GDPR and American AI: can EU firms use Claude

    |8 min read
    Joachim Sahlin, CEO & AI Advisor

    Joachim Sahlin

    CEO & AI Advisor

    Pick a time for a call
    Painterly desk by a window with an open notebook, a brass lamp and candles, looking out over a misty river valley, illustrating GDPR and American AI tools for European businesses

    The question we hear every week from European IT and data protection leads is whether the company may use American AI at all. Claude and ChatGPT are both built in the US, and somebody has usually paused the AI project with a reference to the GDPR. The short answer to the GDPR and American AI question is yes. Most companies already gave that answer the day they rolled out Microsoft 365.

    The guide below covers what the GDPR asks for, where the one real difference between suppliers sits and which four documents you need before the first prompt with personal data goes out. It is written for a business that uses Claude or ChatGPT as a tool, not for one that trains its own models.


    Can European companies use American AI under the GDPR?

    The GDPR contains no ban on American suppliers, and European companies have run Microsoft, Google and Amazon clouds with personal data inside for years. Chapter V of the regulation, Articles 44 to 50, sets one condition for every transfer of personal data out of the EU and EEA, namely that it rests on a valid legal basis.1

    A rule of "no American tools" would therefore remove Microsoft 365, Azure, Google Workspace and half the IT stack of a typical 200-person company. Saying no to Anthropic on the ground that it is American, while Outlook runs on Microsoft, is not a consistent position. The useful question is narrower: is the transfer of personal data handled correctly.

    Three worries, and why two of them point the wrong way

    Certifications. Anthropic lists ISO 27001:2022, ISO/IEC 42001:2023 for AI management systems and SOC 2 Type I and Type II reports for its commercial products.2 Every serious supplier clears that bar in 2026, so a security review that stops at "do they have SOC 2" measures the wrong thing.

    American law. Every US provider, Microsoft and Anthropic alike, falls under the same US surveillance and disclosure laws. One of them is the CLOUD Act, which lets US authorities order a provider to hand over data in its control regardless of where the data is stored.3 The exposure is equal across suppliers, which makes it a reason to minimise data and not a reason to pick one American supplier over another.

    Where the data sits. Server location is the myth that holds on hardest, and it gets its own section.

    Why does EU data residency not settle the question?

    Running Claude through Frankfurt keeps the storage and processing in Europe, and Amazon Bedrock offers exactly that through an EU cross-region profile covering regions such as Frankfurt, Ireland, Paris and Stockholm.4 The legal picture changes less than people hope, because the US parent company still controls the service and the CLOUD Act reaches data in its control wherever the server stands.3

    What changes the risk is what you put into the prompt. Claude has to read a prompt in plain text to answer it, so encryption cannot hide the content from the supplier the way it can for stored files. Data minimisation and pseudonymisation, meaning replacing names and ID numbers with placeholders before sending, is the measure that works here. The EDPB recommendations describe it as effective when the recipient does not need to know who the person is.5 A support team in Madrid that writes "customer 4471 has a delayed order" instead of the full name and address has done more for the GDPR than any region setting.

    EU residency still has value, since it lowers latency and keeps storage inside Europe, which some customer contracts require in writing. It simply does not make the transfer lawful on its own.

    The one real difference: the transfer basis

    The GDPR gives two main routes for sending personal data to the US, and here Microsoft and Anthropic do differ.

    • Microsoft states that it complies with the EU-US Data Privacy Framework, so it can rely on the Commission's adequacy decision under Article 45.61
    • Anthropic names adequacy decisions and Standard Contractual Clauses as its transfer mechanisms and does not list the Data Privacy Framework.7 Its data processing agreement, the DPA, includes the SCCs and is part of the Commercial Terms, so accepting the terms means accepting the DPA.8

    Both routes are lawful under the GDPR. The difference is paperwork, because the SCC route asks you to document a transfer impact assessment, a written check of whether the destination country's law undermines the protection, which the adequacy route lets you skip.

    Is Claude different from Microsoft 365 in legal terms?

    On everything except the transfer basis the answer is no, with the same certifications, the same exposure to US law and the same duties for you as the controller. Microsoft itself has onboarded Anthropic as a subprocessor for its AI features, which means Microsoft reviewed Anthropic's safeguards before putting Claude models inside its own products.9

    The same Microsoft page adds one honest caveat. Anthropic models inside Microsoft's products are excluded from the EU Data Boundary and are switched off by default for customers in the EU, EFTA and UK, so an admin has to opt in.9 A company that needs European storage therefore has one clean route today, which is Claude through a cloud platform in the EU. That means Amazon Bedrock with the EU cross-region inference profile or Google Cloud Vertex AI in an EU region. A direct Anthropic plan stores data in the US, so it needs the transfer documents in order instead.

    The SCC route also holds an irony. On 3 September 2025 the EU General Court upheld the Data Privacy Framework, and an appeal to the Court of Justice has been pending since 31 October 2025.10 If the framework falls one day, a company that relied only on adequacy has to find a new basis quickly, while a customer on SCCs with a transfer assessment on file keeps working.

    Which documents do you need before you start?

    Four documents cover the transfer layer, whichever supplier you pick:

    1. A DPA with SCCs. For Claude Team, Enterprise and the API it comes with the Commercial Terms, so save a dated PDF copy in your contract register.8
    2. A named transfer basis per supplier. Write down adequacy or SCCs for each tool, and check that a supplier claiming the Data Privacy Framework appears on the official list.6
    3. A transfer impact assessment where SCCs apply. The CNIL practical guide from January 2025 follows the six EDPB steps, and one AI supplier usually takes four to eight pages.11
    4. Supplementary measures on paper. Prompt rules for pseudonymisation, access control through single sign-on and a short list of data that never goes into any AI tool.

    Underneath sit the usual GDPR steps: a legal basis for the processing itself, an entry in your record of processing and an AI policy people can read in five minutes. Our AI policy template covers the last one, and the AI Act layer on top is in our EU AI Act guide.

    How we handle it at satori.

    Nearly every first conversation contains the GDPR worry, and nearly every time it rests on a feeling rather than on the law. Broken down, it becomes two afternoons of work: one to collect the DPA and name the transfer basis, one to write the transfer impact assessment and the prompt rules. We do not give legal opinions, so a company that processes health or financial data at scale should have its data protection officer or a lawyer sign the assessment.

    A Claude setup through satori-claude costs €490 once, then €24 per user per month for a Standard licence and €14 per user per month for support. Anthropic's DPA comes with the licences, so the transfer documents start from the same contract you would sign direct. All satori. prices are fixed and exclude VAT.

    Open your contract register and find the data processing agreement for every AI tool your company pays for. In twenty minutes you know which suppliers have a named transfer basis and which ones still need a transfer impact assessment before personal data goes in.


    Sources

    Footnotes

    1. European Union (2016). Regulation (EU) 2016/679 (General Data Protection Regulation), Chapter V. EUR-Lex. https://eur-lex.europa.eu/eli/reg/2016/679/oj ↩ ↩2

    2. Anthropic (2026). What certifications has Anthropic obtained? Anthropic Privacy Center. https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained ↩

    3. US Department of Justice (2026). CLOUD Act Resources. https://www.justice.gov/criminal/cloud-act-resources ↩ ↩2

    4. Amazon Web Services (2026). Regional availability of models in Amazon Bedrock. https://docs.aws.amazon.com/bedrock/latest/userguide/models-region-compatibility.html ↩

    5. European Data Protection Board (2021). Recommendations 01/2020 on measures that supplement transfer tools. https://www.edpb.europa.eu/our-work-tools/our-documents/recommendations/recommendations-012020-measures-supplement-transfer_en ↩

    6. Microsoft (2026). Microsoft U.S. entities covered by Data Privacy Framework certification. https://www.microsoft.com/en-us/privacy/microsoft-data-privacy-framework-covered-entities ↩ ↩2

    7. Anthropic (2026). How does Anthropic protect the personal data of Claude users? Anthropic Privacy Center. https://privacy.claude.com/en/articles/10458704-how-does-anthropic-protect-the-personal-data-of-claude-users ↩

    8. Anthropic (2026). How do I view and sign your Data Processing Addendum (DPA)? Anthropic Privacy Center. https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa ↩ ↩2

    9. Microsoft Learn (2026). Anthropic models in Microsoft Online Services. https://learn.microsoft.com/en-us/copilot/microsoft-365/connect-to-ai-subprocessor ↩ ↩2

    10. Court of Justice of the European Union (2025). The General Court dismisses an action for annulment of the new framework for the transfer of personal data between the EU and the USA. Press release 106/25. https://curia.europa.eu/site/upload/docs/application/pdf/2025-09/cp250106en.pdf ↩

    11. CNIL (2025). Practical guide: Transfer Impact Assessment, final version January 2025. https://www.cnil.fr/sites/cnil/files/2025-01/guide_tia.pdf ↩

    Cookies

    We use analytics cookies to see which pages people read, and marketing cookies stay off unless you tick them under Details.