62 Total
25 High severity
34 Medium severity
3 Low severity

Key Facts

Is Mistral AI prohibited from combining Personal Data with any other personal data or information?
Mistral AI is prohibited from combining Personal Data with any other personal data or information it collects, directly or via any third party, except as expressly permitted under Applicable Data Protection Law for Processors.
What is Mistral AI prohibited from combining Personal Data with?
Mistral AI is prohibited from combining Personal Data with any other personal data or information it collects, directly or via any third party, except as expressly permitted under Applicable Data Protection Law for Processors.
Is Mistral AI prohibited from processing Personal Data for any commercial purpose?
Mistral AI is prohibited from processing Personal Data for any commercial purpose other than as necessary to provide the Mistral AI Products to Customer.
What commercial purposes is Mistral AI prohibited from processing Personal Data for?
Mistral AI is prohibited from processing Personal Data for any commercial purpose other than as necessary to provide the Mistral AI Products to Customer.
Is Mistral AI prohibited from processing Personal Data outside of the direct business relationship between Mistral AI as Processor and Customer?
Mistral AI is prohibited from processing Personal Data outside of the direct business relationship between Mistral AI as Processor and Customer.
Does Customer grant Mistral AI authorization to appoint Subprocessors?
Customer grants Mistral AI a prior and general authorization to appoint Subprocessors to assist in the provision of the Mistral AI Products and in the Processing, in accordance with the terms of the DPA.
What does Customer grant Mistral AI authorization to appoint Subprocessors to do?
Customer grants Mistral AI a prior and general authorization to appoint Subprocessors to assist in the provision of the Mistral AI Products and in the Processing, in accordance with the terms of the DPA.
What must Customer provide for Mistral AI to process Personal Data under the DPA?
Customer is required to provide notice and obtain all consents and rights required by Applicable Data Protection Law for Mistral AI to process Personal Data under the DPA.
What must Customer obtain for Mistral AI to process Personal Data under the DPA?
Customer is required to provide notice and obtain all consents and rights required by Applicable Data Protection Law for Mistral AI to process Personal Data under the DPA.
As what is Mistral AI authorized to process Personal Data?
Mistral AI is authorized to process Personal Data as Controller for the purpose of training its artificial intelligence models in accordance with its Privacy Policy, unless the Customer has opted out of training or uses a Mistral AI Product that is opted out by default and has not opted in.
Stay ahead of the changes
Track Mistral AI and get the diff the day its terms change.
Summary

This document is a data processing agreement that sets out how Mistral AI handles personal data it processes on a business customer's behalf. Mistral AI is only permitted to use that data to deliver its products, not for broader commercial purposes, and must delete or return all data after the service ends. Mistral AI may also use personal data to train its AI models as a Controller, unless the customer has opted out or uses a product that defaults to opted-out.

Analysis

This Data Processing Addendum establishes the terms under which Mistral AI processes Personal Data as a Processor on behalf of Customer, confining all processing to what is necessary to provide the Mistral AI Products within the direct Processor-Customer relationship. Mistral AI is prohibited from combining Personal Data with other data it collects or from processing it for any commercial purpose outside service delivery. Customer bears the obligation to provide required notices and obtain all consents under Applicable Data Protection Law. Mistral AI retains a distinct Controller role for AI model training purposes, subject to Customer opt-out rights. The addendum incorporates Module 4 Standard Contractual Clauses for International Data Transfers, requires prompt breach notification, mandates ongoing technical and organizational security measures, and preserves Mistral AI's liability for Subprocessor failures under a prior and general authorization to engage Subprocessors.

What this means for you

For individuals whose personal data is processed through a business customer's use of Mistral AI products, this document limits Mistral AI to processing that data solely to provide those products and prohibits combining it with other datasets. Mistral AI may process personal data as a Controller to train its AI models unless the business customer has opted out of training or uses a product that defaults to opt-out. If your organization is a Mistral AI customer, it can opt out of AI training data use, which stops Mistral AI from acting as Controller over your personal data for that purpose.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

3 important changes detected

4 versions captured · Last updated: September 2026

What changed An update was detected in Mistral AI's Data Processing Addendum on September 4, 2026. The change involved removal of the "Markdown" export option from the document interface. The updated version now displays "Copy" and "Versions" controls instead. This is a minor formatting or interface modification with no material change to the substantive data processing terms or obligations.
Why this matters This change affects how users access and export the Data Processing Addendum document itself, not the substantive data processing obligations. The removal of the Markdown export option means users can no longer download the DPA in Markdown format; the Copy function remains available for accessing the document text. The underlying data processing terms and obligations stated in the DPA are not materially altered.
View full change record →
What changed In an update detected on September 3, 2026, Mistral AI restructured its Data Processing Addendum to add a comprehensive table of contents and detailed section headers covering definitions, roles of parties, security obligations, data breach procedures, subprocessing, cross-border transfers, audit rights, data return/destruction, and exhibits describing processing activities and technical measures. The document's core substantive provisions remain effective as of July 27, 2026, but the updated formatting and explicit section structure provide clearer navigation and organization of data protection obligations.
Why this matters The updated Data Processing Addendum adds explicit section numbering and a table of contents that organize existing data protection obligations into 12 labeled categories plus two exhibits. The substantive terms governing data processing, security, breach notification, subprocessing, and audit rights remain substantively unchanged; this change primarily improves document navigability and structure for parties reviewing their data protection commitments.
View full change record →

July 28, 2026 low

Mistral AI updated its Data Processing Addendum effective July 27, 2026, making four targeted revisions. The most significant change clarified the conditions under which Mistral AI may use personal data …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

62 provisions
12 featured
16 clause types
25 high severity
Liability Limitation 1 1 high
Platform Discretion 1 1 high
Stay ahead of the changes

Monitoring

Mistral AI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle CCPA prohibition on combining Personal Data with other data and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
CFAA
United States Federal
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured September 4, 2026 00:56 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000771
Version ID CA-V-006400
SHA-256 99ff8f168daf37ecba1bee3f803b215914f11294cf32c5c3998ac50a7b48a2e9
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans