Anthropic Data Processing Addendum (Summary)

This document summarizes the key provisions of Anthropic's DPA. For the full, legally binding text, please refer to the official source.

A. Definitions

Defines key terms like "Applicable Data Protection Laws", "Customer Personal Data", "GDPR", "Security Breach", and "Standard Contractual Clauses".

B. Processing of Customer Data

Establishes Customer as the data controller and Anthropic as the processor. Anthropic commits to only process data based on customer instructions and not to "sell" or "share" customer personal data.

C. Subprocessors

Customer grants general authorization for Anthropic to use subprocessors. Anthropic will provide 15 days' notice for new subprocessors, allowing customers to object.

D. Data Subject Requests

Anthropic will promptly forward any Data Subject Requests to the customer and provide reasonable assistance.

E. Security

Anthropic commits to implementing and maintaining appropriate technical and organizational security measures, as detailed in Schedule 2.

F. Compliance and Audits

Anthropic undergoes annual third-party audits (e.g., SOC 2). Customers can request audit reports or conduct their own audits under specific conditions.

G. Security Breaches

Anthropic will notify customers of a Security Breach without undue delay, and in any event within 48 hours.

H. Deletion and Return

Anthropic will delete or return customer data within 30 days of the agreement's termination.

I. Standard Contractual Clauses (SCCs)

The DPA incorporates the EU SCCs (Module Two and Three) for international data transfers. It specifies that Irish law governs the agreement and that disputes will be resolved in Irish courts.

Schedule 1: Details of Processing

Outlines the parties involved, categories of data subjects and personal data (determined by the customer), and the purpose of processing (to provide the Services).

Schedule 2: Technical and Organizational Measures

Details Anthropic's security program, including access controls (MFA, least privilege), encryption (AES-256 at rest, TLS 1.2+ in transit), vulnerability management, and incident response.

Schedule 3: International Data Transfers

Includes specific addenda for transfers subject to UK and Swiss data protection laws, adapting the EU SCCs for those jurisdictions.


This is a summary for informational purposes. For the complete legal text, please visit the official DPA at https://www.anthropic.com/legal/data-processing-addendum.