Skip to content

Does GDPR let you put other people's data into a personal AI account?

Last updated 2026-08-17 · Confidence: documented — Anthropic’s terms pages plus the GDPR and EU AI Act texts; how they combine for a specific workplace is a call for the org’s privacy advisor, not this page.

Not for work data: a personal Claude account runs on consumer terms with no data-processing agreement, so the employer whose data lands there has no GDPR processor contract with Anthropic. The compliant route is a commercial plan — Team, Enterprise, or the API — where a DPA makes Anthropic the processor.

Why a personal account fails: no processor contract

Section titled “Why a personal account fails: no processor contract”

When you handle other people’s data at work — HR files, applicants, clients — your organization is the controller, and Article 28 GDPR lets it hand data only to processors “governed by a contract or other legal act… binding on the processor”. Anthropic’s Data Processing Addendum is incorporated into its Commercial Terms, which state plainly that “our consumer offerings (e.g., Claude.ai) are governed by our Consumer Terms of Service instead” — so Free, Pro, and Max accounts carry no such contract. GDPR’s own carve-out for individuals covers only “purely personal or household activity”, not anything professional.

Since a September 28, 2025 consumer-terms update, consumer accounts can also opt in to model training with five-year retention — so a colleague’s data pasted into a personal account may additionally end up in training data.

Under the Commercial Terms, Anthropic “may not train models on Customer Content” and acts as processor under the DPA — the paperwork a privacy reviewer needs. The question then shifts to organizational controls: who can export chats (Team data) and which sources connectors expose (Connector scoping).

The AI Act regulates uses rather than data flows: employment uses — filtering applications, promotion or termination decisions, monitoring performance — are high-risk under Annex III §4, and from August 2, 2026 deployers must inform affected workers, assign human oversight, and keep logs (Article 26). Chatting with an assistant over work documents is not automatically high-risk; for where the data may go, GDPR remains the binding constraint.