8 Total
1 High severity
6 Medium severity
1 Low severity
Summary

This is Mistral AI's Data Processing Addendum, the legal contract that governs how Mistral AI handles personal data on behalf of business customers who use its AI products and APIs. Under this document, Mistral AI may use customer data to train its AI models unless the business customer has actively opted out or is using a product that is opted out by default. Business customers should check their account configuration to confirm whether AI model training is active or disabled for their use case, and should subscribe to Mistral AI's Trust Center to receive notifications when new subprocessors are added.

Technical / Legal Breakdown

This Data Processing Addendum (DPA), effective March 12, 2026, governs the processing of personal data by Mistral AI on behalf of commercial customers under the main service agreement, establishing Mistral AI as a Processor and the customer as the Controller under GDPR and CCPA frameworks. The agreement states that Mistral AI processes personal data only on documented customer instructions, but separately authorizes Mistral AI to act as Controller for purposes including AI model training (unless the customer opts out or uses a product opted out by default), automated abuse moderation, and aggregated usage analytics. Notably, the DPA permits Mistral AI to terminate the agreement or affected products if a customer objects to a new subprocessor appointment and no resolution is reached within a 10-day objection window, a condition that places practical leverage on the vendor side; additionally, on-site audit rights are constrained by a 90-day advance notice requirement, a joint auditor selection process, and a customer-borne cost structure, which together represent a more restricted audit framework than some enterprise data processing agreements. The DPA explicitly engages GDPR (including SCCs via EU Commission Decision 2021/914 for international data transfers) and CCPA, with French law governing SCC Module 4 disputes for customers in non-adequate third countries. Compliance teams should evaluate the opt-out configuration for AI model training, the subprocessor notification subscription mechanism via the Trust Center, and the 30-day post-termination data deletion timeline against their own data retention and regulatory obligations.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 1 provision
Medium — 6 provisions
Low — 1 provision

Monitoring

Mistral AI has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Mistral AI as Controller for AI Model Training and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
CFAA
United States Federal
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 11, 2026 10:30 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000771
Version ID CA-V-002393
SHA-256 11ede9710f5d5e475d2e3a86c1d1ba75073d2e0193a368f8c7adcc592a40268c
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans