Study notes · 2.8% of the exam

Ensure compliance with regulations (e.g., GDPR, HIPAA, FedRAMP)

Build compliance into the architecture: minimise and pseudonymise data before it reaches the model, choose the deployment path and contractual instruments (BAA, DPA, ZDR, regional endpoints, FedRAMP-authorized platforms) that match the regulation, and design your own stores for retention limits and erasure.

Key points

  1. 1

    Data minimisation first: send only the fields the task needs, redact or tokenize identifiers before the API call, keep the re-identification mapping in-house, and keep raw PII out of your logs. Output instructions, Base64 encoding and retention agreements do not minimise what is processed.

  2. 2

    Anthropic's commercial terms incorporate a Data Processing Addendum with Standard Contractual Clauses; accepting the terms accepts the DPA. Access through a cloud platform (Bedrock, Google Cloud) is governed by that platform's terms and the cloud provider is the data processor.

  3. 3

    GDPR by design: maintain a record of processing, set retention limits, and make erasure possible in every store you control (conversation logs, vector indexes, eval datasets). Hashing or pseudonymising identifiers does not anonymise data; the provider's deletion window is not your erasure tooling.

  4. 4

    Commercial API retention: inputs and outputs are deleted from Anthropic's backend within a default window (30 days) unless otherwise agreed; content flagged for trust and safety and legal holds are retained longer. API data is not used for training by default.

  5. 5

    Zero data retention (ZDR) is enabled per organisation on request and covers eligible features of the Messages and Token Counting APIs; it does not cover features that must store data (Message Batches, Files API, Managed Agents sessions, Console usage) or consumer plans. Retention can be turned on per workspace in a ZDR organisation for those features.

  6. 6

    HIPAA: PHI requires a signed Business Associate Agreement and a HIPAA-enabled organisation; use only BAA-eligible features (Messages API yes; Batch, Files and computer use excluded at the time of writing), and keep PHI out of third-party integrations. Some newer "covered" models require 30-day retention and are not available under ZDR unless authorised.

  7. 7

    Anthropic's published credentials include SOC 2 Type I and Type II, ISO 27001, ISO/IEC 42001 and a HIPAA-ready configuration with BAA; reports are requested through the Trust Center. Do not treat a SOC 2 report as equivalent to a regulatory authorization.

  8. 8

    FedRAMP: authorization attaches to a cloud service boundary. US government workloads reach Claude through FedRAMP-authorized cloud platforms (for example Amazon Bedrock, which is listed at Moderate in commercial regions and High in GovCloud); inference_geo, SOC 2 and ZDR are not FedRAMP authorizations.

  9. 9

    Data residency has two parts: where inference runs and where data rests. The first-party API's inference_geo offers "us" or "global" (US-only at a pricing premium) with workspace-level defaults and allowlists; EU or other regional pinning uses regional endpoints on Bedrock or Google Cloud, also at a premium. Your own stores must be placed in region separately.

  10. 10

    Enterprise plans support custom retention periods (minimum 30 days) set by an owner; features built on Claude Code on the web and some others are outside those controls.

  11. 11

    Cloud platforms recommend logging activity on a rolling basis for misuse investigation; enabling those logs does not give the cloud provider or Anthropic access to your content.

  12. 12

    Common distractors: "not used for training" presented as HIPAA or GDPR compliance, consumer accounts for regulated data, name-only redaction as de-identification, DPA or SCCs presented as data residency, and ZDR presented as covering every endpoint.

Test yourself on Ensure compliance with regulations (e.g., GDPR, HIPAA, FedRAMP)

Ten questions, with the answer and explanation after each one.