This isn't legal advice, just the operator's perspective I use to run Claude in my own business, including with real client data. Claude privacy and GDPR mostly come down to which plan you're on: on Free, Pro, and Max you can turn training on and off yourself, while on Team, Enterprise, and the API your data is excluded from training by default according to Anthropic, and a data processing addendum is part of the contract automatically.
I run my business with a workforce of eight AI employees on Claude and have them process real client receipts and emails. I looked into these rules not out of curiosity, but because I have to follow them in my own setup. The other building blocks of my Claude setup are on the Claude overview page.
Claude privacy by plan: training, DPA, and role
The short answer differs clearly between the consumer plans and the commercial offerings:
| Plan |
Trains on your data |
DPA included automatically |
Your role according to Anthropic |
| Free, Pro, Max (including Claude Code from these accounts) |
Yes, if the "Help improve our AI models" toggle is on, or a safety review applies |
No |
you, as an individual user |
| Team and Enterprise (Claude for Work) |
No, not by default |
Yes, automatically part of the Commercial Terms |
you as controller, Anthropic as processor |
| API |
No, not by default |
Yes, automatically part of the Commercial Terms |
you as controller, Anthropic as processor |
The decisive difference isn't primarily the price, it's whether you're on a consumer account or a commercial product. For how this compares to ChatGPT, which has similar toggles, see Claude vs ChatGPT 2026: Compared.
The toggle that decides on training
On Free, Pro, and Max, and therefore also Claude Code run from one of those accounts, your chats are used for training according to Anthropic if the "Help improve our AI models" toggle is on, or if a safety review kicks in. The toggle sits under claude.ai/settings/data-privacy-controls, and turning it off applies to all new chats from that point on. This is documented in Anthropic's help article on privacy settings (privacy.claude.com).
A second exception is Incognito chats: according to the same source, they're never used for training, regardless of the toggle's state. In practice, that toggle is the first click I make on any new account, before a single client case goes into a chat.
How long Claude keeps your data
On consumer plans with training enabled, Anthropic states it stores data for up to 5 years, de-identified. Deleted chats disappear from the backend within 30 days. If you violate the usage policies, data can be kept for up to 2 years, and trust and safety classifications for up to 7 years. Source: Anthropic's help article on data retention (privacy.claude.com).
Commercial products follow a different logic, since no training on your content happens there in the first place: "By default, we will not use your inputs or outputs from our commercial products ... to train our models," as Anthropic's documentation puts it (privacy.claude.com). Retention periods for operating the service itself are a separate matter, governed by the relevant contract terms, which I'm not quoting in detail here since I haven't reviewed them myself.
The data processing addendum: automatic or not
On Team, Enterprise, and the API, a data processing addendum with standard contractual clauses is automatically part of the Commercial Terms, you don't need to sign anything extra. In that setup, Anthropic acts as processor, and you remain the controller for your data. Two Anthropic pages back this up: on the role split (privacy.claude.com) and on the DPA itself (privacy.claude.com).
On Free, Pro, and Max there's no such automatic agreement; those plans run under the consumer terms rather than the Commercial Terms. Anthropic maintains a current list of subprocessors at trust.anthropic.com/subprocessors, in case you need that for your own documentation.
Which client data I let into a chat in the first place
Even with a DPA and training turned off, I decide case by case what goes into a chat, not blanket by plan. My own traffic light for that looks like this:
- Green, goes in directly: general business data such as invoice amounts, company names, standard phrasing, appointment suggestions without special details.
- Yellow, only with a DPA or anonymized: personal data of clients in a normal business context, such as a name and address on an invoice.
- Red, never without my own review: health data, third-party bank data, and other special categories of personal data.
I go into more depth on how I draw these lines in general, independent of Claude specifically, in AI and Privacy: What the AI Gets to See.
Practice at my end: Frieda with receipts and the inbox
My AI employee Frieda sorts my inbox, suggests appointments, and prepares receipts for bookkeeping, running on an account with a DPA, so outside the consumer tier. In a normal week she sees invoices from service providers, appointment requests, and receipts for small expenses, all green data by my own traffic light.
Picture the following case: an email attachment turns out to be a travel expense report that, alongside the receipts, also includes a doctor's note, clearly attached by mistake. Frieda's personnel file has a fixed rule for exactly this kind of case: stop and report unusual or red content instead of processing it further on your own. So she sets the attachment aside and flags it, instead of filing it automatically like the rest of the mail. Whether and how that one document gets processed any further is my decision afterward, not hers.
What that rule does and does not achieve deserves saying plainly. For Frieda to recognise a doctor's note as such, she has to have read the attachment. The rule does not prevent that first read; it prevents every further step, every filing, and every hand-off. If you want to rule out the read itself, you have to separate up front rather than stop after the fact: keep attachments like that out of the mailbox the AI has access to, or filter them out before handing anything over. The German data protection authorities point out that even entering personal data into an AI system requires a legal basis and should be avoided through clear routines (the DSK guidance on AI and data protection). The stop rule is therefore the second line of defence for the case that slips through anyway, not the first.
Team as the path for more than one person
If several people are going to work with Claude while handling client data, Team is the plan with an automatic DPA, no training on your content, central administration, and access roles. Team starts at 25 dollars a month per person, as of September 2026, with further pricing tiers in Claude Pricing and Plans Explained.
Whether that already pays off for two or three people, or whether several separate Pro accounts are enough, is something I work through in detail in Claude Team: Cost and When It Pays Off.
Frequently asked questions
Does Anthropic use my chats for training?
On Free, Pro, and Max, only if you leave the "Help improve our AI models" toggle on, or if a safety review applies. On Team, Enterprise, and the API, the opposite applies by default: no training on your inputs and outputs.
Do I need a data processing addendum as a solo freelancer?
Yes, as soon as you process personal client data through Claude. A single Pro account doesn't come with an automatic DPA; for that you need a commercial product like Team, which can be booked from just a couple of seats, or the API.
Where is my data stored?
Anthropic is a US provider. For transfers out of the EU, standard contractual clauses are automatically part of the Commercial Terms. For a binding assessment of your specific case, that belongs in front of a professional.
Is Pro with training turned off enough for client data?
The training toggle alone doesn't turn a Pro account into a DPA contract. For client data with a personal reference, I use a commercial product instead of a single consumer account, regardless of how the toggle is set.
Do I need to mention Claude in my privacy policy?
If you process personal data through Claude, using it generally belongs in your privacy policy, along with proof of a DPA and details of the service you use. That is a pointer to check it as a matter of principle, not the check itself.
How to think this through for yourself
The two clicks I'd start with right away: check the training toggle on the right account, and before anything with a personal reference goes into a chat, work in a commercial product instead of a single consumer account. Everything else, the traffic light for client data and how you react to edge cases, is on you and your role as controller.
How these questions change once a model runs entirely on your own hardware instead of in the cloud is something I cover in Local AI and Privacy: Cloud or Server?. All eight packages of my AI workforce, Frieda included, are available in my Community.