Guide · GDPR
The data processing agreements of the four main model providers read on 15 September 2026, the exact logic that makes a DPIA mandatory, a ready-to-fill record of processing entry for an AI agent, and recent decisions from the CNIL, the EDPB and the Italian Garante.
The starting point
You remain the controller. The model provider is your processor, and its contract sets what you can promise.
In brief
This guide covers contracts and GDPR documentation. Technical controls (prompt injection, permissions, logging) are in our guide to AI agent security, and the timeline of the EU AI regulation is in the AI Act for businesses.
The table
Every cell comes from the provider page listed in the sources, read on 15 September 2026. Where information is not published or two sources disagree, the cell says so.
| Criterion | OpenAI | Anthropic | Mistral AI | Google Gemini |
|---|---|---|---|---|
| DPA and version | Data Processing Addendum, updated 1 January 2026 | Data Processing Addendum, effective 24 February 2025 | Data Processing Addendum of 27 July 2026 | Workspace: Cloud Data Processing Addendum. Paid Gemini API: to be verified |
| EU contracting entity | OpenAI Ireland Ltd (EEA and Swiss customers) | Anthropic Ireland, Limited (EEA, Switzerland, UK) | Mistral AI SAS, Paris | To be verified |
| Role | Processor | Processor, customer is controller | Processor, but controller for training unless the customer opts out | Processor (Workspace) |
| Training by default | No for the API (since 1 March 2023) and business offers | No: the Commercial Terms bar training on Customer Content | Vibe Free and Pro: yes unless opt-out. Vibe Enterprise: no. Studio API: opt-out available. Pro and Team: conflicting sources | Workspace and paid API: no. Unpaid API: yes, with human review |
| Default API retention | Up to 30 days (abuse monitoring) | Deleted within 30 days. Policy violations: 2 years (inputs and outputs), 7 years (classifier scores) | Default not published, to be verified. Data inaccessible 30 days after termination | 55 days according to the usage policies page. Grounding with Search and Maps: 30 days, cannot be disabled |
| Zero data retention (ZDR) | Eligible customers, on approval: ZDR or Modified Abuse Monitoring (MAM) | Only by separate agreement | Paid plans, case by case, stateless endpoints only (excludes Agents, Batch, files, Vibe) | Through customer configuration (store=false, no caching, delete files) |
| EU residency | eu.api.openai.com (EEA and Switzerland) with approved ZDR or MAM, +10% on models released from 5 March 2026. ChatGPT: new Enterprise and Edu workspaces only | None first-party: inference us (1.1x) or global, workspace us only | EU hosting by default, US only through the US endpoint | Vertex AI EU regions according to secondary sources, to be verified. Gemini API: paid services only in the EEA |
| Transfer mechanism | SCCs or adequacy. DPF certification: check the registry | SCCs Modules 2 and 3, UK and Swiss addenda. DPF certification: conflicting sources | SCCs 2021/914 for sub-processors outside the EU | Google LLC certified under EU-US DPF, UK Extension and Swiss-US DPF, plus SCCs |
| Sub-processor list | openai.com/policies/sub-processor-list | anthropic.com/subprocessors | trust.mistral.ai/subprocessors, including US companies | Google Cloud sub-processor page, to be verified |
| Certifications | SOC 2 Type 2. ISO: to be verified (gated trust portal) | ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I and II, HIPAA BAA | SOC 2 Type II, ISO 27001 and 27701, reports on request | Gemini for Workspace: SOC 1, 2 and 3, ISO 27001, 27017, 27018, 27701, 9001, ISO 42001, FedRAMP High |
Reading it
Mistral changes role for training. Its DPA of 27 July 2026 makes Mistral AI a controller for training on inputs, outputs and user feedback, as long as the customer has not opted out. On Vibe Free and Pro, training is on by default. On Team, an admin can switch it off, but the default is unclear: one documentation page says Pro and Team are not used for training, while the help centre says the opposite for Pro. Opt out in writing before going live, and note it in your record.
Anthropic offers no first-party EU residency. The Data residency page of the Claude documentation lists its limits: inference only in us or global, workspace storage only in us, and the workspace geo cannot be changed after creation. The us option is billed at 1.1x the standard rate on Claude 4.6 and later models. On Amazon Bedrock and Google Cloud, the region depends on the endpoint. If EU hosting is a requirement, the choice is made at platform level, a topic covered on our Claude integration page.

OpenAI's EU residency comes with conditions and a price. The eu.api.openai.com endpoint stores and processes data in the EEA and Switzerland, but you first need ZDR or MAM approval and a Modified Retention amendment. Models released from 5 March 2026 cost 10% more on these endpoints. GPU inference stays in region, while some CPU processing may be global. For ChatGPT, residency is only available to new Enterprise and Edu workspaces, so Business workspaces and existing workspaces do not get it. Our Claude vs ChatGPT for business comparison covers the plans.

Google is the only US provider in the table whose Data Privacy Framework certification can be checked on its own page. Mistral, an EU company, is out of scope. For OpenAI, a third party reports it absent from the registry as of 8 September 2026; for Anthropic, a German law firm (June 2026) and an aggregator give opposite answers. The dataprivacyframework.gov registry loads with JavaScript and could not be read: check it yourself. Without certification, standard contractual clauses still work, but they require a transfer impact assessment on your side.
Location changes the bill. The 1.1x multiplier at Anthropic and the 10% uplift at OpenAI come on top of token costs. Our guide to Claude API pricing shows how to build them into a budget.
The law
| Article | What it requires | What it means for an AI agent |
|---|---|---|
| Art. 28 | Processors with sufficient guarantees, a contract covering instructions, confidentiality, security, sub-processors, help with data subject rights, deletion at the end, audits | The model provider's DPA must be signed or accepted and its sub-processor list tracked: a general authorisation gives you a right to object to each addition |
| Art. 30 | A written record kept by controller and processor. The under-250-employees exemption does not apply to risky, non-occasional or special-category processing | An agent in production is non-occasional processing: it gets its own entry |
| Art. 35 | A DPIA before processing likely to result in high risk, especially with new technologies: description, necessity, risks, measures, DPO advice | To be done before go-live, using the logic below |
| Art. 22 | Right not to be subject to a decision based solely on automated processing with legal or similar effects. Exceptions need safeguards: human intervention, right to contest | An agent that rejects an application, a file or a service without human sign-off is in scope |
| Art. 44 to 46 | Transfers outside the EEA only under an adequacy decision (including the DPF for certified companies) or appropriate safeguards (SCCs, BCRs) | Every call to a model hosted outside the EU is a transfer: record the mechanism |
Impact assessment
The CNIL, the French data protection authority, applies two tests in sequence. First: is the processing on its list of processing operations that require a DPIA (deliberation 2018-327 of 11 October 2018)? If so, the DPIA is mandatory. If not, second test: does the processing meet at least two of the nine criteria in the WP29 guidelines (WP248), endorsed by the EDPB? A separate list, deliberation 2019-118, sets out the processing that is exempt.

The nine criteria, as the CNIL presents them (page in French):

Applied to three common agents:
| Agent | Criteria met | Conclusion |
|---|---|---|
| Customer support chatbot (orders and products) | Innovative use (a cautious reading for a generative model). Large scale depending on volume. No sensitive data expected | To be decided: 1 certain criterion, a 2nd depending on volume. Document the reasoning in the record |
| CV pre-screening | Evaluation or scoring, innovative use, exclusion from a contract, automated decision if rejections go out without a human | DPIA mandatory (at least 3 criteria) |
| Patient intake and triage at a clinic | Sensitive data (health), vulnerable people (patients), innovative use | DPIA mandatory (3 criteria) |
CV screening also brings in Article 22 and Annex III of the AI Act; see our guide to screening CVs with AI and our page on AI for HR. For patient intake, see AI in healthcare, and for law firms pre-qualifying client requests, AI for legal.
On method, the EDPB announced a DPIA template version 1.0 on 10 March 2026, open for consultation until 9 June 2026 and optional to use, according to its press release. The CNIL also provides its PIA software, downloadable from its DPIA page.
Template
The CNIL simplified record template (an .ods file published on 23 July 2019) still works. Here are the fields filled in for a common example: an agent that reads incoming web form requests, classifies them, drafts a reply and creates a CRM record.
| Field | Filled-in example | AI-specific point |
|---|---|---|
| Purpose | Qualify and route incoming requests, draft a reply reviewed by an adviser | One purpose per agent. Reusing conversations for something else (training, marketing) is a new purpose |
| Legal basis | Pre-contractual steps at the request of the person (Art. 6(1)(b)), or legitimate interest with the 3-step test | If the provider trains on the data, its own legal basis does not cover yours |
| Categories of people and data | Prospects and customers: identity, contact details, message content, CRM history | Free text can contain unsolicited sensitive data: plan filtering or deletion |
| Recipients | Sales team; model provider (processor); orchestrator host; CRM vendor | List the provider's sub-processors by linking its public list, with the date you checked it |
| Transfers outside the EU | Depending on provider: none (Mistral, EU endpoint) or United States under SCCs or the DPF | State the configured inference and storage region |
| Retention | Unconverted requests: period set in your retention policy. Provider logs: up to 30 days at OpenAI and Anthropic (or ZDR) | Separate your logs, the orchestrator logs and the provider logs |
| Security measures | API keys in a vault, named accounts, call logging, encryption, access reviews | Agent-specific controls are detailed in our security guide |
| Human oversight | Nothing is sent without adviser approval; rejections are always decided by a person | Addresses Article 22 and the error cascade risk raised by the CNIL |
When the agent talks to people, add a line on the information given to them: since 2 August 2026, Article 50 of the AI Act requires disclosing that people are interacting with an AI (see the AI agent transparency obligation).
Responsibilities
No text specifically addresses an agency building an AI agent for a client. What follows is our reading of Article 28, to be checked with your DPO.
| Set-up | Client | Agency | Model provider |
|---|---|---|---|
| The client opens the API account and hosts the agent | Controller | Processor during build and maintenance if it accesses the data, otherwise out of scope | Direct processor of the client |
| The agency runs the agent and holds the API account | Controller | Processor of the client | Sub-processor: the agency needs the client's authorisation and must flow down the obligations |
| The agency reuses the data for its own purposes (improving a product) | Controller for its purpose | Controller for that reuse, with its own legal basis | Depends on its contract with the agency |
In the second set-up, the agency remains liable to the client for the model provider's failures. That is why the agency contract should name the provider, the region and the retention option chosen. Our custom AI agent page describes how these choices come up at design time.
Guidance
CNIL Q&A of 18 July 2024 on using a generative AI system. The CNIL asks organisations to clarify who is provider and who is deployer, sign a processor contract, carry out a DPIA, prefer on-premise deployment for sensitive data, set lists of allowed and banned uses, involve the DPO and train users.
CNIL recommendations on developing AI systems, finalised 22 July 2025. They add sheets on the status of models under the GDPR, annotation and security. They mainly target those who train models; work on the allocation of responsibilities along the value chain has been announced.
CNIL and CIANum note on agentic AI, 20 July 2026. An exploratory note that identifies four risks: data flowing across services, persistent memory drifting into profiling, unclear allocation of responsibility and error cascades. It points out that the GDPR and the AI Act already apply to agents.
EDPB Opinion 28/2024 of 18 December 2024, requested by the Irish Data Protection Commission. Three points: whether a model is anonymous is assessed case by case; legitimate interest requires the three-step test; unlawful processing during development can affect the lawfulness of deployment. For a deployer, that is a reason to ask the provider how its model was trained.
Coming next. The EDPB opened consultation on draft Guidelines 02/2026 on anonymisation on 7 July 2026 (until 30 October 2026), and joint EDPB and Commission guidelines on the GDPR and the AI Act are expected at the end of 2026. No EDPB position specific to AI agents was found as of 15 September 2026.
Enforcement
| Case | Date | Measure | Outcome |
|---|---|---|---|
| Garante vs OpenAI | Decision no. 755 of 2 November 2024, announced 20 December 2024 | €15M and a 6-month information campaign: 2023 breach not notified, no legal basis for training, transparency, no age verification | Annulled by the Tribunale di Roma on 18 March 2026 (R.G. 4785/2025) on jurisdiction grounds, as reported by the Italian legal press |
| Garante vs DeepSeek | 30 January 2025 | Urgent, immediate limitation of the processing of Italian users' data | No fine found as of 15 September 2026 |
The annulment ground matters: OpenAI set up its main establishment in Ireland on 15 February 2024, which brings in the one-stop-shop and the Irish authority. The court did not rule on the merits. For a European business, the practical point is that the contracting entity (OpenAI Ireland Ltd, Anthropic Ireland or Mistral AI SAS) determines the provider's lead authority, while your own national authority remains competent for your own processing.
Interplay
Most business agents (support, qualification, drafting) are not high-risk, so neither Article 26(9) nor Article 27 applies: that is our reading. GDPR Article 35 applies whenever the criteria are met. CV screening falls under Annex III, whose obligations apply from 2 December 2027 following the Digital Omnibus (Regulation 2026/1744, in force 27 July 2026).
Before you sign
About
Lumyniq is a Paris-based agency that builds custom AI agents, Claude integrations and n8n workflows for small and mid-sized businesses, with a focus on real estate, legal, healthcare and HR. Every project starts with an audit of the process, which covers the choice of model provider, region and GDPR documentation, before any quote.
FAQ
Related guides
The technical controls: permissions, prompt injection, logging.
The timeline after the Digital Omnibus and obligations by role.
Plans, prices and terms of both platforms.
Links verified at publication. Regulatory texts change — always defer to the official source.
A question, a project, an idea? We respond within 24h. Free audit, no commitment.