Provision record
Anthropic · Anthropic Privacy Policy (Superseded Capture) · View original document ↗

Cross-Border Data Transfer Mechanisms

Medium severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Anthropic and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy states that EEA and UK personal data transferred outside those regions is covered by either European Commission adequacy decisions under Article 45 GDPR or Standard Contractual Clauses under Article 46 GDPR, with equivalent mechanisms for UK and Switzerland transfers, and that Brazil transfers rely on ANPD-approved SCCs.

This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the legal transfer mechanisms supporting Anthropic's global data flows for EEA, UK, Swiss, and Brazilian personal data, and specifies reliance on GDPR Articles 45 and 46 mechanisms. Compliance teams should verify that SCCs are executed with all relevant processors and that the subprocessor list referenced in the Trust Center is current.

Clause Stability Stable

0
Changes
6
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, personal data from EEA, UK, and Swiss users is transferred to the US and other countries under Standard Contractual Clauses or adequacy decisions; Brazilian users' data is transferred under ANPD-approved SCCs; Canadian users are disclosed that data may be transferred to jurisdictions with less stringent data protection laws.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EEA, UK, and Swiss users may submit data subject rights requests, including objection to international transfers, by contacting privacy@anthropic.com or the Data Protection Officer at dpo@anthropic.com.

Cross-platform context

See how other platforms handle Cross-Border Data Transfer Mechanisms and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Where Anthropic transfers information outside the EEA or the UK, we ensure it benefits from an adequate level of data protection by relying on: Adequacy decisions: These are decisions from the European Commission under Article 45 GDPR (or equivalent decisions under other laws) where they recognize that a country outside of the EEA offers an adequate level of data protection. We transfer your information as described in 'Collection of Personal Data' to some countries with adequacy decisions, such as the countries with EU adequacy decisions listed here and countries with UK adequacy decisions listed here; or Standard contractual clauses: The European Commission has approved contractual clauses under Article 46 GDPR that allows companies in the EEA to transfer data outside the EEA. These (and their approved equivalent for the UK and Switzerland) are called standard contractual clauses. We rely on standard contractual clauses to transfer information as described in 'Collection of Personal Data' to certain affiliates and third parties in countries without an adequacy decision.

Excerpt from Anthropic's Privacy Policy (Superseded Capture)

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Articles 45 and 46, UK GDPR equivalent provisions, Swiss Federal Act on Data Protection transfer requirements, and Brazil's LGPD international transfer framework as administered by the ANPD.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
Anthropic Privacy Policy (Superseded Capture)
Entity
Anthropic
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016556
Document ID
CA-D-00012
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e91b78d120f18b8a635385fb036a9ad6b0135fe530a2e4aadcc4d575da32fca0
Analysis generated
July 9, 2026 17:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Anthropic
Document: Anthropic Privacy Policy (Superseded Capture)
Record ID: CA-P-016556
Captured: 2026-07-09 17:12:50 UTC
SHA-256: e91b78d120f18b8a…
URL: https://conductatlas.com/platform/anthropic/anthropic-privacy-policy-superseded-capture/provision/CA-P-016556/cross-border-data-transfer-mechanisms/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Anthropic's Cross-Border Data Transfer Mechanisms clause do?

This provision establishes the legal transfer mechanisms supporting Anthropic's global data flows for EEA, UK, Swiss, and Brazilian personal data, and specifies reliance on GDPR Articles 45 and 46 mechanisms. Compliance teams should verify that SCCs are executed with all relevant processors and that the subprocessor list referenced in the Trust Center is current.

How does this clause affect you?

Under this clause, personal data from EEA, UK, and Swiss users is transferred to the US and other countries under Standard Contractual Clauses or adequacy decisions; Brazilian users' data is transferred under ANPD-approved SCCs; Canadian users are disclosed that data may be transferred to jurisdictions with less stringent data protection laws.

Is ConductAtlas affiliated with Anthropic?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.