Your legal team has been asking one question about every AI vendor since the start of this year, and your technology team has struggled to answer it: where does our data actually sit after the model responds? For most of 2025 the honest answer was that nobody outside the vendor knew. That answer stopped being acceptable in 2026.
Reviewed by the UD enterprise AI team. Last updated 4 September 2026.
What is zero data retention in enterprise AI?
Zero data retention (ZDR) is a contractual and technical commitment that an AI provider does not store your prompts or the model's outputs after the request completes. Nothing is written to the provider's systems, nothing is used for training, and no employee of the provider reads your content.
The term matters because the default is the opposite. Standard consumer and business tiers typically retain inputs for a defined window so that the provider can investigate abuse, debug failures and, in some cases, improve models.
ZDR removes that window. It is the difference between a vendor promising not to look and a vendor being unable to look because the data was never written down.
Why did zero data retention become a procurement issue in 2026?
Because the largest AI providers changed their positions in public, within days of each other, after enterprise customers pushed back. Data handling moved from a clause buried in an addendum to a headline product feature that vendors now compete on.
On 1 September 2026, Anthropic announced Enterprise Frontier Safeguards, replacing a data retention policy that had drawn complaints from regulated-industry customers. CNBC reported the change followed sustained customer pressure.
OpenAI had already published zero data retention for frontier model API customers, and operates a parallel mechanism it calls Private Safety Processing.
Three providers arriving at the same architectural answer in the same quarter is a signal. It tells you the market has settled on what an acceptable enterprise deal looks like, and that you now have leverage you did not have twelve months ago.
How does zero data retention actually work?
Modern ZDR does not mean abandoning safety monitoring. The current design keeps the monitoring but relocates where the evidence lives, moving it from the provider's infrastructure into storage the customer already owns and controls.
Under Anthropic's model, activity data used for misuse monitoring can be written to your own Amazon S3, Azure Blob Storage or Google Cloud Storage account, under your encryption keys, your access policies and your audit logging.
Automated monitoring still scans for misuse. What changes is the escalation path. Flags go to your own review team rather than to the provider's staff, so no external employee reads your content as a matter of routine.
The commercial terms are worth noting precisely. Anthropic charges nothing for the capability itself. You pay your own cloud provider for storage, reads, writes and egress, exactly as you would for any other bucket.
What does this mean under Hong Kong's PDPO?
Hong Kong does not currently have an in-force statutory restriction on cross-border transfers, but that is not the same as having no obligation. The Data Protection Principles apply in full, and the PCPD has made clear that contractual protections weigh in its assessment when something goes wrong.
Section 33 of the Personal Data (Privacy) Ordinance, which would restrict transfers of personal data outside Hong Kong, has never been brought into force since the Ordinance's enactment. Many boards misread this as meaning cross-border AI use is unregulated. It is not.
The PCPD's Recommended Model Contractual Clauses cover both data-user-to-data-user and data-user-to-data-processor transfers. The Commissioner has stated that incorporating the RMCs, or equivalent provisions, will be taken into account when investigating a suspected PDPO breach.
The practical translation for a Hong Kong enterprise is direct. A ZDR architecture combined with RMC-aligned contract terms gives you a defensible position. Neither one alone does.
Data handling is one of three governance questions arriving together this year, alongside the PCPD's agentic AI guidance and the certification requirements now appearing in enterprise RFPs.
How should you evaluate a vendor's data handling?
Use five questions. They are ordered deliberately, because each one is harder for a vendor to answer with marketing language than the one before it, and the answers together tell you whether a claim is architectural or aspirational.
The five questions to put to any AI vendor
--- Which specific plan or tier includes zero data retention, and what does it cost relative to the tier below it?
--- Is retention set to zero by default, or does someone on our side have to configure it correctly for every workload?
--- If safety monitoring still runs, where is the evidence written, who holds the encryption keys, and who reviews a flag?
--- Does the commitment extend to the model provider's own subprocessors, and to any cloud marketplace route we buy through?
--- What contractual remedy exists if the commitment is breached, and does it survive our contract's termination?
The fourth question catches the most expensive mistake. An enterprise that buys the same model through a cloud marketplace rather than direct is buying under a different contract, and the data terms may not travel with it.
What does this look like in practice for a Hong Kong enterprise?
Consider a Hong Kong insurance group with 400 staff running a claims-summarisation pilot. The technology worked. The pilot stalled for eleven weeks in legal review, and the blocker was never model quality.
The compliance team could not confirm three things: whether claimant medical details were retained anywhere outside Hong Kong, who at the vendor could read them, and what the group would tell the PCPD if asked.
Under a customer-held storage architecture, all three become answerable. The monitoring artefacts sit in the group's own regional cloud account. The keys belong to the group. Escalations route to the group's own privacy officer.
The pilot did not need better technology. It needed a data architecture that a compliance officer could describe in a single paragraph without qualification.
This is why the sequencing matters. Organisations that settle data handling before selecting a use case move faster overall, even though the first month looks slower.
What goes wrong when organisations get this wrong?
The common failures are not exotic. They are procedural, and they recur across industries because the responsibility for data terms falls between the technology team and the legal team, so nobody owns the question end to end.
Four recurring failure patterns
--- Assuming the enterprise tier covers everything. Retention settings often vary by product surface. A coding assistant, a chat interface and a raw API can sit under different terms with the same vendor.
--- Treating zero retention as zero risk. ZDR governs what the provider stores. It says nothing about what your own staff paste into a prompt, or what your application logs on its own side.
--- Signing before the capability ships. Anthropic's safeguards roll out in phases beginning later in autumn 2026. A commitment on a roadmap is not a control you can evidence today.
--- Skipping the shadow inventory. Staff who cannot access an approved tool will use an unapproved one, and no contract term reaches a personal account.
The fourth pattern is the one that most often surfaces during an audit rather than during procurement, which is the worst possible moment to discover it.
How is zero data retention different from encryption or a no-training promise?
They are three separate controls that vendors often present as one. Encryption protects data in transit and at rest. A no-training promise limits one downstream use. Zero data retention removes the stored copy entirely. Only the third eliminates the underlying exposure.
Encryption is necessary and universal. Every major provider encrypts traffic and storage, which is why it appears in every security datasheet and tells you almost nothing about how one vendor differs from another.
A no-training commitment is narrower than most buyers assume. It restricts how retained data may be used, but the data is still retained, still discoverable, and still within reach of a subpoena, a breach or an insider.
Zero data retention is the only one of the three that changes what exists. If the prompt was never written to the provider's systems, there is no copy to misuse, leak or produce under legal process.
When a vendor answers a retention question by describing its encryption standard, treat that as a non-answer and ask again. The substitution is common enough to be a useful signal in itself.
Does zero data retention slow anything down?
It introduces real trade-offs, and pretending otherwise damages credibility with your own engineering team. The main costs are diagnostic, not performance-related. Latency is unaffected. What you lose is the provider's ability to help you investigate your own incidents.
When something goes wrong in a retained-data environment, the vendor's support team can look at the failing request. Under ZDR they cannot, because the record does not exist on their side.
That shifts the burden to your own observability. Teams that adopt ZDR without building their own request logging discover the gap during their first production incident, which is an expensive place to learn it.
Some features also depend on stored context. Long-running assistant memory, usage analytics and certain abuse-prevention tools may behave differently or be unavailable under a strict zero-retention configuration.
None of these are reasons to avoid ZDR. They are reasons to budget for your own logging layer in the same business case, rather than discovering it as an unplanned cost in month four.
What should you do in the next 30 days?
Three actions, in order. Each is achievable inside a month by an existing team, and each produces an artefact you can put in front of a board or a regulator rather than a status update.
--- Week one to two. Inventory every AI tool in active use, including the ones nobody approved, and record the plan tier and retention setting for each.
--- Week two to three. Map each tool against the PCPD's Recommended Model Contractual Clauses and note the gaps in writing.
--- Week three to four. Take the five vendor questions above into your next renewal conversation, and ask for the answers in the contract rather than in an email.
None of this requires a new budget line. It requires someone to own the question, which is usually the actual constraint.
The strategic takeaway
Zero data retention has moved from a technical footnote to the term that determines whether an AI deployment clears legal review. The organisations that will deploy fastest over the next twelve months are not the ones with the largest AI budgets. They are the ones whose data architecture a compliance officer can already explain.
That shift also changes what you should expect from a technology partner. The useful partner is no longer the one who can name the most models. It is the one who can sit in the room with your privacy officer and your CFO and answer the same question consistently to both.
We understand AI. We understand you. With UD by your side, AI never feels cold. Twenty-eight years of working alongside Hong Kong enterprises has taught us that the hardest part of technology is rarely the technology.
Where to start
Before you renegotiate a single vendor contract, it helps to know where your organisation actually stands. We'll walk you through every step, from an AI readiness assessment and a data-handling review to vendor selection, deployment and performance tracking, with twenty-eight years of Hong Kong enterprise experience behind you.