Pick up to 4 tools and see their data-handling and certification positions side by side.
Choose vendors (2 of 4)
| Dimension | ChatGPT (OpenAI) | Claude (Anthropic) |
|---|---|---|
Overall risk posture Aegis Firma’s summary read of the vendor’s published position for regulated business use. | Medium risk | Low risk |
DPA available A Data Processing Addendum is a precondition for lawful processing of personal data under GDPR. Without one, the deployment is hard to defend at all. | Yes | Yes |
Trains on your data Whether your inputs feed model training. "No" is the posture you want — training on customer data creates a disclosure and purpose-limitation problem under GDPR. | No | No |
Data retention How long inputs are held. Shorter is better for data-minimisation; zero-retention modes are the strongest position. | 30 days | 30 days |
SOC 2 (vendor-published) The vendor states it holds SOC 2. Aegis Firma has NOT read any SOC 2 report — they are issued under NDA and cannot be verified by an outsider. Request it from the vendor. | Vendor states yes | Vendor states yes |
GDPR posture Whether the vendor publishes a GDPR-aligned processing position (DPA, SCCs, transfer mechanism). | Documented | Documented |
EU data residency Whether data can be kept in the EU. Absence is not fatal — SCCs can cover transfers — but residency materially simplifies the transfer analysis. | Not by default | Not by default |
EU AI Act tier The vendor’s own model tier. Your obligations depend on YOUR use of the tool, not only on the model’s tier — a minimal-risk model used for hiring still puts you in Annex III. | GPAI — Standard (not systemic risk) | GPAI — Standard (not systemic risk) |
Your obligations follow how YOU use the tool, not the vendor’s model tier.
| Use case | ChatGPT (OpenAI) | Claude (Anthropic) |
|---|---|---|
| Customer support (no PII) | ||
| Content generation | ||
| Internal productivity | ||
| Medical / legal advice | ||
| HR decisions (hiring, firing) | ||
| Processing sensitive personal data |
Positions as of April 2026
Acceptable for most business use cases with a signed DPA. Not suitable for sensitive personal data of EU residents without additional safeguards. Enable zero data retention API mode for maximum privacy.
Full risk breakdown →Positions as of April 2026
One of the better privacy postures among major AI vendors. DPA available. Best for organizations prioritizing privacy and safety alignment. Enable zero retention API flag for sensitive use cases.
Full risk breakdown →Where this comes from · positions as of April 2026
Vendor-published trust documentation (each vendor's own trust centre, security page, DPA and EU AI Act statements), compiled by Aegis Firma. Aegis Firma has not audited these vendors and has not reviewed their SOC 2 reports — those are issued under NDA and must be requested from the vendor directly.
Aegis Firma tracks which of your AI tools touch regulated decisions, and generates the assessments and disclosures each one needs.
Start free