Guide · GDPR

GDPR and AI agents: records, DPIAs and the OpenAI, Anthropic and Mistral DPAs compared (2026)

The data processing agreements of the four main model providers read on 15 September 2026, the exact logic that makes a DPIA mandatory, a ready-to-fill record of processing entry for an AI agent, and recent decisions from the CNIL, the EDPB and the Italian Garante.

Zakaria El Asri18 min

The starting point

You remain the controller. The model provider is your processor, and its contract sets what you can promise.

In brief

The short answer

For an AI agent built on an API, OpenAI, Anthropic, Mistral AI and Google act as processors (GDPR Article 28) and the company deploying the agent remains the controller. As of 15 September 2026, none of the four trains on data from its paid APIs by default, but Mistral becomes a controller for training unless you opt out (DPA of 27 July 2026). Default retention is up to 30 days at OpenAI and Anthropic, and 55 days for the Gemini API according to Google's usage policies page. Mistral hosts in the EU by default, OpenAI offers EU residency under conditions (+10% on models released from 5 March 2026) and the first-party Claude API offers no EU residency. Transfers rely on standard contractual clauses, and Google is also certified under the Data Privacy Framework.

This guide covers contracts and GDPR documentation. Technical controls (prompt injection, permissions, logging) are in our guide to AI agent security, and the timeline of the EU AI regulation is in the AI Act for businesses.

The table

The OpenAI, Anthropic, Mistral and Google DPAs compared

Every cell comes from the provider page listed in the sources, read on 15 September 2026. Where information is not published or two sources disagree, the cell says so.

CriterionOpenAIAnthropicMistral AIGoogle Gemini
DPA and versionData Processing Addendum, updated 1 January 2026Data Processing Addendum, effective 24 February 2025Data Processing Addendum of 27 July 2026Workspace: Cloud Data Processing Addendum. Paid Gemini API: to be verified
EU contracting entityOpenAI Ireland Ltd (EEA and Swiss customers)Anthropic Ireland, Limited (EEA, Switzerland, UK)Mistral AI SAS, ParisTo be verified
RoleProcessorProcessor, customer is controllerProcessor, but controller for training unless the customer opts outProcessor (Workspace)
Training by defaultNo for the API (since 1 March 2023) and business offersNo: the Commercial Terms bar training on Customer ContentVibe Free and Pro: yes unless opt-out. Vibe Enterprise: no. Studio API: opt-out available. Pro and Team: conflicting sourcesWorkspace and paid API: no. Unpaid API: yes, with human review
Default API retentionUp to 30 days (abuse monitoring)Deleted within 30 days. Policy violations: 2 years (inputs and outputs), 7 years (classifier scores)Default not published, to be verified. Data inaccessible 30 days after termination55 days according to the usage policies page. Grounding with Search and Maps: 30 days, cannot be disabled
Zero data retention (ZDR)Eligible customers, on approval: ZDR or Modified Abuse Monitoring (MAM)Only by separate agreementPaid plans, case by case, stateless endpoints only (excludes Agents, Batch, files, Vibe)Through customer configuration (store=false, no caching, delete files)
EU residencyeu.api.openai.com (EEA and Switzerland) with approved ZDR or MAM, +10% on models released from 5 March 2026. ChatGPT: new Enterprise and Edu workspaces onlyNone first-party: inference us (1.1x) or global, workspace us onlyEU hosting by default, US only through the US endpointVertex AI EU regions according to secondary sources, to be verified. Gemini API: paid services only in the EEA
Transfer mechanismSCCs or adequacy. DPF certification: check the registrySCCs Modules 2 and 3, UK and Swiss addenda. DPF certification: conflicting sourcesSCCs 2021/914 for sub-processors outside the EUGoogle LLC certified under EU-US DPF, UK Extension and Swiss-US DPF, plus SCCs
Sub-processor listopenai.com/policies/sub-processor-listanthropic.com/subprocessorstrust.mistral.ai/subprocessors, including US companiesGoogle Cloud sub-processor page, to be verified
CertificationsSOC 2 Type 2. ISO: to be verified (gated trust portal)ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I and II, HIPAA BAASOC 2 Type II, ISO 27001 and 27701, reports on requestGemini for Workspace: SOC 1, 2 and 3, ISO 27001, 27017, 27018, 27701, 9001, ISO 42001, FedRAMP High
Sources: DPAs, commercial terms, help centres and documentation of the four providers, read on 15 September 2026. 'To be verified': not published or not accessible. 'Conflicting sources': two official or recognised sources disagree.

Reading it

What the table shows

Mistral changes role for training. Its DPA of 27 July 2026 makes Mistral AI a controller for training on inputs, outputs and user feedback, as long as the customer has not opted out. On Vibe Free and Pro, training is on by default. On Team, an admin can switch it off, but the default is unclear: one documentation page says Pro and Team are not used for training, while the help centre says the opposite for Pro. Opt out in writing before going live, and note it in your record.

Anthropic offers no first-party EU residency. The Data residency page of the Claude documentation lists its limits: inference only in us or global, workspace storage only in us, and the workspace geo cannot be changed after creation. The us option is billed at 1.1x the standard rate on Claude 4.6 and later models. On Amazon Bedrock and Google Cloud, the region depends on the endpoint. If EU hosting is a requirement, the choice is made at platform level, a topic covered on our Claude integration page.

Claude documentation Data residency page, 'Current limitations' block: inference geo only us and global, workspace geo only us
Source: platform.claude.com, Data residency documentation, captured 15 September 2026.

OpenAI's EU residency comes with conditions and a price. The eu.api.openai.com endpoint stores and processes data in the EEA and Switzerland, but you first need ZDR or MAM approval and a Modified Retention amendment. Models released from 5 March 2026 cost 10% more on these endpoints. GPU inference stays in region, while some CPU processing may be global. For ChatGPT, residency is only available to new Enterprise and Edu workspaces, so Business workspaces and existing workspaces do not get it. Our Claude vs ChatGPT for business comparison covers the plans.

'Data controls in the OpenAI platform' page, 'Data residency controls' section mentioning a 10% uplift for models released on or after March 5, 2026
Source: developers.openai.com, Your data guide, captured 15 September 2026.

Google is the only US provider in the table whose Data Privacy Framework certification can be checked on its own page. Mistral, an EU company, is out of scope. For OpenAI, a third party reports it absent from the registry as of 8 September 2026; for Anthropic, a German law firm (June 2026) and an aggregator give opposite answers. The dataprivacyframework.gov registry loads with JavaScript and could not be read: check it yourself. Without certification, standard contractual clauses still work, but they require a transfer impact assessment on your side.

Location changes the bill. The 1.1x multiplier at Anthropic and the 10% uplift at OpenAI come on top of token costs. Our guide to Claude API pricing shows how to build them into a budget.

The law

The GDPR articles that apply to an AI agent

ArticleWhat it requiresWhat it means for an AI agent
Art. 28Processors with sufficient guarantees, a contract covering instructions, confidentiality, security, sub-processors, help with data subject rights, deletion at the end, auditsThe model provider's DPA must be signed or accepted and its sub-processor list tracked: a general authorisation gives you a right to object to each addition
Art. 30A written record kept by controller and processor. The under-250-employees exemption does not apply to risky, non-occasional or special-category processingAn agent in production is non-occasional processing: it gets its own entry
Art. 35A DPIA before processing likely to result in high risk, especially with new technologies: description, necessity, risks, measures, DPO adviceTo be done before go-live, using the logic below
Art. 22Right not to be subject to a decision based solely on automated processing with legal or similar effects. Exceptions need safeguards: human intervention, right to contestAn agent that rejects an application, a file or a service without human sign-off is in scope
Art. 44 to 46Transfers outside the EEA only under an adequacy decision (including the DPF for certified companies) or appropriate safeguards (SCCs, BCRs)Every call to a model hosted outside the EU is a transfer: record the mechanism
Paraphrase of Regulation (EU) 2016/679. Article 28 reread on 15 September 2026; full text on EUR-Lex.

Impact assessment

Does your AI agent need a DPIA?

The CNIL, the French data protection authority, applies two tests in sequence. First: is the processing on its list of processing operations that require a DPIA (deliberation 2018-327 of 11 October 2018)? If so, the DPIA is mandatory. If not, second test: does the processing meet at least two of the nine criteria in the WP29 guidelines (WP248), endorsed by the EDPB? A separate list, deliberation 2019-118, sets out the processing that is exempt.

Decision tree: CNIL list 2018-327, then at least 2 of the 9 WP248 criteria, leading to a mandatory DPIA or a record entry only
Lumyniq diagram based on CNIL deliberation 2018-327 and the WP248 guidelines.

The nine criteria, as the CNIL presents them (page in French):

CNIL page 'Quand est-ce qu'une analyse d'impact est obligatoire ?' listing the two conditions and the nine WP29 criteria
Source: cnil.fr, 'Ce qu'il faut savoir sur l'analyse d'impact relative à la protection des données (AIPD)', captured 15 September 2026.

Applied to three common agents:

AgentCriteria metConclusion
Customer support chatbot (orders and products)Innovative use (a cautious reading for a generative model). Large scale depending on volume. No sensitive data expectedTo be decided: 1 certain criterion, a 2nd depending on volume. Document the reasoning in the record
CV pre-screeningEvaluation or scoring, innovative use, exclusion from a contract, automated decision if rejections go out without a humanDPIA mandatory (at least 3 criteria)
Patient intake and triage at a clinicSensitive data (health), vulnerable people (patients), innovative useDPIA mandatory (3 criteria)
Lumyniq reading of the WP248 criteria, 15 September 2026. Also check CNIL list 2018-327 for your case.

CV screening also brings in Article 22 and Annex III of the AI Act; see our guide to screening CVs with AI and our page on AI for HR. For patient intake, see AI in healthcare, and for law firms pre-qualifying client requests, AI for legal.

On method, the EDPB announced a DPIA template version 1.0 on 10 March 2026, open for consultation until 9 June 2026 and optional to use, according to its press release. The CNIL also provides its PIA software, downloadable from its DPIA page.

Template

The record of processing entry for an AI agent, ready to fill

The CNIL simplified record template (an .ods file published on 23 July 2019) still works. Here are the fields filled in for a common example: an agent that reads incoming web form requests, classifies them, drafts a reply and creates a CRM record.

FieldFilled-in exampleAI-specific point
PurposeQualify and route incoming requests, draft a reply reviewed by an adviserOne purpose per agent. Reusing conversations for something else (training, marketing) is a new purpose
Legal basisPre-contractual steps at the request of the person (Art. 6(1)(b)), or legitimate interest with the 3-step testIf the provider trains on the data, its own legal basis does not cover yours
Categories of people and dataProspects and customers: identity, contact details, message content, CRM historyFree text can contain unsolicited sensitive data: plan filtering or deletion
RecipientsSales team; model provider (processor); orchestrator host; CRM vendorList the provider's sub-processors by linking its public list, with the date you checked it
Transfers outside the EUDepending on provider: none (Mistral, EU endpoint) or United States under SCCs or the DPFState the configured inference and storage region
RetentionUnconverted requests: period set in your retention policy. Provider logs: up to 30 days at OpenAI and Anthropic (or ZDR)Separate your logs, the orchestrator logs and the provider logs
Security measuresAPI keys in a vault, named accounts, call logging, encryption, access reviewsAgent-specific controls are detailed in our security guide
Human oversightNothing is sent without adviser approval; rejections are always decided by a personAddresses Article 22 and the error cascade risk raised by the CNIL
Lumyniq template built on the Article 30 fields and the CNIL simplified record, 15 September 2026.

When the agent talks to people, add a line on the information given to them: since 2 August 2026, Article 50 of the AI Act requires disclosing that people are interacting with an AI (see the AI agent transparency obligation).

Responsibilities

Agency, client, model provider: who is responsible for what

No text specifically addresses an agency building an AI agent for a client. What follows is our reading of Article 28, to be checked with your DPO.

Set-upClientAgencyModel provider
The client opens the API account and hosts the agentControllerProcessor during build and maintenance if it accesses the data, otherwise out of scopeDirect processor of the client
The agency runs the agent and holds the API accountControllerProcessor of the clientSub-processor: the agency needs the client's authorisation and must flow down the obligations
The agency reuses the data for its own purposes (improving a product)Controller for its purposeController for that reuse, with its own legal basisDepends on its contract with the agency
Lumyniq reading of GDPR Article 28, an inference not settled by any authority, 15 September 2026.

In the second set-up, the agency remains liable to the client for the model provider's failures. That is why the agency contract should name the provider, the region and the retention option chosen. Our custom AI agent page describes how these choices come up at design time.

Guidance

What the CNIL and the EDPB say

CNIL Q&A of 18 July 2024 on using a generative AI system. The CNIL asks organisations to clarify who is provider and who is deployer, sign a processor contract, carry out a DPIA, prefer on-premise deployment for sensitive data, set lists of allowed and banned uses, involve the DPO and train users.

CNIL recommendations on developing AI systems, finalised 22 July 2025. They add sheets on the status of models under the GDPR, annotation and security. They mainly target those who train models; work on the allocation of responsibilities along the value chain has been announced.

CNIL and CIANum note on agentic AI, 20 July 2026. An exploratory note that identifies four risks: data flowing across services, persistent memory drifting into profiling, unclear allocation of responsibility and error cascades. It points out that the GDPR and the AI Act already apply to agents.

EDPB Opinion 28/2024 of 18 December 2024, requested by the Irish Data Protection Commission. Three points: whether a model is anonymous is assessed case by case; legitimate interest requires the three-step test; unlawful processing during development can affect the lawfulness of deployment. For a deployer, that is a reason to ask the provider how its model was trained.

Coming next. The EDPB opened consultation on draft Guidelines 02/2026 on anonymisation on 7 July 2026 (until 30 October 2026), and joint EDPB and Commission guidelines on the GDPR and the AI Act are expected at the end of 2026. No EDPB position specific to AI agents was found as of 15 September 2026.

Enforcement

The OpenAI and DeepSeek decisions

CaseDateMeasureOutcome
Garante vs OpenAIDecision no. 755 of 2 November 2024, announced 20 December 2024€15M and a 6-month information campaign: 2023 breach not notified, no legal basis for training, transparency, no age verificationAnnulled by the Tribunale di Roma on 18 March 2026 (R.G. 4785/2025) on jurisdiction grounds, as reported by the Italian legal press
Garante vs DeepSeek30 January 2025Urgent, immediate limitation of the processing of Italian users' dataNo fine found as of 15 September 2026
Sources: Garante per la protezione dei dati personali press releases; Federprivacy for the annulment. Read on 15 September 2026.

The annulment ground matters: OpenAI set up its main establishment in Ireland on 15 February 2024, which brings in the one-stop-shop and the Irish authority. The court did not rule on the merits. For a European business, the practical point is that the contracting entity (OpenAI Ireland Ltd, Anthropic Ireland or Mistral AI SAS) determines the provider's lead authority, while your own national authority remains competent for your own processing.

Interplay

GDPR and the AI Act: the DPIA and the fundamental rights impact assessment

  • Article 26(9) of Regulation (EU) 2024/1689: deployers of high-risk systems use the information supplied by the provider under Article 13 to carry out their DPIA under GDPR Article 35.
  • Article 27(1): the fundamental rights impact assessment (FRIA) only applies to public bodies, private entities providing public services, and the uses in Annex III point 5(b) and (c), namely credit scoring and life and health insurance pricing.
  • Article 27(4): where a DPIA already exists, the FRIA complements it and can reuse its content.

Most business agents (support, qualification, drafting) are not high-risk, so neither Article 26(9) nor Article 27 applies: that is our reading. GDPR Article 35 applies whenever the criteria are met. CV screening falls under Annex III, whose obligations apply from 2 December 2027 following the Digital Omnibus (Regulation 2026/1744, in force 27 July 2026).

Before you sign

Ten checks before choosing a model provider

  1. Get the dated version of the DPA and the contracting entity (Ireland for OpenAI and Anthropic, France for Mistral).
  2. Check the stated role, and any clause that makes the provider a controller (training, feedback, improvement).
  3. Opt out of training in writing where needed, and keep the proof.
  4. Note the default retention period and ask for ZDR if your data justifies it, checking which features it excludes.
  5. Configure the inference and storage region, and price in any multiplier (1.1x at Anthropic, +10% at OpenAI).
  6. Identify the transfer mechanism and, without a verified DPF certification, document a transfer impact assessment.
  7. Download the sub-processor list and subscribe to change notifications.
  8. Ask for the certification reports (SOC 2, ISO 27001) instead of relying on a logo.
  9. Run the agent through both DPIA tests (CNIL list, 2 of 9 criteria) before go-live.
  10. Create the record entry, including human oversight and information given to people.

About

Who wrote this guide

Lumyniq is a Paris-based agency that builds custom AI agents, Claude integrations and n8n workflows for small and mid-sized businesses, with a focus on real estate, legal, healthcare and HR. Every project starts with an audit of the process, which covers the choice of model provider, region and GDPR documentation, before any quote.

FAQ

Frequently asked questions about the GDPR and AI agents

Yes, for their business offers and APIs. Their data processing addendums (DPAs) name them as processors and the customer as controller. One exception as of 15 September 2026: the Mistral AI DPA dated 27 July 2026 makes Mistral a controller for training its models on inputs, outputs and feedback, unless the customer opts out.

Related guides

Read next

Sources

Links verified at publication. Regulatory texts change — always defer to the official source.

Let's talk about your project

A question, a project, an idea? We respond within 24h. Free audit, no commitment.

Contact details