Anthropic Plans New Claude Data Retention Rules

💡Enterprise Claude users may need to revisit compliance, deletion, and data-governance controls.
⚡ 30-Second TL;DR
What Changed
Anthropic is planning a change to Claude’s enterprise data retention policy.
Why It Matters
A retention-policy change could affect enterprise compliance, privacy reviews, and internal data-handling procedures. Organizations using Claude should verify whether their existing governance controls will remain suitable.
What To Do Next
Ask your Anthropic account team for the proposed Claude retention terms and update your data-processing assessment before the change takes effect.
Key Points
- •Anthropic is planning a change to Claude’s enterprise data retention policy.
- •The policy change specifically concerns enterprise use of Claude.
- •Details about retention duration and rollout timing have not been provided.
🧠 Deep Insight
Background and context from public sources — not the original article. 26 sources cited.
🔑 Enhanced Key Takeaways
- •Anthropic's existing enterprise policy for products like Claude for Work and the API specifies that data is never used for model training, with retention periods typically 30 days by default, and Zero Data Retention (ZDR) options available, all protected by Data Processing Agreements (DPAs).
- •A significant shift in Anthropic's consumer privacy policy occurred in September 2025 (effective October 2025), introducing an opt-in mechanism for users to allow their conversations to be used for model training, which extends data retention from 30 days to up to five years if accepted.
- •For API users, Anthropic reduced standard log retention from 30 days to 7 days as of September 14, 2025, with data explicitly not used for model training, and ZDR remains an option for qualifying enterprise customers.
- •The planned policy change specifically targets Anthropic's most advanced models, such as Claude Fable 5 and Mythos-class models, requiring a mandatory 30-day data retention period for safety and abuse monitoring, even for organizations with ZDR enabled.
- •A key modification to this new 30-day retention requirement for advanced enterprise models is the provision for customers to host this retained data on their own cloud computing infrastructure, addressing significant enterprise compliance concerns.
📊 Competitor Analysis▸ Show
| Feature/Policy | Anthropic Claude (Enterprise) | OpenAI (ChatGPT Enterprise/API) | Microsoft (Azure OpenAI Service) | Google (Gemini API/Vertex AI/Enterprise App) |
|---|---|---|---|---|
| Data Used for Training | No, by default for commercial products. | No, by default for business/enterprise products. | No, by default. | No, by default for paid API/Vertex AI. |
| Default Data Retention | Contract-controlled (30 days standard for enterprise API, 7 days for standard API as of Sep 2025). New 30-day for advanced models. | Admin-controlled; deleted conversations removed within 30 days. API usage: 30 days for abuse detection. | 30 days for abuse monitoring. | Paid API/Vertex AI: Limited periods for safety/abuse. Consumer: 18 months (configurable). |
| Zero Data Retention (ZDR) | Available for qualifying enterprise customers. | Available for eligible API customers. | Available for eligible customers via 'modified abuse monitoring' program. | Available for eligible enterprise customers via contractual commitments. |
| Data Hosting Control for Retention | New policy allows customers to host required 30-day data on their own cloud infrastructure for advanced models. | Not explicitly stated for retained data, generally within OpenAI systems. | Stored securely within Microsoft's Azure environment. Abuse monitoring logs stored in Microsoft-operated infrastructure, outside customer tenant by default. | Data stored transiently or cached in Google facilities, subject to region config. Gemini Enterprise app supports Google Vault for customer-controlled retention. |
| Compliance Certifications | HIPAA-ready offerings for eligible products. GDPR, SOC 2, ISO 27001, HIPAA considerations. | HIPAA, SOC 2, ISO 27001 compliance documentation available. | HIPAA, SOC 2, ISO 27001 supported. | Meets strict cloud compliance requirements (e.g., data residency, audit logging). |
| Employee Access to Data | By default, employees cannot access conversations unless explicit consent or safety review. | Not available to OpenAI personnel for review for ZDR customers. | Not accessible to other customers or OpenAI. Human review for abuse monitoring is isolated by customer. | You own your data, not Google. |
| Encryption | Encrypted at rest (AES-256 GCM) and in transit (TLS 1.2+). | Encrypted at rest and in transit (AES-256, TLS 1.2+). | Encrypted in transit and at rest (AES-256). | Encrypted at rest and in transit. |
🛠️ Technical Deep Dive
- Anthropic employs a multi-tenant architecture for serving responses from its inference models.
- All customer data stored by Anthropic is encrypted at rest using AES-256 GCM and protected in transit using TLS 1.2 or higher.
- Employee access to customer conversations is strictly limited, requiring explicit user consent (e.g., for debugging) or necessity for safety review of flagged content, with strict access controls for designated Trust & Safety team members.
- For Claude Code, Anthropic utilizes OS-level sandboxing, specifically Seatbelt on macOS and bubblewrap on Linux, to restrict the agent's access to the user's filesystem and deny network access by default, while permitting writes only within the designated workspace.
- Claude Code manages its context window through a system called "Compressor wU2," which automatically summarizes conversations and stores important information as Markdown documents to serve as project memory, a pragmatic solution to context limitations.
- The updated enterprise data retention policy for advanced models allows the mandatory 30-day retained data to be stored on the customer's own cloud computing infrastructure, providing greater control over data residency and security.
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
📎 Sources (26)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: iTNews Australia ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
Weekly AI briefing
One email a week. Unsubscribe anytime.

