Registry / DeepSeek API (first-party)
DeepSeek API (first-party)
First-party API access to DeepSeek models via the DeepSeek Open Platform, operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. Its privacy policy states personal data is collected, processed and stored in the People's Republic of China, and no public security certifications, trust center, DPA, or EU AI Act Code of Practice signature were found as of 2026-07-05.
Watch-outs 9
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: No public evidence DeepSeek's privacy policy describes general security measures but no SOC 2 Type II report or trust center is publicly available.
- ISO 27001: No public evidence DeepSeek's official pages do not list ISO/IEC 27001 certification.
- ISO 42001: No public evidence Search of DeepSeek's official domains (deepseek.com, cdn.deepseek.com, api-docs.deepseek.com) shows no public statement or certificate for ISO/IEC 42001, so evidence is absent
- HIPAA BAA: No public evidence DeepSeek's privacy policy contains no mention of a HIPAA Business Associate Agreement.
- GDPR DPA: No public evidence No public DPA, SCCs, or subprocessor list found on DeepSeek domain
- No-training default: No public evidence DeepSeek states it may use a small portion of user input for training, so no public commitment to refrain.
- Retention / ZDR: Partial no public zero‑data‑retention offering
- Residency: No public evidence DeepSeek provides no public statement that API data can be pinned to the EU region
- GPAI Code: No, verified DeepSeek is not listed among the signatories on the European Commission's complete GPAI Code of Practice signatory list, confirming it is not a signatory.
The cited page is DeepSeek's own authoritative privacy policy containing the quoted security-measures language, and no public evidence of a DeepSeek SOC 2 Type II report was found on the provider's domain or elsewhere.
We maintain commercially reasonable technical, administrative, and physical security measures that are designed to protect your Personal Data
A thorough search of DeepSeek's own site and documentation found no public statement of ISO/IEC 27001 certification for the API.
We maintain commercially reasonable technical, administrative, and physical security measures that are designed to protect your Personal Data.
Search of DeepSeek's official domains (deepseek.com, cdn.deepseek.com, api-docs.deepseek.com) shows no public statement or certificate for ISO/IEC 42001, so evidence is absent
Last Update: Feb 10, 2026
The publicly accessible DeepSeek Transparency Center page lists models and reports, satisfying the definition of a maintained trust/compliance portal.
Transparency Center Here we disclose DeepSeek's major released models
No public DeepSeek page mentions offering a HIPAA BAA, and the privacy policy states the service is not intended for health data, indicating no publicly available BAA.
The Services are not designed or intended to process sensitive Personal Data (e.g., ... health ...). We do not ask for, and you should not provide sensitive Personal Data to the Services.
DeepSeek’s own site provides only a privacy policy and contains no publicly available DPA, SCCs, or subprocessor list.
For detailed rules on how we collect, protect, and use personal information, please carefully read the DeepSeek Privacy Policy.
The provider explicitly notes that some user input may be used for training, contradicting a commitment not to train on API data.
During the optimization training phase, ... a small portion potentially based on user input. ... Users are also given the right to opt out.
DeepSeek publicly documents its data retention period, but no authoritative DeepSeek page shows a zero‑data‑retention option for the API.
We retain Personal Data for as long as necessary to provide our Services and for the other purposes set out in this Privacy Policy.
Searches of DeepSeek's own site reveal no authoritative page asserting EU data residency for the API, and the privacy policy only identifies China as the data controller.
Data Controller: The Services are provided and controlled by Hangzhou DeepSeek Artificial Intelligence Co., Ltd., with its registered address in China ("we" or "us").
DeepSeek is not listed among the signatories on the European Commission's complete GPAI Code of Practice signatory list, confirming it is not a signatory.
## Signatories of the code of practice - AI Studio Delta - Aleph Alpha - Almawave - Amazon - Anthropic - Black Forest Labs - Bria AI - Cohere - Domyn - Dweve - Fastweb - IBM - LINAGORA - Microsoft - Mistral AI - Open Hippo - OpenAI - Pleias - ServiceNow - WRITER
DeepSeek's own policy page publicly links the EC‑template training‑content summaries for V3.1, V3.2 and V4, satisfying Art. 53(1)(d) without any access gate.
To enhance transparency, DeepSeek hereby publishes Training Data Summaries – [DeepSeek-V3.1 Training Data Summary] - [DeepSeek-V3.2 Training Data Summary] - [DeepSeek-V4 Training Data Summary] ...
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.