{"id":1418,"date":"2026-06-10T21:46:19","date_gmt":"2026-06-10T19:46:19","guid":{"rendered":"https:\/\/pletzenauer.com\/2026\/06\/10\/claude-desktop-gdpr-compliance\/"},"modified":"2026-06-10T21:46:19","modified_gmt":"2026-06-10T19:46:19","slug":"claude-desktop-gdpr-compliance","status":"publish","type":"post","link":"https:\/\/pletzenauer.com\/en\/2026\/06\/10\/claude-desktop-gdpr-compliance\/","title":{"rendered":"Claude Desktop in the enterprise: data protection and GDPR in practice"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The most common question in consulting conversations is not which features Claude Desktop has \u2013 it is where the data ends up. A fair question. I always answer it with a counter-question: which data is going in at all?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The data flows behind every request<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Inputs leave the device over a TLS connection to api.anthropic.com. The default region is the USA. With AWS Bedrock the path can be redirected to an EU region \u2013 for many companies that is the decisive step.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The model reads the input, produces the answer, and then forgets the session context. What remains depends on the plan and on enabled features such as knowledge bases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic stores log files for a limited time, primarily for abuse prevention. In the enterprise plan this retention can be restricted further.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The levers I recommend<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Choose the plan.<\/strong> Pro, Team, and Enterprise accounts do not train on inputs by default. Anyone who wants to rule this out chooses a paid plan and checks the workspace settings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Clarify data residency.<\/strong> Anyone processing content with personal data should seriously evaluate AWS Bedrock. The EU regions cover most compliance requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sign a data processing agreement.<\/strong> As soon as personal data is processed, a DPA is mandatory. Anthropic offers one for Team and Enterprise plans. With Bedrock, the AWS DPA is added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Introduce a usage policy.<\/strong> A short written rule on which data may go into the app and which may not. It replaces ten discussions per quarter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What local storage means<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Skills, knowledge bases, and caches live in the app&#8217;s configuration path. There they belong in the backup plan \u2013 and in the deletion plan as soon as people leave. This is regularly overlooked.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data flows, data residency, bring-your-own-key: what I always clarify first in consulting projects before Claude Desktop is rolled out in a company.<\/p>\n","protected":false},"author":1,"featured_media":1467,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[],"class_list":["post-1418","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-automatisierung"],"_links":{"self":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/posts\/1418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/comments?post=1418"}],"version-history":[{"count":0,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/posts\/1418\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/media\/1467"}],"wp:attachment":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/media?parent=1418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/categories?post=1418"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/tags?post=1418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}