Registry / DeepSeek API (first-party)
DeepSeek API (first-party)
First-party API access to DeepSeek models via the DeepSeek Open Platform, operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. Its privacy policy states personal data is collected, processed and stored in the People's Republic of China, and no public security certifications, trust center, DPA, or EU AI Act Code of Practice signature were found as of 2026-07-05.
Watch-outs 9
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: No public evidence DeepSeek public policies contain no mention of a SOC 2 Type II report.
- ISO 27001: No public evidence No ISO/IEC 27001 certificate found publicly; may be sales‑gated.
- ISO 42001: No public evidence DeepSeek privacy policy contains no mention of ISO/IEC 42001 certification
- HIPAA BAA: No public evidence DeepSeek's privacy policy states the service is not intended for health data and provides no public BAA information, so no public evidence of a HIPAA BAA exists.
- GDPR DPA: No public evidence The cited page is DeepSeek's own domain and the quote is verbatim present. Neither the privacy policy nor any DeepSeek public page offers a DPA with SCCs or a published subprocessor list, so no_public
- No-training default: No public evidence DeepSeek trains on API inputs by default; users must opt out.
- Retention / ZDR: Partial Zero‑data‑retention option is not published on DeepSeek’s own site.
- Residency: No public evidence DeepSeek's own privacy policy states personal data is stored in the People's Republic of China; no EU or other region-pinning option is documented anywhere in its public docs.
- GPAI Code: No, verified DeepSeek is absent from the complete, official EU Commission signatory list, which by definition makes the claim false.
Search of DeepSeek's official site and review of its privacy policy and terms reveal no public SOC 2 Type II report, and no gated portal was found.
"We will also make efforts to enhance and improve technology to ensure a better user experience."
Extensive search of DeepSeek's official site and documents found no publicly available ISO/IEC 27001 certification for the DeepSeek API.
Last Update: Feb 10, 2026
Extensive search of DeepSeek's own domain and public pages found no authoritative statement of ISO/IEC 42001 certification.
Last Update: Feb 10, 2026
The DeepSeek website hosts a publicly accessible Transparency Center page that lists models and related documentation, serving as a compliance portal.
Transparency Center Here we disclose DeepSeek's major released models
DeepSeek's privacy policy states the service is not intended for health data and provides no public BAA information, so no public evidence of a HIPAA BAA exists.
The Services are not designed or intended to process sensitive Personal Data (e.g., personal data revealing ... health ...).
The cited page is DeepSeek's own domain and the quote is verbatim present. Neither the privacy policy nor any DeepSeek public page offers a DPA with SCCs or a published subprocessor list, so no_public_evidence is correct.
Please be informed that the processing rules for Personal Data collected from end users when accessing downstream systems or applications developed by developers using our open platform services are not covered by this privacy policy.
The privacy policy states DeepSeek uses data to train models by default and only offers an opt‑out, providing no public commitment not to train on customer API data.
We use your Personal Data ... to train and improve our technology, such as our machine learning models and algorithms.
The privacy policy documents data retention, but no public page from DeepSeek describes a zero‑data‑retention offering, so only part of the claim is satisfied.
We retain Personal Data for as long as necessary to provide our Services and for the other purposes set out in this Privacy Policy.
DeepSeek's authoritative privacy policy (cdn.deepseek.com) states data is directly collected, processed and stored in the PRC and no regional data-pinning feature is documented for the first-party API, so no_public_evidence stands; the recorded source chat-deep.ai is a third-party aggregator and was
To provide you with our services, we directly collect, process and store your Personal Data in People's Republic of China.
DeepSeek is absent from the complete, official EU Commission signatory list, which by definition makes the claim false.
## Signatories of the code of practice - AI Studio Delta - Aleph Alpha - Almawave - Amazon - Anthropic - Black Forest Labs - Bria AI - Cohere - Domyn - Dweve - Fastweb - IBM - LINAGORA - Microsoft - Mistral AI - Open Hippo - OpenAI - Pleias - ServiceNow - WRITER
DeepSeek’s own policy page publicly provides a training‑data summary, satisfying the Article 53 developer obligation.
To enhance transparency, DeepSeek hereby publishes Training Data Summary…
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.