GDPR check

Is Mentimeter GDPR compliant? What universities should check

Mentimeter is a Swedish tool for live polls, quizzes and Q&A in lectures. This page sets out what Mentimeter publicly documents about hosting, its position on data processing agreements, subprocessors, AI features and security, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Mentimeter AB (publ) is a Swedish company in Stockholm, so it is directly subject to the GDPR and supervised in the EU. It hosts customer data at rest on AWS in Ireland by default, publishes separate lists of processors and subprocessors, and says it has carried out transfer impact assessments for every subprocessor that transfers data outside the EU/EEA. Its terms say content is not used to train AI models. The point that needs attention is the contract: Mentimeter's published statement explains that it acts as a controller for the personal data it relies on and does not sign DPAs for that data. A university should settle the roles for presentation content and participant responses before rolling it out.

What Mentimeter documents publicly

This summary reflects Mentimeter's legal pages, trust centre and pricing pages as read on 7 October 2026.

TopicWhat the vendor statesSource
Company and establishmentDocumented Mentimeter AB (publ), a Swedish limited liability company (registration number 556892-5506), Tulegatan 11, Stockholm. It is the controller for the processing described in its privacy policy.Privacy Policy [1]
Where data is stored and processedDocumented Customer data at rest is hosted in the EU by default, on AWS servers in Ireland, replicated across availability zones in the hosting region. Mentimeter describes its hosting as multi-regional. Limited data may be transferred outside the EU/EEA.[1], GDPR transparency statement [2]
Data processing agreementPlan-dependent Mentimeter's DPA statement says it is a controller for the personal data it depends on to provide the service (for example account email addresses) and that, in its view, signing a DPA for that data is neither required nor appropriate. The Enterprise terms add that where Mentimeter is a controller, it is independently responsible for complying with data protection law. A processor agreement for presentation content and participant responses was not found in public documentation (checked 7 October 2026).DPA statement [3], Enterprise terms [4]
SubprocessorsDocumented A subprocessor list naming Amazon Web Services EMEA SARL (hosting of presentation contents), ClickHouse, Cloudflare, Vercel, Lunaweb (Cloudconvert, Germany), Imgix, Ably, Knock Labs, Snowflake Computing Netherlands and OpenAI Ireland Ltd (AI). A separate processors list covers data for which Mentimeter is controller, such as analytics and customer communication tools. Customers can subscribe to notices of new subprocessors.Subprocessors [5], Processors [6]
International transfers (DPF, SCCs)Documented As an EU company, Mentimeter does not need the EU-US DPF for its own operations. It says transfers outside the EU/EEA rely on the 2021 SCCs or an adequacy decision, that it has carried out transfer impact assessments on all subprocessors transferring data outside the EU/EEA, and that its first choice is EU-based providers.[1], [2]
AI features and training on customer contentDocumented The standard terms say Mentimeter does not and will not permit any third party to use your content or user data to improve or train AI models. The Enterprise terms say Mentimeter does not, and will not permit any third party to, use customer content or data for that purpose. Output from AI features is treated as the user's or customer's data.Terms [7], [4]
Retention and deletionDocumented Users can delete Mentis and results at any time, and free or single-account users can delete their whole account. Participant device and log data used to run Mentis and prevent abuse is archived and deleted within 90 days. Other retention periods are listed per purpose in the privacy policy.[1]
Security certificationsDocumented Mentimeter describes itself as ISO 27001 (ISMS) certified. Its security policy (last updated 28 May 2025) describes annual penetration testing by independent experts and hosting in AWS data centres accredited under ISO 27001 and SOC 1 and SOC 2.[2], Security policy [8]
Institution controls (SSO, admin, education licence)Plan-dependent The education pricing page lists Free, Basic and Pro plans and a Campus plan with single sign-on and SCIM provisioning, plus the option to require participants to log in with SSO. Organisations can ask for staff accounts using an institutional email to be moved into their Team Workspace.Education pricing [9], [1]

What this means for a university

Validemic's analysis

Student data. Typical use collects little: students join with a code and answer polls, often without giving a name. The personal data risk rises when presenters ask for names or emails, collect open-text answers about personal experiences, or run recurring surveys. Mentimeter's privacy policy places responsibility for personal data that users and participants put into Mentis with the user or, for team members, their organisation [1]. That makes guidance to teachers about what not to ask important.

Minors. Mentimeter says its services are not directed at children under 13 [1]. At university this matters only for outreach activities with school pupils.

The controller question. Mentimeter's position is clearly explained and, for account and billing data, common among SaaS providers [3]. For content the university's staff and students put into Mentis, many DPOs will still expect a processor arrangement under Article 28 GDPR, which requires a contract when a processor acts on a controller's behalf [10]. The difference matters for who decides retention, who answers access requests and who may use the data for other purposes. This is a negotiation point, not a red flag, and it is better settled in writing before a campus-wide licence.

DPIA likelihood. Ordinary anonymous polling is unlikely to reach the Article 35 GDPR threshold of likely high risk [10]. Collecting sensitive opinions with identifiers, or using it for graded quizzes linked to student identities, would call for at least a documented screening.

Transfers and plan tier. EU hosting by default [2], an EU legal entity and documented transfer assessments give Mentimeter a comparatively simple transfer picture, credit where it is due. Several subprocessors are still US companies [5]. SSO and participant verification come only with the Campus plan [9], so free and individual paid accounts sit outside institutional control.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Mentimeter before approving it

  1. For presentation content and participant responses created under our Campus licence, does Mentimeter act as our processor or as an independent controller? Can we sign terms that reflect that role?
  2. If Mentimeter is a controller for some data, for which purposes does it use that data, and can we limit product analytics on our staff accounts?
  3. Which data leaves the EU/EEA in practice, through which subprocessors, and can we see a summary of the transfer impact assessments?
  4. Which AI features send content to OpenAI Ireland Ltd, where is it processed, and can administrators disable AI features?
  5. Can we require participant login through our SSO for selected sessions, and what is then stored about each participant?
  6. How are existing staff accounts on personal plans moved into our Team Workspace, and who can see their past Mentis?
  7. Can we receive the ISO 27001 certificate and its scope?
  8. What default retention applies to Mentis and results that staff never delete?

The EU AI Act angle

Mentimeter's AI features help build presentations and summarise responses. They are general productivity functions and do not match the education uses listed as high-risk in Annex III, such as evaluating learning outcomes or monitoring students during tests [11]. If quiz results produced with AI assistance were used for grading, that would deserve a closer look. The obligation that applies now is Article 4: deployers must take measures to support the AI literacy of staff using AI systems on their behalf [12]. Emotion recognition in education is prohibited by Article 5(1)(f) [13]; we found no such feature in Mentimeter's documentation. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [14].

Sources

  1. Mentimeter Privacy Policy (last updated 14 September 2026), retrieved 7 October 2026
  2. Mentimeter GDPR transparency statement, retrieved 7 October 2026
  3. With reference to requests for Data Processing Agreements, Mentimeter, retrieved 7 October 2026
  4. Mentimeter Enterprise terms, retrieved 7 October 2026
  5. Mentimeter Subprocessors, retrieved 7 October 2026
  6. Mentimeter Processors, retrieved 7 October 2026
  7. Mentimeter Terms, retrieved 7 October 2026
  8. Mentimeter Security policy (last updated 28 May 2025), retrieved 7 October 2026
  9. Educational Pricing, Teachers and Students, Mentimeter, retrieved 7 October 2026
  10. Regulation (EU) 2016/679 (GDPR), Articles 28 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  11. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  12. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  13. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  14. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Mentimeter's privacy policy, GDPR transparency statement, DPA statement, standard and Enterprise terms, processor and subprocessor lists, security policy and education pricing page, plus the relevant EU legal texts, on 7 October 2026. Statements about Mentimeter come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Mentimeter complies with the GDPR. If you spot an error or Mentimeter has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Mentimeter GDPR compliant?

No tool is GDPR compliant on its own. Mentimeter AB is a Swedish company, hosts customer data at rest in the EU (Ireland) by default and publishes subprocessor lists and a GDPR transparency statement. It explains that it acts as a controller for the personal data it needs to run the service and does not sign DPAs for that data. A university should agree how responsibilities are split.

Where does Mentimeter store data?

Mentimeter says customer data at rest is hosted in the EU by default, on AWS servers in Ireland, and that it offers multi-regional hosting. Some limited data goes to providers outside the EU/EEA under standard contractual clauses or an adequacy decision.

Will Mentimeter sign a data processing agreement?

Mentimeter's published DPA statement says it is a controller for the personal data it depends on, such as users' email addresses, and that signing a DPA covering that data would be neither required nor appropriate in its view. Whether a processor agreement is available for presentation content and participant responses was not found in public documentation, so ask during procurement.

Does Mentimeter use responses to train AI?

Mentimeter's terms say it does not and will not permit any third party to use your content or user data to improve or train AI models. Its Enterprise terms say Mentimeter does not, and will not permit any third party to, use customer content or data for that purpose. AI features use OpenAI Ireland Ltd as a subprocessor.

Does Mentimeter support SSO for universities?

Mentimeter's education pricing page lists single sign-on and SCIM provisioning, and the option to verify participants with SSO, on its Campus plan.