NACH
·Tarek Nachnouchi

Are your AI vendor contracts compliant? What the DPA needs to cover

The absence of a data processing agreement with an AI publisher puts a company in immediate GDPR violation. A governance risk rarely checked, unlike the tool's usage itself.

An employee who sends personal data to an artificial intelligence tool, with no data processing agreement signed between their company and that tool's publisher, puts their employer in immediate GDPR violation. This risk, known in theory by most leaders, is nonetheless rarely checked in practice, even though it is one of the simplest compliance points to fix once identified.

A Data Processing Agreement contractually governs how a subcontractor, in this case the AI tool's publisher, handles the personal data entrusted to it. Without this document, no contractual guarantee governs what the publisher actually does with the data sent, how long it retains it, who it might share it with, or how it secures it. This contractual gap alone constitutes a GDPR failure, independent of the publisher's actual practices.

This risk particularly concerns free, consumer-facing versions of AI tools, which almost never come with a data processing agreement formalized for professional use. Several surveys conducted in 2026 converge on a similar finding, a majority of French employees use AI tools not approved by their company at least once a week, often through personal accounts created outside any professional framework, and therefore with no DPA tied to the professional use made of them.

A DPA sufficient to cover this risk does not need to be exhaustive to the point of requiring a specialized law firm for every tool used, but it must cover an identifiable minimum baseline. The precise nature and purpose of the processing carried out by the tool, the retention period for data sent, the security guarantees applied by the vendor, and the conditions for deleting or returning data upon contract termination are the four elements to systematically check before any professional use of an AI tool involving personal data.

A paid professional subscription markedly increases the likelihood that a compliant DPA exists, without automatically guaranteeing it. Some publishers offer paid subscriptions without providing an explicit or sufficiently detailed DPA, which means a company cannot simply assume compliance just because it pays for a service, it must explicitly verify the existence and content of the corresponding document.

The most effective approach for an SMB is to first build a complete inventory of the AI tools actually used across the organization, including those spontaneously adopted by teams outside any official approval, which most often escape any contractual check entirely. This inventory almost always reveals uses unknown to leadership, each representing a potential compliance risk until individually checked, tool by tool.

This risk stays largely invisible until an incident or an audit concretely reveals it, which explains why it rarely tops an SMB's spontaneous priority list. But its lack of immediate visibility does nothing to reduce its real exposure in a dispute with a customer, a candidate, or a CNIL inspection, where artificial intelligence and personal data processing now rank among the priority areas of vigilance.

This is what the Framing step of the IMPACT method should systematically include, a review of the existence and content of DPAs for every AI tool used in the company, whether officially approved by leadership or spontaneously adopted by teams with no formal approval. Vendor contract compliance is not the most visible topic in AI governance, yet it is often the one that most directly exposes a company that never paid it any attention. A five-business-day diagnostic checks the compliance of your AI vendor contracts.

Let's take action

Ready to structure your AI transformation?

Free 30-minute diagnostic to identify your top priorities and estimate concrete ROI for your organization.

Book my free diagnostic →

Related articles