Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

DeepSeek

DeepSeek

Further reviewEU: UnavailableOpt-out availableDeployment retentionChina / self-hosted

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out DeepSeek safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Hosted API pricing varies; self-hosting costs depend on infrastructure

Enterprise Features

Self-hosting or independent EU hosting can create a separate data route

Last Updated

September 10, 2026

Reviewed on 10 September 2026 by WAIMAKERS B.V.

⚠️ Critical compliance warning

DeepSeek must be split into its direct hosted service/API, an independent third-party host, and a self-hosted model. For the direct service, DeepSeek's current policy says personal data is processed and stored in the People's Republic of China, may be used for training, and follows variable rather than fixed retention. That route therefore warrants heightened review for European organisational data.

1 Purpose and route comparison

Route Data flow Practical assessment
DeepSeek website/app/direct API DeepSeek receives prompts, files and service metadata and says it stores/processes personal data in China. Do not approve for personal, confidential or special-category data without a defensible transfer mechanism, DPA terms and completed risk assessment.
Independent EU host using DeepSeek weights The host, not necessarily DeepSeek, receives prompts. Assess the host's DPA, region, logs, training, licence and subprocessors. Do not inherit the direct-service conclusion automatically.
Self-hosted weights The operator receives and controls runtime data. Can avoid sending prompts to DeepSeek, while leaving all GDPR, security and licence duties with the operator.

2 GDPR compliance assessment

DeepSeek's English privacy policy was updated on 10 February 2026. It identifies Hangzhou DeepSeek Artificial Intelligence Co., Ltd. in China as controller, lists account details, prompts, uploaded files/images, chat history, device/network/log and payment information, and says personal data is directly processed and stored in the PRC. It warns users not to provide sensitive personal data.[1]

The same policy says DeepSeek may use personal data to improve and train its technology. It offers European users a right to opt out of training. Retention varies by data and purpose: account, input and payment information can be retained while the account exists, and some data can be retained for legal, safety or violation-handling reasons. This does not support claims of universal ZDR or a single fixed deletion period.

DeepSeek's Open Platform terms place duties on application developers to establish a lawful basis, inform end users and handle their rights. The direct privacy policy also says downstream applications built on the platform have their own controllers and policies.[2]

3 EU regulatory evidence

On 30 January 2025 the Italian data-protection authority ordered an urgent limitation on processing relating to Italian users after finding DeepSeek's response insufficient. The authority described the measure as an urgent limitation and opened an investigation; this source does not prove a permanent EU-wide ban.[3]

The EDPB's February 2025 plenary minutes recorded the Italian provisional measure and interest from other supervisory authorities in coordinated consideration. That is not evidence that all EU authorities reached the same merits decision or that a stated number of final enforcement cases exists.[4]

4 Self-hosting and licences

DeepSeek publishes weights and code that can be deployed outside its hosted service. The exact repository and licence matter: DeepSeek-R1 materials use the MIT licence, while DeepSeek-V3 includes a separate model licence. The model licence itself warns that model output may contain personal information and that the operator needs an appropriate legal basis.[5][6]

Self-hosting avoids direct prompt transfer to DeepSeek only if the deployment does not call DeepSeek services, telemetry or external tools. It does not cure risks in training data, output, security, logs or downstream use.

5 Minimum due diligence and EU rollout checklist

For the direct service, require a current DPA, controller/processor analysis, subprocessor list, Chapter V transfer mechanism, retention schedule, training opt-out evidence, deletion test and incident terms. No public DPA or SCC package for the direct hosted route was located in the official materials reviewed for this page; treat that as an unresolved procurement question, not proof that no private agreement exists.

For an EU host or self-hosted model, document the exact weights and licence, infrastructure region, access, encryption, prompt/output logs, updates, vulnerability management, rights handling and prohibited data. The host's brand and contract determine the managed-service privacy properties.

  1. Obtain the current DPA, role analysis and subprocessor list.
  2. Establish a defensible Chapter V transfer mechanism for the direct route.
  3. Record and test training opt-out, retention and deletion controls.
  4. For hosted or self-hosted weights, verify licence, region, logging, access and external calls.
  • ⚠️ Keep sensitive, confidential and special-category data out until the selected route is approved.

API prices and model names change frequently. Confirm the live API documentation and do not use pricing as privacy evidence.[7]

6 Verdict summary

DeepSeek's direct service merits heightened review because its own policy describes PRC storage and processing, training use with an opt-out, and variable retention. An independently hosted or self-hosted DeepSeek model is a separate deployment and may have a different risk profile, but it is not automatically GDPR-compliant.

7 Disclaimer

This is an editorial procurement assessment, not a legal determination or legal advice.

Compare related tools

Figma WeaveChatGPT (OpenAI)

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy