WellWired Journal
Is DeepSeek AI Safe? UK Guide
DeepSeek is legal in the UK but the ICO has an open enquiry into it. Here's what that means and what to keep out of the chat.

Quick summary: DeepSeek is legal to use in the UK. It's a free built by a Chinese company, and its servers sit in China, a country the UK has not given a data adequacy decision to. The ICO has written to DeepSeek asking how it protects UK users' data. It's fine for casual, low-stakes questions, but you should never type anything personal, financial, or medical into it.
DeepSeek made headlines in early 2025 when it briefly overtook ChatGPT at the top of the app store charts. It was free, it was fast, and it came from a company almost nobody in the UK had heard of before that week. If someone mentioned it to you, or you saw it in the news, it's reasonable to wonder whether it's actually safe to try.
The short version: you can use it, but you should know a few things first. Read on and you'll have everything you need to make your own call.
What Is DeepSeek?
DeepSeek is an AI chatbot, the same kind of tool as ChatGPT or Claude. You type a question or a request, and it writes back in plain text within a few seconds.
It's made by Hangzhou DeepSeek Artificial Intelligence, a company based in China. Its most talked-about model, DeepSeek-R1, was built at a fraction of the cost that companies like OpenAI reportedly spent on their own models, which is a large part of why it made global news. You can use it through the DeepSeek app, the DeepSeek website, or an if you're technically minded, none of which require anything more than an email address to sign up.
At WellWired we spent time testing DeepSeek against everyday questions, the sort of things you might genuinely ask it: recipe ideas, help drafting a letter, a summary of a news story. It handled all of them competently. The concerns here are not about how well it works. They're about what happens to what you type once you've sent it.
Is DeepSeek Safe to Use in the UK?
There is no UK ban on DeepSeek. Unlike Italy, which blocked the consumer app in early 2025, the UK has taken a watch-and-monitor approach rather than a ban. You can download it, sign up, and use it exactly as you would any other chatbot.
"Safe" is really two separate questions, though. Is it safe from a scam or malware point of view? Yes, as far as anyone has found. It's a legitimate product from a real company, not a fake app designed to steal your details. Is it safe from a data privacy point of view? That's murkier, and it's the part worth ten minutes of your attention.
Our view is that DeepSeek is fine for low-stakes, general questions, the kind you wouldn't mind a stranger reading over your shoulder. For anything involving your finances, your health, or another person's private details, we'd point you towards a tool with a clearer UK data protection track record, which we'll get to below.
Why Is the ICO Looking Into DeepSeek?
The Information Commissioner's Office, or ICO, is the UK's data protection regulator. According to reporting from legal and regulatory specialist MLex, the ICO wrote to DeepSeek in early 2025 requesting information about how it protects the data of UK residents. The regulator has said it continues to actively monitor developers, DeepSeek included, and will act if it finds UK users' information rights are not being respected.
The UK is not alone here. Germany and Italy have opened their own enquiries into DeepSeek's data practices, while South Korea suspended new downloads and Australia and India banned it for government use, according to a Reuters regulatory roundup. Italy went further and blocked the app entirely.
The core issue is where your data ends up. DeepSeek's own privacy policy confirms that personal data is collected, processed and stored on servers in China. Under UK GDPR, China does not have what's called an adequacy decision, meaning the UK government has not formally judged that Chinese data protection law offers the same standard of protection as UK law. The ICO's own guidance on adequacy regulations sets out what that means in practice: organisations sending data to a non-adequate country need extra legal safeguards in place, and DeepSeek has not published details of what safeguards it uses for UK users.
None of this means anything sinister has happened to your specific conversations. It means the regulator responsible for protecting your data rights has open questions it hasn't had answered yet.
What Data Does DeepSeek Collect?
DeepSeek's privacy policy lists a fairly broad set of information. It includes your account details (email, phone number, date of birth, username and password), everything you type or upload during a chat, and technical data about your device, including your IP address and device model. Reporting from Tom's Guide found the policy also allows for keystroke pattern collection, which is unusual and goes beyond what most mainstream chatbots gather.
There was also a real security incident. In January 2025, cybersecurity firm Wiz Research found that a DeepSeek database had been left open on the internet with no password protection at all. It contained over a million lines of internal logs, including chat history and access keys. Wiz reported the issue directly to DeepSeek, which secured it within an hour. Nobody has confirmed the exposed data was accessed by anyone with bad intentions, but it happened because of a basic configuration mistake, and that's worth knowing before you decide how much you trust the platform with your information.
Does a VPN Make DeepSeek Safe?
You'll see this suggested a lot, often by companies that sell VPNs. It's worth being clear about what a VPN actually does here, because it's less than the marketing implies.
A VPN hides your internet traffic from your broadband provider and disguises your location. That's genuinely useful for some things. What it does not do is change where DeepSeek stores your data once you've sent it, or who at the company can access it, or whether Chinese law applies to that data. Once you type a message and hit send, a VPN's job is finished. The message has already arrived at DeepSeek's servers exactly as it would have without one.
If a website tells you a VPN solves the China data storage concern, it's not being straight with you. A VPN is a reasonable general privacy tool. It is not a fix for this specific issue.
What Should You Never Type into DeepSeek?
The same rule applies here as with any AI chatbot: don't type anything you wouldn't be comfortable with a company storing indefinitely on servers you don't control.
- Your NHS number or National Insurance number. No chatbot needs these for anything you'd realistically ask it.
- Bank details, sort codes or card numbers. There's never a good reason to hand these to an AI tool.
- Passwords or PINs. Not here, not anywhere.
- Passport or driving licence numbers. Treat these the same as financial details.
- Health details that identify you. General health questions are fine; your specific diagnosis, medication list, or a family member's condition is not.
- Other people's personal information. If you're writing about a friend or relative, leave their name and identifying details out.
Our full guide on what not to share with any AI chatbot covers this in more depth, and everything in it applies just as much to DeepSeek as to the tools it was written about.
Should UK Seniors Consider Using DeepSeek?
Honestly, we'd suggest starting somewhere else.
DeepSeek is capable and it's free, and for a lot of everyday questions that's genuinely appealing. But two things count against it for a first-time UK user. The regulatory picture is unsettled, with a UK data protection regulator that has open questions it hasn't published answers to. And the data collection is broader than most alternatives, including keystroke tracking that goes further than what tools like ChatGPT or Claude collect.
Neither ChatGPT nor Claude is perfect, and both have their own privacy considerations worth reading up on. But both have a longer track record with UK regulators, clearer opt-out settings, and neither stores your data in a country without a UK adequacy decision. For most people getting started with AI, either is a simpler and steadier first choice.
If you do want to try DeepSeek, keep it to general, low-stakes questions, avoid the app's optional permissions where you can, and never share anything from the list above. You'll find more guidance like this in our AI safety hub.
If you'd like to build real confidence with AI tools, privacy included, the WellWired Academy walks through it all in plain English, with nothing assumed and nothing rushed.
FAQ
Is DeepSeek banned in the UK?
No. The UK has not banned DeepSeek for consumers or businesses. Italy blocked the consumer app in early 2025 over data protection concerns, but the UK's approach so far has been to monitor and request information rather than restrict access.
Is DeepSeek Chinese owned, and does that matter?
Yes, DeepSeek is built and run by Hangzhou DeepSeek Artificial Intelligence, a company based in China, and it stores user data on servers there. It matters because China does not have a UK GDPR adequacy decision, so the legal protections around your data are less clear than with a company storing data in the UK, EU, or a country the UK has approved.
Does DeepSeek use my conversations to train its AI?
DeepSeek's privacy policy allows for collected data, including your chat content, to be used to improve its services, which typically includes AI training. This is common practice among free AI chatbots, though DeepSeek's policy is broader in scope than some competitors, particularly around device and keystroke data.
What happened in the DeepSeek data leak?
In January 2025, security researchers at Wiz Research discovered a DeepSeek database left open on the internet without any password protection. It exposed over a million log entries, including chat history and internal access keys. DeepSeek secured the database within an hour of being told about it. There's no confirmed evidence the exposure was exploited before it was fixed, but it happened due to a basic security oversight.
Is DeepSeek better than ChatGPT?
For raw capability on everyday tasks, DeepSeek performs competently and compares well on cost, since it's free. For UK users prioritising data protection and a longer regulatory track record, ChatGPT currently has fewer open questions attached to it. Which is "better" depends on what matters most to you: capability and cost, or a clearer privacy picture.
Was this page helpful?
Stay a step ahead of the scammers.
Join our free weekly email, written for people over 50 in plain English. Here is what lands in your inbox:
- This week's scam to watch, so you spot it before it reaches you
- One simple thing to try, in plain English, with the exact words to type
- Your free 5-page AI Starter Kit, sent the moment you join
Free forever. We never share your email, and you can unsubscribe in one click.
About the Author
Want to keep learning?
Explore more in-depth guides or start a structured learning path built for beginners.