ZDR and DPA: Contractual Data-Handling Terms That Gate Delivery-Route Choice
SupplementalSelect the appropriate connection protocol: MCP, API/CLI, or agent-to-agent · Difficulty 2/5
Explanation
Two contractual terms round out the regulatory vocabulary an architect needs alongside BAA, HIPAA, GDPR, FedRAMP, and data residency — and they matter specifically because they can gate which delivery route (Anthropic direct, Bedrock, Vertex AI, Foundry) a client is legally permitted to use.
| Term | Definition |
|---|---|
| DPA (Data Processing Agreement) | A contract governing how a data processor handles and protects personal data on a controller's behalf — typically required alongside GDPR compliance whenever a vendor processes EU personal data for a client |
| ZDR (Zero Data Retention) | A configuration or contractual option where the vendor does not retain input/output data beyond the immediate processing window — relevant for the most data-sensitive delivery-route decisions, since not every delivery route or model configuration supports it |
Both terms are data-handling commitments, not model-capability features, which is why they belong in the same conversation as delivery-route selection rather than model-tier selection: a client whose regulatory posture requires ZDR, or requires a DPA covering a specific processing arrangement, may find that requirement is easier to satisfy through one delivery route than another — for example, if the client's existing AWS or Azure contract already includes a DPA covering that CSP's services, extending coverage to Claude via Bedrock or Foundry can be simpler than negotiating a new DPA directly with Anthropic, and vice versa if the client's most mature data-processing terms already sit with Anthropic. As with BAA/HIPAA/GDPR, the underlying discipline is the same: ask what data is collected, where it's processed, who can access it, and how long it's retained — DPA and ZDR are just two more concrete, name-able answers to those questions.
Key Takeaways
- DPA (Data Processing Agreement): the contract governing how a data processor handles personal data on a controller's behalf, typically required alongside GDPR compliance
- ZDR (Zero Data Retention): a configuration/contractual option where the vendor doesn't retain input/output data beyond the immediate processing window
- Both are data-handling commitments that can gate which delivery route a client can legally use, not model-capability features
Related Concepts