8 min
ByDiego Carrion·Co-founder, Duotach
Claude CodeGDPRAI Act

Claude Code and GDPR: what a business needs to know

Half the content circulating about AI and compliance uses AI Act dates that no longer apply. This guide explains what Anthropic terms actually say, which obligations apply in 2026 and which only in December 2027, and how a GDPR-compliant Claude Code deployment is designed.

01

Short answer

Claude Code can be used in a European business in compliance with GDPR. Anthropic commercial terms state that customer content from API, Team and Enterprise customers is not used to train models, and for sensitive cases there is a zero data retention agreement so inputs and outputs are not stored.

The AI Act is not the blocker it is often made out to be either: typical business uses carry no high-risk obligations, and the obligations that do exist follow a concrete timeline worth knowing with the correct dates, because much of the published content still cites the old ones.

02

The real AI Act timeline

Updated July 31, 2026, after the Digital Omnibus.

The dates that apply today

The June 2026 Digital Omnibus package moved the calendar. These are the dates in force.

Aug 2026
Article 50 transparency obligations: disclose when a user interacts with AI
Dec 2027
Annex III high-risk obligations, postponed by the June 2026 Digital Omnibus
2027
Verifactu, the Spanish verifiable invoicing system, postponed by RDL 15/2025
0
high-risk obligations for typical Claude Code uses: development, internal automation, administrative agents

Beware of outdated guides

Much of the Spanish-language content on AI compliance was written before the Digital Omnibus and still says high-risk obligations apply in August 2026. If a vendor pressures you to sign "before the AI Act kicks in", ask for their source: the current date for high risk is December 2027, and most business projects do not even fall in that category.

03

What Anthropic terms say

What is written, without creative interpretation.

No training on customer data

Commercial terms (API, Team, Enterprise) state customer content is not used to train models. This does not apply to free consumer accounts: company data always goes through commercial products.

Zero data retention on the API

An agreement available to organizations under which inputs and outputs are not stored: processed and discarded. The standard configuration for health, financial or legal data.

DPA included

The Anthropic Data Processing Addendum is accepted together with the commercial terms and covers the processor role and international transfers.

Code is covered too

Proprietary code that Claude Code reads travels to the API under the same terms: it is not trained on, and with zero data retention it is not stored either.

04

The other half: architecture

What Anthropic terms cannot solve for you.

The vendor covers what happens inside its service. Everything else depends on implementation: what data the agent sees, where it lives, and how the processing is documented. A serious Claude Code deployment defines this before writing the first line.

Read scope

The agent sees the repositories and folders it needs for its task, not the whole company. Like an external consultant: access by necessity, not convenience.

Data residency

When a project requires data in the EU or on own infrastructure, company systems stay on your side and only what each task needs is sent to the model.

Processing records

Which personal data is processed, for what purpose and for how long. Written down, in your records of processing activities, not implicit in the code.

Human approval for the irreversible

Sending, publishing, deleting and paying sit behind explicit approval. Good engineering that also reduces legal exposure.

The GDPR division of responsibilities is the key to reading all of this: your company is the controller and Anthropic is the processor. That is why two deployments of the same tool can be one flawless and the other in breach: the difference is not in the license, it is in the design.

05

When you need more than the standard setup

Signs your case requires specific compliance design.

Special categories of data

Health, biometric data, union membership. This calls for a DPIA and normally zero data retention from day one.

Large-scale processing of personal data

An agent processing data from thousands of end customers calls for a DPIA and aggressive minimization: pseudonymize before sending the model anything that does not need to be identified.

Regulated sector with its own supervisor

Financial, insurance, healthcare. GDPR coexists with sector rules and the deployment must be documented for both frameworks.

Automated decisions about people

If the system decides on credit, employment or access to services, you enter GDPR Article 22 and, depending on the case, AI Act Annex III with a December 2027 horizon. The only scenario where the AI Act truly weighs.

Frequently asked questions about Claude Code and GDPR

Is Claude Code GDPR compliant?+
Claude Code can be deployed in compliance with GDPR. Anthropic commercial terms state that customer content from API, Team and Enterprise customers is not used to train models, and the API offers a zero data retention agreement that prevents inputs and outputs from being stored. Final compliance depends on architecture: what data the agent sees, where it is processed and how the processing is documented. That is defined by whoever implements it, not by the tool.
Does Anthropic train its models on my company data?+
Not if you use the commercial products. Anthropic commercial terms (API, Team, Enterprise) state that customer content is not used to train models. This differs from the free consumer plan, where conditions are different. The practical rule for a business: work with internal data goes through the API or a commercial workspace, never through free personal accounts.
What happens to my company proprietary code in Claude Code?+
The code Claude Code reads is sent to the Anthropic API to generate responses, under the same commercial terms: it is not trained on. For sensitive cases, zero data retention can be signed, so inputs and outputs are not stored. What the implementation should define is scope: which repositories and folders the agent can read, just as you would with an external consultant.
Does the AI Act prohibit using Claude Code in my company?+
No. For typical business uses of Claude Code (software development, internal automation, administrative agents) the AI Act imposes no high-risk obligations. Article 50 transparency obligations apply from August 2026 and are met by disclosing when a user interacts with AI. High-risk obligations under Annex III were postponed to December 2027 by the June 2026 Digital Omnibus package.
What is Anthropic zero data retention?+
It is an agreement available on the API under which Anthropic does not store the inputs or outputs of your calls: they are processed and discarded. It is the standard configuration for projects with especially sensitive data (health, financial, legal). It is requested from Anthropic for the organization and applies at the API account level.
Do I need a DPIA to use Claude Code?+
It depends on the processing, not the tool. If the agent processes personal data at scale or special categories of data, GDPR requires an impact assessment just as with any other system. If the agent works on code, internal documents without personal data, or operational processes, documenting the processing in your records of processing activities is normally enough. We define which case applies during the initial diagnostic of every project.
Who is responsible for compliance: Anthropic or my company?+
Your company is the data controller; Anthropic acts as processor under its DPA. In practice: Anthropic answers for what happens inside its service (not training on your data, securing its infrastructure), and your company answers for what data enters the system, on what legal basis, and how data subjects are informed. That is why deployment architecture matters as much as the vendor.

Compliance is designed at the start, not patched at the end

All our Claude Code projects are born with data scope, residency and processing records defined during the diagnostic, before building.

How we start

With a scoped diagnostic that defines what to automate first, what data it touches and under which compliance configuration, including the possibility that your case needs nothing beyond the standard commercial setup.