Claude for Enterprise is Anthropic's commercial tier of Claude, launched in September 2024 and expanded through 2025 and 2026. The product ships with SOC 2 Type II, ISO 27001:2022, ISO/IEC 42001:2023, a HIPAA-ready configuration, no training on customer data by default, a Data Processing Addendum with Standard Contractual Clauses that is part of the commercial terms, SSO, SCIM, role-based permissions, audit logs and a Compliance API.

What it does not ship with is EU data residency. An earlier version of this review said otherwise, and that was wrong. Anthropic's privacy centre states that customer data is stored in the US and that traffic may be routed to the US, Europe, Asia or Australia unless agreed otherwise; the only geographic control is US-only inference. The platform documentation is equally clear: the inference_geo parameter accepts global or us, and us is the only workspace geography. If you need Claude to run inside the EU, the route is AWS Bedrock or Google Cloud regional endpoints, where the hyperscaler is the data processor. The EU data residency section below walks through every option.

Anthropic still publishes more on training and safety than OpenAI: the Acceptable Use Policy, model cards with documented limitations, and an ISO 42001 AI management system certification that few vendors hold. None of that is sovereignty, but all of it helps when your DPO is building a Transfer Impact Assessment.

This review is for the AI governance owner choosing between Claude for Enterprise, Claude via an EU hyperscaler, and EU-headquartered alternatives. For the broader comparison, see our EU enterprise AI matrix. For the ChatGPT Enterprise counterpart, see the ChatGPT Enterprise EU review.

US onlyWorkspace storage geography available on Claude Enterprise and the API in 2026; there is no EU option
FRA · IRL · PAR · STOAWS Bedrock EU regions that run Claude in-region, plus an EU cross-region inference profile; Google Cloud adds an EU multi-region endpoint (GA May 2026)
ISO 42001SOC 2 Type II, ISO 27001:2022 and ISO/IEC 42001:2023 AI management certification, HIPAA-ready configuration
USAnthropic is US-incorporated (Delaware); Schrems II analysis still applies

What Claude for Enterprise Delivers

At the platform layer Claude for Enterprise is comparable to ChatGPT Enterprise in feature breadth, with two EU-relevant strengths and two structural weaknesses.

Strength 1: Contract and certification depth. The Data Processing Addendum with EU Standard Contractual Clauses is incorporated into the commercial terms automatically, so there is no separate paper to negotiate. No training on customer data is the default for every commercial product. Anthropic holds SOC 2 Type II, ISO 27001:2022 and ISO/IEC 42001:2023, the AI management system standard that auditors increasingly ask for under the AI Act.

Strength 2: Documentation that feeds Annex IV. Anthropic publishes its constitutional AI methodology, model cards with documented limitations, and the Acceptable Use Policy. Deployers building EU AI Act Annex IV technical documentation can reuse a good part of it. ChatGPT Enterprise's equivalent material is thinner.

Weakness 1: No EU data residency. This is the point the earlier version of this review got wrong. Claude Enterprise and the first-party API offer global or US-only inference and US workspace storage. OpenAI, by contrast, has offered EU data residency for ChatGPT Enterprise and the API since February 2025. If in-region processing is a hard requirement, Claude only meets it via AWS Bedrock or Google Cloud, with a different processor and a different contract.

Weakness 2: Single-vendor lock-in. Claude for Enterprise is Anthropic-only. Multi-LLM platforms route to Claude alongside other providers; Claude for Enterprise itself does not. For buyers with a vendor-independence policy, this is the same gap ChatGPT Enterprise has.

Claude for Enterprise vs ChatGPT Enterprise (EU Lens)

DimensionClaude for EnterpriseChatGPT Enterprise
EU data residency mechanismNone on Claude Enterprise or the API: inference global or US-only, storage US. EU processing only via AWS Bedrock or Google Cloud regional endpointsEU data residency for ChatGPT Enterprise workspaces and API projects since February 2025 (storage at rest in Europe; API in-region with zero retention)
Underlying infrastructureAnthropic-operated, multi-cloud, US storage; or AWS Bedrock / Google Cloud EU regions with the hyperscaler as processorMicrosoft Azure EU regions (Microsoft-managed)
Schrems II exposureUS-incorporated; CLOUD Act + FISA 702 analysis requiredUS-incorporated; CLOUD Act + FISA 702 analysis required
Annex IV technical documentation helpStrong: constitutional AI + model cards + safety docs publishedModerate: model cards exist but less depth on training data
Annex Section 5 training-data lineage disclosurePartial; 'licensed data + Common Crawl filtered + human feedback' is public stancePartial; 'publicly available + licensed + human feedback' is public stance
Multi-LLM (vendor independence)Single-vendor (Anthropic only)Single-vendor (OpenAI only)
Model strengthClaude Opus 5, Sonnet 5 and Fable 5: strongest on long-context reasoning, agentic coding and tool useGPT-5 family: strong on creative work, image generation and breadth of integrations
Constitutional AI transparencyPublicly documented methodology + safety guidelinesLess detailed public methodology
Pricing (typical)$30-50/seat/month enterprise; usage-based API tier$40-60/seat/month enterprise; usage-based API tier

Audit Your Claude Deployment Compliance

Free 8-minute AI governance assessment maps your Claude for Enterprise (or any LLM) deployment against DSGVO, EU AI Act, NIS2, and AIBOM requirements. Structured AI report.

Try It Free

Where Claude for Enterprise Fits Best

Choose Claude for Enterprise when

  • You want a US frontier model but care about Schrems II posture more than feature breadth

  • You need long-context reasoning (200K-1M token windows for legal, research, code review)

  • Your DPIA process benefits from rich Annex IV technical doc starter material

  • You value Anthropic's constitutional AI / safety positioning for board and customer-trust narrative

  • You can accept single-vendor and US-incorporation risk after a documented TIA

  • Your buying pattern is direct enterprise SaaS (not via Microsoft 365 add-on)

Choose an EU-HQ alternative when

  • You need to fully avoid US-incorporated providers (strict residency, public sector)

  • Multi-LLM vendor independence is a strategic procurement priority

  • Your AI deployment is Annex III high-risk HR (need vendor-side conformity assessment)

  • Your Betriebsrat refuses US-vendor Betriebsvereinbarung KI

  • WhatsApp Business API + deskless-worker delivery is a primary use case

  • Microsoft 365 lock-in already drives you toward Copilot for general knowledge work

The Bottom Line

Claude for Enterprise in 2026 is a strong US frontier model with an unusually complete compliance file: SOC 2 Type II, ISO 27001, ISO 42001, a DPA with SCCs baked into the terms, no training by default, and audit tooling that includes a Compliance API. It is not the most EU-friendly US option on data residency, because it has none: OpenAI offers EU residency for ChatGPT Enterprise, Anthropic does not.

It is still US-incorporated. Schrems II analysis still applies, and without EU residency the transfer is the rule rather than the exception. Annex III conformity assessment for HR-AI is still on the deployer. Betriebsvereinbarung KI is still your work in EU subsidiaries. For EU-headquartered companies with strict residency requirements or vendor-independence procurement policies, an EU-hosted multi-LLM platform that can route to Claude on Bedrock or Vertex, alongside Mistral or Aleph Alpha, remains the more defensible choice. Use our EU enterprise AI matrix to map your buyer profile.

The operational reality for most German and Austrian enterprises in 2026: if the model quality of Claude is what you want, run it through an EU hyperscaler region or through an EU-hosted platform that does so for you, and keep the direct Claude Enterprise contract for teams whose data can leave the EU under a documented TIA. Most enterprises end up running both.

Run an AI Readiness Check

Free 8-minute AI readiness assessment maps your current LLM deployment (Claude, ChatGPT, or any) against EU-HQ alternatives and compliance gaps. Structured AI report.

Try It Free

Key Takeaways

1. Claude for Enterprise has no EU data residency in 2026. Inference is global or US-only, workspace storage is US. Anthropic's own docs say so; an earlier version of this review got it wrong.

2. EU processing of Claude exists, through the hyperscalers. AWS Bedrock (Frankfurt, Ireland, Paris, Stockholm) and Google Cloud EU regional or multi-region endpoints run Claude in-region, with AWS or Google as your processor.

3. The compliance file is otherwise strong. SOC 2 Type II, ISO 27001, ISO 42001, DPA with SCCs in the terms, no training by default, SCIM, audit logs, Compliance API, custom retention, optional zero data retention.

4. Schrems II applies in full. US-incorporated, and without EU residency every prompt is a transfer. Document the TIA, or route through an EU region.

5. Most defensible posture for EU-HQ companies: an EU-hosted multi-LLM platform that reaches Claude via Bedrock or Vertex, with EU models next to it. Direct Claude Enterprise for teams whose data may leave the EU.

Anthropic Claude EU Data Residency 2026: Regions and Options That Actually Exist

There are four ways to buy Claude, and they differ more on data location than on anything else. Anthropic's data residency documentation and regional compliance page are the primary sources; everything below is checked against them as of August 2026.

Claude for Enterprise and Claude Team (claude.ai). Conversations, files and projects are stored in the US. Inference is routed globally by default; Enterprise customers on usage-based billing can switch on US-only inference. There is no EU setting.

Claude API (first party). The inference_geo request parameter accepts global or us; US-only inference costs 1.1x list price on Claude 4.6 and later models. Workspace geography, which governs storage at rest and endpoint processing, is us only and cannot be changed after creation.

AWS Bedrock. Claude runs in-region in Ireland, Stockholm, Frankfurt and Paris depending on the model, with an EU cross-region inference profile that keeps routing inside the EU geography. AWS is the data processor, and your existing AWS DPA and BaFin or C5 documentation apply. Anthropic's own retention rules for Covered Models still require 30-day retention, but the retained data stays in your cloud tenant.

Google Cloud (Vertex AI, renamed Gemini Enterprise Agent Platform in April 2026). Regional endpoints such as europe-west3 (Frankfurt) and, since 15 May 2026, an EU multi-region endpoint that fails over only within the EU geography. Google is the processor.

Microsoft Foundry. Claude is generally available on Foundry, but as of August 2026 there is no EU data zone; deployments use global or US Data Zone routing. Anthropic lists Foundry in Europe as coming in 2026 without a date.

RouteInference locationStorage at restData processorEU residency
Claude for Enterprise / Team (claude.ai)Global by default; US-only optional on EnterpriseUSAnthropic No
Claude API (first party)global or us via inference_geo (us = 1.1x price)US (only workspace geo)Anthropic No
AWS Bedrock, EU regionIreland, Stockholm, Frankfurt, Paris; EU cross-region profileYour AWS account, EU regionAWS Yes
Google Cloud, EU endpointRegional (e.g. Frankfurt) or EU multi-region, GA May 2026Your GCP project, EUGoogle Yes
Microsoft FoundryGlobal or US Data Zone; no EU zone as of Aug 2026Azure, non-EU routingAnthropicNot yet (announced for 2026)

Do not confuse US-only inference with EU residency. The US-only switch exists so that US-regulated customers can keep inference out of Anthropic's European and Asian capacity. For an EU controller it does the opposite of what you want: it guarantees the transfer.

1

Pick the hyperscaler you already have a DPA with

AWS Bedrock or Google Cloud. Both already sit in your Verzeichnis von Verarbeitungstätigkeiten; adding Claude is a model addition, not a new vendor onboarding.

2

Lock the region and disable global routing

On Bedrock use an EU regional model ID or the EU cross-region inference profile, never the global one. On Google Cloud call the eu multi-region endpoint or a single EU region such as europe-west3.

3

Point Claude Code and your platform at that endpoint

Claude Code supports Bedrock and Vertex backends via environment variables (CLAUDE_CODE_USE_BEDROCK or CLAUDE_CODE_USE_VERTEX plus the region). A multi-LLM platform such as Teamo does the same routing centrally, so individual teams cannot fall back to the US endpoint.

4

Record the 30-day retention in your own tenant

Anthropic's Covered Models require 30-day retention wherever they are offered; on Bedrock and Google Cloud that data stays in your environment. Write it into the DPIA so the retention is a documented control, not a surprise.

Claude Enterprise vs Team Plan: Pricing and Admin Features in 2026

Anthropic's pricing page lists two business plans. Team is the self-serve tier for 2 to 150 seats: $20 per standard seat per month on annual billing ($25 monthly), with premium seats at $100 ($125 monthly) that carry roughly five times the usage and access to the newest models inside plan limits. Usage is included in the seat price. Team includes Claude Code, Cowork, SSO, central billing and admin control over connectors, and no training on your content by default.

Enterprise is $20 per seat as a base fee, with usage billed separately at API rates. That is the number that surprises finance: a busy team of 50 can spend more on usage than on seats. In exchange you get role-based access with fine-grained permissions, SCIM provisioning, audit logs, the Compliance API for observability, custom data retention controls, network access control and IP allowlisting, US-only inference, and a HIPAA-ready configuration for eligible organisations. Zero data retention is not part of the standard plan; it is enabled per organisation for qualified accounts.

There is no published seat minimum for Enterprise, but it is sold through sales, and the usage-based model means small teams rarely get a quote that beats Team. For an SMB in the DACH region the realistic comparison is Team versus an EU-hosted multi-LLM platform, not Team versus Enterprise.

FeatureClaude TeamClaude EnterpriseTeamo (EU-hosted multi-LLM)
Price per seat$20 to $25 standard, $100 to $125 premium$20 base plus usage at API ratesPer seat, no enterprise seat minimum
Seats2 to 150Sales-led, unlimitedFrom 1
ModelsClaude onlyClaude onlyClaude, OpenAI, Google, Mistral, Aleph Alpha, one-line swap
SSO / SCIMSSO yes, SCIM noBothBoth
Audit logs NoYes, plus Compliance APIThree independent logs, 6-month retention
Data locationUSUS; US-only inference optionalEU-hosted; Claude reached via EU hyperscaler regions
Zero data retention NoBy agreement, qualified accountsPer-tenant retention policy

Claude Code Enterprise Features 2026: Admin Controls Worth Knowing

Claude Code, the terminal and IDE agent, is included in both business plans and is where most of the 2026 admin work landed. Anthropic added user groups with custom roles, per-user and per-organisation spend caps, managed Claude Code policies and a Compliance API for Enterprise in spring 2026. In practice the controls that matter for a European rollout are:

Managed settings. Admins push tool permissions, file-access restrictions and an allowlist of MCP servers to every developer, so a Claude Code session cannot reach a data source the organisation has not approved.

Spend limits per seat. Because Enterprise bills usage at API rates, per-user caps are the only way to keep an agentic coding session from turning into an unbudgeted invoice.

Analytics per user and repository. Usage breaks down by person, group and repository, which is what a Betriebsrat will ask about before it agrees to a Betriebsvereinbarung KI. Note that Anthropic's Compliance API retains an activity feed for six years, and local session transcripts follow the same six-year default unless the organisation sets a shorter retention.

Backend choice. Claude Code can run against Bedrock or Vertex instead of the first-party API, which is how EU teams keep coding sessions in-region. See Claude Code on Team and Enterprise for Anthropic's own summary.

Zero data retention for Claude Code is available on Enterprise for qualified accounts; with metrics logging enabled, productivity statistics are exempt and may still be retained.

Anthropic DPA (AVV), Certifications and the Schrems II Position

Anthropic's Data Processing Addendum, effective 24 February 2025, is incorporated into the Commercial Terms of Service automatically: accepting the terms for the API or Claude Enterprise accepts the DPA, so there is nothing separate to sign, though you should still file a copy. It includes the 2021 EU Standard Contractual Clauses (Module 2 controller-to-processor, Module 3 processor-to-processor), and Anthropic acts as processor for commercial customers. Commercial data is not used for training unless you join the Development Partner Program. The certification list names SOC 2 Type I and II, ISO 27001:2022, ISO/IEC 42001:2023 and a HIPAA-ready configuration with BAA.

Retention defaults, from the API and data retention documentation: API inputs and outputs are deleted within 30 days; conversation content is not retained by default except for Covered Models, which require 30-day retention; content flagged by trust-and-safety systems can be kept up to two years; ZDR and custom retention are available by agreement. In August 2026 Anthropic said it would move that 30-day retained data for its newest models into customer-controlled clouds rather than holding it itself.

The Schrems II position follows from the residency facts. The SCCs are in place and the EU-US Data Privacy Framework exists, but Anthropic is a US company subject to FISA 702 and the CLOUD Act, and without an EU processing option every prompt from Claude Enterprise is a third-country transfer. Your Transfer Impact Assessment has to carry the whole weight. Routing through AWS or Google in an EU region does not remove the US-company question, since both are US-headquartered too, but it does keep processing and storage in the EU and gives you contracts your DPO has already assessed. Our EU AI chat DPA checklist lists the Art. 28 clauses to verify in any of these contracts.

Check whether your Claude setup passes a governance review

Free 8-minute AI governance check: data location, DPA coverage, retention, audit trail and AI Act role, scored against what auditors ask for in 2026.

Start free