Option A combines the contractual, technical, and operational measures relevant to a defensible GDPR posture. For commercial services, the Data Processing Addendum defines processor obligations and incorporates safeguards such as Standard Contractual Clauses where applicable. Anthropic states that its DPA is incorporated into its Commercial Terms, while the customer remains responsible for determining lawful purposes, issuing processing instructions, and fulfilling controller obligations.
A defined retention configuration ensures personal data is not retained indefinitely without a documented purpose. Redacting personal information that is unnecessary for the task implements data minimization and reduces exposure in prompts, logs, retrieval stores, and model outputs. Documented data-subject-rights procedures support access, correction, deletion, restriction, and other applicable requests by ensuring the organization can locate and act on relevant records.
Enterprise deployment alone does not establish compliance; the organization must configure and govern the service consistently with its processing activities, risk assessment, lawful basis, and contractual commitments. Options B, C, and D intentionally remove those controls or promote excessive collection.
Study Guide references/topics: [Anthropic Data Processing Addendum guidance](https://privacy.anthropic.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa); [commercial data-retention practices] (https://privacy.anthropic.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data); GDPR data minimization; retention governance; data-subject-rights procedures.
===============