Mistral AI
Mistral AI
Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.
Pricing / Contract Route
Vendor pricing; verify current Vibe and API terms
Enterprise Features
EU-default hosting, DPA, training controls, approved ZDR for eligible stateless API calls, Trust Center reports
Last Updated
September 10, 2026
Reviewed on 10 September 2026 by WAIMAKERS B.V.
Executive summary
Mistral can support a GDPR-controlled deployment, but the result depends on the product, settings, contract and workload. Mistral says data is hosted in the EU by default and is hosted in the United States only when a customer explicitly selects its US API endpoint. Some features can nevertheless involve temporary transfers to non-EU subprocessors; Mistral says it uses GDPR Article 46 safeguards for those transfers.[1]
Do not treat Mistral's chat product and API as one privacy route. The current documentation uses Vibe for the chat/coding workspace and Studio/API for API use. Their training controls and retention options differ.
- ✅ EU hosting is the default; the US API endpoint is an explicit choice.
- ✅ A DPA, subprocessor information, encryption controls and assurance reports are available.
- ⚠️ Ordinary Vibe use is not opted out of model improvement by default; Vibe Enterprise is.
- ⚠️ ZDR is approval-based and limited to supported stateless API calls.
- ❌ EU-default hosting is not a promise that every feature or support flow stays in the EEA.
Comparison of Mistral AI offerings (EU focus)
| Route | Training use | Retention and residency | Practical assessment |
|---|---|---|---|
| Vibe, non-Enterprise | Input and output may be used by default. A user or team administrator can disable model-improvement use. | EU hosting is the default, subject to feature-specific transfers. ZDR is unavailable because Vibe stores conversation state. | Suitable only after the organisation verifies the admin setting, permitted data and deletion workflow. |
| Vibe Enterprise | Mistral says organisations are opted out by default. Submitted feedback is a separate case. | EU default; conversation data remains stateful and is not covered by API ZDR. | Better contractual route, but still requires a DPA, subprocessor review and retention settings. |
| Studio/API pay-as-you-go | A separate API setting controls model-improvement use. Changing the Vibe setting does not change the API setting. | EU default; standard retention depends on the feature. | Verify the API setting and contract before sending personal data. |
| Eligible stateless API with approved ZDR | Mistral says eligible calls are not retained. ZDR must be requested and approved. | Only listed stateless endpoints are covered; files, batch, agents, conversations and other stateful features are excluded. | Strongest managed route when coverage is confirmed in the admin console and contract. |
| Self-deployed open-weight model | Mistral does not receive prompts merely because its weights are used. | The deployer chooses infrastructure, logs and retention. | Offers control, while leaving the deployer responsible for security, lawful basis, rights handling and model governance. |
Notes for Europe
Mistral's current help pages say Vibe users are not opted out by default, except Vibe Enterprise organisations. Studio/API has a separate “Anonymous improvement data” control. Feedback submitted with ratings or comments may be used even where ordinary model-improvement use is disabled.[2][3]
Is Mistral AI GDPR-compliant?
There is no provider-wide yes/no answer. A configured business route can support compliance, but the controller still needs a lawful basis, data minimisation, transparency, rights handling and a documented transfer assessment.
Vibe / Le Chat
- ⚠️ Non-Enterprise input and output may be used for model improvement unless the user or team administrator disables it.
- ✅ Vibe Enterprise organisations are opted out by default according to Mistral.
- ⚠️ Ratings or comments are a separate feedback case and may authorise use of the related input and output.
La Plateforme / Studio API
- ✅ The API training setting is separate from the Vibe setting.
- ✅ Supported stateless calls can qualify for approved ZDR.
- ⚠️ Stateful functions, files, agents, conversations, batch jobs and libraries are outside ZDR.
Self-deployment
- ✅ Downloaded weights do not by themselves send prompts to Mistral.
- ⚠️ The operator remains responsible for infrastructure, logging, security, deletion, licences and model governance.
Retention, security and data flow
Mistral does not publish one universal retention period. Its retention notice lists different periods for account, identity, technical and billing records. Conversations can be deleted by the user; deletion can include a short grace period and data retained for security or legal obligations.[4]
ZDR is available only for approved pay-as-you-go customers and supported stateless API calls. It does not cover Vibe, libraries, agents, conversations, batch jobs, files or other stateful functions. A customer should test the exact endpoint and confirm that ZDR is active rather than relying on a plan name.[5]
Mistral states that it uses AES-256 encryption at rest and TLS 1.2 or later in transit. It also reports SOC 2 Type II assurance and ISO 27001/27701 certification, with reports available through its Trust Center. These are vendor statements; obtain the current report and scope for procurement.[6][7]
Mistral publishes a DPA and subprocessor information. Review both for the selected features, because EU-default hosting does not mean every support or feature-related processing event stays in the EEA.[8]
EU rollout checklist
Before production use:
- Identify whether users will use Vibe, Studio/API, a stateful API feature or a self-hosted model.
- Execute the DPA and record controller/processor roles.
- Verify the Vibe and API training settings separately.
- Select the EU endpoint and review each relevant subprocessor and transfer safeguard.
- Document deletion, data-subject request and incident procedures.
- Prohibit special-category, confidential or client data until the selected route is approved.
Prices, model names and bundled limits change frequently and do not establish a privacy property. Check Mistral's live commercial page and order form when buying.[9]
Conclusion
Mistral merits a conditional business route for a configured and contracted deployment. EU-default hosting is useful, but there is no provider-wide “no training” or fixed-retention promise. ZDR is narrower than the whole API, and self-hosting shifts rather than removes the organisation's GDPR duties.
Disclaimer
This is an editorial procurement assessment, not a legal determination or legal advice.