Our WorkAll ServicesAI VisibilitySEO AutomationProduct ManagementClaude AI ServicesZatrovo BookingStart a Project
ai-search · 9 min read · 18 August 2026

Is Claude AI Safe for Business Data? GDPR for UK Companies

Is Claude AI safe for business data? What UK GDPR actually requires, Anthropic's retention and training rules, and the checks to run before you roll it out.

Jacob Horgan, Founder, Irvale Studio
Jacob Horgan
Founder, Irvale Studio
A UK small business office laptop showing a locked data privacy screen.

Is Claude AI safe for business data?

Claude can be used safely with UK business data, but safety is a property of your setup rather than the tool. The commercial arrangement matters more than the model. On a commercial plan with a signed Data Processing Addendum, Anthropic acts as your processor, states that retained data is never used for model training without your express permission, and publishes concrete retention periods. Everything else, the lawful basis, the staff rules, the impact assessment, and the record of what goes in, stays your responsibility as the controller.

The uncomfortable truth for most UK small businesses is that the leak has usually already happened before anyone asks the question. Staff sign up with a personal email, paste a client contract in to get a summary, and there is no administrative record it ever occurred. Fixing that is an access control problem, not a legal one, and it is solvable in an afternoon.

30 daysbefore API inputs and outputs are deleted from Anthropic's backend
Source: Anthropic privacy centre
2 yearsmaximum retention for content flagged as a Usage Policy violation
Source: Anthropic privacy centre
7 yearsmaximum retention for trust and safety classification scores
Source: Anthropic privacy centre
72 hoursto report a notifiable personal data breach to the ICO
Source: UK GDPR Article 33

Those four numbers are the ones to put in front of a nervous client. The default retention is short, the exceptions run long, and the breach clock is shorter than both. The rest of this piece is about closing the gap between what the platform publishes and what your firm can actually evidence.

What does UK GDPR actually require before you use Claude at work?

UK GDPR does not name any AI product, so there is no approved list to check against. It asks four things of you as the controller: a lawful basis for the processing, transparency with the people whose data it is, data minimisation, and a written processor agreement with whoever handles the data on your behalf. Meeting those four with an AI assistant is ordinary compliance work, not a special regime, and it can be documented in a handful of pages.

Start with the processor agreement, because it is the fastest win. Anthropic publishes a Data Processing Addendum that commercial customers can review and sign through the privacy centre. Without it you have a processor handling personal data with no Article 28 contract in place, which is a straightforward breach regardless of how well behaved the model is.

Then write down what you are actually doing. Not "using AI", but the specific processing: summarising inbound client emails, drafting quotes, extracting figures from supplier invoices. Each of those is a separate entry in your record of processing activities with its own lawful basis. If you have already mapped how work moves through the business, this takes an hour. If you have not, that mapping exercise is worth doing first, and documenting your processes pays for itself well beyond the compliance file.

Does Anthropic train its models on your business data?

On commercial plans, no, not without permission. Anthropic's documentation states that retained data is never used for model training without your express permission, and that conversation content on the API is not retained by default outside features that technically require storage. Consumer plans work differently, where training depends on an individual user's privacy setting. That gap between the two is where most small business exposure sits, and it is closed by buying seats rather than by writing a policy.

According to Anthropic's platform documentation, the API is built so that only what is technically necessary for a feature to work is retained, and retained data is purged on the shortest practical schedule. Certain features step outside that default by design. The Files API keeps files until you delete them. Batch results stay retrievable for roughly a month. Code execution containers hold their contents for the life of the container. If you build anything on the API, read the feature list rather than assuming a blanket position applies everywhere.

How long is your data kept, and what triggers longer retention?

Anthropic's privacy centre states that inputs and outputs sent via the API are automatically deleted from its backend within 30 days of receipt or generation, and that Team and Enterprise chats leave backend storage within 30 days of deletion. Two exceptions extend well beyond that. Content flagged as a Usage Policy violation can be retained for up to two years, and trust and safety classification scores can be kept for up to seven years.

Those exceptions are the part worth reading twice, because they are exactly what an auditor or an inquisitive client will ask about. Anthropic's commercial retention policy sets them out in plain terms, and your record of processing activities should reflect the full picture rather than the comfortable headline number.

If your risk appetite is lower than that, zero data retention is negotiated with Anthropic rather than toggled on in a small business plan, and the flagged content exception still applies underneath it. Check the current position with their sales team before you commit to it in a client contract.

Do you need a DPIA, and what goes in it?

Assume you need one. Article 35(1) of the UK GDPR requires a data protection impact assessment where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of individuals. Applying a generative model to correspondence, staff records, or client files fits that description closely enough that the cheaper decision is to write the assessment rather than argue about whether it applies.

The text on legislation.gov.uk is clear that the assessment happens prior to the processing, not after the rollout. A usable version for a small firm covers what data goes in, why, the lawful basis, who the processor is, the documented retention periods, the risks you identified, the controls you added, and the residual risk you accepted. Keep it to a few pages and review it whenever someone adds a new use case.

Where does your data go, and does the transfer need paperwork?

Anthropic is a US company, so a UK business using it is almost certainly making a restricted transfer of personal data outside the UK. That is permitted, but the transfer mechanism has to be recorded in your file. In practice it is handled by the transfer terms inside the Data Processing Addendum, so the work is checking that the signed version covers UK transfers rather than negotiating anything new.

If a client contract or a regulator requires data to stay in a particular region, do not promise that on a standard commercial plan. The usual route to regional control is running Claude through a cloud provider that lets you choose the region, such as Amazon Bedrock or Google Cloud Vertex AI, where your existing agreement with that provider governs where data sits. Confirm the current terms before you put a jurisdiction claim in writing, because promising more than the platform delivers is worse than promising nothing.

What should never be pasted into a chat window?

Anything you would not put in an email to an external supplier. That means no card numbers, no passwords or API keys, no unredacted health records, no criminal offence data, and no complete client databases. Special category data under Article 9 needs its own condition and a completed impact assessment before it goes anywhere near a model. Everything else comes down to whether the person doing the work has been told where the line sits.

Pseudonymisation is the practical technique that costs nothing. Replace names with Client A and Client B, strip account numbers, send the structure of the problem, and reinsert the identifiers locally once you have the output. Most drafting, summarising, and analysis tasks work perfectly well on data that has been stripped this way, which is why professional firms handling privileged material tend to standardise on it. Firms in regulated professions such as accountancy and law should check their regulator's position alongside the ICO's, because professional confidentiality duties sit on top of data protection law rather than inside it.

Which plan actually fits a UK small business?

For anything touching company data, use a commercial plan with an organisation you administer. That gives you the signed processing addendum, visibility over who has access, and the ability to revoke a leaver on their last day. Consumer plans give you none of those, and the account belongs to the individual rather than the business, so recovering or deleting company data from it is not within your control.

The decision is usually made on cost, and that is the wrong axis. Weigh the seat cost against a reportable personal data breach, which carries a 72 hour notification deadline and a conversation with clients you would rather not have. For teams already running assistant tasks such as triaging the inbox or chasing unpaid invoices, the seats are being used daily anyway, so the only real question is whether the company owns them or a member of staff does.

What does a safe rollout look like in the first month?

Four steps, in order, and none of them require a consultant. Sign the Data Processing Addendum. Create the organisation and move every member of staff onto company seats. Write a one page acceptable use rule naming what may and may not be pasted in. Complete the impact assessment before the first live use case goes into daily operation. That sequence takes a few hours and closes the gaps that actually cause incidents.

Then add one habit that most firms skip: keep a short log of approved use cases. When someone wants to try a new task, it gets added, assessed briefly, and either approved or refused. That log is the difference between telling a client you have controls and showing them.

How do you prove compliance if the ICO or a client asks?

You prove it with documents, not with confidence. Four artefacts do almost all the work: the signed processing addendum, your record of processing activities with the AI entries filled in, the completed impact assessment, and the acceptable use rule with evidence staff have read it. Add the approved use case log and you can answer most questions in a single email rather than a scramble.

Regulators and enterprise clients ask broadly the same things, so the file serves both. Keep the retention periods accurate, including the two year and seven year exceptions, because a vague answer invites a follow up question and a precise one usually ends the exchange. Review the whole set once a year, or sooner if the platform changes its published position. Read the full picture of what Claude does inside a small business before deciding which use cases are worth the paperwork, and start with the ones where the data is least sensitive and the time saved is most obvious.

Next stepSee how Claude fits a UK business setupDeployment, access control and the compliance file, done properly.
Common Questions

Is Claude AI Safe for Business Data? GDPR for UK Companies — FAQ

Is Claude AI GDPR compliant for UK businesses?

No AI tool is compliant or non-compliant on its own. UK GDPR compliance describes what you do with it. Anthropic can supply the processor side of the arrangement, including a Data Processing Addendum and documented retention rules, but you remain the controller. That means you decide the lawful basis, tell staff and customers what is happening, keep personal data to the minimum needed, and assess the risk before you start. Article 35(1) of the UK GDPR requires a data protection impact assessment where processing uses new technologies and is likely to result in high risk to people's rights, according to the text published on legislation.gov.uk. Sign the addendum, write the assessment, set the rules, then roll it out.

Does Anthropic train Claude on business data?

Anthropic's commercial documentation states that retained data is never used for model training without your express permission, and that conversation content on the API is not retained by default outside features that technically require storage. That is a different arrangement from consumer accounts, where training depends on an individual user's privacy setting. The practical risk for a UK small business is not the API. It is a member of staff using a personal free or Pro login for work, on a personal device, outside your administrative control. Buy the seats, invite staff to the organisation, and make personal accounts for company work a disciplinary matter rather than a preference.

How long does Anthropic keep business data?

Anthropic's privacy centre states that inputs and outputs sent through the API are automatically deleted from its backend within 30 days of receipt or generation. Team and Enterprise chats stay until deleted, then leave backend storage within 30 days. Two exceptions matter for your records. Content flagged as a Usage Policy violation can be kept for up to two years, and trust and safety classification scores can be kept for up to seven years. Batch processing results carry their own shorter window of roughly a month. Write these periods into your record of processing activities rather than describing retention as short, because the exceptions are what an auditor will ask about.

Can UK client or patient data go into Claude?

Sometimes, with controls, and it depends entirely on the category of data. Ordinary business contact details and correspondence sit in a different risk bracket from health records, criminal offence data, or anything covered by professional confidentiality. Before any special category data goes near a model, you need a lawful basis, an Article 9 condition, a completed impact assessment, and usually a client or patient notice that says so plainly. Regulated firms should check their own regulator's position as well as the ICO's. For lower risk work, pseudonymise first. Replace names and account numbers with placeholders, send the structure, and reinsert identifiers locally afterwards.

Do we need a DPIA before using Claude?

Assume yes and write one anyway. Article 35(1) of the UK GDPR requires an assessment where a type of processing, in particular using new technologies, is likely to result in high risk to the rights and freedoms of individuals, as published on legislation.gov.uk. Generative AI applied to correspondence, staff records, or client files sits squarely in that description. A workable assessment for a ten person firm runs to a few pages: what you are processing, why, the lawful basis, who the processor is, where the data goes, the documented retention periods, the risks you identified, and the controls you put in place. Review it when you add a new use case.

Is the free version of Claude safe for company work?

Treat consumer plans as unsuitable for company data. The controls a UK business needs sit on commercial plans: a signed Data Processing Addendum, administrative visibility over who has access, the ability to remove a leaver's access on their last day, and the documented commercial retention position. A free personal login gives you none of that, and the account belongs to the individual rather than the company, so you cannot retrieve or delete what they put in it. The cost of proper seats is small next to a reportable personal data breach, which carries a 72 hour notification deadline under Article 33 of the UK GDPR.

Next stepGet this run for youWe run Claude AI, websites, booking and SEO for UK small businesses. From £495 a month.
Start a Project