Data Rules and Acceptable Use
The Google Doc rule
Before putting anything into Claude, ask yourself one question:
"Would I be comfortable putting this in a shared Google Doc that everyone in the company could read?"
If yes, it is fine in Claude. If no, keep it out.
This is not a perfect analogy — Claude Enterprise has stronger isolation than a company-wide Google Doc — but it is the right mental habit. It stops people from overthinking edge cases and produces the right behaviour in almost every situation.
What must never go into Claude
Some categories of data are always prohibited, regardless of which Project you use or how it is configured:
Personal data about individuals
This includes:
- Named employees: salary, performance reviews, disciplinary records, medical information
- Customers: names, addresses, email addresses, financial account details, transaction history
- Any information that identifies a real person and was provided in a context that implies confidentiality
Why: Claude Enterprise processes data on Anthropic's infrastructure. While Enterprise contracts include strong data protections, uploading customer PII creates unnecessary risk and may violate your data protection obligations under GDPR or similar regulations. The risk is not just technical — it is legal.
Credentials and security data
- Passwords, PINs, unlock codes
- API keys, access tokens, private certificates
- SSH private keys or any key material
Why: once in a conversation, these can appear in Claude's output, be copied by mistake, or stored in conversation history. There is no legitimate use case for pasting a password into Claude.
Confidential financial data you have not been cleared to share
- Unpublished quarterly earnings or guidance
- Board-level financial plans before they are approved
- Details of proposed acquisitions, disposals or restructuring
Why: in publicly listed companies, some of this data constitutes material non-public information. Mishandling it can create regulatory exposure, not just internal policy violations. If in doubt, ask Legal before uploading.
Patient or regulated health data
- Any data that is HIPAA-regulated (US) or falls under GDPR special categories (EU)
- Clinical notes, diagnoses, prescription information, mental health records
Why: there are specific legal regimes governing this data that require explicit data processing agreements. Claude Enterprise contracts do not automatically cover these use cases. Contact your DPO if health data is part of your use case.
Pending litigation and regulatory investigation details
- Details of ongoing legal proceedings
- Regulatory investigation correspondence
- Privileged legal advice
Why: these materials are protected by legal privilege. Placing them in a third-party system is the kind of action that could inadvertently waive that privilege. Your legal team will tell you this emphatically if you ask them.
The newspaper test
For any grey area, apply the newspaper test:
"If this ended up on the front page of a newspaper — 'Company feeds [X] to AI system' — would that be a problem?"
If the answer is yes or maybe, do not put it in. This test catches the cases the Google Doc rule misses: technically permissible data that would cause reputational or compliance damage if it became public.
What you can put in (freely)
To balance the restrictions, here is what is clearly fine:
- Internal documents that do not contain personal data: policies, procedures, templates, guidelines
- Your own work product: drafts, notes, presentations, reports that do not contain restricted categories
- Publicly available information: press releases, market research, published data, regulatory guidance
- Anonymised or synthetic data: real scenarios with names/identifiers replaced or removed
- Industry knowledge: product specs, technical documentation, professional knowledge
- Communication drafts: emails, announcements, meeting agendas — as long as they do not embed restricted data
As a manager: your accountability
You are accountable for what your team puts into Claude. "I didn't know they were doing that" is not a sufficient answer to a data protection breach — as a manager you are expected to know how your team is using company tools.
This has three practical implications:
1. Make the rules visible. Do not assume your team has read the acceptable-use policy. In your next team meeting, spend 10 minutes on what goes in and what does not. The categories above are worth naming explicitly.
2. Create a culture of asking. If someone on your team is unsure whether something is appropriate, they should ask — not proceed and hope. Explicitly tell them: "If you are not sure, ask me or post in [feedback channel] before putting it in Claude. No question is too small."
3. Act when you see misuse. If you see a team member paste customer names and account numbers into Claude, or load a board presentation that was sent to them confidentially, you need to address it the same way you would address any data policy violation. It is not a minor procedural slip.
What happens to your data
Enterprise contracts include:
- Data not used for Anthropic model training (opt-out confirmed during setup — see Admin Console → Privacy)
- Data processing agreement with Anthropic as the data processor
- Encryption in transit and at rest
These protections are meaningful. They are not, however, a reason to ignore the categories above — some of those categories carry legal risk independent of what Anthropic does with the data.
Key takeaway
One question decides most cases: would this belong in a shared Google Doc? For the rest, apply the newspaper test. The five prohibited categories — personal data, credentials, uncleared financial data, health data, and privileged legal material — are non-negotiable. Make these rules visible to your team and create a culture where asking is the default when anyone is unsure.
📖 Official Documentation See this in practice in Anthropic's live support docs: