Is DeepSeek GDPR compliant? What universities should check
DeepSeek's chat app and API attracted wide attention in 2025, and so did the reactions of European data protection authorities. Its models are also published as open weights. This page sets out what DeepSeek publicly documents, what EU authorities have officially decided, and how a university can tell the hosted service apart from running the models itself.
Short answer
DeepSeek's chat app and API are provided by Hangzhou DeepSeek Artificial Intelligence Co., Ltd., a company registered in China, which is the controller under its privacy policy. The policy says personal data is collected, processed and stored in the People's Republic of China, a country without an EU adequacy decision, and it does not name a specific transfer mechanism. DeepSeek has appointed Prighter Group as its EU and UK representative, lets users opt out of model improvement, and publishes its models as open weights. We found no data processing agreement, subprocessor list or security certification in its public documentation. The Italian Garante ordered an urgent limitation of processing for Italian users in January 2025, and the Berlin data protection authority reported the app to Apple and Google in June 2025. For a university, the hosted service and self-hosted open-weight models are two very different cases.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers an AI assistant for research work with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What DeepSeek documents publicly
All sources were read on 7 October 2026. On that date the address DeepSeek uses for its US English privacy policy served a Japanese-language version (last updated 10 February 2026), so we relied on the English version published at DeepSeek's UK address, which carries the name "DSeek", is dated 27 March 2026 and contains a supplement for the EEA, Switzerland and the UK. Both versions name the same controller. "Not found publicly" means we did not find it in the sources listed; it does not mean it does not exist.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented The services are "provided and controlled by Hangzhou DeepSeek Artificial Intelligence Co., Ltd." with its registered address in China. The English version says Prighter Group is appointed as privacy representative for the EU and the UK. Entities in DeepSeek's corporate group process data for functions including storage, research and development, and foundation model training. | [1], [2] |
| Where data is stored and processed | Documented "we directly collect, process and store your Personal Data in People's Republic of China." China does not appear on the European Commission's list of adequacy decisions. | [1], [11] |
| Data processing agreement | Not found publicly A DPA for the app or the API. The Open Platform Terms (effective 29 April 2026) require developers to inform their end users, to have a legal basis, including for "delegation of personal information processing" to DeepSeek, and to handle end users' rights requests. They are governed by the law of mainland China. | [4] |
| Subprocessors | Not found publicly A named subprocessor list. The privacy policy describes categories of recipients: service providers, security partners and group companies. | [1] |
| International transfers | Partly documented The policy says that "where required" DeepSeek will use "appropriate safeguards" in line with applicable law, without naming a mechanism such as Standard Contractual Clauses. The EU-US Data Privacy Framework does not apply, as DeepSeek is not a US company. | [1] |
| AI model training on user content | Opt-out The terms say DeepSeek may, after de-identification, use inputs and outputs to "develop or improve the Services or the underlying technologies", and that users can opt out by turning off "Improve the model for everyone". For European users the privacy policy relies on legitimate interests for training and improving its models. | [3], [1] |
| Retention and deletion | Partly documented Personal data is kept "for as long as necessary" to provide the services and for legal, contractual and legitimate business purposes, with no fixed periods. Users can delete chat history and their account in settings; after account deletion, certain data may be kept where the law requires. | [1], [3] |
| Security certifications | Not found publicly Independent certifications such as ISO 27001 or SOC 2. | [1], [3] |
| Institution and enterprise controls | Not found publicly An organisational plan with admin controls, SSO or a processor contract for the chat service. The terms say the services are "primarily intended for adults"; users under 18 should use them with guardian consent, and the privacy policy says the services are not aimed at children. | [3], [1] |
Actions by EU data protection authorities
Only official statements from the authorities themselves are summarised here.
- Italy, 30 January 2025. The Garante per la protezione dei dati personali announced that it had ordered, urgently and with immediate effect, the limitation of the processing of Italian users' data by Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence, and had opened an investigation at the same time. The Garante described the content of the companies' communication, received that day, as "del tutto insufficiente" (entirely insufficient): according to the press release, they said they did not operate in Italy and that European law did not apply to them [6].
- Germany (Berlin), 27 June 2025. The Berlin Commissioner for Data Protection and Freedom of Information reported the DeepSeek app to Apple and Google as unlawful content under Article 16 of the Digital Services Act, so that the platforms would decide on blocking it in Germany. The Commissioner stated that Hangzhou DeepSeek Artificial Intelligence Co., Ltd. infringes Article 46(1) GDPR by transferring users' data to China, and said the company had not complied with a request of 6 May 2025 to remove its apps from the German app stores, stop the transfers to China or meet the legal requirements for third-country transfers. The step was coordinated with the authorities of Baden-Württemberg, Rhineland-Palatinate and Bremen [7].
These are the official sources we read on 7 October 2026. Other authorities have published guidance, and proceedings may have moved on, so check the authorities' own sites before relying on this summary.
What this means for a university
Validemic's analysis
The hosted app and API. For staff using DeepSeek's chat service for university work, DeepSeek is the controller, there is no processor contract, and data goes to China, which has no adequacy decision [1], [11]. Under Chapter V of the GDPR, a transfer to a third country needs an adequacy decision, appropriate safeguards such as SCCs, or a narrow derogation [12]. We did not find SCCs or a DPA in DeepSeek's documentation, and two EU authorities have taken formal steps over its processing [6], [7]. Most universities will find it difficult to approve the hosted service for personal data on that basis, and the API is in the same position.
Open weights are a different case. DeepSeek publishes its models as open source [5]. A university that runs those models on its own servers, or uses an EU host under a DPA, sends nothing to DeepSeek. The assessment then covers the hosting provider and the university's own security, plus the usual checks on model behaviour and output quality. This is a genuine strength of DeepSeek's approach and the route most relevant to research groups.
Personal accounts. Staff and students may already use the app privately. If the university decides not to approve it, a clear statement in the AI guidance, plus an approved alternative, works better than silence.
Credit where due. DeepSeek has appointed an EU and UK representative, published a European supplement with legal bases and rights, offers a training opt-out and chat deletion, and documents how its models are trained [1], [3], [5].
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask before using DeepSeek
- Will DeepSeek sign a data processing agreement with Standard Contractual Clauses for the API or the chat service?
- Which transfer mechanism does DeepSeek rely on for data of EEA users, and will it provide a transfer impact assessment?
- Which group companies and service providers receive users' prompts and files, and in which countries?
- How long are prompts, files and chat history kept, including after an opt-out or account deletion?
- Does turning off "Improve the model for everyone" also stop use for de-identified service improvement, and does it apply retroactively?
- For self-hosting: which open-weight model versions and licences apply, and who in the university operates and secures the infrastructure?
- If an EU cloud provider hosts DeepSeek models, does its DPA cover inference logs and prompt retention?
The EU AI Act angle
Using a chat assistant for writing or research support is normally not a high-risk use under the AI Act, Regulation (EU) 2024/1689 [8]. Annex III, point 3 lists the education uses that are: deciding admission or access, evaluating learning outcomes, assessing the level of education a person will receive, and monitoring students during tests. A university that deploys any model for those purposes, self-hosted or not, takes on deployer obligations.
Article 4 on AI literacy has applied since 2 February 2025, and Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, turned it into a duty to take measures to support AI literacy and moved the Annex III high-risk rules to 2 December 2027 [9]. Obligations for general-purpose AI models, applying since 2 August 2025, fall on model providers. DeepSeek does not appear on the European Commission's list of signatories of the General-Purpose AI Code of Practice [10]; signing is voluntary.
Sources
- DeepSeek, Privacy Policy, English version at the UK address (titled "DSeek Privacy Policy", last update 27 March 2026), with supplement for the EEA, Switzerland and UK, retrieved 7 October 2026
- DeepSeek, Privacy Policy at the US English address (served in Japanese on the check date, last updated 10 February 2026), retrieved 7 October 2026
- DeepSeek, Terms of Use (titled "DSeek Terms of Use", last update 27 March 2026), sections 2.1, 2.5 and 4.3, retrieved 7 October 2026
- DeepSeek, Open Platform Terms of Service (released 22 April 2026, effective 29 April 2026), retrieved 7 October 2026
- DeepSeek, Model Mechanism and Training Methods, retrieved 7 October 2026
- Garante per la protezione dei dati personali, press release "Intelligenza artificiale: il Garante privacy blocca DeepSeek", 30 January 2025 (in Italian), retrieved 7 October 2026
- Berliner Beauftragte für Datenschutz und Informationsfreiheit, press release of 27 June 2025 on DeepSeek (in German), retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 4 and 113 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026
- European Commission, The General-Purpose AI Code of Practice (signatories), retrieved 7 October 2026
- European Commission, Adequacy decisions, retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Chapter V (Articles 44 to 49), retrieved 7 October 2026
About this page
We read DeepSeek's privacy policy, terms of use, Open Platform terms and model documentation, the official press releases of the Italian Garante and the Berlin data protection authority, and the EU legal texts, on 7 October 2026. We did not test the product. This page describes public documentation and official decisions only. It is not legal advice and not a verdict on whether DeepSeek or any university's use of it complies with the GDPR.
If you work at DeepSeek or an authority mentioned here and something is out of date or incomplete, please contact us and we will review it promptly.
Frequently asked questions
Where does DeepSeek store user data?
DeepSeek's privacy policy says it directly collects, processes and stores personal data in the People's Republic of China. The European Commission has not adopted an adequacy decision for China, and the policy does not name a specific transfer mechanism such as Standard Contractual Clauses (checked 7 October 2026).
Is DeepSeek banned in the EU?
There is no EU-wide ban. On 30 January 2025 the Italian Garante ordered, urgently and with immediate effect, the limitation of the processing of Italian users' data against the two Chinese companies providing DeepSeek, and opened an investigation. On 27 June 2025 the Berlin Commissioner for Data Protection reported the DeepSeek app to Apple and Google as unlawful content under the Digital Services Act. Check the authorities' own sites for later steps.
Does DeepSeek train on my chats?
DeepSeek's terms of use say it may use inputs and outputs, after de-identification, to develop and improve its services and underlying technology, and that users can refuse by turning off "Improve the model for everyone". Its privacy policy lists training and improving its models among the purposes, based on legitimate interests for European users.
Does DeepSeek have an EU representative?
Yes. DeepSeek's privacy policy says it has appointed Prighter Group, with local partners, as its privacy representative for the EU and the UK, reachable at rep_deepseek@prighter.com.
Can a university use DeepSeek models without sending data to China?
DeepSeek publishes its models as open source. Running the open-weight models on university-controlled infrastructure, or through a provider hosting them in the EEA under a DPA, does not involve DeepSeek's own app or API. The GDPR assessment then concerns whoever operates that infrastructure, not DeepSeek.