Anthropic

Last Reviewed: 27 Jul 2026

GDPR Addressed

At a Glance

Anthropic's DPA addresses the key GDPR requirements, including SCCs and UK/Swiss addenda for international transfers, 48-hour breach notification, and a clear restriction against using Customer Personal Data for purposes such as model training. The main reason for confidence is this strong sole-processor commitment.

Company & Product Details

HQ

United States, Ireland

Products

AI Language Model Platform (Claude)

Product description

Provides the Claude family of AI models via API and enterprise products for building AI-powered applications and workflows.

What data is being processed?

Customer Personal Data — personal data submitted through the Services by or for Customer or a Customer Affiliate; categories of data subjects and personal data are determined by Customer's use and configuration of the Services

Document Details

Date of DPA

24 Feb 2025

Additional date information

Document states "Effective February 24, 2025" directly under the title.

What jurisdictions are covered?

GDPR/EU, UK GDPR, and Swiss Data Protection Laws are explicitly addressed via SCCs, a UK Addendum, and a Swiss Addendum; governing law/jurisdiction for the SCCs is Ireland, with the Swiss FDPIC as competent authority for transfers governed exclusively by Swiss law (Schedule 3).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA is automatically incorporated into and forms part of Anthropic's Commercial Terms of Service; accepting the Commercial Terms means also accepting the DPA, with no separate execution required (Preamble; Commercial Terms Section C).

Location & Transfers

Where is data held or processed?

Not Explicitly Stated The DPA does not state where Customer Data is stored or hosted; it addresses only international transfer mechanisms (SCCs, UK Addendum, Swiss Addendum) under Schedule 3.

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU SCCs (Module Two Controller-to-Processor and/or Module Three Processor-to-Processor, as applicable) are incorporated by reference and deemed executed by the parties; a UK Addendum (ICO template B.1.0) applies for UK GDPR transfers, and a Swiss Addendum adapts the SCCs for transfers governed by Swiss Data Protection Law, with the FDPIC as supervisory authority where transfers are exclusively Swiss (Section I, Schedule 3 A–C).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Extensive measures are set out in Schedule 2, including AES-256 encryption at rest and TLS 1.2+ in transit, MFA and RBAC access controls, SSO enforcement, annual third-party penetration testing and security assessments, incident response procedures, and logical data separation between customers (Schedule 2).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Clause B.3 restricts Anthropic from selling or sharing Customer Personal Data, from using or disclosing it for any purpose other than the specified business purposes (providing the Services and maintaining their quality, security and integrity), and from combining it with data from other sources. The related Commercial Terms of Service additionally confirm Anthropic may not train models on Customer Content. No controller rights or independent-use provisions over Customer Personal Data were identified (clause B.3).

Subprocessing

General authorization

General
Customer grants general authorization for Anthropic to use the subprocessors listed in Schedule 4 (published at anthropic.com/subprocessors) and any additional subprocessors added per clause C.3. For new subprocessors, Anthropic gives reasonable notice before granting access; Customer may object within 15 days on reasonable data privacy/security grounds, and if so the parties work in good faith toward a resolution (clauses C.1, C.3).

Do all the DPA terms flow down to sub-processors?

Yes
Anthropic imposes data protection obligations on each subprocessor that are substantially as protective as its own obligations under this DPA, and remains liable to Customer for subprocessors' acts and omissions to the same extent as for its own (clause C.2).

Is data only processed on the instruction of the controller?

Yes
Anthropic processes Customer Personal Data only to provide/maintain the Services and in compliance with Customer's documented instructions as set out in the Agreement and this DPA; Anthropic will promptly inform Customer if an instruction appears to violate Applicable Data Protection Law (clauses B.2, B.5).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Anthropic will promptly forward any Data Subject Request it receives to Customer, and provide reasonable and timely assistance as necessary for Customer to fulfil its obligation to respond (clauses D.1, D.2).

Does the contract include staff confidentiality clauses?

Yes
Anthropic ensures each person it authorizes to process Customer Personal Data is subject to an appropriate duty of confidentiality, and personnel sign confidentiality agreements as part of pre-employment screening (clause B.7; Schedule 2 C.1, C.3).

Are there audit rights for the data?

Structured
Anthropic undergoes annual third-party industry-standard audits and will share audit reports/certificates (e.g. SOC 2) on request. Customer may also conduct or commission its own Audit of Anthropic's controls, but no more than once every 12 months (absent non-compliance indicators or a regulatory requirement), subject to mutually agreed scope and confidentiality, and Customer bears the costs unless the audit is legally required or breach-driven (clauses F.1–F.4).

Is there assistance with DPIA requests?

Yes
Anthropic will cooperate with and provide reasonable assistance to Customer for data protection impact assessments and related consultations with supervisory authorities where Customer reasonably considers these required under Applicable Data Protection Laws (clause B.6).

How much notice is provided for data breaches?

Anthropic will notify Customer in writing without undue delay, and in any event within 48 hours, of becoming aware of a Security Breach, providing details of its nature, likely consequences, and mitigation measures, and will assist Customer's investigation (clauses G.1, G.2).

What happens to the data on termination?

Within 30 days of termination or expiration, Anthropic will, if requested, return Customer Data (or provide self-service functionality to do so) and will delete all copies held by Anthropic or its subprocessors, except where retention is required by law, to resolve a dispute between the parties, or to combat harmful use of the Services (clause H.1).