AI Tool Risk Directory ← All 26 tools Verdict assessed 29 July 2026

Is DeepSeek safe for work? Verdict: Prohibited

Prohibited

DeepSeek should not be used for company work. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Prohibited. DeepSeek’s own privacy policy states it collects, processes and stores personal data in the People’s Republic of China and uses data to train its models, and Italy’s data protection authority ordered an urgent block on processing Italian users’ data. There is no enterprise governance tier to fix any of that. This is the clean example of a Prohibited-tier tool: capable model, unacceptable data terms for company use. Block it and offer approved alternatives.

This verdict reflects DeepSeek (Hangzhou)’s published terms as we read them on 29 July 2026. A vendor can change its terms the day after; the primary sources below are how you check.

DeepSeek at a glance

VendorDeepSeek (Hangzhou)
CategoryGeneral assistant
Our tier verdictProhibited (assessed 29 July 2026) — DeepSeek’s own privacy policy states it collects, processes and stores personal data in the People’s Republic of China and uses data to train its models, and Italy’s data protection authority ordered an urgent block on processing Italian users’ data. There is no enterprise governance tier to fix any of that. source
Trains on your data?Yes
Yes, with an opt-out on request. DeepSeek’s privacy policy describes using data to train and improve its models and lists, among your rights, "the right to opt-out of using your Personal Data for training our models or optimizing our technologies" — an opt-out you must exercise, not a default. source
Data retentionDeepSeek states it directly collects, processes and stores personal data in the People’s Republic of China, and retains personal data for as long as necessary to provide its services. source
Admin controlsNone. No enterprise tier, no admin console, and no data-processing agreement suitable for a US/EU company.
Compliance certificationsNone found in DeepSeek’s published policies on this check date.
HIPAA / BAANo — No.

Does DeepSeek train on your data?

Yes, with an opt-out on request. DeepSeek’s privacy policy describes using data to train and improve its models and lists, among your rights, "the right to opt-out of using your Personal Data for training our models or optimizing our technologies" — an opt-out you must exercise, not a default.

Retention: DeepSeek states it directly collects, processes and stores personal data in the People’s Republic of China, and retains personal data for as long as necessary to provide its services.

Is DeepSeek HIPAA compliant?

No. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

Comparing vendors on this specifically? See BAA status for all 26 tools →

Is DeepSeek SOC 2 certified?

Not verified from a primary document on this check date. None found in DeepSeek’s published policies on this check date. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how DeepSeek runs its controls, not what your agreement with them permits.

Industry risk notes

Healthcare

Do not allow DeepSeek anywhere near patient information. No.

Financial services

DeepSeek fails the basic vendor-due-diligence test for financial services: inputs feed the vendor’s models and there is no auditable control surface. SEC/FINRA recordkeeping duties also mean untracked AI channels are an examination finding waiting to happen.

Legal & professional services

Privilege and DeepSeek do not mix: entering client matter details into a consumer AI service you cannot govern is an uncontrolled disclosure risk no engagement letter contemplates.

Primary sources

Every vendor claim above traces to a document the vendor publishes, and every document below is one we actually opened and read — each carries the date we read it. All of them were read on 29 July 2026. The verdict date on this page is not a build stamp and is not "today": it is the oldest of those dates, because a verdict is only as current as the stalest document under it. Rebuilding the site does not move it.

Where a fact is not in one of these documents, the page says so rather than filling the gap. That is why some rows read "not publicly documented" or "not established from a primary source" instead of naming a certification or rounding an open question to a convenient answer.

Why the tier verdict is "generic": Prohibited is the right starting classification for most 50–500 person companies — but a healthcare company, a law firm, and a SaaS startup should not have identical tool lists. The $79 policy kit classifies DeepSeek and 25 other tools specifically for your industry, company size, and the data your team handles.

And a verdict has a shelf life: vendor data policies change quietly — a terms update can move a tool between tiers overnight. This page states what we read on 29 July 2026. The $149/mo Monitor plan exists precisely because that date keeps receding.

Frequently asked questions

Is DeepSeek safe for work?

DeepSeek should not be used for company work. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Prohibited. DeepSeek’s own privacy policy states it collects, processes and stores personal data in the People’s Republic of China and uses data to train its models, and Italy’s data protection authority ordered an urgent block on processing Italian users’ data. There is no enterprise governance tier to fix any of that. This is the clean example of a Prohibited-tier tool: capable model, unacceptable data terms for company use. Block it and offer approved alternatives.

Does DeepSeek train on your data?

Yes, with an opt-out on request. DeepSeek’s privacy policy describes using data to train and improve its models and lists, among your rights, "the right to opt-out of using your Personal Data for training our models or optimizing our technologies" — an opt-out you must exercise, not a default.

Is DeepSeek HIPAA compliant?

No. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

Is DeepSeek SOC 2 certified?

Not verified from a primary document on this check date. None found in DeepSeek’s published policies on this check date. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how DeepSeek runs its controls, not what your agreement with them permits.

What tier should DeepSeek be in an AI acceptable use policy?

We classify DeepSeek as Prohibited for a typical 50–500 person company, assessed 29 July 2026. DeepSeek’s own privacy policy states it collects, processes and stores personal data in the People’s Republic of China and uses data to train its models, and Italy’s data protection authority ordered an urgent block on processing Italian users’ data. There is no enterprise governance tier to fix any of that. Your own classification should reflect your industry, data types, and which plan or account type your company actually uses.

New to the topic? Start with what shadow AI is — definition, examples and risks, then measure your own exposure with the shadow AI scorer.

Your team is using DeepSeek. Does your AI policy cover it?

Most policies name a handful of tools and go stale the month after they are written. Two ways to find out where yours stands: check an existing policy for gaps in 30 seconds, or generate a policy that classifies DeepSeek by name — free preview, no account. Starting from scratch? The free 14-section AI acceptable use policy template is the document itself, ungated.

Get the full policy kit

$79 one-time

A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies DeepSeek and 25 other tools for your company, industry, and data. Generated in about 10 minutes.

Generate my policy kit →

Keep it current with Monitor

$149/mo

We re-check vendor terms monthly and alert you when DeepSeek’s data policy changes — plus regenerate your whole kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.

See Monitor plan →

Work out where DeepSeek leaves you exposed

Compare with general assistants and AI search

Already have an AI policy? Check it for gaps in 30 seconds →