DeepSeek Data Jurisdiction: The Real Question Behind Chinese AI

Table of Contents

DeepSeek tends to provoke a stronger reaction than any other AI platform in this series, and the reaction usually arrives before the detail does. “Chinese AI” has become shorthand for a category of worry in a way no Western provider quite triggers, fairly or not. The detail that actually matters is DeepSeek data jurisdiction, not the headline.

That reaction deserves a proper answer, not a shrug in either direction. DeepSeek’s governance question is real and specific. It is a different kind of question to the default-setting and tier-confusion problems covered elsewhere in this series. It is a jurisdiction question, not a model-quality question, and it is worth being precise about which one you are actually asking.

DeepSeek data jurisdiction: what is actually different here

DeepSeek’s hosted consumer service stores user data, including submitted prompts, on servers located in China, as DeepSeek’s own privacy policy confirms, and is subject to Chinese law governing data access by state authorities. That is a materially different legal exposure from a US or EU-hosted platform, regardless of how the underlying model performs technically.

The policy does grant a right to opt out of having data used for model training, alongside the standard access, correction, and deletion rights, and names a UK and EU representative under Article 27 GDPR. None of that changes where the data itself is processed and stored, which the policy states plainly is the People’s Republic of China. The DeepSeek terms of use are worth reading alongside the privacy policy, since they set out the contractual relationship governing that processing.

For UK organisations handling personal data, this raises the same international transfer questions GDPR requires for any non-adequate jurisdiction: what safeguards apply, what assessment has been done, and whether the transfer is appropriate for the data category involved. DeepSeek does not get a pass on these requirements because the model is free or impressive.

A useful comparison point: this is the same category of question raised by Bing web search inside Copilot, or by Anthropic’s own subprocessor routing, both covered earlier in this series. The mechanism differs. The underlying question, where does the data actually go and under whose law, does not.

Open weights change the calculation, not the conclusion

DeepSeek has also released open-weight versions of its models, which organisations can run on their own infrastructure rather than through the hosted Chinese service. Self-hosting removes the jurisdictional data transfer concern almost entirely, because nothing leaves infrastructure the organisation controls.

That distinction matters enormously and is frequently lost in the broader “Chinese AI” conversation. Using DeepSeek’s hosted consumer app and running a DeepSeek open-weight model on your own servers are two completely different governance positions, even though both involve the same underlying model family.

This is worth spelling out plainly, because it is the part most coverage skips. A model and a hosting decision are not the same thing. Treating them as one collapses two different risk profiles into a single, less useful verdict.

Separating the technical question from the jurisdictional one

Model capability and data jurisdiction are separate questions, and conflating them produces bad decisions in both directions. A capable model hosted somewhere inappropriate for your data is still inappropriate. An unfashionable model hosted entirely on your own infrastructure may carry less jurisdictional risk than a Western consumer app with weak retention terms.

We have had the same conversation with clients in both directions: the board that wants DeepSeek banned on sight, and the team that wants to roll it out because the benchmark scores looked good. Neither has asked the only question that actually matters here, which is where the data sits and under whose law. That question is the same one we would ask of any vendor, Chinese, American, or otherwise.

What to check on DeepSeek data jurisdiction before rollout

If staff are using DeepSeek’s hosted app, treat it as you would any consumer AI tool processing data outside an adequate jurisdiction. Assess the transfer. Document the decision. Restrict sensitive categories accordingly. If your organisation is evaluating a self-hosted open-weight deployment, the governance questions shift toward infrastructure security and model provenance instead.

Either way, write the decision down. “We looked at this and decided X, for these reasons” is a defensible position with a regulator. Silence is not, even when the underlying decision was perfectly reasonable.

Our piece on

AI sovereignty covers the data sovereignty dimension in more depth, and applies directly to evaluating any platform, DeepSeek included, hosted outside a jurisdiction your organisation trusts by default. Public AI vs private AI: what organisations get wrong is also worth reading, since the consumer-versus-self-hosted distinction above is a specific case of that broader argument, and what procurement needs to ask about AI suppliers sets out the supplier due diligence questions jurisdiction risk should prompt.

Black Chili’s AI Exposure Review gives you an honest, independent assessment of exactly which AI platforms are in use across your organisation, jurisdiction included.

Related Posts