DeepSeek has rocked the tech world with its claims of an AI model that rivals ChatGPT for a fraction of the price with less compute power, and now data protection watchdogs are mounting their questions.
The Chinese company broke headlines earlier in the week as stocks of tech titans tumbled after the launch of its app, which quickly rose to the top spot on the US, UK, and Chinese app stores.
Since then, critics have doubted the company’s claims, while others, including OpenAI CEO Sam Altman, welcomed the transformative competition. President Donald Trump called it a “wake-up call” to US tech firms which have tried to maintain their market dominance with support of US sanctions against chip imports to China and mass funds for data centres.
Now, it is time for DeepSeek to reckon with the bane of all AI large language models’ (LLMs) existence: data protection regulations.
A consumer group, Euroconsumers, has already filed a complaint to the Italian Data Protection Authority (DPA), requesting and inquiry to see if DeepSeek’s handling of personal data is within GDPR.
The Italian DPA has confirmed it wrote to DeepSeek requesting information around the company’s personal data practices.
“The data of millions of Italians is at risk,” the Italian DPA noted, giving the fresh AI company 20 days to respond.
In its privacy statement and terms of conditions, DeepSeek seems to cover its legal bases. While the company operates in China – not an especially safe haven for data privacy – it says that any data transferred to China from a foreign entity is done “in accordance with the requirements of applicable data protection laws.”
The company’s privacy policy does note the different types of data DeepSeek collects, which is stored in China, as well as that it will, in accordance with the law, share this data with authorities if the company has “good faith belief that is it necessary” under the law.
It does say that a person’s data rights depend on where they live, and that exercising certain rights can impact a users ability to use some or all of DeepSeek’s services.
Recommended reading
- Could DeepSeek Topple the US’s AI Market Dominance?
- Trump Calls DeepSeek A “Wake-up Call” For US Tech
- Is the UK Lagging Behind in Global AI Race?
- Gartner: Global AI Chips Revenue to Total £56BN in 2024
Euroconsumers, and the Italian DPA, however, want more information, specifically what type of personal data is collected, from what sources, and for what purposes. It also seeks to know what information is used to train AI, as well as DeepSeek’s legal basis for data processing, something that is key to GDPR.
The Italian data watchdog also asked DeepSeek to explain how those who had personal data collected to train their AI model, through data scraping, have been informed about the processing of their data.
The consumer coalition was also concerned that DeepSeek’s policies seem to lack information about how the data of minors is treated – the company simply says its service is not recommended for those under 18, and that those between 14 and 18 years of age should read the privacy policy with adult supervision.
It remains to be seen how DeepSeek will respond to the letter, and how other questions around its data policy, training, and efficiency are answered.





