Practical guide

Claude and GDPR in business

The objective is to assess Claude use by plan, data flow and control obligations. The review baseline covers data class, account type, connectors, retention and human approval.

WERKVERSTAND / CONNECTING INTELLIGENCE

The essential answer

Claude is neither categorically GDPR-compliant nor categorically impermissible. The purpose, lawful basis, actual product access and entire data path determine the assessment. Review and document business terms, retention, connectors and possible international transfers for the specific workflow.

01 / FIT

A good fit when

  • A concrete assignment and an accountable domain owner are defined.
  • Reviewable evidence links the use case to documented account settings, affected connector permissions and the relevant provider documentation. Unconfirmed information remains explicitly unresolved.

02 / LIMITS

Not the first choice when

  • Avoid: blanket compliance claims without a concrete data path. Without a named data path, verified conditions and accountable approval, this guide cannot establish whether a specific use is permissible.

Establish purpose and lawful basis before uploading

Describe why personal information is processed and which details are actually needed. GDPR Article 6 requires an applicable lawful basis; special categories can introduce additional requirements. Internal approval or a paid Claude account does not replace that assessment. Initial tests should use data representing the chosen task without unnecessary personal information.

Review the actual Claude access route

Anthropic distinguishes commercial offerings from personal accounts. Commercial use involves the DPA and contractual rules; third-party platforms have their own terms. The documented training commitment for commercial chats and coding sessions has exceptions for explicit participation or feedback. It is therefore neither a general deletion promise nor a guarantee covering every connected service.

Complete the assessment for one concrete workflow

For a customer-response workflow, record input, processing, storage and onward sharing separately. Assess processor arrangements, international transfers where applicable, transparency duties, deletion and access. Where high risk is likely, establish whether a data protection impact assessment is required. Record the permitted scope, unresolved matters and triggers for renewed review.

Decision matrix

Decision pointProceed whenStop when
Data and accountabilityDocumented: data class, account type, connectors, retention and human approval.Scope, data or accountability remains unresolved.
Control evidenceReviewable evidence links the use case to documented account settings, affected connector permissions and the relevant provider documentation. Unconfirmed information remains explicitly unresolved.There is only an unevaluated demo without acceptance evidence.
Approval boundaryOwner, approval, fallback and next review date are defined.Avoid: blanket compliance claims without a concrete data path. Without a named data path, verified conditions and accountable approval, this guide cannot establish whether a specific use is permissible.

Keep it verifiable

Primary sources

The next sensible step

Which AI system fits your business?

Eight steps from a general interest in AI to a clearer decision for your business.

Start AI System Check
FreeProvider-neutralNo credentials