CompanyScope
by Janus Compliance

AI Vendor Data Protection Files

A dated, sourced record of what each AI vendor's own published documents say about data protection. Each answer is a quotation with its source URL, the date the page was read, and, where the document prints one, its own effective date. Where the published documents do not settle a question, a File records that rather than filling the gap.

Written by Michael K. Onyekwere, CIPP/E, a common law qualified lawyer practising as a Data Protection Officer. Each File is the primary-source evidence layer beneath a vendor compliance profile. Free to read and cite; the analysis is legal analysis of public facts, not legal advice.

Claude Team and ChatGPT Business, side by side

The same questions, answered from each vendor's own documents. Each cell is a compressed summary. The full quotes and sources are in the Claude Team File and the ChatGPT Business File.

QuestionClaude TeamChatGPT Business
Who a UK customer contracts withAnthropic Ireland, Limited. The UK is grouped with the EEA and Switzerland.OpenAI OpCo, LLC, the US entity. The governing law and venue stay Irish, in Dublin.
Training on your dataProhibited by default in the Commercial Terms. Two documented opt-ins override it.Prohibited by default in Business Terms 4.2. One documented opt-in overrides it.
Personal-data breach noticeWithin 48 hours of becoming aware.Without undue delay. No fixed number of hours.
Are the retention periods contractual?Almost none. Only deletion on termination, within 30 days, is written into a contract.The conversation periods are on the FAQ. A 30-day content-deletion clock is contractual (11.3).
Special-category dataSchedule 1 records "None" while the product can process it. Unreconciled.The schedule intends none. Section 5.4 bars only HIPAA health data, not UK GDPR health. Unreconciled.
UK Article 27 representativeNone named. Anthropic Limited (UK) exists, so the establishment question is open.None named. OpenAI UK Ltd exists, so the establishment question is open.
International transfersThe EU SCCs plus the ICO UK Addendum.The EU SCCs plus the UK Addendum. UK data is processed in the US by OpenAI OpCo.
EU-US Data Privacy FrameworkNot certified. Anthropic is absent from the participant registry, active and inactive.Not certified either. So at both vendors the SCCs carry the transfer alone, and a transfer impact assessment is required.

A compressed reading is not the File. Where a summary and a File differ, the File governs.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe - free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

For the analysis behind these records, see the vendor compliance profiles. For real agent failures analysed for legal liability, the AI Agent Incident Register.