GDPR check

Is DeepL GDPR compliant? What universities should check

DeepL is the translation tool many European researchers, administrators and students reach for first, and DeepL Write is increasingly used to polish English texts. This page sets out what DeepL publicly documents about the free and Pro versions, its data processing agreement, infrastructure and AI training, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

DeepL SE is a German company based in Cologne, so it is directly subject to the GDPR. The key question is which version people use. For the free DeepL Translator and DeepL Write, DeepL says it processes texts for a limited period to train and improve its models, and its terms forbid translating texts that contain any personal data. For DeepL Pro, DeepL says texts are only stored temporarily, are not used for training, and are covered by a data processing agreement that forms part of the Pro terms. In April 2026 DeepL added Amazon Web Services as a sub-processor and said it would no longer process data exclusively within Europe, while offering Europe-only set-ups on request. A university should license Pro, check the hosting configuration in its contract and tell staff and students not to use the free version for personal data.

What DeepL documents publicly

The table below summarises DeepL's privacy policy, Pro terms, security page, plan page and company blog, all read on 7 October 2026. DeepL's Trust Centre, which hosts the DPA and further security documents, refused our automated request on that date, so we could not read those documents directly.

TopicWhat the vendor statesSource
Company and establishmentDocumented DeepL SE and DeepL AI GmbH, Maarweg 165, 50825 Cologne, Germany, are named in the privacy policy, which also names an external data protection officer. The Pro terms are concluded with DeepL SE.Privacy Policy [1], Pro terms [2]
Where data is stored and processedPlan-dependent On 23 April 2026 DeepL announced it was adding AWS as a sub-processor alongside its European infrastructure, so data would no longer be processed exclusively within Europe. It offers to configure solutions for customers with data residency requirements so their data never leaves Europe. The Pro terms say the processing location may depend on where the customer and its users are and on infrastructure capacity. The privacy policy, read the same day, still says document translation in Pro and the free Translator is processed on DeepL's infrastructure in the EEA.DeepL blog [4], [2], [1]
Data processing agreementPlan-dependent The Pro terms say transfers of personal data to DeepL through the services are governed by DeepL's DPA, which forms an integral part of the agreement and is downloadable from the Trust Centre. The free versions are not covered: users may not submit personal data there. The Pro terms also say customers on the free API Developer plan must not process personal data with the API.[2], [1]
SubprocessorsPartly documented AWS is named as a sub-processor in the April 2026 announcement. The privacy policy names other providers for specific purposes, such as Stripe for payments and AWS EMEA SARL for DeepL Voice for Meetings. A full subprocessor list was not found on the public website (checked 7 October 2026); DeepL points to its Trust Centre.[4], [1]
International transfers (DPF, SCCs)Unclear As an EU company, DeepL does not rely on the EU-US Data Privacy Framework for its own operations. The transfer mechanism for any processing by AWS outside Europe was not found in public documentation (checked 7 October 2026); it is likely set out in the DPA, which we could not read.[4], [2]
AI features and training on customer contentPlan-dependent Free Translator and Write: DeepL processes uploaded content and its translations or improvements "for a limited period of time to train and improve" its models. Pro: the privacy policy says texts are not used to improve the quality of DeepL's services, and the security page says texts are "never stored or used for model training without your consent".[1], Pro data security [3]
Retention and deletionPlan-dependent Pro texts and documents are not stored permanently, are kept only as long as needed to produce and send the result, and are deleted once the service is performed. Customer translations that a customer asks DeepL to store are deleted 90 days after the agreement ends. For the free versions, the retention period for training use is described only as "limited".[1], [2]
Security certificationsDocumented DeepL lists ISO 27001, SOC 2 Type 2 and Germany's BSI C5 Type 2 attestation, plus HIPAA alignment. Its plan page lists ISO 27001, SOC 2 Type 2, TLS encryption and a bring-your-own-key option for Enterprise.[4], [3], Plans [5]
Institution controls (SSO, admin, education licence)Plan-dependent Team administration is available from two users; single sign-on is listed for Team and Business plans from 50 users and for Enterprise. With SSO, the organisation sends the user's email address and name to DeepL. A dedicated education plan was not found on DeepL's own plan page (checked 7 October 2026), although sector buyers such as SWITCH in Switzerland resell DeepL Pro to universities.[5], [1], SWITCH [6]

One point deserves care. SWITCH, which has offered DeepL Pro to Swiss universities since 2021, wrote in November 2025 that DeepL's servers are located in Europe [6]. That was accurate for the time, but it predates DeepL's April 2026 announcement about AWS [4]. Internal guidance written before mid-2026 may need updating.

What this means for a university

Validemic's analysis

The free versus Pro line is the whole story. DeepL is unusually clear about the difference, which is to its credit. The free version trains on input and is off limits for personal data by DeepL's own terms [1]. Almost everything a university translates contains personal data: emails with names, reference letters, student appeals, interview transcripts, grant reports naming staff. In practice, a university that has not licensed Pro has staff using the free version for exactly these texts. Licensing Pro, providing SSO and saying plainly in guidance that the free version is not for work documents closes most of the gap.

DeepL Write and student work. Write improves texts rather than translating them, so it raises the same data question plus an academic integrity one. Students pasting thesis chapters or peer feedback into free Write are submitting that text for model training under DeepL's free terms [1]. Course guidance should say which version is approved and for what.

Hosting has changed. Until 2026 a common argument for DeepL was that processing stayed in Europe. DeepL's own announcement changes that default and offers Europe-only processing as a configuration [4]. Under Article 28 GDPR, the processor contract must set out the subject matter and conditions of processing, including authorisation of sub-processors [7]. Ask for the current subprocessor list and confirm in writing whether your licence is configured to keep data in Europe.

DPIA likelihood. Translating routine administrative texts on a Pro licence is unlikely to reach the Article 35 threshold of likely high risk on its own [7]. Large-scale translation of health, disciplinary or research interview data, or processing outside Europe without a clear transfer basis, would justify at least a documented screening.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask DeepL before approving it

  1. Which version of the DPA applies to our licence, and can we receive the current subprocessor list with locations and transfer mechanisms?
  2. Is our account configured so that texts, documents and Write content are processed only in Europe, and is that commitment in the contract or only in an account setting?
  3. For any processing by AWS outside the EEA, which transfer mechanism applies, and is there a transfer impact assessment?
  4. How long are Pro texts and documents held in memory or temporary storage, and do logs contain any content?
  5. Can we enforce SSO for all staff and students using our licence, and block personal free accounts on institutional email addresses?
  6. Are glossaries and customer training data stored, where, and how are they deleted at the end of the contract?
  7. Does DeepL Voice for Meetings, if we enable it, rely on other subprocessors such as Microsoft or AWS, and with what retention?
  8. Can we obtain the ISO 27001 certificate, SOC 2 Type 2 report and C5 attestation under NDA?

The EU AI Act angle

Machine translation and text improvement are general-purpose productivity uses, not the education uses listed as high-risk in Annex III, such as evaluating learning outcomes or monitoring students during tests [8]. If a department used DeepL to translate exam answers before marking, the translation would sit inside an assessment process and deserves a closer look, but the tool itself would not become high-risk. The obligation that applies today is Article 4: deployers must take measures to support the AI literacy of staff using AI systems on their behalf [9]. For translation, that means teaching people that fluent output can still change meaning, especially in legal and medical texts. We found nothing in DeepL's documentation suggesting emotion recognition, which Article 5(1)(f) prohibits in education [10]. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [11].

Sources

  1. DeepL Privacy Policy, retrieved 7 October 2026
  2. DeepL Pro Terms and Conditions, retrieved 7 October 2026
  3. DeepL Pro data security, retrieved 7 October 2026
  4. We're expanding DeepL's data infrastructure, DeepL blog, 23 April 2026, retrieved 7 October 2026
  5. DeepL Pro plans, retrieved 7 October 2026
  6. DeepL Pro for greater efficiency in research and teaching, SWITCH, 17 November 2025, retrieved 7 October 2026
  7. Regulation (EU) 2016/679 (GDPR), Articles 28 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  8. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  9. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  10. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read DeepL's privacy policy, Pro terms, Pro data security page, plan page and its April 2026 infrastructure announcement, SWITCH's article on DeepL Pro for Swiss universities and the relevant EU legal texts on 7 October 2026. DeepL's Trust Centre, where the DPA and subprocessor details sit, could not be read by our automated check that day, so statements about those documents rely on how DeepL describes them elsewhere. Our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of DeepL complies with the GDPR. If you spot an error or DeepL has updated a document, please contact us and we will correct it.

Frequently asked questions

Is DeepL GDPR compliant?

No tool is GDPR compliant on its own. DeepL SE is a German company, offers a data processing agreement that forms part of its Pro terms and says Pro texts are not used to train its models. The free version works differently: DeepL processes free texts for a limited period to train and improve its models, and its terms say free users may not translate texts containing personal data.

Can staff use the free DeepL Translator for university documents?

DeepL's privacy policy says that, under its Terms of Use, the free DeepL Translator and Write may not be used for texts containing personal data of any kind. Emails, student work, HR documents and most research data contain personal data, so a university would normally steer that work to a Pro account covered by a DPA.

Does DeepL use my texts to train its AI?

For the free versions, DeepL's privacy policy says it processes uploaded content and its translations or improvements for a limited period to train and improve its neural networks. For DeepL Pro, the policy says texts are not used to improve the quality of its services, and DeepL's security page says texts are never stored or used for model training without the customer's consent.

Does DeepL keep data in the EU?

DeepL announced on 23 April 2026 that it was adding Amazon Web Services as a sub-processor and would no longer process data exclusively within Europe. It says customers with specific data residency requirements can work with DeepL on set-ups where their data never leaves Europe. Ask which configuration applies to your contract.

Does DeepL Pro support single sign-on?

DeepL's plan page lists single sign-on for Team and Business plans from 50 users and for Enterprise plans. Its privacy policy explains that with SSO, the organisation passes the user's email address and name to DeepL.