Which plan should you choose? — Confidentiality, GDPR and client data
For a consultant, a consulting firm or an executive who handles sensitive client data (strategy, M&A, financial data, personal data), the choice of a Claude plan isn't just about features — it's a compliance decision.
The question your clients will ask you
Recommendations by profile — the short answer
🔴 Independent consultant — sensitive data
Minimum: Pro + "Help improve Claude" disabled + Incognito Mode used consistently.
Residual risk: data passes through Anthropic's servers (US) for 30 days even when not used for training. No enforceable DPA. Acceptable for non-nominative analysis. Insufficient for personal client data under GDPR.
🟢 Consulting firm / team — regular client data
Recommended: Team plan ($30/user/month).
Native protection: no training, configurable retention, DPA available (Data Processing Agreement). The admin controls access and can disable sensitive features. You can tell your clients: "Our data is never used to train the AI — it's contractual."
🟢 Large enterprise / strict regulation
Recommended: Enterprise or API via AWS Bedrock / Google Vertex AI.
Custom DPA, audit logs, SAML SSO, SCIM, configurable data residency. For regulated sectors (finance, healthcare, defense), routing through your own AWS/GCP infrastructure gives you full control: your data never leaves your VPC.
The details — full comparison, confidentiality angle
| Criterion | Free | Pro ($20) | Max ($100) | Team ($30/u) | Enterprise |
|---|---|---|---|---|---|
| Data used for training | Yes by default | Yes by default | Yes by default | Never ✦ | Never ✦ |
| Can be turned off manually | Yes (Settings) | Yes (Settings) | Yes (Settings) | N/A (already off) | N/A (already off) |
| Data retention (training off) | 30 days | 30 days | 30 days | Admin-configurable | Admin-configurable |
| Data retention (training on) | 5 years | 5 years | 5 years | N/A | N/A |
| Contractual guarantee | Standard ToS | Standard ToS | Standard ToS | DPA available (data processing agreement, GDPR art. 28) | DPA + custom clauses |
| Incognito Mode | ✓ | ✓ | ✓ | ✓ | ✓ |
| SSO / SAML (single sign-on via the company directory) | No | No | No | Basic SSO | SAML + SCIM |
| Audit logs | No | No | No | No | Yes ✦ |
| Centralized admin control | No | No | No | Yes | Yes (advanced) |
| Data residency (where your data is processed) | US only | US only | US only | US only | Configurable |
| Cowork (local files) | No | ✓ | ✓ | ✓ | ✓ |
| Usable with client data? | NO | WITH PRECAUTIONS | WITH PRECAUTIONS | YES ✦ | YES ✦ |
GDPR: what you need to know
📍 Where is data processed?
Anthropic is based in the United States. All data is processed on US servers (GCP us-east and AWS us-east). There is not yet a European data center. (For your technical teams: the inference_geo API parameter lets you constrain the processing region.)
📋 International transfers
The EU→US transfer is covered by the EU-US Data Privacy Framework (DPF) since July 2023. Anthropic adheres to it. For Enterprise plans, Standard Contractual Clauses (SCC) are available in addition.
🛡️ Processing under GDPR
If you process your clients' personal data through Claude, you are the data controller and Anthropic is the data processor. A DPA (available on Team/Enterprise plans) is mandatory to comply with Article 28 of the GDPR.
⚖️ AI Act 2026
The European AI Act takes effect in 2026. Claude is classified as a general-purpose AI system. Anthropic publishes transparency reports (model cards). For high-risk uses (HR, credit, healthcare), additional obligations apply on the user's side.
🔏 Watermark: every text Claude produces is marked
Since Fable 5.1, every generated text carries an invisible statistical watermark — Claude picks its words according to a secret key, no hidden characters, no extra tokens — everywhere and with no opt-out; generated Word, Excel, PowerPoint files and images receive signed provenance metadata (C2PA). It proves Claude was involved, not authorship: a heavy rewrite removes it, a copy-paste keeps it. Detection is restricted to authorized bodies (regulators, media, researchers). The reason: Article 50(2) of the AI Act. The reflex: own it and proofread it.
Is your data used to train the AI?
| Plan | Training | Retention | Action |
|---|---|---|---|
| Free / Pro / Max | Opt-in | 30d (off) / 5 years (on) | Disable |
| Team / Enterprise | Never | Configurable | Protected ✓ |
| API / Bedrock / Vertex | Never | Contract | Protected ✓ |
Open Settings → Privacy and check the state of "Help improve Claude".
Expected result : The option is off, or you are on Team / Enterprise.
Operational checklist — securing your usage
Disable "Help improve Claude" — Settings → Privacy → Off. Check for every team member.
Use Incognito Mode for any conversation involving nominative client data.
Anonymize whenever possible — replace proper names with codes before submitting to Claude.
Document your usage — keep a record of processing activities (GDPR Article 30) that includes Claude as a processor.
Inform your clients — mention the use of AI in your terms and conditions or engagement letters.
Move to the Team plan as soon as you handle client data regularly — that's the compliance threshold.
Request the DPA from Anthropic (available in the Team/Enterprise plan settings).
→ Share confidential client documents without having disabled training.
→ Use Claude for automated decisions affecting people (HR, credit) without human oversight.
→ Assume that "local" Cowork mode exempts you from precautions — prompts and summaries pass through the servers.
The information in this module is provided for educational purposes and reflects our understanding of the plans as of September 2026. It does not constitute legal advice: for any compliance decision (GDPR, client data), confirm with your DPO or legal counsel.


