Two-column comparison: what OpenAI and Anthropic documentation says region selection covers and excludes for API data.

Data residency is not data control.

AI Under Your Terms, episode 2. Every claim below traces to OpenAI’s or Anthropic’s own documentation, retrieved 20 August 2026. Recheck date: 20 November 2026, or on any vendor terms update.

Picking a data-residency region feels like the control decision is done. Vendor documentation from OpenAI and Anthropic, reviewed here directly, shows region and routing settings cover a defined slice of data and explicitly exclude other categories. This piece sets out what each vendor’s own pages state, what that leaves open, and a written test for checking the rest before signing anything.

What the two vendors’ pages actually say.

Control area OpenAI (API) Anthropic (API)
Region setting covers Customer content at rest, only where the endpoint needs persistence Traffic routing to selected countries by default
Stored regardless of region System data (account data, metadata, usage data, billing, support requests) may be stored outside the region Data is stored in the US, regardless of routing region
Training use by default API data is not used to train models by default since 1 March 2023, unless opted in Retained data is never used for training without express permission
Default retention Abuse-monitoring logs kept up to 30 days by default Conversation content not retained by default (exception: Covered Models, not enumerated in the source)
Retention floor and exceptions Zero Data Retention excludes customer content from abuse logs Flagged or legally required data may be retained up to 2 years
Key custody Enterprise Key Management with customer-held keys via external KMS; in-region TLS termination available Not stated in the reviewed source
Zero data retention option Available for eligible endpoints Zero data retention and HIPAA-ready arrangements available on the API, per a feature-eligibility table
Processor of record Not addressed in the reviewed source On Amazon Bedrock and Google Cloud, the cloud provider is the data processor
Sources: developers.openai.com, your data guide; privacy.claude.com, server location article; platform.claude.com, API and data retention. All retrieved 20 August 2026.

Does selecting a region mean all my data stays in that region?

On the evidence reviewed, no. For OpenAI, residency stores customer content at rest in the selected region only to the extent the endpoint needs data persistence. The same page states residency does not apply to system data: account data, metadata, and usage data such as billing information and support requests, which may be processed and stored outside the region.

Source: developers.openai.com, your data guide. Retrieved 20 August 2026.

What else does OpenAI’s residency setting exclude?

Beyond system data, OpenAI’s documentation states residency does not apply to transmission or storage caused by an end user’s or customer’s own infrastructure location, to products from parties other than OpenAI, or to any data outside the definition of Customer Content. Each of these is a place where “we chose the EU region” stops being the whole answer.

Source: developers.openai.com, your data guide. Retrieved 20 August 2026.

For Anthropic, is a region setting the same thing as storage location?

Anthropic’s documentation states that by default, customer traffic may be routed to select countries in the US, Europe, Asia and Australia, unless otherwise agreed. It then states that data is stored in the US. Routing and storage are described as separate matters, and that distinction is the core of this episode. The page also notes that data may be processed in Anthropic’s operating countries for safety review, product support and incident response.

Source: privacy.claude.com, where are your servers located. Retrieved 20 August 2026.

Is my content used to train the models?

For OpenAI’s API, data sent is not used to train or improve models by default, as of 1 March 2023, unless you explicitly opt in. For Anthropic, retained data is never used for model training without express permission, and conversation content is not retained by default, with a stated exception for Covered Models that the reviewed source does not enumerate. Training use is a separate lever from residency and needs checking on its own terms.

Sources: developers.openai.com, your data guide; platform.claude.com, API and data retention. Retrieved 20 August 2026.

How long is my data kept?

OpenAI generates abuse-monitoring logs for API usage by default, retained for up to 30 days unless longer retention is legally required; Zero Data Retention, where it applies, excludes customer content from those logs. Anthropic may retain flagged or legally required inputs and outputs for up to two years.

Sources: developers.openai.com, your data guide; platform.claude.com, API and data retention. Retrieved 20 August 2026.

Can I control the encryption keys?

OpenAI offers Enterprise Key Management, which lets customers encrypt content using keys from their own external key management system, alongside in-region TLS termination for regional endpoints. These are controls you ask for; they do not come bundled with a region choice. The Anthropic sources reviewed here do not address key custody, so that is recorded as a known unknown.

Source: developers.openai.com, your data guide. Retrieved 20 August 2026.

Who is responsible for my data on a cloud marketplace version of these models?

For Anthropic’s API on Amazon Bedrock or Google Cloud, the cloud provider is stated to be the data processor, which means the cloud provider’s own retention and compliance controls apply. Which processor is responsible depends on which cloud you run on. The OpenAI sources reviewed here do not address this point for equivalent marketplace deployments.

Source: platform.claude.com, API and data retention. Retrieved 20 August 2026.

What is unconfirmed here.

The reviewed sources do not detail OpenAI’s ChatGPT Enterprise residency coverage as distinct from the API, or OpenAI’s audit-logging capabilities. Anthropic’s full zero-data-retention eligibility table and its Covered Models list are referenced by the vendor without being enumerated in the source reviewed. Exact eligibility, regions, and cost or contract conditions for either vendor’s residency or routing options are not established here. Confirm each in writing before any decision.

The buyer test: six questions, in writing.

Put these to the vendor for the specific plan and endpoint you will use, and keep every written answer on file:

  1. Does region selection cover storage, processing, or both, and what is explicitly excluded (system data, metadata, logs)?
  2. Is my content used to train or improve models by default? How do I opt out?
  3. What is the retention period? Is zero data retention available for these exact endpoints? What is retained regardless (flagged content, legal holds), and for how long?
  4. Can I bring my own encryption keys?
  5. Who are the subprocessors, and in which countries do they operate?
  6. On this cloud, who is the data processor of record, you or the cloud provider?

The principle.

A region tells you where a defined slice of data physically sits. Control is a separate set of questions: training use, retention terms, key custody, subprocessor footprint, and who is accountable as processor. On the evidence from both vendors reviewed, a region setting answers none of those on its own. The longer form of this review, written for buying committees, is in the Agentic AI Procurement Handbook.

Sources.

  • developers.openai.com/api/docs/guides/your-data. Retrieved 20 August 2026.
  • privacy.claude.com, “Where are your servers located? Do you host your models on EU servers?”. Retrieved 20 August 2026.
  • platform.claude.com/docs/en/manage-claude/api-and-data-retention. Retrieved 20 August 2026.

Recheck date: 20 November 2026, or on any vendor terms update.

Josh Olayemi · Founder, Handvantage · September 2026

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *