Claude can be used in a way that meets UK GDPR requirements, but only under Anthropic’s commercial terms with the correct setup. Anthropic provides a data processing addendum, Standard Contractual Clauses for international transfers, and a UK Addendum as part of its commercial plans. Compliance depends on your organisation establishing a lawful basis, minimising personal data input, updating records, and completing a data protection impact assessment if needed. The vendor provides the tools; you must use them correctly.
Claude Free and Pro plans, which are consumer free offerings, are unsuitable for business data processing. These consumer plans lack a data processing agreement and treat Anthropic as an independent data controller. Using them with customer, client confidential, or personal data is unlikely to comply with UK GDPR.
Claude can be used in a way that meets UK GDPR requirements, but only under Anthropic’s commercial terms with the correct setup. Anthropic provides a data processing addendum, Standard Contractual Clauses for international transfers, and a UK Addendum as part of its commercial plans. Compliance depends on your organisation establishing a lawful basis, minimising personal data input, updating records, and completing a data protection impact assessment if needed. The vendor provides the tools; you must use them correctly.
Claude Free and Pro plans, which are consumer free offerings, are unsuitable for business data processing. These consumer plans lack a data processing agreement and treat Anthropic as an independent data controller. Using them with customer, client confidential, or personal data is unlikely to comply with UK GDPR.
Claude can be used in a way that meets UK GDPR requirements, but only under Anthropic’s commercial terms with the correct setup. Anthropic provides a data processing addendum, Standard Contractual Clauses for international transfers, and a UK Addendum as part of its commercial plans. Compliance depends on your organisation establishing a lawful basis, minimising personal data input, updating records, and completing a data protection impact assessment if needed. The vendor provides the tools; you must use them correctly.
Claude Free and Pro plans, which are consumer free offerings, are unsuitable for business data processing. These consumer plans lack a data processing agreement and treat Anthropic as an independent data controller. Using them with customer, client confidential, or personal data is unlikely to comply with UK GDPR.
There is no single switch that makes an AI system “GDPR compliant.” Compliance depends on two sides working together: what the vendor provides and what your organisation does with it.
Anthropic’s commercial terms include a data processing addendum that sets out security measures, subprocessor obligations, and deletion commitments. GDPR compliance is a shared responsibility between vendors and organisations. Anthropic holds ISO 27001:2022 certification, ISO/IEC 42001:2023 certification for AI management systems, and SOC 2 Type II certification. Encryption standards include AES-256 for data at rest and TLS 1.2+ for data in transit. These certifications support enterprise procurement assessments and are relevant for regulatory compliance documentation.
Anthropic models used in Claude models are designed with privacy and security in mind, ensuring that data processing is controlled and compliant under the commercial terms.
You must establish a lawful basis for processing personal data under UK GDPR (Article 6), such as legitimate interests or performance of a contract. You must be transparent with data subjects about what data you collect, how Claude processes personal data, and where it goes. You must practise data minimisation, only inputting what is necessary and anonymising where possible. And you must carry out a risk assessment, including a formal data protection impact assessment where the processing is high risk.
The distinction matters. Anthropic can give you the contractual and technical controls. Whether your deployment of Claude is compliant depends on how you configure and govern it within your organisation.
When your business uses Claude to handle personal data, your organisation is the data controller. You decide what data to send, why, and for what purpose. Anthropic acts as your data processor, processing that data on your behalf according to your instructions.
Under Article 28 of the UK GDPR, this controller-processor relationship requires a binding data processing agreement. The DPA must set out the scope of processing, security obligations, subprocessor arrangements, breach notification procedures, and your rights to audit. Claude Team and Enterprise plans include a data processing agreement. Consumer plans do not include a data processing agreement.
This is where consumer plans create a problem. Under Anthropic’s consumer terms, Anthropic may act as an independent controller of data you input. That means there is no DPA in place between your organisation and Anthropic, no contractual obligation for Anthropic to process data only on your instructions, and no Article 28 protections. For any UK business processing personal data, this is a compliance gap, not a technicality.
A signed DPA is required before processing personal data through Claude in a business context. Anthropic’s data processing addendum is included in commercial plans only. The DPA covers Team, Enterprise, and API tiers. When you accept those commercial terms, the DPA is automatically incorporated.
The DPA incorporates EU Standard Contractual Clauses for international data transfers and includes the UK Addendum, which makes those clauses valid under UK GDPR when data flows from the UK to jurisdictions without an adequacy decision.
Before deploying Claude, review the DPA for:
Confirm it covers the categories of personal data and processing activities your business needs
Check which third parties will handle your data and where they are located
Understand what happens to conversation data after processing and what custom retention controls are available on your plan
Confirm the timeframe and process Anthropic follows if a data breach occurs
Check whether you or a nominated third party can audit Anthropic’s compliance with the DPA terms
Confirm it covers the categories of personal data and processing activities your business needs
Check which third parties will handle your data and where they are located
Understand what happens to conversation data after processing and what custom retention controls are available on your plan
Confirm the timeframe and process Anthropic follows if a data breach occurs
Check whether you or a nominated third party can audit Anthropic’s compliance with the DPA terms
Data residency refers to where your data is stored and where the AI model runs its processing. This matters under UK GDPR because personal data transferred outside the UK needs a lawful transfer mechanism.
When you use the Claude API or Claude’s web interface under commercial terms, the data involved may be processed on infrastructure outside the UK. Anthropic’s published documentation does not currently confirm a UK-only data residency option through its direct service. For organisations that need EU data residency, Anthropic supports deployments through AWS Bedrock, Google Vertex AI, and Microsoft Foundry, which may offer EU-only processing through regional endpoints. AWS Bedrock EU profiles and Google Cloud Vertex configurations may allow you to keep workspace data storage and inference within an EU data boundary.
For international transfers under Anthropic’s direct service, the DPA uses Standard Contractual Clauses and the UK Addendum as the transfer mechanism. This is the same approach used across the industry when EU personal data or UK personal data moves to the United States or other jurisdictions.
What to ask Anthropic’s sales team before you commit:
If Anthropic cannot confirm data residency arrangements that meet your requirements, document that gap in your risk assessment and consider whether alternative deployment routes through Google Vertex or AWS Bedrock address it.
Handling customer data through Claude processes personal data with particular caution. Your organisation remains the data controller and must ensure that any personal data or confidential information you input is processed lawfully and securely.
Confidential documents, such as contracts, client records, or sensitive internal papers, should only be input into Claude under strict policies that limit access and ensure compliance with data protection principles. Avoid inputting special category data unless you have explicit lawful basis and safeguards.
Implement clear staff guidance on what constitutes confidential data and how to handle it within Claude. Define escalation procedures for any suspected data breaches or misuse.
Verify you are on a commercial Claude plan (Team, Enterprise, or API) with Anthropic's data processing agreement active. Consumer plans (Claude Free, Pro, Max) do not include a DPA and are not suitable for processing personal data in a business context.
Under Article 6 of the UK GDPR, you need a lawful basis for each type of personal data processing you intend to carry out through Claude. Common bases for business use are legitimate interests or performance of a contract. Record your reasoning.
Set clear rules for what data can and cannot be entered into Claude. Specify that confidential documents, special category data (such as health records or biometric data), and client confidential data must not be input without explicit authorisation and safeguards. Define escalation protocols and who approves exceptions.
If your use case involves health data, racial or ethnic origin, biometric data, or any other special category data, you need a separate lawful basis under Article 9 of the UK GDPR. Consult your Data Protection Officer or adviser before proceeding.
Add Claude to your processing records: what categories of personal data are processed, retention periods, data flows including international transfers, subprocessors, and the lawful basis for each activity.
A DPIA is legally required under Article 35 for high risk processing. If you are deploying Claude across the organisation, handling large volumes of personal data, or inputting sensitive data, carry out a DPIA before go-live. Your DPO should assess whether your specific use case triggers this requirement.
Ensure only authorised staff can access Claude under your commercial plan. Check whether your plan provides audit logs to support usage policy enforcement and accountability.
Claude Enterprise is Anthropic’s highest-tier commercial offering, designed for organisations that require enhanced governance, compliance controls, and security features. It includes single sign-on with SCIM provisioning, audit logs, custom retention controls, and an optional Zero Data Retention add-on for sensitive data.
Many professional services and legal teams adopt Claude Enterprise for workflows involving confidential documents, contract review, and compliance documentation. Its extended context windows support large document analysis and multi-document workflows.
Most UK SMEs we work with know they should be doing something about AI governance but do not have the internal resource to build a compliance framework from scratch. The Core AI Security Pack gives you the structure.
The pack costs £29.68 per user per month (not-for-profit rate: £26.98), excluding VAT, on a three-year term. It is available only to clients on Complete Unlimited IT Support. It includes AI policy templates, DPIA frameworks, and the compliance documentation your organisation needs to demonstrate that deploying Claude (or any other AI tools) has been done with proper governance in place.
The pack does not replace legal advice. It gives your business the operational framework that sits between the legal requirements and the day-to-day reality of staff using Claude with real data.
This page covers general UK GDPR principles as they apply to using Claude and Anthropic’s services in a UK business context. It is not legal advice. Compliance depends on your specific use case, the types of data involved, your risk assessment, and how you configure and govern the tool.
Organisations should confirm their position with their own data protection adviser or solicitor, particularly where special category data, solely automated decisions affecting individuals, or high-risk processing is involved.
The regulatory layer around AI and data protection is still developing. Anthropic’s terms, the ICO’s guidance, and the broader legal landscape for international transfers all continue to evolve. Review your compliance position regularly, not just at initial deployment.
We Do Your IT Support helps UK businesses implement AI tools with proper data protection governance in place. If you are considering deploying Claude across your organisation and want to understand your compliance position before staff start using it with real data, we can help.
Book a free 30-minute AI Security Review. We will assess your current setup, identify gaps in your DPA coverage, data residency arrangements, and internal policies, and set out clear next steps. The Core AI Security Pack then gives you the complete framework to move from assessment to compliant deployment.
Get in touch to discuss your Claude implementation and compliance requirements.
Anthropic does not train models on data from commercial plans. Claude’s commercial terms prohibit training on customer data. This is a contractual commitment built into Anthropic’s commercial terms, not a user setting you need to toggle. Under consumer terms, data may be used for model training depending on your settings, with retention of up to five years if you opt in to allow training data use.
Retention policies differ by plan and data type. Anthropic deletes API inputs and outputs within 30 days. Claude retains deleted chats for 30 days by default. Zero data retention (ZDR) is available for eligible API traffic and for qualifying enterprise customers handling sensitive data, preventing storage beyond the active session. Some data may be retained for up to 2 years for safety reviews where content has been flagged. Data retention policies aim to keep personal data only as long as necessary for specified purposes.
There is no confirmed UK-only data residency option through Anthropic’s direct service at the time of writing. Alternative routes through AWS Bedrock or Google Cloud Vertex may offer EU data residency through regional endpoints. Confirm current options directly with Anthropic, as these arrangements may change. Ask specifically about whether inference and storage can both be confined to a UK or EU region for your plan.
A data protection impact assessment is often necessary for deployment, particularly where your organisation is rolling out Claude across teams, handling large volumes of personal data, or processing special category data. Article 35 of the UK GDPR requires a DPIA for high-risk processing. Your Data Protection Officer should assess whether your specific use case meets that threshold. Even where a DPIA is not strictly required, completing one demonstrates good governance.
The team plan, by comparison, offers standard seats and premium seats at fixed rates billed annually or monthly with a minimum of five seats, giving you more predictable budgeting.
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.