Ensure compliance with regulations (e.g., GDPR, HIPAA, FedRAMP)
Build compliance into the architecture: minimise and pseudonymise data before it reaches the model, choose the deployment path and contractual instruments (BAA, DPA, ZDR, regional endpoints, FedRAMP-authorized platforms) that match the regulation, and design your own stores for retention limits and erasure.
Key points
- 1
Data minimisation first: send only the fields the task needs, redact or tokenize identifiers before the API call, keep the re-identification mapping in-house, and keep raw PII out of your logs. Output instructions, Base64 encoding and retention agreements do not minimise what is processed.
- 2
Anthropic's commercial terms incorporate a Data Processing Addendum with Standard Contractual Clauses; accepting the terms accepts the DPA. Access through a cloud platform (Bedrock, Google Cloud) is governed by that platform's terms and the cloud provider is the data processor.
- 3
GDPR by design: maintain a record of processing, set retention limits, and make erasure possible in every store you control (conversation logs, vector indexes, eval datasets). Hashing or pseudonymising identifiers does not anonymise data; the provider's deletion window is not your erasure tooling.
- 4
Commercial API retention: inputs and outputs are deleted from Anthropic's backend within a default window (30 days) unless otherwise agreed; content flagged for trust and safety and legal holds are retained longer. API data is not used for training by default.
- 5
Zero data retention (ZDR) is enabled per organisation on request and covers eligible features of the Messages and Token Counting APIs; it does not cover features that must store data (Message Batches, Files API, Managed Agents sessions, Console usage) or consumer plans. Retention can be turned on per workspace in a ZDR organisation for those features.
- 6
HIPAA: PHI requires a signed Business Associate Agreement and a HIPAA-enabled organisation; use only BAA-eligible features (Messages API yes; Batch, Files and computer use excluded at the time of writing), and keep PHI out of third-party integrations. Some newer "covered" models require 30-day retention and are not available under ZDR unless authorised.
- 7
Anthropic's published credentials include SOC 2 Type I and Type II, ISO 27001, ISO/IEC 42001 and a HIPAA-ready configuration with BAA; reports are requested through the Trust Center. Do not treat a SOC 2 report as equivalent to a regulatory authorization.
- 8
FedRAMP: authorization attaches to a cloud service boundary. US government workloads reach Claude through FedRAMP-authorized cloud platforms (for example Amazon Bedrock, which is listed at Moderate in commercial regions and High in GovCloud);
inference_geo, SOC 2 and ZDR are not FedRAMP authorizations. - 9
Data residency has two parts: where inference runs and where data rests. The first-party API's
inference_geooffers"us"or"global"(US-only at a pricing premium) with workspace-level defaults and allowlists; EU or other regional pinning uses regional endpoints on Bedrock or Google Cloud, also at a premium. Your own stores must be placed in region separately. - 10
Enterprise plans support custom retention periods (minimum 30 days) set by an owner; features built on Claude Code on the web and some others are outside those controls.
- 11
Cloud platforms recommend logging activity on a rolling basis for misuse investigation; enabling those logs does not give the cloud provider or Anthropic access to your content.
- 12
Common distractors: "not used for training" presented as HIPAA or GDPR compliance, consumer accounts for regulated data, name-only redaction as de-identification, DPA or SCCs presented as data residency, and ZDR presented as covering every endpoint.
Read the source
- API and data retention (ZDR and HIPAA readiness)
- Data residency
- How long do you store personal data? (commercial)
- Business Associate Agreements (BAA) for commercial customers
- How do I view and sign your Data Processing Addendum (DPA)?
- What certifications has Anthropic obtained?
- Claude on Amazon Bedrock (global vs regional endpoints)
- AWS FedRAMP services in scope
Test yourself on Ensure compliance with regulations (e.g., GDPR, HIPAA, FedRAMP)
Ten questions, with the answer and explanation after each one.