← Back to incidents

Italian Data Protection Authority Blocks DeepSeek Over GDPR Privacy Violations

High

Italy's data protection authority blocked Chinese AI company DeepSeek from processing Italian user data over GDPR violations, citing lack of transparency and proper legal basis for data processing.

Category
Privacy Leak
Industry
Technology
Status
Ongoing
Date Occurred
Jan 27, 2025
Date Reported
Jan 27, 2025
Jurisdiction
EU
AI Provider
Other/Unknown
Model
DeepSeek-V3
Application Type
chatbot
Harm Type
privacy
Human Review in Place
Unknown
Litigation Filed
No
Regulatory Body
Garante per la Protezione dei Dati Personali
GDPRprivacydata protectionregulatory enforcementAI complianceItalyDeepSeekcross-border data transfer

Full Description

On January 27, 2025, Italy's data protection authority Garante per la Protezione dei Dati Personali issued an order blocking DeepSeek, a Chinese AI company, from processing personal data of Italian users. The action mirrors the regulator's March 2023 temporary ban on ChatGPT, demonstrating continued scrutiny of AI companies' compliance with the General Data Protection Regulation (GDPR). The Garante cited several specific violations in its enforcement action against DeepSeek. The primary concerns included the company's failure to provide transparent information about how personal data is collected and processed, lack of adequate legal basis for processing personal data under GDPR Article 6, and insufficient privacy safeguards for European users. The regulator noted that DeepSeek's privacy policy and terms of service did not meet EU standards for clarity and comprehensiveness. DeepSeek, developed by Chinese company High-Flyer Capital Management, had gained significant attention for its competitive performance relative to leading Western AI models while claiming lower computational costs. The service processes user conversations and queries, potentially collecting vast amounts of personal data including sensitive information shared in conversations. The Italian regulator expressed particular concern about the cross-border transfer of this data to China without adequate safeguards. This enforcement action is part of a broader pattern of EU regulators challenging AI companies over privacy compliance. Following Italy's ChatGPT ban in 2023, which was lifted after OpenAI implemented additional privacy measures, other EU authorities have increased scrutiny of AI services. The European Data Protection Board has emphasized that AI companies must demonstrate clear lawful basis for processing personal data and implement privacy-by-design principles. The blocking order requires DeepSeek to immediately cease processing personal data of Italian users until it can demonstrate full GDPR compliance. This includes appointing an EU representative, conducting data protection impact assessments, implementing appropriate technical and organizational measures, and revising its privacy documentation to meet EU standards. The company faces potential fines of up to 4% of global annual revenue if it fails to comply.

Root Cause

DeepSeek failed to provide adequate transparency about data processing activities, lacked proper legal basis for processing personal data under GDPR, and did not implement sufficient privacy safeguards for EU users.

Mitigation Analysis

Implementation of comprehensive GDPR compliance frameworks including clear privacy notices, lawful basis documentation, data processing impact assessments, and EU representative appointment could have prevented this block. Regular privacy audits and proactive engagement with EU data protection authorities would have identified compliance gaps before enforcement action.

Lessons Learned

This incident reinforces that AI companies operating globally must implement region-specific privacy compliance measures from launch, not as an afterthought. The pattern of EU enforcement against AI services demonstrates that regulators will not hesitate to block access to protect citizen privacy rights.

Sources

Garante Order Against DeepSeek
Garante per la Protezione dei Dati Personali · Jan 27, 2025 · regulatory action
Italy blocks DeepSeek over privacy concerns
Reuters · Jan 27, 2025 · news