62 Total
25 High severity
34 Medium severity
3 Low severity

Key Facts

Is Mistral AI prohibited from combining Personal Data with any other personal data or information?
Mistral AI is prohibited from combining Personal Data with any other personal data or information it collects, directly or via any third party, except as expressly permitted under Applicable Data Protection Law for Processors.
What is Mistral AI prohibited from combining Personal Data with?
Mistral AI is prohibited from combining Personal Data with any other personal data or information it collects, directly or via any third party, except as expressly permitted under Applicable Data Protection Law for Processors.
Is Mistral AI prohibited from processing Personal Data for any commercial purpose?
Mistral AI is prohibited from processing Personal Data for any commercial purpose other than as necessary to provide the Mistral AI Products to Customer.
What commercial purposes is Mistral AI prohibited from processing Personal Data for?
Mistral AI is prohibited from processing Personal Data for any commercial purpose other than as necessary to provide the Mistral AI Products to Customer.
Is Mistral AI prohibited from processing Personal Data outside of the direct business relationship between Mistral AI as Processor and Customer?
Mistral AI is prohibited from processing Personal Data outside of the direct business relationship between Mistral AI as Processor and Customer.
Does Customer grant Mistral AI authorization to appoint Subprocessors?
Customer grants Mistral AI a prior and general authorization to appoint Subprocessors to assist in the provision of the Mistral AI Products and in the Processing, in accordance with the terms of the DPA.
What does Customer grant Mistral AI authorization to appoint Subprocessors to do?
Customer grants Mistral AI a prior and general authorization to appoint Subprocessors to assist in the provision of the Mistral AI Products and in the Processing, in accordance with the terms of the DPA.
What must Customer provide for Mistral AI to process Personal Data under the DPA?
Customer is required to provide notice and obtain all consents and rights required by Applicable Data Protection Law for Mistral AI to process Personal Data under the DPA.
What must Customer obtain for Mistral AI to process Personal Data under the DPA?
Customer is required to provide notice and obtain all consents and rights required by Applicable Data Protection Law for Mistral AI to process Personal Data under the DPA.
As what is Mistral AI authorized to process Personal Data?
Mistral AI is authorized to process Personal Data as Controller for the purpose of training its artificial intelligence models in accordance with its Privacy Policy, unless the Customer has opted out of training or uses a Mistral AI Product that is opted out by default and has not opted in.
Stay ahead of the changes
Track Mistral AI and get the diff the day its terms change.
Summary

This document is a data processing agreement that sets out how Mistral AI handles personal data it processes on a business customer's behalf. Mistral AI is only permitted to use that data to deliver its products, not for broader commercial purposes, and must delete or return all data after the service ends. Mistral AI may also use personal data to train its AI models as a Controller, unless the customer has opted out or uses a product that defaults to opted-out.

Analysis

This Data Processing Addendum establishes the terms under which Mistral AI processes Personal Data as a Processor on behalf of Customer, confining all processing to what is necessary to provide the Mistral AI Products within the direct Processor-Customer relationship. Mistral AI is prohibited from combining Personal Data with other data it collects or from processing it for any commercial purpose outside service delivery. Customer bears the obligation to provide required notices and obtain all consents under Applicable Data Protection Law. Mistral AI retains a distinct Controller role for AI model training purposes, subject to Customer opt-out rights. The addendum incorporates Module 4 Standard Contractual Clauses for International Data Transfers, requires prompt breach notification, mandates ongoing technical and organizational security measures, and preserves Mistral AI's liability for Subprocessor failures under a prior and general authorization to engage Subprocessors.

What this means for you

For individuals whose personal data is processed through a business customer's use of Mistral AI products, this document limits Mistral AI to processing that data solely to provide those products and prohibits combining it with other datasets. Mistral AI may process personal data as a Controller to train its AI models unless the business customer has opted out of training or uses a product that defaults to opt-out. If your organization is a Mistral AI customer, it can opt out of AI training data use, which stops Mistral AI from acting as Controller over your personal data for that purpose.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

1 important change detected

2 versions captured · Last updated: July 2026

What changed Mistral AI updated its Data Processing Addendum effective July 27, 2026, making four targeted revisions. The most significant change clarified the conditions under which Mistral AI may use personal data for AI model training: the prior language required opt-out by either the customer or the product default status, while the updated language states that Mistral AI may train unless 'Customer is or has opted-out of training,' simplifying the opt-out condition. Additional changes include correcting a tense issue regarding data transfer authorization (from 'authorized' to 'authorizes') and minor wording adjustments to audit provisions (removing 'the' before 'a'). These revisions clarify operational procedures without materially expanding or restricting processing rights.
Why this matters The updated Data Processing Addendum clarifies the conditions under which Mistral AI may train its AI models on customer data. Previously, the language stated that Mistral AI could train unless the customer opted out or the product was opted out by default without opt-in; the revised language states that Mistral AI may train unless the customer is or has opted out. This simplifies the opt-out framework by establishing a single condition rather than a dual condition. Customers retain the ability to opt out of AI training, and the revision does not expand Mistral AI's processing rights beyond what was previously permitted.
View full change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

62 provisions
12 featured
16 clause types
25 high severity
Liability Limitation 1 1 high
Platform Discretion 1 1 high
Stay ahead of the changes

Monitoring

Mistral AI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle CCPA prohibition on combining Personal Data with other data and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
CFAA
United States Federal
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 28, 2026 00:52 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000771
Version ID CA-V-005312
SHA-256 d3d8da540e833750342a27ed8ceff4c763a8493fe594ae2c112429aba89d6985
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans