No data to China
The AI runs on your PC. Neither prompts nor files go to a server, in any country.
DeepSeek privacy is less of a grey area than with other AI services: according to its own privacy policy, DeepSeek stores users’ data in the People’s Republic of China. The Berlin data protection commissioner considers this unlawful and Italy has blocked the processing. This guide explains what happens to your prompts, which incidents are documented and what businesses should take from it.

In short: for personal data, the DeepSeek app or website is hard to justify at work. Data goes to China, which has neither an EU adequacy decision nor UK adequacy regulations. The Berlin data protection commissioner reported the app to Apple and Google as illegal content in June 2025; Italy’s regulator blocked the processing in January 2025.
It is worth separating the service from the model. The problems concern DeepSeek’s app, website and API, where your prompts end up on its servers. DeepSeek has also published model weights openly, for example DeepSeek-R1 under the MIT licence. If you run such a model on your own hardware, nothing is sent to DeepSeek. More on that below.
DeepSeek’s privacy policy (last updated 10 February 2026) says:
The Berlin commissioner explains her action by saying that Chinese authorities have far-reaching access rights to data held by Chinese companies and that DeepSeek could not show the data is protected to an equivalent standard.
The following events are documented by regulators or reputable media. Sources are listed at the end of the page.
Security researchers at Wiz found a publicly accessible DeepSeek database that required no login and held over a million log lines, including chat histories, secret keys and backend details. DeepSeek secured it promptly after being told.
Italy’s Garante ordered an immediate limitation on processing Italian users’ data and opened an investigation. It found the company’s answers wholly insufficient: DeepSeek had said it did not operate in Italy and that European law did not apply to it.
Australia’s Department of Home Affairs directed all government entities to remove DeepSeek products from their systems and devices. Private devices are not affected.
The data protection regulator PIPC suspended new downloads of the app. In April 2025 it found that DeepSeek had transferred South Korean users’ data to companies in China and the US without consent, including prompts to a ByteDance subsidiary. After a revised privacy policy, the app returned at the end of April.
The Berlin data protection commissioner reported the DeepSeek apps to Apple and Google under Article 16 of the Digital Services Act. She considers the transfer of user data to China unlawful because there is no equivalent protection there. A request of 6 May 2025 to withdraw the apps or make the transfers lawful had not been complied with.
The Czech cyber security agency NÚKIB warned against DeepSeek products, apps, web services and APIs. The government banned their use in state administration.
The Berlin report obliges Apple and Google to examine the notice. DeepSeek remains reachable in a browser regardless. For businesses, the legal position on personal data does not depend on whether an app is in a store.
If you use DeepSeek privately, do not enter personal data, delete chats you no longer need and, if in doubt, delete the account and opt out of training by email.
DeepSeek-R1’s weights are publicly available under the MIT licence, along with smaller distilled versions. If such a model runs on your own computer, no prompt reaches DeepSeek. The data protection problems above concern the service, not the file.
That said, the largest model needs data centre hardware, and setting up a model by hand is not everyday office work. You would also have no link to your programs, such as dictation, Outlook or Word. A ready-made local assistant fills exactly that gap.
Germany’s data protection authorities consider technically closed systems preferable, meaning applications where data never leaves your own environment. A local assistant meets that without extra effort:
SpeechToWork brings speech recognition and a language model to your Windows PC: dictation, writing emails, asking questions about documents, meeting minutes, transcribing audio and reading receipts. The limits are part of the picture: the model is smaller than the big cloud models, it does not search the web, it runs only on Windows, and it needs a reasonably recent PC. More in our guides to GDPR-compliant AI and local AI.
Last reviewed: September 2026. We checked every statement against the sources listed on 29 September 2026. Plans, settings and proceedings change often; the provider’s current documents always take precedence. This guide is not legal advice.
The AI runs on your PC. Neither prompts nor files go to a server, in any country.
Without a transfer, your content needs no standard contractual clauses and no transfer risk assessment.
No setting up a model by hand: SpeechToWork picks the right model for your hardware on start.
Speech recognition and the language model are installed on your PC and run there. What you dictate ends up in your program and nowhere else. How the data flow works.
Audio and text stay on your computer. There is no server listening in and no AI provider in the background.
No third party processes your dictations. So there is no data processing agreement to sign and no international transfer to assess.
Once installed, SpeechToWork works offline. Only the licence check needs a connection.
For personal data, there are strong reasons against it. DeepSeek’s privacy policy says data is stored in China, which has no EU adequacy decision or UK adequacy regulations. The Berlin data protection commissioner considers the transfer unlawful and reported the app to Apple and Google in June 2025. Italy blocked the processing in January 2025.
In the People’s Republic of China. The privacy policy (last updated 10 February 2026) says so word for word: DeepSeek collects, processes and stores personal data there. The controller is Hangzhou DeepSeek Artificial Intelligence, registered in China. It has no establishment in the EU, only a representative under Article 27 GDPR.
We are not aware of a UK ban for private users. Other countries have acted: Australia and the Czech Republic banned DeepSeek in government, South Korea paused downloads, Italy blocked the processing and the Berlin data protection commissioner reported the app to Apple and Google. For businesses, UK GDPR transfer rules matter most.
Yes. According to its privacy policy, inputs are also used to train and improve its models. You have a right to opt out, which the policy says you exercise by email to privacy@deepseek.com. DeepSeek names no fixed retention period; data is kept as long as necessary for the service and legal obligations.
Yes, the openly published model. DeepSeek-R1 is available under the MIT licence, and smaller versions run on your own hardware. Then no prompt goes to DeepSeek. Setting it up needs technical knowledge and suitable hardware, though. A ready-made local assistant such as SpeechToWork handles office work without that effort.
Among others, Italy’s data protection authority with a processing limitation in January 2025, South Korea’s PIPC with a download halt in February 2025 and the Berlin data protection commissioner with a report to Apple and Google in June 2025. Australia and the Czech Republic banned DeepSeek in government.
SpeechToWork is about to launch. As soon as the first version is ready, you can download it here: one click, one file, no form.
Coming soonFor Windows 10/11 (64-bit). The download will be available here as soon as it is ready.
One installer for Windows, straight from our server.
A double click is all it takes. No administrator rights needed.
On first start: enter your name and business email, no payment method.
On first start, SpeechToWork downloads the language models once (4 to 6 GB). Already have a licence key? Enter it on first start. What is transferred in the process is explained in our privacy policy.