Business customers can conduct one on-site audit per year to verify Mistral AI's data processing compliance, but must give 90 days advance notice, use a jointly selected independent auditor, and pay all audit costs themselves.
This analysis describes what Mistral AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The 90-day advance notice requirement, jointly selected auditor, and customer-borne costs collectively create a high practical threshold for exercising on-site audit rights, which may limit their utility as a real-time compliance verification tool. These conditions are notable relative to some enterprise DPA frameworks that impose shorter notice periods or allow customer-selected auditors.
This provision affects business customers' ability to independently verify Mistral AI's data processing practices. The cost and procedural requirements mean that practical audit oversight is primarily available to larger enterprises with dedicated compliance resources.
How other platforms handle this
TINDER ASSUMES NO RESPONSIBILITY FOR ANY CONTENT THAT YOU OR ANOTHER USER OR THIRD PARTY POSTS, SENDS, RECEIVES, AND/OR ACTS ON THROUGH OUR SERVICES, NOR DOES TINDER ASSUME ANY RESPONSIBILITY FOR THE IDENTITY, INTENTIONS...
we do not warrant that Offering descriptions are accurate, complete, reliable, current, or error-free.
Please note that these third parties are responsible for their own privacy practices.
"Only to the extent Customer cannot reasonably be satisfied with Mistral AI's compliance with this DPA through the exercise of the audit set out in Section 9.1 (Document Audit) of this DPA, Customer may conduct up to one (1) on-site audit per year to verify Mistral AI's compliance with this DPA, under the conditions defined below: This audit must be conducted with reasonable advance written notice of at least ninety (90) calendar days... This audit shall be carried out by an independent auditor selected jointly by the Parties for its expertise, independence and impartiality and which is, in any event, not a direct or indirect competitor of the Mistral AI... The costs of this audit shall be borne exclusively by Customer.Excerpt from Mistral AI's Data Processing Addendum
(1) REGULATORY LANDSCAPE: GDPR Article 28(3)(h) requires processor agreements to include provisions allowing controllers to conduct audits and inspections.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The 90-day advance notice requirement, jointly selected auditor, and customer-borne costs collectively create a high practical threshold for exercising on-site audit rights, which may limit their utility as a real-time compliance verification tool. These conditions are notable relative to some enterprise DPA frameworks that impose shorter notice periods or allow customer-selected auditors.
This provision affects business customers' ability to independently verify Mistral AI's data processing practices. The cost and procedural requirements mean that practical audit oversight is primarily available to larger enterprises with dedicated compliance resources.
ConductAtlas has identified this type of provision across 287 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mistral AI.