Listen to this Post

The Berlin Commissioner for Data Protection has called for the immediate removal of the DeepSeek AI app from Google and Apple app stores, citing violations of the European Union’s General Data Protection Regulation (GDPR). This move follows accusations that DeepSeek AI is unlawfully transferring extensive personal data of its German users to servers in China, raising significant privacy concerns.
In a formal request issued on May 6, 2025, the Data Protection Commissioner urged the Chinese AI company to cease its illegal data transfers and to comply with EU regulations by meeting legal data transfer requirements. After DeepSeek AI failed to address the concerns, the Commissioner invoked the Digital Services Act on June 27, 2025, demanding that both Apple and Google review the issue and take appropriate action. This request was coordinated with German state data protection officers and the Federal Network Agency.
DeepSeek AI, which operates in Germany without an EU office, is available through both the Google Play Store and Apple App Store with German-language support. The app collects a wide range of personal data from its users, including chat histories, uploaded files, device information, and location data, all of which are transferred to servers in China. Without EU safeguards or an adequacy decision for China, DeepSeek AI is in clear violation of the GDPR.
Meike Kamp, Berlin’s Commissioner for Data Protection, emphasized that the app’s actions expose German users’ data to potential access by Chinese authorities, who have extensive rights to personal data under Chinese law. She further noted that users in China do not have enforceable rights or legal remedies equivalent to those guaranteed within the EU. The Commissioner has since alerted both Apple and Google, demanding they act swiftly to protect user privacy.
This move follows Italy’s data protection authority’s decision in January 2025 to block the app over similar privacy concerns, marking a growing European pushback against Chinese tech companies in the face of rising cybersecurity and privacy concerns.
What Undercode Says: The Growing Battle Over Data Privacy
The DeepSeek case represents a larger issue currently gripping the tech world—how to balance innovation and convenience with data protection. The GDPR, one of the strictest privacy laws in the world, was designed to ensure that companies handling personal data follow strict protocols to protect individuals’ privacy. The fact that DeepSeek AI has violated these principles, transferring data to a country where legal protections for foreign users are weaker, has raised alarms about the future of cross-border data transfers.
This issue isn’t limited to DeepSeek alone. Numerous tech companies, especially those based outside the EU, are grappling with the question of how to comply with the GDPR while maintaining their business models. The EU’s strict stance on data privacy could lead to a broader shift in how international companies interact with European consumers. As more regulatory bodies in Europe take action against data privacy violations, we may see increased scrutiny of foreign tech firms operating in the region.
The case is also noteworthy because it highlights the complex dynamics between international data transfer laws and the global reach of tech companies. The use of personal data is becoming increasingly tied to national security interests, as governments seek to protect their citizens from potential foreign surveillance and cyber threats. The decision to involve both Google and Apple underscores the importance of platform operators in regulating apps and services that could jeopardize user privacy.
Given the current landscape, companies that collect vast amounts of personal data must rethink their approach to user privacy—especially when it comes to data transfers outside of the EU. The Berlin Data Protection Commissioner’s intervention is a stark reminder of the EU’s commitment to upholding its data protection standards, and this could set a precedent for future regulatory actions.
🔍 Fact Checker Results
Data Transfer Concerns: DeepSeek AI’s transfer of personal data to Chinese servers is in violation of the GDPR due to the lack of adequate safeguards for foreign data protection.
Regulatory Backlash: European regulators, including Italy’s data watchdog, have already taken steps to block DeepSeek AI’s services, confirming concerns about user privacy.
Legal Precedent: The Digital Services Act is being invoked more frequently, showcasing a shift toward stronger enforcement of privacy laws across the EU.
📊 Prediction: The Future of AI Privacy Regulation
As regulatory bodies like the Berlin Data Protection Commissioner continue to crack down on data privacy violations, we can expect a tightening of the rules surrounding AI and data handling in the EU. This could result in more stringent requirements for foreign tech companies operating in the region, especially those handling sensitive personal data. Additionally, with growing public concern over data privacy, there may be increased demand for transparency in how companies collect, store, and share personal information. If DeepSeek AI and similar companies fail to meet these expectations, we might see even more widespread bans and legal consequences for non-compliance in the future.
In the long run, this could lead to a fragmented global landscape for tech companies, with different countries implementing their own stringent data protection laws. Companies may need to develop separate operations for the EU and non-EU markets to avoid the complexities of compliance, ultimately reshaping the international tech industry.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




