Anthropic
Last Reviewed: 27 Jul 2026
At a Glance
Anthropic's DPA addresses the key GDPR requirements, including SCCs and UK/Swiss addenda for international transfers, 48-hour breach notification, and a clear restriction against using Customer Personal Data for purposes such as model training. The main reason for confidence is this strong sole-processor commitment.
Company & Product Details
HQ
United States, Ireland
Products
AI Language Model Platform (Claude)
Product description
Provides the Claude family of AI models via API and enterprise products for building AI-powered applications and workflows.
What data is being processed?
Customer Personal Data — personal data submitted through the Services by or for Customer or a Customer Affiliate; categories of data subjects and personal data are determined by Customer's use and configuration of the Services
Document Details
Date of DPA
24 Feb 2025
Additional date information
Document states "Effective February 24, 2025" directly under the title.
What jurisdictions are covered?
GDPR/EU, UK GDPR, and Swiss Data Protection Laws are explicitly addressed via SCCs, a UK Addendum, and a Swiss Addendum; governing law/jurisdiction for the SCCs is Ireland, with the Swiss FDPIC as competent authority for transfers governed exclusively by Swiss law (Schedule 3).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not Explicitly Stated The DPA does not state where Customer Data is stored or hosted; it addresses only international transfer mechanisms (SCCs, UK Addendum, Swiss Addendum) under Schedule 3.
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Extensive measures are set out in Schedule 2, including AES-256 encryption at rest and TLS 1.2+ in transit, MFA and RBAC access controls, SSO enforcement, annual third-party penetration testing and security assessments, incident response procedures, and logical data separation between customers (Schedule 2).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Anthropic will notify Customer in writing without undue delay, and in any event within 48 hours, of becoming aware of a Security Breach, providing details of its nature, likely consequences, and mitigation measures, and will assist Customer's investigation (clauses G.1, G.2).
What happens to the data on termination?
Within 30 days of termination or expiration, Anthropic will, if requested, return Customer Data (or provide self-service functionality to do so) and will delete all copies held by Anthropic or its subprocessors, except where retention is required by law, to resolve a dispute between the parties, or to combat harmful use of the Services (clause H.1).