Yes, Claude can be run in a GDPR-compliant way, provided you use the right plan. On Claude's commercial terms (Team, Enterprise and the API), Anthropic does not train its models on your Customer Content, offers a Data Processing Agreement, deletes chats you remove within 30 days, and holds SOC 2 Type II, ISO 27001:2022 and ISO/IEC 42001:2023 certifications. The free and Pro consumer plans are not covered by the DPA, so businesses should not run client data through them. Facts checked 22 Jul 2026.
This post covers the specific compliance and security questions we're asked before a Claude rollout goes ahead. If you want the wider case for adopting Claude first, see our piece on Claude AI agents for business.
Does Claude train on your business data?
No, not if you're on a commercial plan. Under Anthropic's commercial terms, which cover Team, Enterprise and the API, Anthropic does not use your Customer Content (your prompts and outputs) to train its models. This is a contractual commitment written into the terms you sign, not a setting you have to remember to switch off, and it only applies once you've moved off the free consumer product.
How long Claude keeps your data
Retention periods differ by plan and by data type. The table below sets out the defaults.
| Data type | Default retention |
|---|---|
| Team or Enterprise chats you delete | Removed from Anthropic's back-end within 30 days |
| API inputs and outputs | Auto-deleted within 30 days by default |
| Content flagged for trust and safety review | Up to 2 years |
| Safety classification scores | Up to 7 years |
| Feedback you submit (thumbs up/down, corrections) | 5 years |
From 09 Jun 2026, Anthropic also applies a specific 30-day retention policy to inputs and outputs from what it terms "Covered Models", worth checking against your own model list if you're relying on a particular retention period for a compliance sign-off.
Zero data retention (ZDR)
Zero data retention (ZDR) is a per-organisation arrangement, agreed directly through Anthropic's sales team, under which eligible API traffic and Claude Code activity are not retained at all once a response has been returned. ZDR is available, but only for API workloads, and only by arrangement. It does not extend to the standard Team or Enterprise chat interface, to the Console, or to the consumer Free and Pro plans, all of which follow the standard retention periods set out above. See Anthropic's API and data retention documentation for the current scope.
Certifications and attestations
Anthropic maintains a set of independent certifications and attestations that cover Claude's commercial plans. The table below reflects the current position.
| Certification / attestation | Status |
|---|---|
| SOC 2 | Type I and Type II held |
| ISO 27001 | 2022 version held |
| ISO/IEC 42001 | 2023 version held |
| HIPAA | HIPAA-ready configuration, with a BAA available |
Anthropic publishes and updates the current list on its trust and compliance page, which is worth checking directly before quoting a certification in a customer-facing document.
Deploying Claude safely: what to set up before go-live
Before any personal data flows through Claude, three things need to be in place: a signed Data Processing Agreement that accurately describes the processing, confirmation from your Data Protection Officer (DPO) of the lawful basis you're relying on, and clarity on international transfers. None of this is legal advice, more a checklist your DPO will expect answered before sign-off.
International data transfers
Anthropic's infrastructure and operations span multiple jurisdictions, so UK or EU personal data processed through Claude will typically involve a cross-border transfer. As provided for in Anthropic's Data Processing Agreement, transfers are governed by the safeguards it sets out, including EU Standard Contractual Clauses together with the UK-required transfer safeguards.
Single sign-on and admin controls
Single sign-on (SSO) is available on both the Team and Enterprise plans, not on Enterprise alone. It's delivered via SAML, with support for Okta, Google and Microsoft Entra as identity providers, which lets IT de-provision access centrally the moment someone leaves rather than relying on a separate Claude password.
Do you need a DPIA?
A UK organisation processing personal data at scale through Claude, particularly special category data or data covering a large number of individuals, will likely need a Data Protection Impact Assessment (DPIA) before go-live. That's a decision for your DPO, not something SpotDev or Anthropic can rule on, but the ICO's DPIA guidance is the standard starting point for working out whether one is required and what it should cover.
Five steps to a safe Claude rollout
Once the paperwork above is under way, a Claude rollout usually follows the same five steps. For a fuller walkthrough of the mechanics, see our Claude for Work deployment guide for UK companies.
- Pick the right plan: use a business or enterprise tier so the no-training default, the DPA and the admin controls all apply.
- Sign the paperwork: get the DPA in place and have your DPO confirm the lawful basis and the transfer cover before real data flows.
- Turn on SSO and define admins: connect Claude to your identity provider and name a small, accountable group of administrators.
- Set usage rules: write a short, plain policy covering what staff may and may not put into Claude, and brief everyone on it.
- Start with a contained pilot: begin with one team and one or two use cases, review what is being logged, then widen access.
If you're building wider AI governance rather than a single rollout, our AI governance framework for mid-sized UK businesses covers policy, oversight and risk beyond this post. For our own accreditations and delivery record behind this checklist, see our credentials.
Where SpotDev fits
SpotDev specialises in Claude implementation for UK organisations. Our in-house team has completed over 300 technology projects with no subcontracting, so the people who design your security and governance setup are the same people who build it. Rather than reselling tools, we handle the engineering and configuration needed to establish controlled, audited deployments. Fixed-price packages range from £8,000 to £45,000, with typical first rollouts completed in two to three weeks, via our Claude implementation packages.
SpotDev designs, builds and deploys custom Claude agents and enterprise Claude rollouts for UK businesses, with fixed packages from £8,000 to £45,000 and a first rollout live in two to three weeks. Explore our Claude implementation packages or get in touch about a rollout.
FAQs
Is Claude GDPR compliant?
Yes, on the right plan. Anthropic's Data Processing Agreement covers the Team, Enterprise and API tiers, but not the Free or Pro consumer plans, so client or staff personal data should never be processed on those. Whole-organisation compliance also depends on your own configuration, the lawful basis you rely on, and the usage rules you set for staff.
Does Claude train on my business data?
No. Under Anthropic's commercial terms, covering Team, Enterprise and the API, your Customer Content is not used to train Anthropic's models. This is a contractual commitment written into those terms, not a setting to remember to switch off, though it only applies once you're on a commercial plan rather than the free consumer product.
How long does Claude keep deleted data?
By default, chats you delete in Team or Enterprise, and API inputs and outputs, are removed from Anthropic's back-end within 30 days. Some categories are held longer: content flagged for trust and safety review for up to 2 years, and safety classification scores for up to 7 years, under Anthropic's published retention schedule.
What is zero data retention and who can get it?
Zero data retention (ZDR) is a per-organisation arrangement agreed directly with Anthropic's sales team, covering eligible API traffic and Claude Code, where nothing is retained after the response is returned. It does not cover the standard Team or Enterprise chat interface or the Console, so most day-to-day chat use still follows the normal retention periods above.
Does Claude support single sign-on?
Yes. SSO is available on both the Team and Enterprise plans, not Enterprise only, delivered via SAML, with support for Okta, Google and Microsoft Entra as identity providers. That lets IT de-provision access centrally the moment someone leaves, rather than relying on a separate Claude password.
Do we need a DPIA before deploying Claude?
Usually, yes, if you're processing personal data at scale or handling special category data. It's a decision for your DPO, not a call SpotDev or Anthropic can make for you, but the ICO's DPIA guidance is the standard reference point for working out whether one is required and what it should cover.
Is Claude safe for business use?
Yes, provided you use the right plan and set it up properly. Team, Enterprise and API deployments come with a DPA, no training on your content by default, and independent certifications; the free consumer product does not. Safety in practice also depends on the access controls, usage rules and DPIA work covered above.
Stay Updated with Our Latest Insights
Get expert HubSpot tips and integration strategies delivered to your inbox.



