← All pages

1. What the document is: Anthropic's GDPR-style Data Processing Addendum (DPA) for business customers, plus an attached subprocessor list (Schedule 4) naming every third-party vendor Anthropic uses — Stripe for billing, WorkOS for sign-in, Twilio for communications, Microsoft Azure for infrastructure, Brave Search for web-search features, and more.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

Claude.ai – Data Processor Agreement

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/Claude.ai/Data Processor Agreement/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2026-03-27

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: Anthropic’s GDPR-style Data Processing Addendum (DPA) for business customers, plus an attached subprocessor list (Schedule 4) naming every third-party vendor Anthropic uses — Stripe for billing, WorkOS for sign-in, Twilio for communications, Microsoft Azure for infrastructure, Brave Search for web-search features, and more.

2. Input rights: Out of scope — this document governs Anthropic’s role as a Data Processor (the entity that handles data on a customer’s behalf), not content licensing. See Claude.ai_Commercial_Terms.md for the no-training commitment.

3. Output restrictions: None — not applicable to a DPA.

4. Non-explicit predatory clauses: None found. The document is built entirely around limiting Anthropic’s data handling to documented instructions, with a 15-day window for customers to object to a new subprocessor, annual audit rights, and breach notification.

5. Regulatory references: Extensive and explicit — defines GDPR verbatim (“Regulation (EU) 2016/679”), names the Standard Contractual Clauses (Module Two/Module Three — the EU’s pre-approved contract text for moving data abroad, citing the specific European Commission decision), and the UK Addendum (under the UK Data Protection Act 2018, S119A(1)). No EU AI Act reference.

6. Regional variation: Implicit, via the SCC/UK Addendum transfer mechanisms — this DPA exists specifically to cover the EEA/Switzerland/UK customer segment referenced in Claude.ai_Commercial_Terms.md’s jurisdiction split — though the DPA text itself doesn’t set separate obligations by region the way the Commercial Terms’ Governing Law clause does.

7. Key risk to users: Low — a protective, compliance-oriented contract. The most notable practical detail is the Subprocessor List itself (Schedule 4), which discloses a wide and frequently-changing set of third parties with access to Customer Data (including some, like Palantir Federal Cloud Service, scoped only to Claude for Government) — worth periodic review by privacy-conscious business customers, since 4 of this dataset’s 7 captured dates differ only in this list.

Flagged Keywords & Risks (LLM-assigned)

Regulatory & Research Context

Davidson et al. (2026), who include Anthropic among the providers they studied, would situate the named Module Two/Module Three SCC citations and UK Addendum here as a comparatively concrete regulatory hook, consistent with their broader finding that named EU/UK transfer mechanisms appear more often in business-facing DPAs than in consumer-facing Terms. The Subprocessor List’s frequent churn — 4 of this dataset’s 7 captured dates differ only in vendor additions/removals, including Claude-for-Government-scoped entities like Palantir Federal Cloud Service — illustrates the kind of granular, ongoing compliance documentation that Pandit et al. (2026) note is difficult to audit consistently, reflected in their own report of inter-annotator disagreement (10 cases for Claude alone) when manually coding GenAI terms of this density.


Changes Summary

DateWhat changed
2025-11-11Baseline version (first capture in this dataset).
2026-01-26Subprocessor list only: Intercom, Twilio, and Iterable’s product scope narrowed to “All Products except Claude for Government.” No change to DPA legal text.
2026-01-29Subprocessor list only: Stripe’s and WorkOS’s product-scope labels updated to reflect a product rename (“Anthropic API” → “Claude Developer Platform”). No change to DPA legal text.
2026-02-27Subprocessor list only: Brave Search’s product scope widened from “All products except Claude for Government” to “All products.” No change to DPA legal text.
2026-03-11Cosmetic-only restructuring: the entire DPA reformatted from nested numbered lists (1., 2., 3…) to section-letter-prefixed paragraphs (A.1, A.2, B.1…); definitions (GDPR, SCCs, UK Addendum, etc.) preserved verbatim. Subprocessor list also gained new entries (Sift, Arkose Labs, ElevenLabs, Palantir Federal Cloud Service) and lost others in the same edit. No substantive change to any Processor obligation.
2026-03-21Cosmetic: two subprocessor citation links reformatted (bracket markdown removed/changed) plus the UK Addendum’s source URL updated to a new ICO hosting path; subprocessor list lost the Sift entry. No change to DPA legal text.
2026-03-27Subprocessor list only: added Microsoft Azure (Cloud Infrastructure, Worldwide) and two new user-support vendors (Nutun, Boldr); removed Iterable and Sentry. No change to DPA legal text.

Version History

2025-11-11

Clause: gdpr

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Anthropic Commercial Terms of Service or other agreement between Customer and Anthropic that references this DPA and governs Customer’s use of the Services (the “Agreement”), and applies to Anthropic’s processing of Customer Data (defined below). […] “GDPR” means Regulation (EU) 2016/679. […] “Standard Contractual Clauses” or “SCCs” means Module Two (controller to processor) or Module Three (processor to processor) of the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.


2026-01-26

gdpr unchanged from 2025-11-11 — this date’s only change was the subprocessor list (see Changes Summary).


2026-01-29

gdpr unchanged from 2025-11-11 — this date’s only change was the subprocessor list.


2026-02-27

gdpr unchanged from 2025-11-11 — this date’s only change was the subprocessor list.


2026-03-11

Clause: gdpr (wording updated — reformatted to section-letter paragraphs, definitions otherwise unchanged)

A. Definitions. A.1. “Applicable Data Protection Laws” means all applicable privacy or data protection laws and regulations relating to the processing of personal data, as may be amended from time to time. […] A.6. “GDPR” means Regulation (EU) 2016/679. […] A.8. “Standard Contractual Clauses” or “SCCs” means Module Two (controller to processor) or Module Three (processor to processor) of the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.


2026-03-21

gdpr unchanged from 2026-03-11 — only a citation-link formatting change.


2026-03-27

gdpr unchanged from 2026-03-11 — this date’s only change was the subprocessor list.