BITS Group
Turning off AI training doesn't make your business GDPR compliant

Turning off AI training doesn't make your business GDPR compliant

We're seeing this constantly with clients at the moment. AI tools spread through a business from the bottom up. Someone on the team finds Claude or ChatGPT genuinely useful, upgrades to a personal subscription because it's about £16 to £20 a month on a card, and starts using it for real work. Nobody signed it off. Nobody checked what happens to the data. Most business owners, when we ask, genuinely don't know what their staff are using AI for or what's going into it.

The bit everyone gets wrong: a privacy setting is not a contract

Here's the confusion we keep untangling. Turning off model training and having a data processing agreement (a DPA, the contract UK GDPR requires whenever a third party processes personal data on your behalf) are two completely different things, and a lot of businesses assume the first one covers the second.

Claude Pro, the individual subscription most people sign up for, sits under Anthropic's consumer terms of service. You can switch off the setting that lets Anthropic use your conversations to improve its models, and that's genuinely worth doing. But it doesn't change which set of terms your account runs on. Anthropic's own privacy centre confirms the DPA, bundled with the Standard Contractual Clauses that make international transfers lawful, is "automatically incorporated" into Anthropic's Commercial Terms of Service, and it's the commercial terms, not the consumer ones, that cover Claude for Work, Claude Team, Enterprise, and the API. Claude Pro doesn't get a DPA, however many boxes you tick.

Under UK GDPR, if a processor is handling personal data on your behalf, you're required to have a written contract in place covering exactly this. The ICO is clear that a contract isn't optional here: Article 28(3) makes it a legal requirement, not a nice-to-have, every single time a controller hands personal data to a processor. A training toggle is a privacy setting. A DPA is a contract. You need the contract.

And this isn't a Claude quirk. The same pattern holds wherever your team has quietly drifted. ChatGPT Plus sits under OpenAI's consumer agreement; ChatGPT Team, Enterprise and the API sit under business terms built to bring the DPA with them. If your team is using Gemini or Copilot for work, the same question applies: which set of terms does the account actually run under, not what's ticked in the settings menu. Check the plan, not the toggle, whatever the tool.

For the more technical among you

Article 28(3) of UK GDPR doesn't just require a contract to exist. It specifies what has to be in it: the subject matter, duration, and purpose of the processing; an obligation on the processor to only act on your documented instructions; confidentiality commitments covering anyone who touches the data; appropriate technical and organisational security measures; conditions for engaging sub-processors (and a duty to tell you who they are); assistance with data subject rights requests and breach notifications; deletion or return of the data at the end of the engagement; and audit rights so you can actually check compliance rather than take it on trust.

None of that is covered by a model-training toggle. Turning training off tells you one thing only: whether your inputs get used to further train the model. It says nothing about retention periods, who the sub-processors are, what happens to the data on contract termination, or whether you have any audit rights at all. If you're running Claude through the API rather than the chat interface, it's also worth knowing that Anthropic offers separate, more granular retention controls there, including zero data retention arrangements for qualifying use cases, which is a genuinely different lever to the consumer-facing toggle and worth raising directly with Anthropic or your provider if your workflow needs it.

What Claude Team actually buys you

Claude Team closes the gap, because it runs under the commercial terms, the DPA and SCCs come with it automatically. You also get admin controls that Pro simply doesn't have: single sign-on, domain capture so you can see every account using your company email, role-based permissions, and spend controls at both organisation and user level. It's the difference between hoping everyone's being sensible and actually being able to prove it.

It's more accessible than most business owners expect, too. Anthropic's Team plan runs for teams of two to 150 seats, with standard seats from $20 a month on annual billing (Anthropic prices in dollars, so the sterling cost moves a little with the exchange rate, but it's roughly £16 to £20 depending on your bank's rate on the day). For a two or three person business, let alone a ten person one, that's a small line item for a real compliance improvement, not an enterprise-only cost.

What to actually check this week

If you want to pressure-test where you stand, this is worth ten minutes with a coffee.

  1. Ask your team, honestly, which AI tools they're using and whether it's a personal or company account.

  2. Check whether anyone's on a personal-tier plan like Claude Pro or ChatGPT Plus for work, rather than a business-tier plan with a DPA behind it.

  3. Look at what's actually going into those tools. Client names, contracts, financials, and HR records shouldn't be going anywhere without a contract covering the processing.

  4. Confirm whether your team has had any training on what's safe to put into an AI tool and what isn't.

  5. Decide whether you need a written AI usage policy, not just a verbal "use your judgement."

Most businesses fail on the first question already, simply because nobody's asked it before.

If you want a straight answer

We can run a report that shows you exactly what AI tools your team is using and flags anywhere personal or sensitive data might be going somewhere it shouldn't, so you're working from facts rather than assumptions. Beyond that, get in touch if you want help moving your team onto a business-tier plan, drafting an AI usage policy, or training staff on what's safe to share. It's a much easier conversation to have before something's gone wrong than after.


Further reading

Need IT Support?

Contact us today for a free consultation and discover how we can help your business.

Get Started Today