Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

Mistral AI

Mistral AI

ConditionalEU: AvailablePlan-dependentRetention by featureEU with exceptions

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out Mistral AI safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Vendor pricing; verify current Vibe and API terms

Enterprise Features

EU-default hosting, DPA, training controls, approved ZDR for eligible stateless API calls, Trust Center reports

Last Updated

September 10, 2026

Reviewed on 10 September 2026 by WAIMAKERS B.V.

Executive summary

Mistral can support a GDPR-controlled deployment, but the result depends on the product, settings, contract and workload. Mistral says data is hosted in the EU by default and is hosted in the United States only when a customer explicitly selects its US API endpoint. Some features can nevertheless involve temporary transfers to non-EU subprocessors; Mistral says it uses GDPR Article 46 safeguards for those transfers.[1]

Do not treat Mistral's chat product and API as one privacy route. The current documentation uses Vibe for the chat/coding workspace and Studio/API for API use. Their training controls and retention options differ.

  • ✅ EU hosting is the default; the US API endpoint is an explicit choice.
  • ✅ A DPA, subprocessor information, encryption controls and assurance reports are available.
  • ⚠️ Ordinary Vibe use is not opted out of model improvement by default; Vibe Enterprise is.
  • ⚠️ ZDR is approval-based and limited to supported stateless API calls.
  • ❌ EU-default hosting is not a promise that every feature or support flow stays in the EEA.

Comparison of Mistral AI offerings (EU focus)

Route Training use Retention and residency Practical assessment
Vibe, non-Enterprise Input and output may be used by default. A user or team administrator can disable model-improvement use. EU hosting is the default, subject to feature-specific transfers. ZDR is unavailable because Vibe stores conversation state. Suitable only after the organisation verifies the admin setting, permitted data and deletion workflow.
Vibe Enterprise Mistral says organisations are opted out by default. Submitted feedback is a separate case. EU default; conversation data remains stateful and is not covered by API ZDR. Better contractual route, but still requires a DPA, subprocessor review and retention settings.
Studio/API pay-as-you-go A separate API setting controls model-improvement use. Changing the Vibe setting does not change the API setting. EU default; standard retention depends on the feature. Verify the API setting and contract before sending personal data.
Eligible stateless API with approved ZDR Mistral says eligible calls are not retained. ZDR must be requested and approved. Only listed stateless endpoints are covered; files, batch, agents, conversations and other stateful features are excluded. Strongest managed route when coverage is confirmed in the admin console and contract.
Self-deployed open-weight model Mistral does not receive prompts merely because its weights are used. The deployer chooses infrastructure, logs and retention. Offers control, while leaving the deployer responsible for security, lawful basis, rights handling and model governance.

Notes for Europe

Mistral's current help pages say Vibe users are not opted out by default, except Vibe Enterprise organisations. Studio/API has a separate “Anonymous improvement data” control. Feedback submitted with ratings or comments may be used even where ordinary model-improvement use is disabled.[2][3]

Is Mistral AI GDPR-compliant?

There is no provider-wide yes/no answer. A configured business route can support compliance, but the controller still needs a lawful basis, data minimisation, transparency, rights handling and a documented transfer assessment.

Vibe / Le Chat

  • ⚠️ Non-Enterprise input and output may be used for model improvement unless the user or team administrator disables it.
  • ✅ Vibe Enterprise organisations are opted out by default according to Mistral.
  • ⚠️ Ratings or comments are a separate feedback case and may authorise use of the related input and output.

La Plateforme / Studio API

  • ✅ The API training setting is separate from the Vibe setting.
  • ✅ Supported stateless calls can qualify for approved ZDR.
  • ⚠️ Stateful functions, files, agents, conversations, batch jobs and libraries are outside ZDR.

Self-deployment

  • ✅ Downloaded weights do not by themselves send prompts to Mistral.
  • ⚠️ The operator remains responsible for infrastructure, logging, security, deletion, licences and model governance.

Retention, security and data flow

Mistral does not publish one universal retention period. Its retention notice lists different periods for account, identity, technical and billing records. Conversations can be deleted by the user; deletion can include a short grace period and data retained for security or legal obligations.[4]

ZDR is available only for approved pay-as-you-go customers and supported stateless API calls. It does not cover Vibe, libraries, agents, conversations, batch jobs, files or other stateful functions. A customer should test the exact endpoint and confirm that ZDR is active rather than relying on a plan name.[5]

Mistral states that it uses AES-256 encryption at rest and TLS 1.2 or later in transit. It also reports SOC 2 Type II assurance and ISO 27001/27701 certification, with reports available through its Trust Center. These are vendor statements; obtain the current report and scope for procurement.[6][7]

Mistral publishes a DPA and subprocessor information. Review both for the selected features, because EU-default hosting does not mean every support or feature-related processing event stays in the EEA.[8]

EU rollout checklist

Before production use:

  1. Identify whether users will use Vibe, Studio/API, a stateful API feature or a self-hosted model.
  2. Execute the DPA and record controller/processor roles.
  3. Verify the Vibe and API training settings separately.
  4. Select the EU endpoint and review each relevant subprocessor and transfer safeguard.
  5. Document deletion, data-subject request and incident procedures.
  6. Prohibit special-category, confidential or client data until the selected route is approved.

Prices, model names and bundled limits change frequently and do not establish a privacy property. Check Mistral's live commercial page and order form when buying.[9]

Conclusion

Mistral merits a conditional business route for a configured and contracted deployment. EU-default hosting is useful, but there is no provider-wide “no training” or fixed-retention promise. ZDR is narrower than the whole API, and self-hosting shifts rather than removes the organisation's GDPR duties.

Disclaimer

This is an editorial procurement assessment, not a legal determination or legal advice.

Compare related tools

Wispr FlowLovable

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique· Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy