Home / Personal data, the mandatory caution
What the organisation account guarantees, and what it does not guarantee
On an organisation account, Anthropic does not train its models on conversations, but the organisation remains solely responsible for the processing of the data it passes through it.
An Anthropic organisation account and an individual Pro or Max account open onto the same Claude interface, but they do not follow the same rules for the conversations that pass through them. Confusing the two amounts to lending an individual account a guarantee that only applies to the organisation account.
What the organisation account guarantees
On an organisation account, Anthropic declares itself a processor within the meaning of the European data protection regulation, with the client organisation remaining the controller; the data processing agreement, standard contractual clauses included, is built into the commercial terms with no separate signature, and the content of conversations is not used to train the models, unless the organisation itself chooses to join Anthropic's development partnership programme. This condition appears in the very sentence you will read at the source: quote the guarantee without it, and the third party who opens the address will see it. Recorded on 2 September 2026, addresses at the end of this lesson. This is a real guarantee, but it answers only one question, that of training. It changes nothing about what the organisation already is: the sole controller of the processing. The record of processing activities, the legal basis invoked, the impact assessment when required, and the data protection officer remain on the organisation's side. No setting in the tool replaces them.
What an individual account does not guarantee
An individual Pro or Max account follows different terms. A setting that allows conversations to improve the models exists there, and it is up to the person signed in to turn it off if they do not want their exchanges to contribute to it. The refusal itself carries an exception written into the privacy policy: a conversation flagged for a safety review, or flagged by a user, can be used for training despite the refusal. The exchanges concerned are then kept for up to two years, and the classification scores for up to seven years. No public text says what triggers this flagging, so it cannot be anticipated. Processing a sensitive document on this type of account, thinking it benefits from the same guarantees as an organisation account, therefore exposes you to a risk the organisation account does not pose in the same way. The length of time conversations are kept also differs from one account to another, and it cannot be summed up here in a single figure: it depends on the terms specific to each account and is checked directly in the open settings, or in writing with Anthropic for an organisation account.
A visual cue is not enough to settle the matter: a layout can change without warning, and getting this wrong costs on a sensitive file. The only test that holds is a written one.
Question à poser à la personne qui administre vos comptes :
« Sur quel contrat mon compte Claude est-il ouvert, un contrat d'organisation
signé par la structure, ou un abonnement personnel ? »
À conserver : la réponse par écrit, avec sa date.
The sorting of sensitive information seen in the previous lesson remains necessary even on an organisation account: the guarantee on model training exempts you from none of the questions covered in that lesson, nor from checking, before opening a sensitive file, which account the session is actually open on.
Organisation account versus individual account, three questions
| Account | Anthropic's status | Model training on conversations | Data retention period |
|---|---|---|---|
| Organisation account | Processor within the meaning of the European regulation, commitment built into the commercial terms | Not used to train the models, unless the organisation voluntarily joins the development partnership programme | Not detailed in the sources available for this lesson, to be confirmed in writing with Anthropic |
| Individual account (Pro or Max) | Consumer terms, not the same contractual commitments as an organisation account | A model-improvement setting exists; even when refused, a conversation flagged for a safety review is used for training anyway | Up to two years for flagged exchanges, seven years for classification scores |
A user opens a Claude session from his personal computer to process a file containing health information. At the top of the screen, the logo is followed by his own name. His access was set up last year by someone else, and he hesitates between two answers when asked which contract his account is opened under.
Write in one sentence what this situation establishes, and in one sentence what it does not establish.
What this establishes: It establishes that this user does not know which contract his account is opened under, and that what he reads at the top of the screen does not tell him.
What this does not establish: It does not establish that the account is personal rather than tied to an organisation, nor what would happen to the health file in either case.
The three most common miscalibrations
- Too broad A paid Pro subscription automatically offers the same contractual guarantees as an organisation account.
- Too narrow This situation only concerns the name displayed at the top of the screen, nothing else distinguishes the two account types.
- Beside the point It establishes that the health file being processed was less sensitive than those usually handled in this organisation.
- On an organisation account, the commitment not to train the models is contractual, and it falls away if the organisation itself joins Anthropic's development partnership programme.
- The guarantee on training never turns Anthropic into the controller of the processing, that role and its obligations remain entirely on the organisation's side.
- On an individual account, refusing to let conversations be used for training still leaves a written exception standing: a conversation flagged for a safety review is used anyway.
- How long data is kept differs by account type and is checked in the settings or in writing, it cannot be inferred from processor status alone.
- Knowing which contract an account is opened under must be asked in writing of whoever administers the accounts, a visual cue on screen proves nothing.
Ask, in writing, whoever administers your accounts which contract your Claude account is opened under, and keep the dated reply before having a sensitive file processed on it.
These points depend on an interface or a rule that may have changed since this was written. Check them on your own screen before relying on them.
- The exact retention period for data, on the organisation account side as well as the individual account side, is not established by the sources available for this lesson and is checked in the account settings or in writing with Anthropic.
- The list of Anthropic's downstream subprocessors, and the exact fate of data after a deletion request, are not documented in the sources available for this lesson.
- The precise terms of the processing agreement, beyond the principle of a contractual commitment built into the commercial terms, remain to be confirmed by the organisation's data protection officer.
Every datable claim in this lesson links here to the public text behind it. A source that does not open proves nothing.
- Anthropic, processor or controller status depending on the account type consultée le 2026-09-02
- Anthropic, the data processing agreement and its standard contractual clauses, built into the commercial terms consultée le 2026-09-02
- Anthropic, privacy policy, exception to the training refusal for flagged conversations consultée le 2026-09-02
- Anthropic, data retention periods consultée le 2026-09-02