Anthropic tightens privacy controls with mandatory identity verification
The updated terms introduce stricter age and identity checks for users exercising privacy rights, while clarifying international data transfer protocols across major jurisdictions.
Anthropic has updated its privacy policy, effective July 8, 2026, to introduce mandatory measures for verifying user age and identity. The AI safety and research company states it may now request specific information, such as email addresses or billing details, to confirm a user’s identity when processing requests regarding personal data. This change applies to users of the company’s website, Claude.ai, and other services, though it explicitly excludes children under the age of 18 and business customers governed by separate enterprise agreements.
The updated policy clarifies that when a user or their authorised agent submits a request to exercise privacy rights, Anthropic may require evidence sufficient to confirm identity. For third-party representatives acting on behalf of a data subject, the company requires formal evidence of authorisation. These measures are part of a broader update published on June 8, 2026, designed to align data handling practices with various jurisdictional requirements, including those in the EU, UK, Canada, Brazil, and South Korea.
Response timeframes for privacy requests have also been standardised. Under the EU GDPR or UK GDPR, Anthropic has committed to responding within one calendar month of receiving a verifiable request. The company reserves the right to extend this period by up to two months for complex or high-volume requests. Users retain the right to appeal denied requests by contacting the privacy team directly.
International data transfers remain a central component of the policy. Anthropic confirms that personal data may be transferred to servers in the US or other countries outside the European Economic Area and the UK. For residents of Brazil, the company relies on standard contractual clauses approved by the Brazilian Data Protection Authority for these transfers. In South Korea, Anthropic Korea, Limited, with Patrick Azubike Ekeruo as the representative, has been designated as the domestic representative for data protection purposes.
The policy distinguishes between personal data collected from individual users and data obtained from third-party sources for model training. The latter is governed by a separate Non-User Privacy Policy. Data controllers are identified as Anthropic Ireland, Limited for the European Region and Anthropic PBC for other jurisdictions. The company maintains that it will not discriminate against users for exercising their privacy rights and continues to apply de-identification techniques where appropriate to minimise privacy impact.
