Claude GuideDevantia × Executive Partners Group
DevantiaExecutive Partners Group
0/23 Jean-Christophe Leroy
Jean-Christophe Leroy
Guide author
✓ Verified on September 3, 2026⏱ 5 min read
Module 13b

Which plan should you choose? — Confidentiality, GDPR and client data

🔎 The "Data & compliance" hub Plans, confidentiality, GDPR and model training are grouped here. See also 10 ways data leaks. Detailed price grid: Pricing Appendix.

For a consultant, a consulting firm or an executive who handles sensitive client data (strategy, M&A, financial data, personal data), the choice of a Claude plan isn't just about features — it's a compliance decision.

The question your clients will ask you

💬 "Do you use AI to process our data?" This is the question that increasingly comes up in client meetings. Your answer must be precise, documented and reassuring. Choosing the right Claude plan lets you respond: "Yes, I use Claude. No, your data is not used for training. Here are the contractual guarantees."
💶 🛡️ Plan cost Compliance guarantees The right plan isn't the cheapest — it's the one that balances your exposure.

Recommendations by profile — the short answer

🔴 Independent consultant — sensitive data

Minimum: Pro + "Help improve Claude" disabled + Incognito Mode used consistently.
Residual risk: data passes through Anthropic's servers (US) for 30 days even when not used for training. No enforceable DPA. Acceptable for non-nominative analysis. Insufficient for personal client data under GDPR.

🟢 Consulting firm / team — regular client data

Recommended: Team plan ($30/user/month).
Native protection: no training, configurable retention, DPA available (Data Processing Agreement). The admin controls access and can disable sensitive features. You can tell your clients: "Our data is never used to train the AI — it's contractual."

🟢 Large enterprise / strict regulation

Recommended: Enterprise or API via AWS Bedrock / Google Vertex AI.
Custom DPA, audit logs, SAML SSO, SCIM, configurable data residency. For regulated sectors (finance, healthcare, defense), routing through your own AWS/GCP infrastructure gives you full control: your data never leaves your VPC.

The details — full comparison, confidentiality angle

Criterion Free Pro ($20) Max ($100) Team ($30/u) Enterprise
Data used for training Yes by default Yes by default Yes by default Never ✦ Never ✦
Can be turned off manually Yes (Settings) Yes (Settings) Yes (Settings) N/A (already off) N/A (already off)
Data retention (training off) 30 days 30 days 30 days Admin-configurable Admin-configurable
Data retention (training on) 5 years 5 years 5 years N/A N/A
Contractual guarantee Standard ToS Standard ToS Standard ToS DPA available (data processing agreement, GDPR art. 28) DPA + custom clauses
Incognito Mode
SSO / SAML (single sign-on via the company directory) No No No Basic SSO SAML + SCIM
Audit logs No No No No Yes ✦
Centralized admin control No No No Yes Yes (advanced)
Data residency (where your data is processed) US only US only US only US only Configurable
Cowork (local files) No
Usable with client data? NO WITH PRECAUTIONS WITH PRECAUTIONS YES ✦ YES ✦

GDPR: what you need to know

📍 Where is data processed?

Anthropic is based in the United States. All data is processed on US servers (GCP us-east and AWS us-east). There is not yet a European data center. (For your technical teams: the inference_geo API parameter lets you constrain the processing region.)

📋 International transfers

The EU→US transfer is covered by the EU-US Data Privacy Framework (DPF) since July 2023. Anthropic adheres to it. For Enterprise plans, Standard Contractual Clauses (SCC) are available in addition.

🛡️ Processing under GDPR

If you process your clients' personal data through Claude, you are the data controller and Anthropic is the data processor. A DPA (available on Team/Enterprise plans) is mandatory to comply with Article 28 of the GDPR.

⚖️ AI Act 2026

The European AI Act takes effect in 2026. Claude is classified as a general-purpose AI system. Anthropic publishes transparency reports (model cards). For high-risk uses (HR, credit, healthcare), additional obligations apply on the user's side.

🔏 Watermark: every text Claude produces is marked

Since Fable 5.1, every generated text carries an invisible statistical watermark — Claude picks its words according to a secret key, no hidden characters, no extra tokens — everywhere and with no opt-out; generated Word, Excel, PowerPoint files and images receive signed provenance metadata (C2PA). It proves Claude was involved, not authorship: a heavy rewrite removes it, a copy-paste keeps it. Detection is restricted to authorized bodies (regulators, media, researchers). The reason: Article 50(2) of the AI Act. The reflex: own it and proofread it.

📌 Governance & administration The Enterprise plan can now be purchased self-service on the website, without going through the sales teams. Administrators get granular roles (billing, privacy — without being Owner), RBAC groups (manual or SCIM), per-role connector control, model entitlements (choosing which models and effort levels are accessible to whom), trusted devices for remote Claude Code sessions, and a Compliance API to plug in their compliance tools. On the healthcare side: HIPAA-ready infrastructure, self-service configurable since July 2026. the Compliance API now returns transcripts of Cowork and Claude Code sessions (generally available since August 26; local Claude Science and Microsoft 365 sessions in beta), and the Console offers personal and service-account API keys that inherit their owner's permissions and are deactivated with them. On data: Fable 5.1 requires 30-day retention through the API — no "zero retention" without Anthropic's express approval.

Is your data used to train the AI?

🔴 Immediate action Free/Pro/Max plans: SettingsPrivacy → disable "Help improve Claude". Otherwise: your conversations are used for training, with a 5-year retention.
The 10-second setting that changes everything Help improve Claude Allow your conversations to be used for training OFF ✓ OFF: 30-day retention, nothing goes to training ✗ ON: training data, 5-year retention On Team & Enterprise, the question doesn't arise: never any training, by contract.
Your data in pro mode: training off · 30-day retention Team / Enterprise: locked by contract 🔒
PlanTrainingRetentionAction
Free / Pro / MaxOpt-in30d (off) / 5 years (on)Disable
Team / EnterpriseNeverConfigurableProtected ✓
API / Bedrock / VertexNeverContractProtected ✓
🛠️ Your turn — 5 minutes

Open Settings → Privacy and check the state of "Help improve Claude".

Expected result : The option is off, or you are on Team / Enterprise.

🧪 Exercise
Your company uses Claude Pro for sensitive client data. What is the main risk and the solution?
A. No risk, Claude is secure by default
B. Using Incognito Mode is enough
C. Migrate to a Team or Enterprise plan: data never used for training, with contractual guarantees

Operational checklist — securing your usage

1

Disable "Help improve Claude" — Settings → Privacy → Off. Check for every team member.

2

Use Incognito Mode for any conversation involving nominative client data.

3

Anonymize whenever possible — replace proper names with codes before submitting to Claude.

4

Document your usage — keep a record of processing activities (GDPR Article 30) that includes Claude as a processor.

5

Inform your clients — mention the use of AI in your terms and conditions or engagement letters.

6

Move to the Team plan as soon as you handle client data regularly — that's the compliance threshold.

7

Request the DPA from Anthropic (available in the Team/Enterprise plan settings).

🔴 Never do this → Paste clients' personal data (names, emails, numbers) into the Free plan.
→ Share confidential client documents without having disabled training.
→ Use Claude for automated decisions affecting people (HR, credit) without human oversight.
→ Assume that "local" Cowork mode exempts you from precautions — prompts and summaries pass through the servers.
🎯 Sample wording for your clients "As part of our engagement, we use Anthropic's Claude (Team plan) as an analysis support tool. Your data is never used to train the AI. We have a GDPR-compliant Data Processing Agreement in place. All data is processed on certified servers, and we systematically anonymize nominative information before processing."
🧪 Exercise — Test what you've learned
A Pro consultant uses Claude to analyze a client contract containing names and amounts. What is the flaw?
A. Claude will share the contract with other users
B. Without a DPA and without disabling training, the data can be retained for 5 years and used by Anthropic
C. The Pro plan technically prevents sensitive data from being sent

The information in this module is provided for educational purposes and reflects our understanding of the plans as of September 2026. It does not constitute legal advice: for any compliance decision (GDPR, client data), confirm with your DPO or legal counsel.