DeepSeek
high riskGenAI Assistantdeepseek.com, chat.deepseek.comverified 2026-06-27profile 85% complete
Data-handling profile
- Trains on input
- Yes, on all tiers
- Retention
- Retains chat inputs, device identifiers, IP addresses, and keystroke patterns for as long as the account is active (or longer for stated 'legitimate business interests'); no published anonymization or minimal-retention policy. Data may be used for model training by default with limited opt-out controls; enterprise-grade zero-retention requires local/self-hosted deployment.
- Data region
- China
- Certifications
- none listed
- DPA available
- No
- Breach history
- Jan 2025: Italy's Garante banned DeepSeek from processing Italian users' data after finding its privacy policy inadequate and confirming personal data storage in China without GDPR-compliant safeguards; formal investigation opened. Separately, an exposed ClickHouse database (reported Jan 2025) briefly leaked chat histories and API keys.
- EU AI Act
- China-based data residency subject to PRC National Intelligence/Data Security Laws; banned/restricted by multiple EU regulators (Italy) over GDPR non-compliance, indicating high EU AI Act and cross-border transfer risk.
By plan and surface
Vendor-level answers are often wrong for a specific tier. These are the precise claims, each with the verbatim sentence we relied on.
| Plan | Surface | Trains | Opt-out default |
|---|---|---|---|
| unknown | unknown | all_tiers | opted_in |
- unknown/unknown: “the right to opt-out of using your Personal Data for training our models or optimizing our technologies.”
Sources
- https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
- https://www.twobirds.com/en/insights/2025/the-garante-imposes-a-definitive-limitation-on-the-processing-of-italian-users%E2%80%99-personal-data
- https://www.euronews.com/next/2025/01/31/deepseek-ai-blocked-by-italian-authorities-as-others-member-states-open-probes
- https://ai-regulation.com/deepseek-one-year-later-regulatory-storm-global-surge/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Control mapping
Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.
- EU AI Act Art. 50 — Transparency obligations for AI systemsattention
trains_on_input = all_tiers. Inputs may be reused for model training — users interacting with this system need to be informed accordingly.
- EU AI Act Art. 26 — Obligations of deployers of high-risk AI systemsapplies
Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).
- ISO/IEC 27001 A.5.19 — Information security in supplier relationshipsapplies
DeepSeek processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.
- ISO/IEC 27001 A.5.20 — Addressing information security within supplier agreementsgap
dpa_available = false. No DPA identified — security and processing terms are not contractually established.
- ISO/IEC 27001 A.5.22 — Monitoring, review and change management of supplier servicesattention
breach_history: Jan 2025: Italy's Garante banned DeepSeek from processing Italian users' data after finding its privacy policy inadequate and confirming personal data storage in China without GDPR-compliant safeguards; formal investigation opened. Separately, an exposed ClickHouse database (reported Jan 2025) briefly leaked chat histories and API keys. Prior incident on record — justify continued use and monitor.
- ISO/IEC 27001 A.5.23 — Information security for use of cloud servicesattention
Cloud AI service; trains_on_input = all_tiers. Data submitted to this cloud service may be retained or reused — define acceptable-use rules for it.
- ISO/IEC 42001 A.10.3 — Suppliers of AI systems and servicesapplies
No certifications listed. No AI-management certification identified; assurance must come from your own supplier assessment.
- GDPR Art. 44–49 — International transfers of personal dataattention
data_region = China. Processing occurs outside the EU/EEA — a transfer mechanism (SCCs or adequacy) must be in place.
- NIS2 Art. 21(2)(d) — Supply chain securityapplies
AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.
- DORA Art. 28 — General principles for ICT third-party riskapplies
AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.
Change history
No material changes recorded since monitoring began.