What Happens to Your Company's Data When You Use Claude?
Current as of 11 September 2026. The policies described here change regularly: check the sources cited before making any binding decision.
Three answers, before the detail. If your teams use Claude from a personal account, your data may be used to train the model and kept for up to five years. If your company goes through a commercial contract — API, Team or Enterprise — Anthropic does not use it for training and generally deletes it within thirty days. But in both cases, through direct access, it is stored in the United States — and that is the point most articles leave out.
This article sets out what actually happens, channel by channel, based on Anthropic's public documentation and the applicable legal texts. It also states plainly what Claude does not allow today.
The right question is not "is Claude secure?"
That is the question everyone asks, and it has no answer. It is like asking whether a car is safe without saying who is driving, or on what road.
The question that lets you decide is a different one: through which door does your data reach Anthropic? There are four, and the legal and technical regime changes radically from one to the next. The same employee, on the same case, pasting the same text into the same window, creates an entirely different risk depending on the route taken.
What actually changes from one channel to the next
Three parameters deserve your attention, and only one of them is usually discussed.
Training. Is your data used to improve the model? For commercial offerings — API, Team, Enterprise, for Government, for Education — Anthropic states: "By default, we will not use your inputs or outputs from our commercial products to train our models." One exception remains: if a user clicks thumbs up or thumbs down to rate a response, that conversation may be used. This feedback data is kept for five years and de-linked from the user identifier. An administrator can disable the feature entirely in the organisation's settings.
Retention. How long does the data stay? This is where the surprises are, set out below.
Location. Where is it physically? This is the parameter most often confused with the other two, and the most decisive in legal terms.
The personal account: blind spot number one
Here is the most common scenario, and there is nothing exotic about it. An employee has a personal Claude account, opened on their own initiative. They paste in a contract extract, a salary table or the minutes of a board meeting to save an hour. Nobody forbade it, and nobody knows.
Since 28 August 2025, consumer accounts — Free, Pro and Max — have worked on an opt-out basis: the user chooses whether their conversations train the model, and the setting is on by default. If they accept, or simply do nothing, retention extends to five years. If they switch it off in the privacy settings, it falls back to thirty days and the conversations stop feeding training.
The contrast is stark: your Enterprise contract, negotiated and signed, protects perfectly the data that passes through it. It protects nothing that passes beside it. Your company's legal exposure therefore rarely turns on the contract, and almost always on the uses nobody has framed.
The practical consequence is simple: an AI usage policy with no professional access provided alongside it achieves nothing. Banning without offering an alternative moves the usage out of your sight; it does not remove it.
How long is your data kept?
The usual answer — "thirty days" — is accurate for the standard case and incomplete for everything else. Here is the real picture.
| Situation | Retention period |
|---|---|
| API, standard case | Deleted within 30 days |
| Personal account with training accepted | Up to 5 years |
| Conversation rated with thumbs up or down | 5 years |
| Content flagged as violating the usage policy | 2 years for inputs and outputs |
| Classification scores attached to a flag | 7 years |
| Activity feed (Enterprise, Compliance API) | 6 years |
| Most recent models, designated "covered" | 30 days, mandatory, with no possible exception |
The last two rows are worth pausing on, because they are counter-intuitive.
Since 9 June 2026, Anthropic designates some of its most capable models as covered models. For those, thirty days of retention are imposed, including on organisations holding a zero data retention agreement, unless expressly authorised by Anthropic. Technically, an organisation that has not enabled retention at workspace level receives an error and simply cannot use these models.
In other words: the more recent the model, the less the zero-retention commitment applies. That is the opposite of what most executive teams assume, and it invalidates a widespread shortcut — "we have ZDR, so we are covered".
Where is your data, physically?
This is where the market's most expensive confusion sits, and it fits in one sentence: zero retention is not data residency.
These are two orthogonal guarantees. Zero retention answers "for how long?". Residency answers "on what territory?". You can perfectly well have no storage at all and still have every token processed on US infrastructure.
Anthropic's documentation is explicit about two distinct settings. The first governs where inference runs: today it accepts the values global and us. The second governs storage at rest: today it accepts only the value us, and it cannot be changed after the workspace is created. The privacy centre, in its 15 June 2026 version, puts it without ambiguity: traffic may be routed to several countries, including in Europe, but "data is stored in the US".
So the wording has to be precise: through direct access you can restrict inference to US territory — billed at 1.1 times the standard rate — but you cannot choose Europe for storage. The option does not exist.
The only genuinely European route means changing your access provider, not your model: going through AWS Bedrock or Google Cloud in a European region. In that setup the cloud provider is the data processor, the region depends on the endpoint you choose, and the data stays inside your cloud environment. Put simply: the way to keep Claude in Europe is to rent it from a European host rather than buy it directly from Anthropic.
The corporate gateway: taking back control of the exit point
You do not choose where Anthropic stores your data. You do, however, choose entirely what leaves your premises, who sends it, and what trace remains. That is exactly what a gateway is for: an intermediate server — most often a simple VPS with a European host — through which every call to the model passes.
The principle fits in one sentence. Today, if ten employees and three applications use Claude, you have thirteen direct accesses, thirteen keys to manage and no overall visibility. With a gateway, nobody calls Anthropic any more: everyone calls your server, and your server alone holds the key.
This seemingly minor shift changes six things.
- One key, revocable in a minute. Staff and applications receive virtual keys that you issue and withdraw at will. A departure, a contractor finishing an assignment, a suspected leak: you cut access without reconfiguring anything else.
- A complete log. You know who sent what, when, and to which model. That is what turns a good-faith declaration into evidence — before a regulator, before a professional body, or under the AI Act's transparency obligation.
- Anonymisation before sending. The gateway can detect and replace names, addresses, national insurance numbers, bank details or case references with tokens, then restore the real values in the response. Identifying data never leaves your infrastructure. This is by far the most effective protection described in this article.
- Filtering. You can block, not merely observe: refuse a file above a certain size, a document carrying a confidentiality marking, or a pattern that looks like a technical secret.
- Per-team quotas. A monthly budget per department, an alert when it is exceeded. Incidental for compliance, decisive for cost control.
- Choice of exit point. Your gateway decides whether to route to the direct API or to a European region on AWS or Google Cloud — and can change later without anyone altering how they work.
What a gateway does not do. Four limits, stated plainly. It changes nothing about where processing happens at Anthropic: it is a control point, not a sovereignty barrier. It concentrates in one place everything your company sends to a model, which makes it a target to be secured and monitored accordingly. Its log is itself a processing operation on personal data, to be entered in your records with a defined retention period. And it in no way stops an employee from opening Claude in a browser: without network blocking and a usage policy, it leaves the personal-account door wide open.
What it costs. The server, almost nothing: no inference happens on your side, the machine merely relays. Two to four cores and four to eight gigabytes of memory are ample, which is a few tens of euros a month with a European host such as OVHcloud, Scaleway or Hetzner. The VPS is not the issue.
The real cost is integration: allow a few days for a gateway built on an open-source component, properly logged and connected to your corporate directory. More if you add automatic anonymisation, which has to be calibrated against your real data — badly tuned, it degrades answers by masking what the model needs in order to reason. Set against the cost of a breach notification or an on-site audit, the trade-off is rarely a close call.
What Claude does not allow today
This section is deliberately blunt. An article that offers nothing but reassurance does not help you decide.
- No European residency through direct access. Storage is American, full stop. The only European route runs through a third-party host.
- No SecNumCloud qualification, and no ANSSI security visa. These French state cloud-security qualifications do not appear among Anthropic's published certifications. If your market or your supervisory authority requires them — as some public bodies and critical-infrastructure operators do — Claude is out of scope, whatever its configuration.
- The US CLOUD Act applies. Anthropic is a US company. American authorities can, within a defined judicial framework, compel the production of data held by a US company, including data stored outside the United States. No contractual clause neutralises that risk; only an architecture in which data never reaches the provider in clear form reduces it.
- Zero retention is shrinking on recent models. See above: covered models impose thirty days.
- You remain the data controller. European regulators are consistent on this point: if you use a third-party model with your customers' or employees' personal data, responsibility for the processing is yours — not the model provider's. Their contract frames your position; it does not discharge it.
What Claude offers in return, and what is verifiable: ISO 27001:2022 certification for information security, ISO/IEC 42001:2023 for AI management systems — Anthropic was among the first to obtain it — SOC 2 Type I and Type II reports, a HIPAA-ready configuration with a business associate agreement, FedRAMP High authorisation and UK Cyber Essentials certification. That is a serious foundation. It does not replace an architectural decision.
The legal framework, and why it is moving right now
Two texts concern you, and one of them is wobbling.
The GDPR governs your relationship with Anthropic through a data processing agreement under Article 28, and transfers to the United States through an adequacy mechanism or standard contractual clauses. Since July 2023, adequacy decision 2023/1795 — the Data Privacy Framework — has permitted such transfers to certified US companies.
That foundation is now contested on two fronts. The General Court of the European Union dismissed the Latombe action on 3 September 2025, confirming the framework's validity; an appeal was lodged with the Court of Justice on 31 October 2025 and remains pending. More importantly, on 29 June 2026 the US Supreme Court held in Trump v. Slaughter that Federal Trade Commission commissioners are removable by the President. The independence of that authority is one of the pillars on which the adequacy finding rests. On 31 July 2026, the European Data Protection Board wrote to the Commission asking it to examine the consequences of that decision.
Precision about the state of the law matters here: the adequacy decision remains in force, no court has annulled it, and transfers to certified companies remain lawful. Some analysts hold that the ruling does not affect the redress mechanism provided for by the framework. But the probability of it being called into question within the next twenty-four months is no longer negligible, and it belongs in your assessment.
The AI Act, for its part, already applies in part. Since 2 August 2026, the transparency obligations of Article 50 have been binding: people must be clearly informed when they are interacting with an AI system, and generated content must be marked. Added to this is an obligation to train your teams on the capabilities, limits and risks of the systems you deploy. Obligations relating to high-risk systems, by contrast, have been postponed by the Digital Omnibus regulation: December 2027 for Annex III, August 2028 for Article 6(1). Maximum penalties reach 35 million euros or 7% of worldwide turnover.
Note the order of priority: what concerns you today is transparency and training. The rest leaves you a year to prepare, provided you start now.
And the others? Claude against ChatGPT, Gemini and Mistral
The honest comparison rests on one observation: on the commitment not to train on business data, all four are equivalent. Where they genuinely diverge is data residency.
| Provider | Training, business tiers | European residency |
|---|---|---|
| Claude (Anthropic) | No, by default | Indirect: via AWS or Google Cloud in an EU region |
| ChatGPT (OpenAI) | No on Team, Enterprise and API; yes by default on consumer tiers | Yes, business option since 2025; excluded from consumer tiers |
| Gemini (Google) | No on the paid API and Vertex AI | Yes, European regions on Vertex AI |
| Mistral | No on the API and Enterprise tiers; on by default on consumer tiers | Yes, by default — no transfer outside the EU to cover |
The structural difference is here: with Anthropic, OpenAI and Google, European residency is an option to switch on and verify. With Mistral it is the default setting, and transfer to the United States becomes the exception you have to ask for. For an organisation whose processing stays entirely within Europe, that removes the transfer question altogether.
Does it follow that you should choose Mistral? No — it depends on what you are building. On long-document analysis, legal reasoning or code generation, capability gaps remain real and weigh just as heavily in the decision. The right trade-off is made use by use, not provider by provider. One company can legitimately route its sensitive documents to a European model and its development work to a US model under contract.
The particular case of regulated professions
For a lawyer, an accountant, a notary or a doctor, the reasoning changes in kind. Professional secrecy is not a best-efforts obligation to be modulated according to risk: it is a matter of public policy, criminally sanctioned, and the client's consent does not release you from it.
Three practical consequences.
The personal account is excluded, without discussion. This is not a question of acceptable risk, it is a question of clear breach. A firm that lets its staff use a consumer account on client matters exposes itself well beyond data protection law.
Minimisation matters more than configuration. The best protection remains not transmitting the identifying information at all. Anonymise the parties, strip case numbers, replace names with roles — most useful tasks, such as summarising, rewriting or finding arguments, have no need whatsoever for the real identity of the people involved. That discipline is worth more than any contractual clause.
Traceability becomes an obligation in its own right. You must be able to demonstrate, in the event of a professional inspection, which tools are authorised, who uses them, on what categories of data, and what human review applies before anything is delivered to a client. That documentation cannot be reconstructed after the fact.
What to do, concretely
Start by classifying your data. No other work makes sense before that, and it is quicker than it sounds: three categories are enough.
Once that grid is in place, seven decisions are enough to put an organisation in order.
- Open a business access before you ban anything. As long as there is no official alternative, a ban merely moves the usage out of your sight.
- Choose the channel according to the most sensitive category you will handle. If clients' personal data is involved, the European region question arises immediately, and it is settled through a third-party host.
- Use a gateway as soon as more than a couple of people or applications are involved. It is the only arrangement that gives you the single key, the defensible log and upstream anonymisation at once. Below two or three users it is unnecessary; beyond that, its absence will be paid for one day.
- Check the training setting on every account, including those opened before your policy existed. On personal accounts it is on by default.
- Include standard contractual clauses as a secondary basis in your data processing agreement, and document your supplementary measures. That is your insurance if adequacy falls.
- Train your teams and keep the record. This is now an obligation, in force since August 2026, and no longer merely good practice.
- Write a one-page usage policy that is readable and says what is allowed, on which tool. A forty-page document nobody reads protects nobody.
None of these decisions is technical. All of them belong to governance, and that is precisely why they get postponed: they have no natural owner on the org chart.
FAQ
Can Anthropic read our conversations?
Not in the normal course of the service. Automated systems analyse exchanges to detect breaches of the usage policy. If a conversation is flagged, inputs and outputs may be kept for two years and the associated classification scores for seven, with the possibility of review. Outside that case and legal obligations, there is no human reading of content.
We have an Enterprise contract. Are we covered?
For what passes through that contract, yes: no training, configurable retention, contractual commitments. But the contract covers neither your employees' personal accounts nor the location of storage, which remains in the United States through direct access. These are two separate matters to handle separately.
Does zero retention settle the GDPR question?
No, and this is the most widespread confusion. It reduces how long data is kept; it changes nothing about where processing happens or about the existence of a transfer outside the European Union. These are two independent guarantees, and only the second answers the transfer question.
Does an intermediate server make us compliant?
No, but it gives you the two things almost always missing when an inspection comes: control over what leaves, and proof of what left. A gateway hosted on your own VPS centralises keys, logs every call and allows data to be anonymised before sending. It does not, however, change where processing happens at Anthropic, nor your status as data controller. It reduces the risk and documents it; it does not remove it.
Can Claude be used with health data?
Anthropic offers a HIPAA-ready configuration with a business associate agreement, but that is the US framework. In France, hosting health data falls under the HDS certification, which does not appear among Anthropic's published certifications. For any processing of personal health data, a prior impact assessment and legal advice are indispensable.
Will this information stay valid?
Partly. This article is current as of 11 September 2026. Anthropic's retention policies have changed three times in eighteen months, and the fate of the transatlantic adequacy decision is being decided right now before the Court of Justice. Check the primary sources before any binding decision, and plan an annual review of your configuration.
In short
Claude is usable by a European company, including on sensitive data, on three conditions: go through a business contract, choose the location of processing deliberately, and frame usage before it frames itself. What exposes an organisation is almost never the technology — it is the absence of an explicit decision on those three points.
This is work of arbitration and governance, not an IT project. It takes a few weeks, and it is documented once and for all.
Studio CodeAI supports SMEs, mid-caps, public bodies and professional firms on exactly this ground: data classification, choice of access channel, drafting the usage policy, GDPR and AI Act compliance, and training teams. If you want to know where your organisation stands, the quickest route is a thirty-minute conversation.
Book a call with Studio CodeAI
Sources
- Anthropic — Privacy Centre: use of data for training, consumer and commercial retention periods, server locations, certifications (accessed 11 September 2026)
- Anthropic — Developer documentation: API data retention and zero data retention, data residency, covered models
- European Commission — Adequacy decision 2023/1795 (Data Privacy Framework)
- General Court of the European Union, 3 September 2025, Latombe case; appeal C-703/25 P, pending
- Supreme Court of the United States, Trump v. Slaughter, 29 June 2026
- European Data Protection Board — letter to the European Commission, 31 July 2026
- Regulation (EU) 2024/1689 on artificial intelligence, and the Digital Omnibus regulation amending its timetable
- CNIL — Recommendations on the development and deployment of AI systems
- OpenAI, Google Cloud and Mistral AI — official documentation on data residency and training (accessed 11 September 2026)
