GDPR check

Is Miro GDPR compliant? What universities should check

Miro is a collaborative whiteboard used for seminars, group work, research workshops and course design. This page sets out what Miro publicly documents about data residency, its data processing addendum, subprocessors, AI features and transfers, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Miro is operated by RealtimeBoard, Inc. in San Francisco, with an EU representative in Amsterdam. It publishes a customer data processing addendum that relies on the EU-US Data Privacy Framework, with standard contractual clauses as a fallback, and a dated subprocessor list. EU data residency (Ireland, with backup in Germany) is available on all plans, although AI processing and some other features can run outside the region. Whether Miro may use your inputs to improve its AI depends on your plan: consent on enterprise contracts, an objection route on other plans. For a university, the plan and the AI settings matter more than the headline policy.

What Miro documents publicly

This summary reflects Miro's own documentation as read on 7 October 2026.

TopicWhat the vendor statesSource
Company and establishmentDocumented RealtimeBoard, Inc. dba Miro, San Francisco, USA. Its representative in the EU is RealtimeBoard BV in Amsterdam. Affiliates include entities in Germany, France, Denmark and the UK.Privacy Policy [1], Subprocessor list (PDF) [3]
Where data is stored and processedDocumented EU data residency is available for all plans, with no additional cost for the EU; US, Australian and Japanese residency are Enterprise only. The EU primary data centre is in Ireland and the backup in Germany. Boards, board content, metadata and organisation settings are stored in region. Miro notes that AI processing may occur outside the region, live video calls can be processed globally, and third-party integrations may store data elsewhere.Data residency at Miro [4]
Data processing agreementDocumented A Customer Data Processing Addendum (effective 17 September 2024) appended to the Master Cloud Agreement or the Terms of Service, covering processing on documented instructions, audits and deletion or return of customer personal data.Customer DPA [2]
SubprocessorsDocumented A list last updated 8 July 2026 naming Amazon Web Services, Anthropic, Braze, Eleven Labs, Gainsight, Google, Intercom, Microsoft, OpenAI, PartnerHero, Skilljar and Zendesk, all with US locations, plus a note that storage may be limited to certain jurisdictions under a data residency offering. Customers can subscribe to at least ten days' notice of new subprocessors and object within 30 days.[3], [2]
International transfers (DPF, SCCs)Documented RealtimeBoard Inc. states that it complies with the EU-US DPF, the UK Extension and the Swiss-US DPF (status read from the vendor's privacy policy). The DPA applies the DPF to restricted transfers to the US and incorporates the 2021 SCCs where the DPF does not apply.[1], [2]
AI features and training on customer contentPlan-dependent Under the AI Terms, customers on a Master Cloud Agreement (for example, the Enterprise plan) are asked for consent before inputs and outputs are used to improve AI features, including training. On free, starter, business or equivalent plans, Miro will provide reasonable means to object. Third-party models come from Amazon, Anthropic, OpenAI and Stability AI, hosted via AWS, Microsoft Azure or the providers.AI Terms [5], [3]
Retention and deletionDocumented Customer content and personal data are retained according to the customer's instructions and agreement. The trust centre states that customer content is purged 30 days after contract termination.[1], Trust Center [6]
Security certificationsDocumented The trust centre lists ISO 27001, SOC 2 Type II and ISO/IEC 42001 (AI management), and offers a SOC 3 report. Further documentation is available on request.[6]
Institution controls (SSO, admin, education licence)Plan-dependent Free Student and Educator plans; an Institution plan, starting at 50% off the regular price, with an organisation-wide account, SSO and advanced administration. Enterprise administrators can enable or disable AI features at organisation or team level, and Enterprise customers can use key management options including bring-your-own-key.Miro for Education [7], [6]

There is a small difference in wording between sources on AI training. The trust centre summary says customer data is excluded from training and that only opted-in, non-enterprise user data may be used [6], while the AI Terms describe an objection route for non-enterprise plans [5]. For contractual purposes the AI Terms are the text to rely on, and a university should confirm with Miro how they apply to its plan.

What this means for a university

Validemic's analysis

Student data. Boards collect names, avatars, sticky notes, comments and uploaded files, and in workshops sometimes personal opinions or research data. Teachers often invite students without accounts, which is convenient but makes it harder to know who saw what. Most of the data protection risk comes from what people put on boards, so guidance to staff is as important as the contract.

Minors. Rarely relevant in higher education, apart from outreach activities with school pupils.

DPIA likelihood. Ordinary teaching use on an institutional plan with EU residency is unlikely, on its own, to trigger a DPIA under Article 35 GDPR [8]. Research workshops with sensitive data, large-scale use of AI features or boards that profile students would change that assessment.

Transfers. EU residency keeps stored board content in Ireland and Germany [4], but every subprocessor on the list has a US location [3] and AI processing can leave the region. The DPF adequacy decision of 10 July 2023 covers transfers to certified US companies [9], and Miro's DPA adds SCCs as a fallback [2]. Verify the DPF listing on the official list before relying on it.

Plan tier. This is the decisive point for Miro. Free educator and student accounts, team plans and an Institution or Enterprise contract differ on AI training terms, administrative control, SSO and residency options. Individual teachers signing up with a university email do not automatically put the institution's data under its own contract.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Miro before approving it

  1. Which agreement will govern our use: the Master Cloud Agreement or the Terms of Service? Does the Institution education plan count as a Master Cloud Agreement for the AI Terms?
  2. Can we set EU data residency for our whole organisation, and how are existing boards created by staff on personal plans migrated?
  3. Which AI features process data outside the EU, through which model providers, and can we disable them for the whole organisation?
  4. Can we confirm in writing that no inputs or outputs from our organisation will be used to improve or train AI models?
  5. How do we subscribe to subprocessor change notices, and to which address should they go?
  6. What audit logs are available to administrators, including AI interaction logs, and where are they stored?
  7. How are boards shared with anonymous or external participants controlled by administrators?
  8. Can we obtain the ISO 27001 certificate, SOC 2 Type II report and ISO 42001 certificate scope?

The EU AI Act angle

Miro's AI features (generating content, summarising boards, clustering sticky notes) are general-purpose productivity functions. Used in ordinary teaching, they do not match the education uses listed as high-risk in Annex III, such as evaluating learning outcomes [10]. If a teacher used AI outputs to grade group work, that would deserve a closer look. For now, the main obligation is Article 4 on AI literacy, which requires deployers to take measures to support the AI literacy of staff using AI systems on their behalf [11]. Emotion recognition in education is prohibited under Article 5(1)(f) [12], and we found no such feature described in Miro's documentation. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [13].

Sources

  1. Miro Privacy Policy (effective 1 August 2025), retrieved 7 October 2026
  2. Miro Customer Data Processing Addendum (effective 17 September 2024), retrieved 7 October 2026
  3. Miro Sub-processors and Third Party AI Model Providers (PDF) (last updated 8 July 2026), retrieved 7 October 2026
  4. Data residency at Miro, Miro Help Center, retrieved 7 October 2026
  5. Miro AI Terms, retrieved 7 October 2026
  6. Miro Trust Center, retrieved 7 October 2026
  7. Miro for Education, retrieved 7 October 2026
  8. Regulation (EU) 2016/679 (GDPR), Article 35, text read from the Publications Office copy, retrieved 7 October 2026
  9. EU-US data transfers, European Commission, retrieved 7 October 2026
  10. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  11. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  13. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Miro's privacy policy, customer DPA, subprocessor and AI model provider list, AI Terms, trust centre, data residency help article and education page, plus the relevant EU legal texts, on 7 October 2026. Statements about Miro come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Miro complies with the GDPR. If you spot an error or Miro has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Miro GDPR compliant?

No tool is GDPR compliant on its own. Miro publishes a customer data processing addendum, says it is certified under the EU-US Data Privacy Framework with SCCs as a fallback, and offers EU data residency on all plans. Compliance for a university depends on its plan, contract, AI settings and how teachers use boards with students.

Does Miro store data in the EU?

Miro says EU data residency is available for all plans at no additional cost, using a primary data centre in Ireland and a backup in Germany. Boards, board content and organisation settings are stored in region, but AI processing, live video calls and third-party integrations can take place outside the chosen region.

Does Miro train AI on customer boards?

It depends on the plan. Miro's AI Terms say that for customers under a Master Cloud Agreement, such as the Enterprise plan, Miro will ask for consent before using inputs and outputs to improve its AI features. For free, starter, business or equivalent plans, Miro will instead provide reasonable means to object.

Does Miro have an education plan with SSO?

Miro's education page lists free plans for students and educators and an Institution plan, starting at 50% off the regular price, that includes an organisation-wide account with SSO and advanced administration.

Do universities need a DPIA for Miro?

Not always. A screening is sensible, and a DPIA becomes more likely if boards hold research data, sensitive student information or are used with AI features at scale. Article 35 GDPR requires one where processing is likely to result in a high risk.