Skip to main content

Claude Code and GDPR: Privacy Setup for Client Projects

Claude Code and GDPR for client projects. Check contracts, telemetry, file permissions, EU processing, and Remote Control before sharing code.

FHFinn Hillebrandt
AI Programming
Claude Code and GDPR: Privacy Setup for Client Projects
Links marked with * are affiliate links. If a purchase is made through such links, we receive a commission.

You’re ready to give Claude Code a client repository.

Then you notice customer names in fixtures and production credentials nearby. The agent needs enough context to fix your code. You need to know which context it can actually collect and transmit.

Claude Code and GDPR require several separate decisions for client work. I’ll walk you through the contract, optional transmissions, file permissions, and model route. You’ll finish with a test plan using fictional data.

If you’re still learning the tool, start with my Claude Code guide. This setup focuses on confidential projects and personal data.

TL;DRKey Takeaways
  • Choose an appropriate commercial route and DPA. Training, retention, and regional processing require separate checks.
  • Disable optional transmissions and constrain both Read and sandboxed Bash. Hooks and MCP servers need their own controls.
  • Test with fictional data. Remote Control, cloud features, and alternative providers each require an explicit assessment.

1. Decide which project data the agent may receive

A repository can contain personal data without looking like a customer database. Names appear in comments, support examples, and test output. An agent fixing a failed test may collect these details indirectly.

I’d start with a sanitized working copy containing fictional records. Keep production credentials outside the environment that the agent can access. Remove unnecessary data before deciding which tools to permit.

Separate the following paths when reviewing Anthropic’s data usage documentation. Each needs a different control.

Separate Claude Code data paths. Documentation checked in October 2026.

Data pathModel request
Possible contentPrompt, selected code, tool output
What to checkData scope, provider, and contract
Data pathLocal transcript
Possible contentConversation and tool activity
What to checkDevice access and deletion policy
Data pathFeedback and diagnostics
Possible contentConversation or technical information
What to checkOptional transmission controls
Data pathRemote Control and integrations
Possible contentSynced transcript or tool inputs
What to checkAssessment for each feature

A filesystem permission controls access on your computer. It doesn’t determine what the recipient may do with transmitted data. That question belongs in your contract review.

2. Match the account and DPA to your intended use

A paid subscription doesn’t automatically provide the processing terms your organization needs. Claude Pro and Max follow consumer terms, while commercial products use a different framework.

My Claude Code pricing guide separates the access routes and billing options. Assess the data terms for the route you actually use.

Anthropic doesn’t train on commercial inputs and outputs by default. Review its Data Processing Addendum for your chosen product. A DPA sets out the obligations for processing personal data on your behalf.

The published DPA lists no special categories of personal data in Schedule 1. Don’t treat that scope as approval for these categories. They require an expressly suitable agreement and a legal assessment before sharing.

Record the organization, applicable terms, permitted data, and processing purpose.

A DPA doesn’t supply the lawful basis for your own processing. Document that basis, the applicable information duties, and procedures for access, rectification, and erasure. Assess the risk before processing. A likely high risk generally requires a data protection impact assessment under Article 35 GDPR. The German supervisory authorities’ AI guidance covers these duties.

Include subprocessors and international transfers in that assessment. For agency work, check the client’s own restrictions on subcontracting.

Retention needs a separate decision. Claude Code describes a regular commercial retention period of 30 days. An approved Zero Data Retention agreement has a defined product scope and exceptions.

Don’t extend that commitment to local files or unrelated service providers. Once the contract fits your use, you can reduce optional client transmissions.

3. Turn off optional telemetry and feedback paths

A cloud model needs to process the context you send it. Telemetry, error reporting, and feedback serve additional purposes. Control those separately from the model connection.

For the CLI on macOS or Linux, set these documented environment variables before starting Claude Code. This example applies to the current shell session.

export DISABLE_TELEMETRY=1
export DISABLE_ERROR_REPORTING=1
export DISABLE_FEEDBACK_COMMAND=1
claude

For a lasting policy, put these settings in your approved launch process. Check separately launched applications, which may not inherit that terminal’s environment.

Anthropic says telemetry doesn’t contain prompts or code. Feedback can include conversation content, so confidential sessions need particular care. Turning off these paths doesn’t change the model provider’s retention terms.

The Claude Code commands guide helps you identify additional functions before using them.

The broader CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC setting disables automatic updates and makes Remote Control unavailable by disabling feature-flag fetching. If you choose it, maintain a separate process for security updates.

The WebFetch domain safety check remains active and sends the requested hostname to Anthropic, including when using Bedrock or Vertex. Approve WebFetch only if that path is permitted. Official marketplace auto-install also needs its own switch, CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL=1.

These controls reduce optional transmissions. File access still needs an enforceable boundary of its own.

4. Constrain Read and sandboxed Bash separately

Telling the agent to stay inside a folder doesn’t enforce filesystem isolation. Different tools can reach files through different processes. Apply permissions at the boundary each tool actually uses.

The sandbox documentation covers sandboxed Bash processes. This example provides a starting point for .claude/settings.json in a test project. Merge it into existing settings rather than replacing them blindly.

Start Claude Code from the project root so it loads this project file. Relative sandbox paths anchor at the session’s primary working directory. Check additional directories you grant through controls such as /add-dir.

The sandbox supports macOS, Linux, and WSL2. On native Windows, failIfUnavailable exits at startup. Use WSL2 or a supported container environment there.

{
  "permissions": {
    "blockReadsOutsideWorkingDirectories": true,
    "deny": [
      "Read(./**/.env)",
      "Read(./**/.env.*)"
    ]
  },
  "sandbox": {
    "enabled": true,
    "failIfUnavailable": true,
    "allowUnsandboxedCommands": false,
    "filesystem": {
      "denyRead": ["~/", "./**/.env", "./**/.env.*"],
      "allowRead": ["."]
    }
  }
}

This requires an available sandbox and blocks unsandboxed retries after a sandbox failure. Existing excludedCommands can still run without it. Commands you type yourself at the ! prompt also run outside the sandbox in most sessions and therefore don’t test its enforcement.

The filesystem rules restrict home-directory access while permitting the working directory. The .env patterns cover files through both access paths, including subdirectories.

They don’t protect inherited environment variables. Start Claude Code without production secrets in its environment. sandbox.credentials.envVars with mode ‘deny’ unsets specifically named variables before sandboxed commands. It doesn’t cover every subprocess. Check what those other processes actually inherit separately.

On Linux and WSL2, read patterns expand into existing paths. Don’t introduce secret files during a running session. Restart after changes to those paths and repeat access checks.

Review the tool permissions. Sandbox denyRead rules don’t automatically cover the built-in Read tool.

Also check the security controls for your actual workflow.

A strict policy may block a required development tool. Add the specific path it needs, then repeat the relevant test. Avoid restoring broad home-directory access simply to make the build succeed.

A checked-in project file doesn’t enforce a team policy. Distribute the rules through MDM or server-managed settings. Set enabled and failIfUnavailable to true, and allowUnsandboxedCommands to false. Setting sandbox.filesystem.allowManagedReadPathsOnly to true makes only managed allowRead entries effective. Use sandbox.network.allowManagedDomainsOnly for managed Bash domain lists.

Still review user exceptions such as excludedCommands and installed mods. Unmanaged settings can widen access. To cover all tools and processes, constrain the entire Claude Code process in a suitable container or VM. The model’s processing route still needs its own assessment.

5. Verify the region for the exact provider route

If your project requires European processing, verify an actual provider commitment and technical route. Model inference means the processing that generates an answer from your input.

Anthropic’s direct API residency documentation doesn’t provide a general EU option. A different approved provider route may therefore be necessary.

Amazon Bedrock offers regional endpoints and inference profiles. Availability and routing depend on the exact model and endpoint.

Vertex AI provides another regional route with its own conditions. Verify the particular model access you intend to approve.

Check retention, diagnostics, support access, and fallback behavior alongside inference.

Record the model identifier, endpoint, and permitted routing in the project approval.

EUrouter also documents a Claude Code gateway integration. This adds another provider to assess. Its regional claim doesn’t replace the contract, retention, and downstream model checks.

If you want to use OpenAI models through Codex instead, review the regional options in my Codex privacy guide.

A regional model route won’t automatically cover every optional Claude feature. Remote Control introduces a particularly relevant additional path.

6. Assess Remote Control and integrations individually

Remote Control runs tools on your computer while synchronizing the conversation and tool activity. Its documentation describes this separate service connection.

Local execution can therefore coexist with a synchronized cloud transcript. Don’t rely on a telemetry opt-out to disable this feature. Check its own policy and the broader switch described earlier.

MCP servers also need individual assessment.

MCP connects the agent to additional tools and data sources. A local server uses its own process permissions; a remote server receives tool inputs.

I’d enable only integrations required for the approved project. Record each recipient and the data it can access. The model provider’s DPA doesn’t automatically cover an unrelated database or calendar service.

Claude models inside Cursor involve different product terms. The Cursor privacy guide covers its additional backend and tool paths.

Once those routes are defined, test the complete workflow with harmless content.

7. Test each boundary with fictional data

Create a small project containing fictional records and clearly recognizable test values. Place another harmless test file outside the allowed area. Never use actual credentials to check whether a secret can leak.

Test the same account and launch process that your team will use. Work through these checks separately.

  1. Confirm the account, provider, client version, and loaded settings.
  2. Read an allowed project file and run a harmless test.
  3. Attempt the blocked access through Read and through Bash independently.
  4. Repeat the access check for each approved hook or MCP server.
  5. Review local transcripts and any enabled remote synchronization.

Record the outcome for each tool instead of giving the entire setup one pass label. A successful build doesn’t establish that a different process respects the same boundary.

If an access restriction fails, keep that path disabled. Correct the underlying permissions, then repeat the test before approving client data.

Local transcripts deserve their own device policy. Anthropic describes unencrypted files under ~/.claude/projects, with different cleanup behavior for some desktop sessions. Review device encryption, user access, backups, and deletion.

Your company AI policy can connect these findings to permitted projects and data. Start with one sanitized test repository and approve client code only after the documented checks.

Frequently Asked Questions

Compliance depends on your particular use, data, contracts, provider, and enabled features. A local installation or training opt-out doesn't establish compliance by itself. Assess the processing purpose, appropriate DPA, transfers, retention, and technical access controls together.

Pro and Max follow Anthropic's consumer data terms. Disabling model improvement doesn't replace an appropriate processing contract. For client projects, assess a commercial organization or API route and confirm its contractual scope. Commercial access still doesn't automatically include ZDR or EU processing.

Its filesystem rules constrain sandboxed shell commands. Built-in Read needs separate permissions. Excluded commands, hooks, MCP servers, and plugins can run outside the sandbox. File restrictions also don’t protect inherited environment variables. Test every approved path independently with fictional data.

You shouldn't rely on the telemetry switch to disable Remote Control. Remote Control has a separate transcript synchronization path. Check its own controls or the broader nonessential-traffic setting, which also disables automatic updates and requires a separate patching process.

Bedrock, Vertex AI, and some gateways offer separate regional routes. Verify the specific model, inference location, retention, contract, and fallback behavior. Anthropic's direct API doesn't document a general EU residency option. Regional inference also doesn't cover every optional Claude feature.
FH

Finn Hillebrandt

AI Expert & Blogger

Finn Hillebrandt is the founder of Gradually AI, an SEO and AI expert. He helps online entrepreneurs simplify and automate their processes and marketing with AI. Finn shares his knowledge here on the blog in 50+ articles as well as through the AI Business Club.

Learn more about Finn and the team, follow Finn on LinkedIn, join his Facebook group for ChatGPT, OpenAI & AI Tools or do like 17,500+ others and subscribe to his AI Newsletter with tips, news and offers about AI tools and online business. Also visit his other blog, Blogmojo, which is about WordPress, blogging and SEO.