Claude Code and GDPR: what a business needs to know
Half the content circulating about AI and compliance uses AI Act dates that no longer apply. This guide explains what Anthropic terms actually say, which obligations apply in 2026 and which only in December 2027, and how a GDPR-compliant Claude Code deployment is designed.
Short answer
Claude Code can be used in a European business in compliance with GDPR. Anthropic commercial terms state that customer content from API, Team and Enterprise customers is not used to train models, and for sensitive cases there is a zero data retention agreement so inputs and outputs are not stored.
The AI Act is not the blocker it is often made out to be either: typical business uses carry no high-risk obligations, and the obligations that do exist follow a concrete timeline worth knowing with the correct dates, because much of the published content still cites the old ones.
The real AI Act timeline
Updated July 31, 2026, after the Digital Omnibus.
The dates that apply today
The June 2026 Digital Omnibus package moved the calendar. These are the dates in force.
Beware of outdated guides
Much of the Spanish-language content on AI compliance was written before the Digital Omnibus and still says high-risk obligations apply in August 2026. If a vendor pressures you to sign "before the AI Act kicks in", ask for their source: the current date for high risk is December 2027, and most business projects do not even fall in that category.
What Anthropic terms say
What is written, without creative interpretation.
No training on customer data
Commercial terms (API, Team, Enterprise) state customer content is not used to train models. This does not apply to free consumer accounts: company data always goes through commercial products.
Zero data retention on the API
An agreement available to organizations under which inputs and outputs are not stored: processed and discarded. The standard configuration for health, financial or legal data.
DPA included
The Anthropic Data Processing Addendum is accepted together with the commercial terms and covers the processor role and international transfers.
Code is covered too
Proprietary code that Claude Code reads travels to the API under the same terms: it is not trained on, and with zero data retention it is not stored either.
The other half: architecture
What Anthropic terms cannot solve for you.
The vendor covers what happens inside its service. Everything else depends on implementation: what data the agent sees, where it lives, and how the processing is documented. A serious Claude Code deployment defines this before writing the first line.
Read scope
The agent sees the repositories and folders it needs for its task, not the whole company. Like an external consultant: access by necessity, not convenience.
Data residency
When a project requires data in the EU or on own infrastructure, company systems stay on your side and only what each task needs is sent to the model.
Processing records
Which personal data is processed, for what purpose and for how long. Written down, in your records of processing activities, not implicit in the code.
Human approval for the irreversible
Sending, publishing, deleting and paying sit behind explicit approval. Good engineering that also reduces legal exposure.
The GDPR division of responsibilities is the key to reading all of this: your company is the controller and Anthropic is the processor. That is why two deployments of the same tool can be one flawless and the other in breach: the difference is not in the license, it is in the design.
When you need more than the standard setup
Signs your case requires specific compliance design.
Special categories of data
Health, biometric data, union membership. This calls for a DPIA and normally zero data retention from day one.
Large-scale processing of personal data
An agent processing data from thousands of end customers calls for a DPIA and aggressive minimization: pseudonymize before sending the model anything that does not need to be identified.
Regulated sector with its own supervisor
Financial, insurance, healthcare. GDPR coexists with sector rules and the deployment must be documented for both frameworks.
Automated decisions about people
If the system decides on credit, employment or access to services, you enter GDPR Article 22 and, depending on the case, AI Act Annex III with a December 2027 horizon. The only scenario where the AI Act truly weighs.
Frequently asked questions about Claude Code and GDPR
Is Claude Code GDPR compliant?+
Does Anthropic train its models on my company data?+
What happens to my company proprietary code in Claude Code?+
Does the AI Act prohibit using Claude Code in my company?+
What is Anthropic zero data retention?+
Do I need a DPIA to use Claude Code?+
Who is responsible for compliance: Anthropic or my company?+
Compliance is designed at the start, not patched at the end
All our Claude Code projects are born with data scope, residency and processing records defined during the diagnostic, before building.
How we start
With a scoped diagnostic that defines what to automate first, what data it touches and under which compliance configuration, including the possibility that your case needs nothing beyond the standard commercial setup.
Artículos Relacionados
Claude Code for businesses in Spain
The complete guide: what it is, prices with VAT, Kit Digital and real cases in Madrid and Barcelona.
How much does implementing Claude Code cost
Licenses, project and maintenance: the three separate costs and the real ranges.
What is an AI agent
The definition, the five components it needs in production, and when not to use one.
