Zero data retention
What zero data retention covers for Claude Code on Claude for Enterprise, what it does not, which features switch off, and how to get it enabled.
Zero data retention (ZDR) means Anthropic processes your Claude Code prompts and responses in real time and does not store them once the response has been returned, apart from where the law or misuse prevention requires it. For Claude Code it is available to qualifying organisations on Claude for Enterprise.
Note: ZDR is not part of the standard Enterprise plan and there is no toggle for it in admin settings. Anthropic enables it separately after confirming eligibility. Talk to Anthropic sales or your account team.
Where ZDR fits
With ZDR on Claude for Enterprise you get zero retention for Claude Code inference while keeping the enterprise admin tooling:
- per-user cost controls;
- the analytics dashboard;
- server-managed settings;
- audit logs.
It applies only to Anthropic's own platform. If you run Claude through Amazon Bedrock, Google Cloud's Agent Platform or Microsoft Foundry, those platforms' retention policies apply instead.
ZDR and HIPAA
ZDR used to be the only way to bring Claude Code under a Business Associate Agreement. Enterprise organisations that have enabled HIPAA can now cover the Claude Code CLI and the Code tab in Claude Desktop under their BAA without ZDR, once the HIPAA configuration is applied to Claude Code (local mode) and Cowork (local mode). See HIPAA setup. Without the HIPAA configuration, ZDR is still required for BAA coverage of Claude Code.
Scope
ZDR covers Claude Code model inference on Claude for Enterprise: the prompts you send from the terminal and the responses Claude generates are not retained. That holds for every model your ZDR organisation can use, though some models require retention by default (see model availability).
Warning: ZDR is switched on per organisation. A new organisation under the same account does not inherit it; ask your account team to enable each one.
Make sure traffic actually lands in the ZDR organisation
Only requests that authenticate into the ZDR-enabled organisation are covered. A developer signed in with a personal account, or using an API key from another organisation, is outside it. Deploy the forceLoginMethod and forceLoginOrgUUID managed settings so claude.ai logins must belong to your organisation. Authentication explains how those keys treat Claude Console logins too.
{
"forceLoginMethod": "claudeai",
"forceLoginOrgUUID": "4b8e2f10-0c7d-4a51-9e3a-2f6d81c0b9aa"
}
(Use your own organisation ID; the one above is made up.)
What ZDR does not cover
These follow standard retention even in a ZDR organisation:
- Chat on claude.ai. Conversations in the Enterprise web interface.
- Cowork sessions.
- Claude Code analytics. No prompts or responses are stored, but productivity metadata such as account emails and usage statistics is collected. Contribution metrics are unavailable for ZDR organisations, so the dashboard shows usage only.
- User and seat management. Emails, seat assignments and similar admin data.
- Third-party integrations. Anything handled by MCP servers or other external tools. Review their data handling yourself.
Features switched off under ZDR
Features that need to store prompts or completions are blocked at the backend:
| Feature | Why it needs storage |
|---|---|
| Cloud sessions, including those started from the desktop app | Session history, prompts and completions live server-side |
| Claude Tag | Keeps channel memory and transcripts |
| Artifacts | Published page content is hosted by Anthropic |
/feedback, /bug, /share | They send conversation data to Anthropic |
| Remote Control | Transcripts are stored to sync devices |
The block is server-side, whatever the client displays. If one of these shows as disabled at startup, trying it returns an error saying your organisation's policies do not allow it. New features that need storage may be disabled in future too.
Model availability
Claude Fable 5.1 and Fable 5 are Covered Models that require data retention by default, so whether a ZDR organisation or workspace can use them is set by the Covered Models policies, not by Claude Code. Where you cannot, they are missing from /model or shown disabled, and the server refuses requests for them regardless of client configuration. Every other model stays available. Fable is not the default, and the best alias (which normally resolves to the latest Fable) resolves to Opus in organisations without Fable access. See Model configuration.
Retention for policy violations
Even under ZDR, Anthropic can retain data when the law requires it or to deal with Usage Policy violations. If a session is flagged, its inputs and outputs may be kept for up to two years, in line with Anthropic's standard ZDR policy.
Getting ZDR
Ask Anthropic sales or your account team. They raise the request internally, Anthropic checks eligibility and enables it on your organisation, and every enablement is audit-logged.
Already using ZDR for Claude Code through pay-as-you-go API keys? You can move to Claude for Enterprise to pick up the admin features while keeping ZDR; your account team will coordinate the migration.