> Quelle: https://souverana.ch/en/insights/anthropic-claude-datenschutz/
> Sprache: en

# Anthropic Claude and Swiss data protection: what to check

Claude works for business data, not for professional secrecy, according to VISCHER. And a promise many organisations rely on has not held for two models since June.

Analysis · Published 21 Jul 2026 · Updated 24 Aug 2026 · Joel Barmettler

## Can Swiss businesses use Anthropic’s Claude in compliance with data protection law?

**For ordinary business data, yes, provided Claude is accessed through the business tiers Team, Enterprise or the API. Anthropic’s data processing agreement, however, does not cover especially sensitive personal data, and for professionals bound to official or professional secrecy, Anthropic is currently not an option, according to the Zurich law firm VISCHER’s assessment. Anyone who wants to process such data with Claude needs the route via a hyperscaler.**

**In brief**

-   For ordinary business data, you can use Claude as soon as access runs through a business tier. The restrictions match those at OpenAI.
-   If you rely on Zero Data Retention, check regularly which models the assurance still covers. Anthropic excluded two models from it in June 2026, without the contract’s name changing at all.
-   If you must keep data in Switzerland or the EU, the direct contract does not get you there. Only access via a hyperscaler shifts where processing happens.
-   Plan your exit before you commit. Anthropic publishes no open models, so the way out of any lock-in always leads to another contract partner.
-   For professional-secrecy data, do not bother asking. According to VISCHER, Anthropic has so far not been willing to discuss it.

The Zurich law firm VISCHER (authors Lucian Hunger and Jonas Baeriswyl) regularly updates a public market overview of AI providers; the July 2026 edition gives Anthropic its own section for the first time, as the “most important new player” alongside the three established hyperscalers. Souverana is not a law firm: what follows is VISCHER’s legal assessment, quoted and put in context, along with the architecture questions that a legal review naturally does not answer.

This is the second part of our series Provider Data-Protection Check, following the same framework as the others: contracts, data residency, professional secrecy, ways out.

Series · Provider Data-Protection Check

1.  1[Is ChatGPT GDPR-compliant? What OpenAI's contracts cover](/en/insights/chatgpt-dsgvo-konform/)
2.  2Anthropic Claude and Swiss data protection: what to checkYou are reading this part
3.  3[Google Gemini & data protection: what SMEs need to know](/en/insights/google-gemini-datenschutz/)
4.  4[Using Microsoft Copilot safely: what data protection allows](/en/insights/microsoft-copilot-datenschutz/)
5.  5[Proton Lumo: what privacy-friendly AI looks like](/en/insights/proton-lumo/)

## What VISCHER criticises about Anthropic

With this edition, VISCHER newly added the Anthropic models to its overview: on one side various consumer offerings, on the other the three business offerings Team, Enterprise and API. As with every other provider, the consumer offerings are not suitable for enterprise use.

The business offerings come with a data processing agreement? (Anthropic DPA), a confidentiality obligation and the assurance that data is not used for training or service improvement. According to VISCHER, that makes enterprise use possible. One caveat remains the same as at OpenAI: the Anthropic DPA only covers personal data that does not qualify as especially sensitive. For especially sensitive personal data within the meaning of the revFADP, the Claude models are therefore not suitable under the publicly available DPA, even where staff are clearly instructed not to enter such data.

Evidence

VISCHER’s assessment comes out the same for both large newcomers: “Here too, OpenAI and Anthropic both show, in our view, the lower maturity of the ‘newcomers’ in data protection and data security compared with the hyperscalers Microsoft, AWS and Google.” For sensitive applications, the firm recommends sourcing Anthropic models via a hyperscaler, not directly.

On its own inquiry about professional secrecy, Anthropic has so far, according to VISCHER, not been willing to hold discussions on the topic.

## Claude Code: the same contract logic, one shortened deadline

VISCHER’s overview does not cover Claude Code, Anthropic’s agentic command-line tool for programming work, separately. What follows is our own research into Anthropic’s public data protection disclosures, as of July 2026, not VISCHER’s assessment.

Contractually, Claude Code hangs on the same hook as Claude itself: anyone using it through Claude for Work (Team or Enterprise) or the API is subject to the same Commercial Terms and the same DPA criticised in the previous section. There is no separate Claude Code DPA.

Risk

On the personal tiers Claude Free, Pro and Max, Anthropic states that it has trained on conversations and code by default since 28 August 2025, unless someone actively opts out; for those who consent, data is retained for up to five years.[Anthropic](https://www.anthropic.com/news/updates-to-our-consumer-terms) Under the business terms for Team, Enterprise, API and via AWS Bedrock and Google Cloud, Anthropic states that it does not train on code or conversations.[Anthropic Legal](https://www.anthropic.com/legal/service-specific-terms)

Two details are worth checking before rollout. For commercial API use, Anthropic currently states a standard retention period of 30 days: inputs and outputs are then automatically deleted and not used for training.[Anthropic Privacy Center](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data) Claude Code is also eligible for Zero Data Retention, either through a commercial API key or through Claude Enterprise.[Anthropic Docs](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention) What that assurance has actually meant since June 2026 is a story of its own: further down in the article, we put the change in context.

## Professional secrecy: why Anthropic falls short

For law firms, medical practices, trustees and banks, the question of [professional secrecy↗](/en/insights/berufsgeheimnis-cloud/) is often more pressing than general GDPR or revFADP compliance. At Anthropic, VISCHER’s answer is short.

Evidence

VISCHER’s conclusion, in substance: even Anthropic’s business contracts are not sufficient for data covered by professional or official secrecy. The firm is not aware of any contract addenda or other solutions that would permit use with such data, despite high demand for the Anthropic models.

Unlike at Microsoft or Google, there is, as of July 2026, no known route to professional-secrecy data directly at Anthropic. VISCHER’s recommendation for this case is clear: do not source Claude models for professional- or official-secrecy data from Anthropic itself, but from one of the three hyperscalers; more on that further below.

## Zero Data Retention: no longer for every model

VISCHER’s overview was finished shortly before a change that matters for ZDR customers. On 9 June 2026, Anthropic classified two new models, Claude Fable 5 and Claude Mythos 5, as “Covered Models”.

Risk

Zero Data Retention still means that Anthropic does not permanently store inputs and outputs after the response. For the two new Covered Models (Fable 5 and Mythos 5), that no longer holds: they require 30 days of retention and are not available under ZDR. Anyone who wants to use them under a ZDR agreement must explicitly enable the 30-day retention per workspace.[Anthropic Privacy Center](https://privacy.claude.com/en/articles/8956058-i-have-a-zero-data-retention-agreement-with-anthropic-what-products-does-it-apply-to)

Independently of that, ZDR is never quite zero: Anthropic states that content flagged as potentially abusive may be retained for up to two years, even under ZDR.[Anthropic Docs](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention) For businesses that chose ZDR precisely for the “no storage” assurance, that means: check which model you are using, and read the current version regularly, long after the contract is signed.

## Where Claude stands on the sovereignty scale

The contract question is one layer. The other is the architecture: which jurisdiction does processing actually fall under, how open is the model behind it, where does operation run, and can you get out of the system again if you need to? How we understand sovereignty is set out in our foundational article, [What is sovereign AI?](/en/insights/was-ist-souveraene-ki/). The same six axes apply concretely to Claude:

less sovereign more sovereign →

Legal jurisdiction

US

EU

Switzerland

Model

closed

open weights

open + training data

Software

proprietary

open code

true open source

Operation

US cloud

Swiss provider

in-house

Data

provider trains on it

contractually forbidden

technically impossible

Integration

proprietary API

open standards

in-house

On legal jurisdiction, Claude sits on the left when accessed directly from Anthropic: processing runs on US infrastructure, and Anthropic offers no dedicated EU or Swiss region. Only access via a hyperscaler shifts this axis, more on that in the next section. On the model axis, Claude stays on the left throughout: unlike OpenAI with gpt-oss or Google with Gemma, Anthropic publishes no open models?. Anyone who wants to self-host an Anthropic model cannot; every use runs through a provider. On integration, it likewise stays a proprietary API, even though it is reachable through three different contract partners.

## The escape route: Claude via the hyperscalers

Unlike OpenAI or Google, Anthropic has no open models on offer [that could be self-hosted↗](/en/insights/llm-selbst-hosten/). The escape route out of direct Anthropic lock-in leads to another contract partner, not to self-hosting: all three hyperscalers, Microsoft, AWS and Google, offer Claude models under their own contracts.

Key figure

3 hyperscalers

Microsoft Azure, AWS Bedrock and Google Cloud offer Claude models under their own, hyperscaler-typical contract terms. For professional- and official-secrecy data, VISCHER has so far only reviewed the route via Google with the necessary add-ons and found it suitable.

Source: VISCHER, AI tools market overview part 31, as of July 2026

At Google, for instance, the contractual relationship is formed with Google itself. The customer additionally agrees to follow the Anthropic Terms of Service. According to its own Service Specific Terms, Anthropic in this case has neither access to the customer’s Google Cloud environment nor to the data processed there; abuse monitoring is then carried out by Google. One exception remains: for so-called Covered Models, particularly capable models with heightened risk potential, Anthropic reserves access to customer data even via a hyperscaler. In doing so, Anthropic commits to complying with the Anthropic DPA.

At Microsoft, processing of Anthropic models, for instance as an alternative to GPT in Copilot, currently still runs in the US; for professional secrecy, this route is therefore off the table for now. VISCHER has, however, learned that Anthropic plans to also run its models on data centres in Europe towards the end of 2026. VISCHER itself has not yet carried out an in-depth review of the situation at AWS.

## How to get started

Before your next Claude contract or the next expansion, clarify four points. First, whether a personal tier (Free, Pro, Max) is running in business use at your organisation, even though training has been enabled by default since August 2025. Second, whether Claude or Claude Code processes especially sensitive personal data or even professional-secrecy data, for which, according to VISCHER, neither the direct Anthropic contract nor the consumer tiers are sufficient. Third, whether an arrangement labelled “Zero Data Retention” at your organisation still delivers on that name since the June 2026 change. Fourth, whether access via a hyperscaler would be the better fit for your use case than the direct Anthropic contract.

Want to know which contract or architecture fits your data: Claude directly, via a hyperscaler, or Claude Code in your development team?

[AI architecture and platform selection](/en/leistungen/ki-architektur/)

The other parts of the series review OpenAI, Google and Microsoft against the same grid, plus Proton, a provider that does it differently.

The author

![Portrait of Joel Barmettler](/_astro/joel-barmettler.CGKHGWrV_sJ0IG.webp)

Joel Barmettler

AI Architect · Souverana, Zurich

Joel Barmettler guides Swiss companies from AI strategy to integration: sovereign, confidential and production-ready. He built the Swiss AI Hub as its architect and today co-owns its architecture; he personally leads every Souverana mandate. Mandates from one-person firms to Fortune 500 corporations.

[Book an intro call](https://meet.brevo.com/joel-barmettler/30-minute-meeting) [More about Souverana](/en/) [LinkedIn](https://www.linkedin.com/in/joel-barmettler-b9ab361b7)

## Frequently asked questions

Is Anthropic's Claude GDPR compliant?

For the business tiers Team, Enterprise and API, in principle yes: a data processing agreement is in place, together with an assurance that data is not used for training. For especially sensitive personal data, however, the contract is not sufficient according to the Zurich law firm VISCHER; a risk-based decision is required.

Can I use Claude for sensitive business data?

For ordinary business data on a business tier, in principle yes, with contractual protection in place. For especially sensitive personal data or professional secrecy, VISCHER explicitly advises against it: in their assessment, Anthropic's own contract is not designed for it, and Anthropic itself has so far been unwilling to discuss the matter.

Is Claude Code safe for enterprise use?

Through Claude for Work (Team/Enterprise) or the API, yes, under the same conditions as Claude itself: no training on your code, with the known restrictions on especially sensitive personal data. Through the personal tiers Free, Pro or Max, Anthropic has trained on your inputs by default since August 2025.

Can Claude be used by professionals bound to secrecy, such as lawyers or doctors?

Not directly at Anthropic, according to VISCHER's assessment: the firm is not aware of any contract addenda that would permit use with data covered by professional or official secrecy. One route runs via a hyperscaler such as Microsoft, AWS or Google, which offer Claude models under their own contracts, better suited to sensitive data.

Does Anthropic offer Swiss or European data residency?

No, not directly from Anthropic: processing runs on US infrastructure by default. European processing can currently only be reached via AWS Bedrock or Google Vertex AI, at correspondingly higher cost.

LinkedIn

## Share this article

Ready-formatted graphics and a suggested post for your LinkedIn feed: download, copy, post.

![Four routes to access Claude compared: direct from Anthropic (professional secrecy: no, US processing), Google Vertex AI (possible with add-ons), Microsoft Azure (not yet, US processing), AWS Bedrock (not reviewed by VISCHER). Anthropic has no open models.](/media/anthropic-claude-datenschutz-en/infografik.png)

[Download infographic (PNG)](/media/anthropic-claude-datenschutz-en/infografik.png)

Suggested post

Does your team work with Claude? Then it is worth asking who your contract partner actually is.

Direct from Anthropic: the data processing agreement excludes especially sensitive personal data, processing runs on US infrastructure, and none of the business contracts covers professional or official secrecy, according to the Zurich law firm VISCHER. There is no dedicated EU or Swiss region.

The way out therefore does not lead to self-hosting, but to the next contract partner: via Google Vertex AI, use is possible with the necessary add-ons, according to VISCHER; Microsoft Azure processes Anthropic models in the US for now. Unlike OpenAI with gpt-oss or Google with Gemma, Anthropic publishes no open models, so self-hosting is ruled out.

Our conclusion: check your ability to exit before you commit. How quickly assurances change was shown in June 2026, when two Claude models were excluded from Zero Data Retention and now require 30 days of storage, without the contract's name changing at all.

Our own assessment, not legal advice. The article covers the four routes to access, where Claude Code stands and six questions to ask before your next contract. Link in the comments.

#AI #DataProtection #Anthropic #Switzerland
