Anthropic · Anthropic Privacy Policy · View original document ↗

Controller/Processor Scope Exclusion

High severity Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Anthropic recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Anthropic Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you use Claude through your employer or through a third-party app that runs on Claude's technology, this privacy policy does not protect you — your employer or that app's company is responsible for your data privacy, not Anthropic.

This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This scope exclusion clarifies the division of data governance responsibility between Anthropic and its commercial customers. When Anthropic processes data as a processor rather than a controller, the commercial customer's privacy obligations and disclosures apply, which affects which entity's privacy terms users should consult for data handling practices.

Clause Stability Stable

0
Changes
3
Months Monitored
Apr 28, 2026
First Seen
Apr 28, 2026
Last Seen
This clause type exists across 381 other provisions on other platforms.

Consumer impact (what this means for users)

If you access Claude via an employer account, a third-party app, or any API-powered product, Anthropic's privacy rights and protections described in this policy — including deletion rights, opt-out of training, and data access — do not apply to your data; you must look to your employer or the third-party operator for those protections.

How other platforms handle this

Amplitude Medium

Amplitude acts as a data controller when we collect and use Personal Information for our own purposes, such as providing and improving our Services, marketing, and other business operations. When Amplitude processes Personal Information on behalf of our customers (for example, event data that our cu...

Redfin Medium

We may record any telephone calls between you and our agents or other representatives for training and quality assurance purposes.

Grubhub Medium

When you use the Platform, we collect internet usage information about you, such as information about your browsing behavior, search history on the Platform, and information about your interactions with the Platform and our advertisements, including advertisement impressions and whether you clicked ...

See all platforms with this clause type →

Monitoring

Anthropic has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
This Privacy Policy does not apply where Anthropic acts as a data processor and processes personal data on behalf of commercial customers using Anthropic's Commercial Services – for example, your employer has provisioned you a Claude for Work account, or you're using an app that is powered on the back-end with Claude. In those cases, the commercial customer is the controller, and you can review their policies for more information about how they handle your personal data.

— Excerpt from Anthropic's Anthropic Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY FRAMEWORK: The controller/processor distinction is defined under GDPR Art. 4(7)-(8) and operationalized through Art. 28 (data processing agreements). CCPA §1798.140(ag) similarly distinguishes service providers from businesses. This exclusion means that commercial customers deploying Claude have independent data controller obligations under GDPR Art. 13/14 (transparency), Art. 28 (processor contracts), and Art. 32 (security). Failure to execute a compliant DPA with Anthropic before deploying Claude constitutes a standalone GDPR Art. 28 violation. 2.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over deceptive practices where consumers may be misled about which entity is responsible for their data when using AI services through third-party deployments.
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
UK GDPR
United Kingdom

Provision details

Document information
Document
Anthropic Privacy Policy
Entity
Anthropic
Document last updated
May 5, 2026
Tracking information
First tracked
March 6, 2026
Last verified
April 28, 2026
Record ID
CA-P-003863
Document ID
CA-D-00012
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
55f589f5c2a5a187a9d045dc6c7e4954a2dbf9ac00fb6e3ea782dbcf9ad69387
Analysis generated
March 6, 2026 20:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Anthropic
Document: Anthropic Privacy Policy
Record ID: CA-P-003863
Captured: 2026-03-06 20:00:36 UTC
SHA-256: 55f589f5c2a5a187…
URL: https://conductatlas.com/platform/anthropic/anthropic-privacy-policy/controllerprocessor-scope-exclusion/
Accessed: June 15, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Anthropic's Controller/Processor Scope Exclusion clause do?

This scope exclusion clarifies the division of data governance responsibility between Anthropic and its commercial customers. When Anthropic processes data as a processor rather than a controller, the commercial customer's privacy obligations and disclosures apply, which affects which entity's privacy terms users should consult for data handling practices.

How does this clause affect you?

If you access Claude via an employer account, a third-party app, or any API-powered product, Anthropic's privacy rights and protections described in this policy — including deletion rights, opt-out of training, and data access — do not apply to your data; you must look to your employer or the third-party operator for those protections.

Is ConductAtlas affiliated with Anthropic?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.