Provision record
Anthropic · Anthropic Privacy Policy (Superseded Capture) · View original document ↗

Controller/Processor Scope Exclusion

High severity Common · 284 of 352 platforms
Get alerted the next time Anthropic changes these terms. Follow Anthropic →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Anthropic recorded 3 documented changes in the last 30 days.
Follow Anthropic →
Monitor governance changes for Anthropic Monitor emails you the same day this changes. The archive stays free.
Follow Anthropic →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

If you use Claude through your employer or through a third-party app that runs on Claude's technology, this privacy policy does not protect you — your employer or that app's company is responsible for your data privacy, not Anthropic.

This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This scope exclusion clarifies the division of data governance responsibility between Anthropic and its commercial customers. When Anthropic processes data as a processor rather than a controller, the commercial customer's privacy obligations and disclosures apply, which affects which entity's privacy terms users should consult for data handling practices.

Clause Stability Stable

0
Changes
4
Months Monitored
Apr 28, 2026
First Seen
Apr 28, 2026
Last Seen
This clause type exists across 3394 other provisions on other platforms.

Consumer impact (what this means for users)

If you access Claude via an employer account, a third-party app, or any API-powered product, Anthropic's privacy rights and protections described in this policy — including deletion rights, opt-out of training, and data access — do not apply to your data; you must look to your employer or the third-party operator for those protections.

How other platforms handle this

MyFitnessPal Medium

We use your personal information to send you newsletters and other promotional communications, including information about MyFitnessPal's new offerings, features, offers, events, webinars, and other information.

Lyft Medium

We may infer certain information from your interactions with the Lyft Platform and other personal information available to us. For example, if you frequently ride to or from airports, we may infer you are a frequent traveler.

See all platforms with this clause type →

Monitoring

Anthropic has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Anthropic → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
This Privacy Policy does not apply where Anthropic acts as a data processor and processes personal data on behalf of commercial customers using Anthropic's Commercial Services – for example, your employer has provisioned you a Claude for Work account, or you're using an app that is powered on the back-end with Claude. In those cases, the commercial customer is the controller, and you can review their policies for more information about how they handle your personal data.

Excerpt from Anthropic's Privacy Policy (Superseded Capture)

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY FRAMEWORK: The controller/processor distinction is defined under GDPR Art. 4(7)-(8) and operationalized through Art. 28 (data processing agreements). CCPA §1798.140(ag) similarly distinguishes service providers from businesses. This exclusion means that commercial customers deploying Claude have independent data controller obligations under GDPR Art. 13/14 (transparency), Art. 28 (processor contracts), and Art. 32 (security). Failure to execute a compliant DPA with Anthropic before deploying Claude constitutes a standalone GDPR Art. 28 violation. 2.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority over deceptive practices where consumers may be misled about which entity is responsible for their data when using AI services through third-party deployments.
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
UK GDPR
United Kingdom

Provision details

Document information
Document
Anthropic Privacy Policy (Superseded Capture)
Entity
Anthropic
Document last updated
May 5, 2026
Tracking information
First tracked
March 6, 2026
Last verified
April 28, 2026
Record ID
CA-P-003863
Document ID
CA-D-00012
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
55f589f5c2a5a187a9d045dc6c7e4954a2dbf9ac00fb6e3ea782dbcf9ad69387
Analysis generated
March 6, 2026 20:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Anthropic
Document: Anthropic Privacy Policy (Superseded Capture)
Record ID: CA-P-003863
Captured: 2026-03-06 20:00:36 UTC
SHA-256: 55f589f5c2a5a187…
URL: https://conductatlas.com/platform/anthropic/anthropic-privacy-policy-superseded-capture/provision/CA-P-003863/controllerprocessor-scope-exclusion/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Anthropic's Controller/Processor Scope Exclusion clause do?

This scope exclusion clarifies the division of data governance responsibility between Anthropic and its commercial customers. When Anthropic processes data as a processor rather than a controller, the commercial customer's privacy obligations and disclosures apply, which affects which entity's privacy terms users should consult for data handling practices.

How does this clause affect you?

If you access Claude via an employer account, a third-party app, or any API-powered product, Anthropic's privacy rights and protections described in this policy — including deletion rights, opt-out of training, and data access — do not apply to your data; you must look to your employer or the third-party operator for those protections.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 284 platforms. See the full comparison.

Is ConductAtlas affiliated with Anthropic?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.