🇦🇺Freshcollected in 27m

Anthropic Plans New Claude Data Retention Rules

Anthropic Plans New Claude Data Retention Rules
PostLinkedIn
🇦🇺Read original on iTNews Australia

💡Enterprise Claude users may need to revisit compliance, deletion, and data-governance controls.

⚡ 30-Second TL;DR

What Changed

Anthropic is planning a change to Claude’s enterprise data retention policy.

Why It Matters

A retention-policy change could affect enterprise compliance, privacy reviews, and internal data-handling procedures. Organizations using Claude should verify whether their existing governance controls will remain suitable.

What To Do Next

Ask your Anthropic account team for the proposed Claude retention terms and update your data-processing assessment before the change takes effect.

Who should care:Enterprise & Security Teams

Key Points

  • Anthropic is planning a change to Claude’s enterprise data retention policy.
  • The policy change specifically concerns enterprise use of Claude.
  • Details about retention duration and rollout timing have not been provided.

🧠 Deep Insight

Background and context from public sources — not the original article. 26 sources cited.

🔑 Enhanced Key Takeaways

  • Anthropic's existing enterprise policy for products like Claude for Work and the API specifies that data is never used for model training, with retention periods typically 30 days by default, and Zero Data Retention (ZDR) options available, all protected by Data Processing Agreements (DPAs).
  • A significant shift in Anthropic's consumer privacy policy occurred in September 2025 (effective October 2025), introducing an opt-in mechanism for users to allow their conversations to be used for model training, which extends data retention from 30 days to up to five years if accepted.
  • For API users, Anthropic reduced standard log retention from 30 days to 7 days as of September 14, 2025, with data explicitly not used for model training, and ZDR remains an option for qualifying enterprise customers.
  • The planned policy change specifically targets Anthropic's most advanced models, such as Claude Fable 5 and Mythos-class models, requiring a mandatory 30-day data retention period for safety and abuse monitoring, even for organizations with ZDR enabled.
  • A key modification to this new 30-day retention requirement for advanced enterprise models is the provision for customers to host this retained data on their own cloud computing infrastructure, addressing significant enterprise compliance concerns.
📊 Competitor Analysis▸ Show
Feature/PolicyAnthropic Claude (Enterprise)OpenAI (ChatGPT Enterprise/API)Microsoft (Azure OpenAI Service)Google (Gemini API/Vertex AI/Enterprise App)
Data Used for TrainingNo, by default for commercial products.No, by default for business/enterprise products.No, by default.No, by default for paid API/Vertex AI.
Default Data RetentionContract-controlled (30 days standard for enterprise API, 7 days for standard API as of Sep 2025). New 30-day for advanced models.Admin-controlled; deleted conversations removed within 30 days. API usage: 30 days for abuse detection.30 days for abuse monitoring.Paid API/Vertex AI: Limited periods for safety/abuse. Consumer: 18 months (configurable).
Zero Data Retention (ZDR)Available for qualifying enterprise customers.Available for eligible API customers.Available for eligible customers via 'modified abuse monitoring' program.Available for eligible enterprise customers via contractual commitments.
Data Hosting Control for RetentionNew policy allows customers to host required 30-day data on their own cloud infrastructure for advanced models.Not explicitly stated for retained data, generally within OpenAI systems.Stored securely within Microsoft's Azure environment. Abuse monitoring logs stored in Microsoft-operated infrastructure, outside customer tenant by default.Data stored transiently or cached in Google facilities, subject to region config. Gemini Enterprise app supports Google Vault for customer-controlled retention.
Compliance CertificationsHIPAA-ready offerings for eligible products. GDPR, SOC 2, ISO 27001, HIPAA considerations.HIPAA, SOC 2, ISO 27001 compliance documentation available.HIPAA, SOC 2, ISO 27001 supported.Meets strict cloud compliance requirements (e.g., data residency, audit logging).
Employee Access to DataBy default, employees cannot access conversations unless explicit consent or safety review.Not available to OpenAI personnel for review for ZDR customers.Not accessible to other customers or OpenAI. Human review for abuse monitoring is isolated by customer.You own your data, not Google.
EncryptionEncrypted at rest (AES-256 GCM) and in transit (TLS 1.2+).Encrypted at rest and in transit (AES-256, TLS 1.2+).Encrypted in transit and at rest (AES-256).Encrypted at rest and in transit.

🛠️ Technical Deep Dive

  • Anthropic employs a multi-tenant architecture for serving responses from its inference models.
  • All customer data stored by Anthropic is encrypted at rest using AES-256 GCM and protected in transit using TLS 1.2 or higher.
  • Employee access to customer conversations is strictly limited, requiring explicit user consent (e.g., for debugging) or necessity for safety review of flagged content, with strict access controls for designated Trust & Safety team members.
  • For Claude Code, Anthropic utilizes OS-level sandboxing, specifically Seatbelt on macOS and bubblewrap on Linux, to restrict the agent's access to the user's filesystem and deny network access by default, while permitting writes only within the designated workspace.
  • Claude Code manages its context window through a system called "Compressor wU2," which automatically summarizes conversations and stores important information as Markdown documents to serve as project memory, a pragmatic solution to context limitations.
  • The updated enterprise data retention policy for advanced models allows the mandatory 30-day retained data to be stored on the customer's own cloud computing infrastructure, providing greater control over data residency and security.

🔮 Future ImplicationsAI analysis grounded in cited sources

Anthropic's enterprise AI adoption will accelerate, particularly in highly regulated sectors.
By allowing customers to host mandatory retained data on their own cloud infrastructure, Anthropic directly addresses critical data governance and compliance concerns, fostering greater trust and enabling broader deployment in sensitive environments.
The competitive landscape for enterprise AI data governance will intensify, pushing rivals to offer similar customer-controlled data solutions.
Anthropic's move sets a new benchmark for enterprise data control, likely compelling competitors like OpenAI, Microsoft, and Google to enhance their own data residency and retention flexibility to remain competitive.
Enterprises will need to develop more sophisticated internal data governance frameworks to manage varying retention policies across different AI models and deployment methods.
As AI providers offer nuanced data handling options, organizations must implement granular policies that account for model capabilities, sensitivity of data, and hosting choices to ensure compliance and mitigate risk.

Timeline

2021-01
Anthropic founded by former OpenAI researchers.
2022-Late
First version of Claude released to select partners and researchers.
2023-07
Claude 2 launched publicly.
2024-Late
Claude Enterprise plan announced.
2025-09
Anthropic's consumer privacy policy updated to include opt-in training data use (5-year retention) and API log retention reduced to 7 days.
2026-06-09
Anthropic introduced a new 30-day data retention policy for its Claude Fable 5 and other Mythos-class models for safety work.
2026-08-20
Anthropic plans to modify the June 2026 data retention policy for advanced models, allowing enterprise customers to host the required 30-day data on their own cloud infrastructure.
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: iTNews Australia

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.