Is Claude Safe for Confidential Data? What Anthropic Does With What You Type
On a business account — Team, Enterprise or API — your data is not used to train Anthropic's models. That is written into the commercial terms, not a setting you have to find. Inputs and outputs are kept briefly for safety and abuse-prevention, then deleted, and a zero-retention arrangement exists for the strictest cases.
On a personal Free, Pro or Max account the rules are different: individuals are asked whether their chats may help improve the models, and many click through without reading. Same chat box, same answers, entirely different terms. Which door your colleagues walked in through is the whole question — and at most companies, nobody has checked.
The distinction that decides everything
Watch what happens when a team first gets serious about using AI on real work. Someone — usually the most sensible person in the room — asks the question that ends the meeting: if we put the client list in this thing, where does it go? Could it come out in someone else's answer? Are we even allowed?
Nobody knows, so the cautious option wins. The team keeps using Claude for polishing emails and summarising public articles, and never hands it the confidential work where it would save real time. That gap is not a technology problem. It is a trust problem, and trust problems are solved with clear answers rather than better models.
Here is the clear answer, and it turns on one thing almost nobody has been told.
| Personal account (Free, Pro, Max) | Business account (Team, Enterprise, API) | |
|---|---|---|
| Used to train models? | Only if the individual agreed — they are asked to choose, and many click through it without reading | No. Written into your company’s commercial terms, not a setting anyone can flip |
| Who agreed the terms | The employee, personally | Your company |
| Data retention | Held under the consumer terms that person accepted | A short operational window for safety and abuse-prevention, then deleted |
| Zero-retention option | No | Yes, arranged with Anthropic |
| Admin visibility and control | None — it is a private account | Yes |
| Right for confidential work | No | Yes |
The company has “approved Claude,” so everyone relaxes. Meanwhile half the team is logged into personal Pro accounts they set up themselves, on consumer terms, pasting in client work. The organisation believes it is on business terms; a good share of its actual usage is not. The fix is unglamorous and matters more than any other item on this page: check which account your people are actually signed into.
Does Claude train on your data?
The fear behind this question is specific: that something confidential you typed resurfaces months later inside a stranger's answer. On business plans the protection is direct — your prompts and Claude's responses are not fed back into training. Anthropic's own documentation is blunt about it, and it covers commercial API usage and business plans.
Data is held briefly. There is a short operational retention window — on the API it can be as little as seven days — after which inputs and outputs are deleted automatically. That window exists for safety and abuse-prevention, not for training. For organisations with the strictest requirements there is Zero Data Retention, where prompts and responses are not stored at rest at all once the answer is returned. It is arranged rather than switched on, and knowing it exists is often what lets a nervous compliance team say yes.
So the repeatable answer, when a colleague asks:
That paragraph unblocks more real AI work than any new feature.
The four terms worth recognising
You do not need to become a compliance expert. You need to recognise four things so you know what to ask for.
- DPA (Data Processing Agreement). The one European teams actually need. It governs how a vendor processes personal data under GDPR — the client names, emails and records your business is responsible for. Your legal or operations person should have one in place.
- Zero Data Retention. The keep-nothing option, for the most sensitive workflows.
- SOC 2 and ISO certifications. Independent audits proving the controls were checked by an outside party rather than merely claimed. Anthropic holds SOC 2 Type II, ISO 27001 and ISO 42001 for its commercial products. That single answer often ends a security review.
- BAA (Business Associate Agreement). Only relevant if you handle U.S. health data. Eligible Enterprise organisations can now enable a HIPAA-ready configuration themselves from settings, with the agreement built in as click-to-accept — a compliance step that used to take weeks of legal back-and-forth. If you never touch U.S. health data, ignore this one.
Where the coverage actually ends
This is the part that gets skipped, and it is the difference between real safety and false confidence.
Compliance coverage is specific, not a general property of the word “Claude.” The HIPAA configuration, for instance, applies to eligible Enterprise organisations on the first-party API and Enterprise plans. It does not extend to Free, Pro, Max or standard Team, and it does not automatically cover features still in beta.
The transferable discipline: match the sensitivity of the data to the right plan and setup, and check rather than assume that the specific feature you want for your most confidential work sits inside the coverage you think it does. When in doubt that is a one-line question to your Anthropic contact, and asking it is a sign of a team doing this properly rather than a sign of paranoia.
GDPR, and the one honest caveat
For a Nordic accounting firm, a UK agency or a German SaaS company, HIPAA is irrelevant — but the underlying category is not. GDPR is the European name for the same situation: you hold data that legally must be protected, and you cannot let a vendor be careless with it.
The reassuring part: the agreements and controls exist. Anthropic operates through a European entity for EU and UK customers, with standard legal transfer mechanisms, publishes independent certifications, and commits contractually on how business data is handled.
The honest caveat, which you should hear from us rather than discover later: business data is stored in the United States, and there is not currently an EU-only storage option. For most companies that is a non-issue, handled by the transfer mechanisms. If strict data residency is a hard requirement in your sector, it is a genuine question to settle with Anthropic before you roll out, not after.
Three checks to run this week
- Find out which accounts your team is actually using. Ask three people to check whether they are signed into the company workspace or a personal login. This takes ten minutes and is the highest-value thing on this page — expect at least one surprise.
- Confirm the DPA exists. One question to whoever owns legal or operations. If the answer is uncertain, that is the gap, and it is a straightforward one to close.
- Write down what is allowed, in one paragraph. Most teams have no rule, so people invent their own and default to the cautious version. A single written line about what may go into Claude and from which account removes the hesitation that is quietly costing you the value.
Getting a team confident about what is safe to put in — which account, what data, where the line sits — is part of every Deployed Kickstart, mapped to your real workflows and your real data. The Partner programme keeps that judgement current as the rules and the products change.
Frequently asked questions
Is Claude safe to use for confidential company information?
On a business account — Team, Enterprise or API — yes, with the usual care. Your inputs and outputs are contractually not used to train Anthropic’s models, they are kept only for a short operational window and then deleted, and a zero-retention arrangement exists for the most sensitive workflows. The important condition is that people are actually signed into the company workspace rather than a personal login.
Does Claude train on my data?
Not on business plans. Your prompts and Claude’s responses are not fed back into training, and that protection is written into the commercial terms rather than being a setting you have to hunt for. On personal Free, Pro and Max accounts it is different — individuals are asked whether their chats may be used to help improve the models, and many click through the choice without reading it.
What is the difference between a personal and a business Claude account?
They look identical and give the same answers, but the terms differ completely. A business account was agreed by your company, excludes your data from training by default, deletes it after a short window, offers a zero-retention option and gives administrators visibility. A personal account was agreed by the employee, on consumer terms, with no admin control. Confidential work belongs in the business workspace.
How long does Anthropic keep my data?
There is a short operational retention window — on the API it can be as little as seven days — after which inputs and outputs are deleted automatically. That window exists for safety and abuse-prevention rather than for training. Organisations with the strictest requirements can arrange Zero Data Retention, where prompts and responses are not stored at rest at all once the answer is returned.
Is Claude GDPR compliant for European companies?
The agreements and controls are in place: Anthropic operates through a European entity for EU and UK customers with standard legal transfer mechanisms, holds SOC 2 Type II, ISO 27001 and ISO 42001, and commits contractually on how business data is handled. The honest caveat is that business data is stored in the United States and there is not currently an EU-only storage option — for most companies the transfer mechanisms cover it, but if strict data residency is a hard requirement in your sector, settle that with Anthropic before you roll out.
Is Anthropic SOC 2 certified?
Yes — Anthropic’s commercial products hold SOC 2 Type II, along with ISO 27001 and ISO 42001. These are independent audits, meaning the controls were checked by an outside party rather than merely claimed, which is usually what a security reviewer is asking about.
Can I use Claude with health data or other regulated information?
Eligible Enterprise organisations can enable a HIPAA-ready configuration themselves from settings, with the Business Associate Agreement built in as click-to-accept. Coverage is specific rather than general, though: it applies to particular plans configured in particular ways and does not automatically extend to features still in beta. Match the sensitivity of the data to the right plan, and check rather than assume that the feature you want sits inside the coverage.
What should we check before letting our team use Claude on real work?
Three things. Find out whether people are signed into the company workspace or personal logins — expect at least one surprise. Confirm a Data Processing Agreement is in place. And write down, in one paragraph, what may go into Claude and from which account. Most teams have no written rule, so people invent their own and default to the cautious version, which is what quietly costs you the value.
Found this useful? Send it to someone who needs it.