OpenAI, Anthropic and Google all exclude enterprise data from model training by default and offer data processing terms. They differ on certifications, retention controls, sales channels and, for Canadian organizations, where prompts can be processed.
This page covers enterprise contracts, compliance and data privacy. For choosing an assistant for everyday team work (plans, prices, writing and brainstorming), see Claude vs ChatGPT vs Gemini for business.
How do OpenAI, Anthropic and Google compare on enterprise data privacy?
On paper the three look similar; the details that decide a regulated deployment sit in residency and retention. Summary as of September 2026:
| OpenAI | Anthropic | ||
|---|---|---|---|
| Training on business data | No by default (ChatGPT Business, Enterprise, Edu, API) | No by default (Claude for Work, API) | No without prior permission (Workspace, Vertex AI) |
| Retention controls | Configurable retention for qualifying organizations; zero data retention on the API after approval | Custom data retention controls on Enterprise | Zero data retention on Vertex AI requires specific customer actions |
| Security certifications | SOC 2 Type 2; ISO 27001, 27701, 42001; CSA STAR Level 1 | SOC 2 Type I and II; ISO 27001:2022; ISO/IEC 42001:2023 | Google Cloud: ISO 27001, ISO/IEC 42001, SOC 2 and others |
| Health data | DPA and BAA offered | HIPAA-ready Enterprise plans (BAA available) | Check Google Cloud compliance offerings per service |
| Sales channels | Direct; Azure OpenAI through Microsoft | Direct; AWS Bedrock, Google Cloud, Microsoft Foundry | Workspace; Vertex AI on Google Cloud |
| Processing in Canada | Azure OpenAI Canada East for some models; OpenAI direct stores at rest only | Not on the first-party API; Bedrock keeps data at rest in Canada, inference in the US | Vertex AI Montréal for Gemini 3.5 Flash, 2.5 Flash and 2.5 Pro |
Do OpenAI, Anthropic and Google use enterprise data to train their models?
No, by default, on business and API products. Each vendor puts the commitment in writing:
- OpenAI: "By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform—including inputs or outputs—for training or improving our models."
- Anthropic: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models."
- Google Cloud (Vertex AI, now renamed Gemini Enterprise Agent Platform): "Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models."
- Google Workspace: "Workspace does not use customer data for training models without customer's prior permission or instruction."
Two gaps remain in practice. Staff on personal or free accounts fall outside these terms. And feedback features (thumbs up or down, shared conversations) can carry their own terms, so check them in the admin console.
How does Anthropic's compliance strategy compare with OpenAI and Google?
Anthropic leans on distribution through the three big clouds; OpenAI builds its own compliance stack next to Microsoft's; Google folds Gemini into Google Cloud and Workspace programmes.
- Anthropic sells Claude through AWS Bedrock, Google Cloud and Microsoft Foundry as well as directly. An enterprise can buy Claude under a cloud agreement its procurement and security teams have already reviewed. Anthropic lists SOC 2 Type I and II, ISO 27001:2022 and ISO/IEC 42001:2023 (AI management systems), with HIPAA-ready Enterprise plans.
- OpenAI holds its own certifications (SOC 2 Type 2; ISO/IEC 27001, 27701 and 42001) and offers a DPA and BAA. It also reaches enterprises through Azure OpenAI, where Microsoft's contracts, regions and controls apply.
- Google runs Gemini under the Cloud Data Processing Addendum and Google Cloud's compliance programme, which lists ISO/IEC 42001 among its offerings.
Canadian regulators are active. In May 2026 the federal Privacy Commissioner and the Quebec, BC and Alberta commissioners found that OpenAI "did not have implied consent" for collecting personal information from public websites to train GPT-3.5 and GPT-4; the complaint was found well-founded and conditionally resolved. The finding concerns model training on public web data. It also confirms that PIPEDA applies to AI vendors serving Canadians.
Which provider can keep enterprise data in Canada?
As of September 2026, in-Canada processing exists for a limited set of models; storage at rest in Canada is more common.
| Path | Data at rest in Canada | Prompts processed in Canada |
|---|---|---|
| Azure OpenAI (Microsoft Foundry) | Yes | Canada East Standard for gpt-4o, gpt-4.1-mini and embeddings; regional provisioned throughput in Canada Central and Canada East for gpt-4o, gpt-4.1, gpt-5.x and others |
| OpenAI direct (API, ChatGPT Enterprise and Edu) | Yes, for eligible customers | No; inference residency covers Europe, the US and the UAE |
| Anthropic API | No | No; "global" or "us" only |
| Claude on AWS Bedrock (ca-central-1) | Yes: logs, knowledge bases, configuration | No; the Canadian geo profile routes inference to US Regions |
| Claude on Google Vertex AI | Per Google Cloud location | No Canada column for partner models |
| Gemini on Vertex AI (Montréal) | Yes | Yes for Gemini 3.5 Flash, 2.5 Flash, 2.5 Pro and some embedding models; newer Gemini 3.6–3.8 Flash are not listed for Canada |
| Google Workspace (Gemini in Gmail, Docs) | Data regions: US or Europe | No Canada option |
| Microsoft 365 Copilot | Not covered here | Microsoft expects local processing for Canada in 2027 |
For Quebec personal information, Law 25 s. 17 requires a privacy impact assessment and a written agreement before it is communicated outside Quebec, including to a vendor that processes it on your behalf.
How do the business models differ, and where does Palantir fit?
OpenAI, Anthropic and Google build frontier models; Palantir sells a platform that puts AI to work on an organization's own data.
| Company | What it sells | How enterprises usually buy |
|---|---|---|
| OpenAI | ChatGPT Business and Enterprise, API, Codex | Direct subscription or API; Azure OpenAI through Microsoft |
| Anthropic | Claude Team and Enterprise, API, Claude Code | Direct, or through AWS, Google Cloud or Microsoft marketplaces |
| Gemini in Workspace, Gemini models on Vertex AI | Workspace licence; Google Cloud consumption | |
| Palantir | AIP, built on its Ontology, for AI apps, actions and agents | Directly from Palantir |
For most mid-sized Canadian organizations the choice is between the three model vendors and their cloud channels. A platform such as Palantir is a separate purchase that sits on top of models and data, with its own evaluation.
What should an enterprise LLM contract include?
Ask for these terms before signing, whichever vendor you pick:
- A signed data processing addendum covering prompts, outputs, files and logs.
- An explicit no-training clause for your data, including feedback.
- Retention periods, and zero data retention where offered.
- The processing region for each model you will use.
- The subprocessor list and notice of changes.
- Breach notification timelines.
- A BAA or equivalent for health information.
- Notice periods for model retirement.
- Exit terms: export of conversations, files and configurations.
- For Quebec data, the written agreement required by Law 25 s. 17.
An AI compliance review for PIPEDA and Law 25 checks a vendor's terms against these points and against your data classes.
Which one should an enterprise choose?
Let your data rules and existing cloud contract decide first, and model quality second.
| Situation | Usual starting point |
|---|---|
| Microsoft 365 and Azure shop, regulated data | Azure OpenAI in a Canadian region, Copilot for staff |
| AWS shop | Claude on Bedrock, with data at rest in Canada |
| Google Workspace and Google Cloud | Gemini in Workspace; Vertex AI Montréal for regulated workloads |
| Personal information must be processed in Canada | Azure OpenAI Canada East or Gemini on Vertex AI Montréal, for the listed models |
| Mixed estate, several use cases | An LLM gateway that routes by data class across two vendors |
Remolda provides a vendor-neutral choice between Copilot, ChatGPT Enterprise and Claude and builds LLM integration with existing systems once the vendor is chosen. Engagements start from fixed-price packages from $490 CAD.
Sources
- OpenAI — Business data privacy
- OpenAI — Security and privacy
- OpenAI — Your data (API data residency)
- OpenAI Help — Data residency and inference residency for ChatGPT
- Anthropic Privacy Center — Is my data used for model training?
- Claude Help — What certifications has Anthropic obtained?
- Claude — Pricing (Enterprise features)
- Anthropic — Data residency
- AWS — Amazon Bedrock model Region compatibility
- AWS blog — Amazon Bedrock cross-Region inference in Canada
- Google Cloud — Generative AI data governance
- Google Cloud — Generative AI data residency
- Google Cloud — Compliance offerings
- Google Workspace Admin Help — Generative AI privacy hub
- Google Workspace Admin Help — Data regions
- Microsoft Learn — Model region availability
- Microsoft — In-country data processing for Microsoft 365 Copilot
- OPC — PIPEDA Findings #2026-002 (OpenAI)
- Palantir — AIP
- LégisQuébec — CQLR c. P-39.1