中文版:/zh/decisions/deepseek-2025/

Key points. The Personal Information Protection Commission ("PIPC") decided its prior inspection of Hangzhou DeepSeek Artificial Intelligence Co., Ltd. on 23 April 2025 (Decision No. 2025-009-026). The outcome was a corrective recommendation under PIPA art. 63-2(2) and an improvement recommendation under art. 61. It was not a sanction: the decision imposes no penalty surcharge and no administrative fine. The Commission found two breaches in definite terms, of the overseas transfer rule in art. 28-8(1) and of the privacy policy rule in art. 30(1) and (2). On training with user prompts it said that removing identifiers did not take the prompts outside the Act and that preprocessing is itself use of personal information, and then chose a recommendation over a finding of illegality. DeepSeek made four arguments. The Commission rejected two of them and accepted parts of the other two.

This note concentrates on one part of the decision: the section headed "Review of the Respondent’s Arguments". In that section DeepSeek put its position on each issue and the Commission answered it point by point.

This note reads that section together with the findings that precede it. Quotations from the decision are our translations from the Korean and are unofficial.

What kind of proceeding this was

The Commission opened a prior inspection (사전 실태점검) under PIPA art. 63-2 after multiple press reports raised concerns about excessive collection and third-party provision of personal data by the DeepSeek service. In this case the inspection ended in recommendations rather than a sanction. If a recommendation is not accepted or not carried out, the decision says the Commission may then carry out an inspection under art. 63(2).

The Commission worked from three sources. It reviewed DeepSeek’s published documents, including the privacy policy and terms of use, and DeepSeek’s written answers to its requests for materials. It also ran its own technical analysis of the DeepSeek website and app.

The decision applied the Act as amended by Act No. 19234, in force from 15 March 2024.

Why Korean law applied

DeepSeek’s privacy policy and terms did not name a service territory. The Commission found the Act applied anyway, on four grounds: DeepSeek had released the service in Korean app markets, offered it in Korean, trained on Korean-language data, and seen a real surge in Korean users. A footnote records that the app ranked first in the Korean Apple and Google app markets as of 30 January 2025.

According to the decision, DeepSeek released the service in Korean app markets on 15 January 2025. Up to 15 February 2025 it collected account data, prompt and other input, user enquiries, device and network data, logs, location and cookies from Korean users. It used that data to provide the service and for AI training, among other purposes, and stored it on servers in China that DeepSeek had built itself.

The corrective recommendation asks DeepSeek to do two things and report within 60 days:

  1. put a lawful basis in place for overseas transfers of personal data, and destroy personal data that was transferred without need; and
  2. publish a Korean-language privacy policy containing the items the Act requires, and keep the service transparent on an ongoing basis.

The improvement recommendation asks for four things, with results and plans to be reported within 60 days:

  1. put enhanced safeguards in place, such as excluding from training data the URLs containing resident registration numbers and other personal data that the Korea Internet & Security Agency ("KISA") provides;
  2. check whether children’s personal data has been collected and take appropriate steps, including destruction;
  3. inspect the personal information processing systems as a whole and fix vulnerabilities; and
  4. appoint a domestic representative, to implement the recommendations, comply with the Act more generally and protect the rights of Korean data subjects.

The closing part of the decision explains the next step. A party that receives a corrective recommendation must tell the Commission within 10 days whether it accepts (art. 63-2(3)). Silence for 10 days counts as non-acceptance. If the party does not accept, or accepts and does not carry the recommendation out, the Commission may inspect under art. 63(2).

Four arguments and how the Commission answered them

IssueDeepSeek’s positionThe Commission’s answerWhere it landed
Privacy policyA Korean policy covering the statutory items was submitted on 28 March 2025, and the existing policy already covered the main itemsNot accepted. The policy has to be written in Korean and built on the Korean Act; the missing items breach art. 30(1) and (2)Corrective recommendation, item 2
Overseas transferThe new Korean policy sets out transfers in detail; prompt input stopped flowing to the SDK destination on 10 April 2025; the SDK provider processes data for service stability and feature improvement, not marketingAccepted in part. The error-handling and UI/UX purpose, and DeepSeek’s control over the data, were partly shown. Sending prompt input had no clear need, and prompts already sent should be destroyedBreach of art. 28-8(1) found; corrective recommendation, item 1
Training on promptsDe-identified prompts are not personal information; if they are, contract necessity applies; an opt-out added on 17 March 2025 means legitimate interests clearly prevailNot accepted on the reasoning. The prompts remained identifiable in DeepSeek’s hands, preprocessing is use, and contract necessity did not apply. The Commission chose not to decide illegalityImprovement recommendation, item 1
SecurityThe exposed database held only test data; the directory exposure showed only public information; no user data leaked; other safeguards are in placeAccepted in part. Basic safeguards were lacking, but with no direct link to a leak it was hard to call a breach on those facts aloneImprovement recommendation, item 3

1. The privacy policy: a Korean policy is not a simple translation

DeepSeek published its privacy policy in Chinese and English. The English version, according to the decision, did not contain several items required by art. 30, including the procedure and method of destruction and the name and contact details of the chief privacy officer. There was no separate Korean policy until DeepSeek drafted one during the inspection and submitted it on 28 March 2025.

DeepSeek asked the Commission to take that draft into account, together with its view that the existing policy already covered the main statutory items. The Commission did not accept this. It restated the position from its guide for overseas businesses that a policy for a service subject to the Act must be written in Korean so that any Korean data subject can easily understand it. The decision then adds that the policy must be drawn up and published according to what the Act requires, "rather than simply translating a privacy policy drawn up on the premise of another country’s laws".

The Commission found that DeepSeek had breached art. 30(1) and (2) and had not met art. 3(5). A draft submitted during the inspection did not change that finding. The practical point for other services is that the Korean policy has to be written against the list of items in art. 30, not against the headings of a GDPR-style global policy.

2. Overseas transfer: the stated purpose has to fit the data actually sent

The Commission found that DeepSeek was transferring personal data to multiple companies located in China and the United States, including an affiliate, while outsourcing processing to them. DeepSeek had neither obtained consent to the items listed in art. 28-8(2) nor disclosed them in its privacy policy. The decision redacts the names of the affiliate and of the other recipients. According to the transfer table in DeepSeek’s own draft policy of 28 March 2025, the affiliate received "all personal information collected" for technical support on the design of the base algorithm and overall architecture.

The Commission’s own analysis of the service then found something the transfer list did not show. User prompt input was being sent through a third party’s SDK to that party’s servers. DeepSeek explained the flow as service improvement, but the Commission noted that the SDK did not require prompt input, so the need for the transfer was unclear. The decision’s before-and-after analysis is captioned to show that, after DeepSeek’s fix, packets sent to volces.com no longer contained the test input.

DeepSeek’s reply had three parts. It said the new Korean policy described the transfers in detail. It said prompt input had not been transferred to the SDK destination since 10 April 2025. And it said the SDK provider processed data only for service stability and feature improvement, not for marketing analysis, and submitted the provider’s terms in support. The draft Korean policy placed the transfers under art. 28-8(1)(3), the route for outsourcing or storage needed to conclude and perform a contract with the data subject.

The Commission accepted part of this. It found that the SDK flow served to fix errors in the service and improve UI/UX, and that DeepSeek retained control over the data, "in part" shown. It did not accept the prompts. In the Commission’s words, the need to send the information users entered in prompts was "unclear in light of 'service improvement' and the other purposes of transfer the respondent explained". The Commission confirmed by its own analysis that the flow had stopped, and said the prompt data of Korean users already sent still needed to be destroyed.

The breach finding under art. 28-8(1) stood. The art. 28-8(1)(3) route that DeepSeek’s draft relied on is available only where the statutory items are disclosed in the privacy policy or notified individually, for example by email, and at the time of the inspection neither had been done. This was the one breach the decision lists as the basis for the corrective recommendation.

3. Training on user prompts: identifiability is judged from what the operator holds

This is the issue most other AI services will recognise.

For pre-training, DeepSeek told the Commission that it used open-source datasets, web data collected by crawlers and data obtained through partnerships with other companies, and that it filtered out personal data that had been included unintentionally. For user prompts, DeepSeek said four things: only a very small share of input was used for training, user identifiers were removed, the data was adapted and personal data inside it removed, and data a user chose to delete was removed and not used. The decision notes that DeepSeek had not obtained consent to training or offered a way to refuse it, and records that DeepSeek introduced a training opt-out on 17 March 2025, during the inspection.

DeepSeek’s legal argument was layered. First, after identifier removal, adaptation and removal of personal data, using the prompts was not use of personal information at all. Second, if it was, contract necessity supplied a lawful basis because the terms of use referred to it. Third, the opt-out meant that the use was necessary for DeepSeek’s legitimate interests and clearly outweighed the rights of data subjects.

The Commission rejected the first step with two findings that deserve to be quoted:

"Even if user identifiers and the like are removed from the information users entered in prompts, [the respondent] can tell, from the 'user prompt input information' itself in the personal information file the respondent holds, which user entered (queried) that data."

"AI training includes not only training an algorithm on data but also the preprocessing for it, such as human review, data adaptation and removal of personal information, so it cannot be said that this is not use of personal information."

The first finding tests identifiability from the operator’s side. The question the Commission asked was whether DeepSeek, holding its own records, could link a prompt back to the user who typed it. It was not whether a stranger reading the de-identified text could do so. The second finding means that a de-identification pipeline does not sit outside the Act. The steps that make the data less identifiable are themselves processing that needs a basis.

On the second step the Commission held that training the language model and providing the DeepSeek service are distinct, that user input is not essential to training the model, and that the terms of use described the purpose only as service provision and improvement. For those reasons the use was not necessary to perform the contract with users.

On the third step the decision does not contain a separate heading for legitimate interests. Its answer appears to be the sufficiency analysis. The Commission observed that the privacy policy and terms said only "service provision and improvement", with no explanation or notice about AI training or the measures DeepSeek applied. Measured against users' ability to foresee the use, their freedom to choose and the risk of undue harm to their interests, the Commission found those measures hard to regard as sufficient. In the earlier findings section it put the conclusion in cautious terms: the use "may" exceed the scope permitted by art. 15(1), and there is a "possibility" of breach of art. 18(1).

The Commission then chose not to decide the point. It weighed four matters: the opt-out introduced during the inspection, the ability to delete input data, the fact that the app had been offered in Korea for only about 30 days, and DeepSeek’s explanation that it deleted resident registration numbers and other key Korean personal data from public data. It concluded that, rather than establishing and deciding illegality, it was necessary to apply the enhanced safeguards developed from its 2024 prior inspection of major AI services. The result was item 1 of the improvement recommendation. The decision refers back to that 2024 inspection, in which the Commission had recommended that major AI businesses give notice of human review of user input with a choice for the user, and act on KISA’s deletion and blocking information for URLs exposing personal data.

The reasoning therefore stands even though the conclusion was a recommendation. In our view, a later case with a longer service period and no opt-out is likely to be read against the same two findings, although the decision itself does not say so. Whether the Commission would then go further than a recommendation is a question each case will answer on its own facts.

4. Security: the finding softened between two parts of the decision

The inspection looked at two incidents. One was a press report that a DeepSeek database had been exposed. DeepSeek explained that it was a development-environment database holding test data generated by developers, that it had been open to anyone, that no user data had leaked and that the problem had been fixed. The other was a web vulnerability the Commission itself confirmed as of 14 February 2025, in which editing part of a DeepSeek website URL exposed the web server’s directory. The decision records that this too had been fixed.

In its legal assessment the Commission said that a database anyone could reach from outside, together with a well-known web vulnerability, suggested DeepSeek had neglected basic safeguards before launch, and that there was a "possibility" of breach of art. 29. In its review of DeepSeek’s arguments the Commission went further in DeepSeek’s favour. It accepted that basic safeguards were lacking even on a development server. However, because the exposure had no direct link to a leak of personal data, "there is also an aspect in which it is difficult to assess it as a breach of the Act on that fact alone". The recommendation that followed asks DeepSeek to inspect its processing systems as a whole and fix what it finds.

Children’s data

DeepSeek did not argue this issue, but the decision addresses it. DeepSeek’s policy stated that it did not collect the data of children under 14, that the service was not offered to anyone under 18, and that users aged 14 to 17 needed parental consent. The Commission found no age-check step at sign-up, so it could not tell whether children’s data had been collected. DeepSeek reported that it introduced an age-check process on 17 March 2025. The Commission’s view was that where children and teenagers are realistically expected to use a service, the operator should check age before providing it. Failing to prevent collection of under-14 data without guardian consent did not meet art. 3(4) and (8) and "may" breach art. 22-2. The matter went into item 2 of the improvement recommendation.

What came after: 9 September 2026

On 9 September 2026 the Commission resolved a follow-up to its 2025 evaluation of privacy policies. It had rechecked businesses rated insufficient in that evaluation, looking at rights-request channels, domestic representatives and access to privacy policies. According to its press release of 16 September 2026, DeepSeek answered a Korean user’s enquiry in Chinese. The Commission recommended that DeepSeek improve its operating system so that requests from Korean data subjects to exercise their rights are received and handled smoothly.

This account rests on the press release. We have not located a published decision text for the 2026 follow-up. Read together with the 2025 decision, the follow-up suggests that the Commission checks not only whether a Korean policy exists but also whether the channels it describes work in Korean.

  1. Map every outbound data flow, including third-party SDKs, before the Commission does. The prompt flow in this case did not appear in the transfer list DeepSeek submitted. The Commission found it by analysing the service’s traffic. The Commission accepted DeepSeek’s explanation of purpose only in part: for the prompt input it found the need unclear against the stated purpose, and it called for data already sent to be destroyed. The finding on the transfer disclosure itself stood. The transfer disclosure therefore has to be checked field by field against what the app actually sends.

  2. Settle the lawful basis and the notice for training before preprocessing begins. The Commission judged identifiability from the files the operator holds, and treated human review, adaptation and redaction as use of personal information. A privacy policy that says only "service provision and improvement" left users unable to foresee training on their input. Contract necessity did not carry training on prompts in this case, because model training and the service were treated as separate. An opt-out and a short service period moved the Commission towards a recommendation rather than a finding of illegality. It would be unsafe to treat that as the likely result in another case.

  3. Write the Korean policy against the Korean Act, and make the Korean channel work. The Commission said a Korean policy has to be written under the Korean Act, not simply translated from a policy built on another country’s law, and later followed up on an enquiry answered in Chinese. The art. 30 items, a working Korean-language rights channel and a domestic representative appear together in this decision’s recommendations and in the 2026 follow-up.

Each of these points turns on the facts of a particular service, and the outcome in another case may differ.

Frequently asked questions

Was DeepSeek fined by the Korean Personal Information Protection Commission?

No. Decision No. 2025-009-026 of 23 April 2025 closed a prior inspection under art. 63-2 of the Personal Information Protection Act. The Commission issued a corrective recommendation under art. 63-2(2), covering the lawful basis for overseas transfers, destruction of data transferred without need, and a Korean-language privacy policy, and an improvement recommendation under art. 61, covering training-data safeguards, children’s data, security and the appointment of a domestic representative. Neither a penalty surcharge nor an administrative fine was imposed. DeepSeek was asked to report the results within 60 days of notification.

If an AI service removes user identifiers from prompts before training, are the prompts still personal information under Korean law?

In the DeepSeek decision the Commission said they were. It reasoned that even with user identifiers removed, DeepSeek could tell from the prompt input information itself, held in its own personal information file, which user had entered it. It added that AI training includes preprocessing such as human review, data adaptation and removal of personal information, so that stage is also use of personal information. The Commission then chose to recommend improved safeguards rather than make a finding of illegality on this issue.

Can a foreign AI service rely on contract necessity to train its models on Korean users' prompts?

Not on the facts of the DeepSeek decision. The Commission held that training the language model and providing the DeepSeek service are distinct, that user input is not essential to training the model, and that the terms of use described the purpose only as service provision and improvement. On that basis it found that the use was not necessary to perform the contract with users. How the point applies to another service depends on its own terms, notices and data flows.


This note is a general summary of one Korean regulatory decision for readers outside Korea and is not legal advice. Quotations from the decision are our unofficial translations; the Korean text governs. The decision applied the Personal Information Protection Act as in force from 15 March 2024 (Act No. 19234), and later amendments may affect how the same facts would be assessed today.

Written by Hyunsub Lee, a Korean-qualified lawyer at SEUM Law in Seoul (firm profile; the page opens in Korean, so use the ENG switch at the top right for the English version). For Korean readers, the questions of where prompt input belongs in a generative AI privacy policy are discussed at 생성형 AI 서비스의 개인정보 처리방침, and what changes once a corrective recommendation is accepted is discussed at 개인정보위가 혐의 없이 점검을 나왔습니다. Published PIPC decisions are listed in English at PIPC enforcement decisions, and the appointment of a domestic representative is covered at Appointing a Domestic Representative.