Table of Contents
Italy’s decision turns a privacy dispute into a test of AI accountability
Italy’s data protection authority, the Garante, has blocked the Chinese AI chatbot DeepSeek over concerns about data privacy. At the centre of the case is a basic but consequential question for any consumer AI service: what happens to the information people provide when they use it?
Chatbots are often treated as simple search tools or writing assistants, but the exchanges they host can be unusually personal. Users may enter work material, private questions, plans, preferences, or fragments of information that would not ordinarily be posted publicly. That makes clarity around collection, processing, storage and access more than a legal formality. It is the minimum information users and regulators need to judge whether a service deserves trust.
Officials said DeepSeek failed to provide adequate information on how it collects, processes and stores user data. The decision followed an inquiry into whether personal data is sent to China and whether the chatbot complies with European privacy laws. The issue is not merely where an app was developed or where its users are located. It is whether the company can clearly explain the path data takes, why it is used and what legal justification it relies on.
The Garante requested specific details, including the sources of collected data, its intended use and the legal basis for processing it. Those requests go to the operating logic of an AI service. A regulator cannot meaningfully assess privacy protections from broad assurances alone; it needs an account of the data involved and the rules governing its use. DeepSeek’s response was deemed insufficient, prompting the immediate ban. The regulator emphasized that protecting Italian users’ data was its priority.
That sequence matters. Italy was not simply reacting to the popularity of a new AI app or to a wider geopolitical argument about Chinese technology. The published basis for the action was DeepSeek’s failure to answer privacy questions adequately. For companies bringing AI products to European users, that is an uncomfortable but clear message: technical ambition does not remove the obligation to explain data practices in terms regulators can evaluate.
For related guidance, see 7 Things You Should Never Share With AI Chatbots.
DeepSeek’s rapid rise made its data practices impossible to ignore
DeepSeek has rapidly gained popularity, surpassing ChatGPT as the top-rated free AI app on Apple’s U.S. App Store. The Chinese startup claims its AI models match or exceed leading U.S. models at a lower cost, potentially disrupting the global AI landscape.
That rise is part of what makes the Italian action significant. An obscure service can avoid sustained public attention for a time; a chatbot attracting mass consumer interest cannot. Once an AI assistant becomes a routine destination for questions, summaries and generated text, its privacy policy and data controls become central to the product rather than fine print around the edges.
The tension is familiar across the AI market. Users are drawn to capability, convenience and free access. Regulators are asking a different set of questions: what data is collected, what is retained, what is done with it and whether the company has a lawful basis for each part of that process. Neither side of that equation is trivial. A service can be compelling and still face legitimate scrutiny if its explanations do not match the sensitivity and scale of the data it may receive.
European authorities are increasing that scrutiny. Regulators in Ireland and France have also questioned DeepSeek’s data practices. This does not mean every inquiry will produce the same result, but it does indicate that the Italian case is not an isolated concern. AI services are increasingly being judged not only by their answers to prompts, but by the governance behind those answers.
The company removed its AI assistant from Italian app stores after inquiries began but insisted it is not subject to Italian regulations. That stance only intensified concerns, leading to the ban. It also created a sharp clash between a regulator asserting responsibility for the protection of people in Italy and a company challenging the reach of those rules.
There is a practical lesson here for users as well as companies. App-store availability can make a service look settled, official and low-risk, but it says little by itself about how data is handled. People should not have to become privacy lawyers before using a chatbot. Still, the information they choose to share remains one of the few controls they can exercise directly when the company’s practices are under dispute.
Related reading: DeepSeek’s AI Censorship: The 85% Blackout on Sensitive Topics, published on January 31, 2025, by SquaredTech.
A block is a powerful signal, but enforcement is rarely tidy
Italy’s Garante has taken a strong stance on AI regulation, previously banning ChatGPT in 2022 over privacy concerns. The DeepSeek case signals a growing trend of European regulators closely monitoring AI firms, particularly those based in China.
The comparison with ChatGPT is useful because it shows that scrutiny of AI privacy is not confined to one company or one country. Regulators are confronting a product category that can absorb large volumes of user input while operating through systems that many users cannot inspect. The central demand is not that AI companies stop offering useful tools. It is that they account for the personal data those tools may collect and process.
Yet a formal block does not necessarily produce an immediate, uniform user experience. Despite the ban, some Italian users report that the chatbot remains functional on previously downloaded apps. The web version is also still accessible, raising questions about enforcement measures. That gap between a regulatory order and what users can still reach online is a recurring challenge for app-based and web-based services.
It also explains why app-store removal is only one part of an enforcement response. Removing a service from Italian app stores can limit new downloads, but it does not automatically resolve access through software already installed or through a browser. For users, the result can be confusing: a product may appear available in practice while its legal and regulatory status remains contested.
Authorities warn that continued non-compliance will keep DeepSeek blocked in Italy. The next question is whether the company can provide the information the Garante says is missing and address the concerns that led to the decision. Until then, the dispute is likely to remain a reference point for the wider AI industry.
As Europe tightens AI regulations, this case could set a precedent for future actions against AI companies that fail to meet strict data privacy standards. The important precedent is not that every foreign AI service will face a ban. It is that popular AI products may be asked to meet the same basic expectation as other services handling personal data: explain what they collect, explain why they use it and show that the practice complies with the law.
More on the company’s wider impact: DeepSeek’s Rise: How a Chinese AI Lab is Disrupting Global Tech Giants, published on January 30, 2025, by SquaredTech.
Also see OpenAI Chief Calls DeepSeek’s R1 Model a Game-Changer in AI, published on January 29, 2025, by SquaredTech.
Stay Updated: Artificial Intelligence

