AI Vendor Data Protection Files
A dated, sourced record of what each AI vendor's own published documents say about data protection. Each answer is a quotation with its source URL, the date the page was read, and, where the document prints one, its own effective date. Where the published documents do not settle a question, a File records that rather than filling the gap.
Written by Michael K. Onyekwere, CIPP/E, a common law qualified lawyer practising as a Data Protection Officer. Each File is the primary-source evidence layer beneath a vendor compliance profile. Free to read and cite; the analysis is legal analysis of public facts, not legal advice.
Anthropic · Data Protection File
The Claude Team Data Protection File
What Anthropic's own legal documents say about data protection for Claude Team (Claude for Work, Team Plan): training, retention, subprocessors, transfers, and the gaps. 19 entries, quoted and dated.
Version 1.0 · Whole-set last verified 10 August 2026 · CC BY 4.0 - reuse with attribution
OpenAI · Data Protection File
The ChatGPT Business Data Protection File
What OpenAI's own legal documents say about data protection for ChatGPT Business (OpenAI’s team and small-business tier): training, retention, subprocessors, transfers, and the gaps. 12 entries, quoted and dated.
Version 1.0 · Whole-set last verified 24 August 2026 · CC BY 4.0 - reuse with attribution
Claude Team and ChatGPT Business, side by side
The same questions, answered from each vendor's own documents. Each cell is a compressed summary. The full quotes and sources are in the Claude Team File and the ChatGPT Business File.
| Question | Claude Team | ChatGPT Business |
|---|---|---|
| Who a UK customer contracts with | Anthropic Ireland, Limited. The UK is grouped with the EEA and Switzerland. | OpenAI OpCo, LLC, the US entity. The governing law and venue stay Irish, in Dublin. |
| Training on your data | Prohibited by default in the Commercial Terms. Two documented opt-ins override it. | Prohibited by default in Business Terms 4.2. One documented opt-in overrides it. |
| Personal-data breach notice | Within 48 hours of becoming aware. | Without undue delay. No fixed number of hours. |
| Are the retention periods contractual? | Almost none. Only deletion on termination, within 30 days, is written into a contract. | The conversation periods are on the FAQ. A 30-day content-deletion clock is contractual (11.3). |
| Special-category data | Schedule 1 records "None" while the product can process it. Unreconciled. | The schedule intends none. Section 5.4 bars only HIPAA health data, not UK GDPR health. Unreconciled. |
| UK Article 27 representative | None named. Anthropic Limited (UK) exists, so the establishment question is open. | None named. OpenAI UK Ltd exists, so the establishment question is open. |
| International transfers | The EU SCCs plus the ICO UK Addendum. | The EU SCCs plus the UK Addendum. UK data is processed in the US by OpenAI OpCo. |
| EU-US Data Privacy Framework | Not certified. Anthropic is absent from the participant registry, active and inactive. | Not certified either. So at both vendors the SCCs carry the transfer alone, and a transfer impact assessment is required. |
A compressed reading is not the File. Where a summary and a File differ, the File governs.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
For the analysis behind these records, see the vendor compliance profiles. For real agent failures analysed for legal liability, the AI Agent Incident Register.