHI can be used in any Anthropic tool the organisation has, including Claude Code.Why is that wrong?
Coverage depends on the surface. Claude Code, the Console for processing PHI, consumer plans and most beta features are outside HIPAA readiness.
Covered in Zero data retention versus HIPAA readiness
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.https://privacy.claude.com/en/articles/10023555-how-do-you-use-personal-data-in-model-trainingOfficial docs
“the commercial customer is the controller”
↩︎ Who is responsible for the data - 2.
“On Amazon Bedrock and Google Cloud's Agent Platform, the cloud provider is the data processor”
↩︎ Who is responsible for the data“Retained data is never used for model training without your express permission.”
↩︎ What gets retained, and who sets it“Conversation content (your prompts and Claude's outputs) is not retained by default; the exception is Covered Models, which require 30-day retention.”
↩︎ What gets retained, and who sets it“The Activity Feed retains data for 6 years.”
↩︎ What gets retained, and who sets it“Under a ZDR arrangement, Anthropic does not store customer prompts or responses at rest after the API response is returned.”
↩︎ Zero data retention versus HIPAA readiness“With a signed BAA and a HIPAA-enabled organization, you can use supported API features to process PHI”
↩︎ Zero data retention versus HIPAA readiness“processing PHI through the Console is not covered”
↩︎ Zero data retention versus HIPAA readiness“Claude Teams and Claude Enterprise product interfaces: These interfaces are not ZDR-eligible.”
↩︎ Exam trap 1“If your organization handles PHI, HIPAA readiness is the arrangement to use; you do not also need ZDR.”
↩︎ Exam trap 2“Claude Code: Claude Code is not covered under HIPAA readiness.”
↩︎ Exam trap 3 - 3.https://privacy.claude.com/en/articles/10023628-what-is-your-approach-to-gdpr-or-related-issuesOfficial docs
“Our Privacy Policy, Data Processing Addendum, and Help Center articles explain how Anthropic handles personal data”
↩︎ Who is responsible for the data - 4.
“Workspace geo: Controls where data is stored at rest and where endpoint processing (such as image transcoding and code execution) happens.”
↩︎ Where data is processed and stored“allowed_inference_geos: Restricts which geos a workspace can use.”
↩︎ Where data is processed and stored - 5.
“The court's reasoning turned on the consumer privacy terms and the absence of attorney direction”
↩︎ Confidentiality and privilege: why the plan matters“where the provider is contractually barred from training on, retaining, or disclosing confidential data beyond what's necessary to render the service”
↩︎ Confidentiality and privilege: why the plan matters