AI Chatbots & Assistants

DeepSeek

Critical risk

Chinese AI lab offering the DeepSeek chatbot app and API on low-cost frontier models, plus open-weight model releases that can be self-hosted.

Verified 2026-08-31DeepSeek (Hangzhou)www.deepseek.com

Is DeepSeek safe for confidential data?

For business use of the hosted app or API, DeepSeek is the clearest no in this directory. Data is processed and stored on servers in China, within reach of Chinese national-intelligence law; South Korea's privacy regulator (PIPC) found in April 2025 that DeepSeek transferred user prompts and device data to Chinese companies — including Beijing Volcano Engine — without consent, and ordered the prompt data destroyed. It has been banned or restricted for Microsoft employees, US federal agencies, Italy, Australia, South Korea, Taiwan, and at least 17 US states, and Cisco reported it failed 100 percent of jailbreak tests against harmful-prompt benchmarks. The essential distinction: these findings attach to the hosted service. The open-weight models, self-hosted on your own infrastructure, send nothing to DeepSeek and become an ordinary model-quality decision rather than a data-sovereignty one.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Hosted app / API (only offering)
Trains on inputs

Consumer-grade terms, China-based processing, no enterprise controls, no DPA. Self-hosting the open weights is a separate deployment choice, not a DeepSeek service tier.

Data handling

Training on inputs

The consumer privacy policy permits use of inputs to improve the service, with no enterprise tier or contractual no-training offering. Assume prompts to the hosted app and API are retained and reusable by the vendor.

Retention

Retained on China-based servers per the privacy policy, with no zero-retention option; South Korea's PIPC documented prompt content transferred to third-party Chinese companies without consent.

Residency

China. Data stored there is subject to Chinese national-intelligence and cybersecurity law, which can compel access. For Canadian organizations this is effectively incompatible with PIPEDA reasonableness expectations and Quebec Law 25 transfer assessments for confidential business data. Self-hosted open weights keep data wherever you run them.

Compliance

  • SOC 2Not verified
  • GDPR / DPANo
  • HIPAA BAANo

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • None published for the hosted service
  • No SSO, admin, or audit offering
  • Self-hosted open weights as the only control path

Frequently asked questions

Is DeepSeek safe for business use?

The hosted app and API are not defensible for confidential business data: processing happens on China-based servers subject to national-intelligence law, South Korea's PIPC found prompts transferred to Chinese companies without consent, and there is no enterprise tier, DPA, or no-training contract to point to. Multiple governments and companies — Italy, Australia, South Korea, US federal agencies, 17+ US states, Microsoft for its employees — have banned or restricted it.

Is DeepSeek data really sent to China?

Yes. DeepSeek's own privacy policy places storage on servers in China, and the April 2025 PIPC investigation documented user prompts and device/network data flowing to Chinese companies, including cloud platform Beijing Volcano Engine, without user consent; the regulator ordered the transferred prompt data destroyed. Separately, Cisco's security testing reported the model failed 100 percent of jailbreak attempts, so even content controls are weak.

Can we use DeepSeek models safely by self-hosting, and what about employees using the app anyway?

Self-hosting the open weights on your own or Canadian-resident infrastructure removes the data-transfer problem entirely — nothing is sent to DeepSeek — leaving normal model governance questions. The harder problem is the free consumer app: it is exactly the kind of capable, free, unsanctioned tool employees paste work into, and no self-hosting decision stops that. Block the hosted endpoints where you can and monitor prompt traffic where you cannot.

Policy changelog

  • Initial entry published from regulator findings and cited coverage.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

DeepSeek is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles