Italy's Garante ordered DeepSeek's Chinese operators to stop processing Italian users' data
By Anthony Guerriero, Founder and lead analyst, The Leveraged Years.
Rome, dateline 30 January 2025. Last verified: 2026-07-25.
On 30 January 2025 the Italian data protection authority, the Garante per la protezione dei dati personali (Guarantor for the protection of personal data), became the first EU regulator to halt a fast-moving Chinese frontier-AI app's processing of local users' personal data on privacy grounds. The instrument is short, it is signed, and it carries a number worth memorizing: Provvedimento n. 33 of 30 January 2025, doc. web n. 10098477. It did not fine DeepSeek, and it did not order the app pulled from Italy. It did something operationally sharper: it ordered the app's operators to stop processing the personal data of people located in Italy, effective the moment they received the order.
That distinction, a limitation on data processing rather than a headline fine, is exactly why US general counsel and AI product leads keep citing this file. It is the clean precedent for what a European regulator can do to a foreign model provider in days, not years.
What the Garante ordered
The operative clause is unusually direct. The Garante did not issue a warning or a request for a remediation plan. It ordered a definitive limitation of processing. In the Italian original:
"ORDINA ai sensi dell'art. 58, par. 2, lett. f) [...] la limitazione definitiva delle attivita di trattamento dei dati personali di interessati che si trovano nel territorio italiano che avvengono nell'ambito del servizio DeepSeek. La predetta limitazione ha effetto immediato a decorrere dalla data di ricezione del presente provvedimento."
English gloss: "ORDERS, pursuant to Art. 58(2)(f), [...] the definitive limitation of the processing of personal data of data subjects located in Italian territory carried out in the context of the DeepSeek service. That limitation takes immediate effect from the date of receipt of this order."
Two named companies are on the receiving end: Hangzhou DeepSeek Artificial Intelligence Co., Ltd. and Beijing DeepSeek Artificial Intelligence Co., Ltd., the operators of the DeepSeek chatbot delivered through app, website, and related software. The Garante used Article 58(2)(f) of the GDPR, the power to impose a temporary or definitive limitation on processing, and invoked it "in via d'urgenza" (as a matter of urgency) while a fuller investigation continued.
What triggered the order: an unsatisfactory reply and data sitting in China
The timeline is tight. On 28 January 2025 the Garante sent the two companies a formal request for information (Reg. No. 10841/25) covering what personal data DeepSeek collects, from which sources, for what purposes, on what legal basis, and whether any of it is stored in China. The companies replied on 29 January 2025 (Reg. No. 11349/25). Their answer, in the Garante's words, was found "del tutto insufficiente" (entirely insufficient).
The companies argued they had not entered and did not plan to enter the Italian market, that they had pulled the DeepSeek app from local app stores, and that the GDPR simply did not apply to them. The Garante rejected that framing on the facts. Its order records four concrete deficiencies against the GDPR:
- Article 6. No granular, per-activity lawful basis for each processing operation in the DeepSeek service.
- Chapter III. The information gaps also impaired data subjects' ability to exercise their rights.
- Article 32. Per DeepSeek's own privacy policy, "i dati raccolti [...] sono conservati presso la Repubblica popolare cinese" (the data collected are stored in the People's Republic of China), which the Garante treated as a security-of-processing failure.
- Article 27. The operators fell under Art. 3(2) because they offered the service to people in the EU, yet had not designated a written EU representative.
So the trigger was twofold: a notice failure, the operators would not or could not account for their processing, and a data-transfer posture, user data landing on servers in China without the GDPR guarantees the Garante expects.
Who is covered: frontier-AI and chatbot operators serving the EU
This order does not name a broad class of companies, but the reasoning does. The Garante grounded jurisdiction in Article 3(2) of the GDPR, the "offering of goods or services" limb. If a chatbot or model provider makes its service available to people located in the EU, the Garante's position is that it is caught by the GDPR regardless of where the company is incorporated or where it says its market is. Claiming "we are not in the Italian market" did not help DeepSeek, because millions of downloads and an available service told a different story.
Practically, the covered set is any foreign frontier-AI or consumer-chatbot operator that (a) is reachable by EU users, (b) processes their prompts and account data, and (c) has not appointed an Art. 27 representative or cannot document its lawful basis and data flows. That is a large group, and it is why the file reads as a template.
Penalties and enforcement: not a fine, but teeth
It is worth being precise here, because press coverage blurred it. The 30 January 2025 order set no monetary penalty. It is a limitation of processing plus a newly opened investigation ("istruttoria"). The enforcement force sits in what happens if the companies ignore it. The order expressly recalls that non-compliance exposes the operators to the criminal sanction under Art. 170 of the Italian Privacy Code and to the administrative fines under Art. 83(5)(e) of the GDPR, the top tier that reaches up to EUR 20 million or 4 percent of total worldwide annual turnover.
| Feature | Garante DeepSeek order (30 Jan 2025) | A typical Art. 83 fine decision |
|---|---|---|
| Legal power used | Art. 58(2)(f) limitation of processing | Art. 58(2)(i) / Art. 83 administrative fine |
| Speed | Days (urgency procedure) | Months to years after full investigation |
| Immediate effect | Yes, on receipt of the order | No, usually payable after appeal windows |
| Money at stake in the act itself | None set | The fine amount |
| Consequence of ignoring it | Art. 170 Code (criminal) plus Art. 83(5)(e) fines | Enforcement of the fine, possible escalation |
Appeal route, for completeness: the operators had 30 days to challenge the order before the ordinary Italian court where the controller resides, or 60 days if the applicant is based abroad.
Cross-border read: why US teams cite this file
For a US audience, the useful takeaway is not "Italy is anti-China." It is that a single national regulator, acting alone, halted a globally downloaded AI service's processing of local users' personal data in under a week, on ordinary GDPR grounds any EU DPA can use. Three lessons travel across the Atlantic.
First, incorporation elsewhere is not a shield. Art. 3(2) attaches to where your users are, not where your servers or your cap table live. A US model provider serving EU consumers is in exactly the position DeepSeek was.
Second, the "we are not really in that market" defense is weak once a service is live and used. The Garante treated availability and download volume as the operative facts.
Third, the fastest regulatory pain is not the fine, it is the processing limitation. An order under Art. 58(2)(f) can stop a service from handling local users' personal data immediately, well before any fine is argued. For a US legal team pressure-testing an EU launch, the Art. 27 representative, a documented lawful basis per Art. 6, transparent notices, and a defensible data-transfer story are the four boxes this order checked and DeepSeek did not.
What this order does NOT do
- It does not impose a fine. Anyone citing a euro figure for the 30 January 2025 order is citing the wrong document.
- It does not ban DeepSeek across the EU. It binds processing of data belonging to people located in Italian territory. Other DPAs acted separately.
- It is not a final ruling on the merits. The Garante expressly reserved further determinations pending its investigation.
- It does not turn on the AI Act. This is a GDPR data-protection action, decided on Articles 3, 6, 27, and 32, not on Regulation (EU) 2024/1689.
- It does not assess model safety, output quality, or bias. The instrument is about personal-data processing and transfers, nothing more.
Key Facts
- Instrument
- Provvedimento (order), Registro dei provvedimenti n. 33 of 30 January 2025, doc. web n. 10098477.
- Issuer
- Garante per la protezione dei dati personali (Italian Data Protection Authority); relatore prof.ssa Ginevra Cerrina Feroni, president prof. Pasquale Stanzione.
- Effective date
- Immediate effect on receipt of the order, dated 30 January 2025 in Rome.
- Who is covered
- Hangzhou DeepSeek Artificial Intelligence Co., Ltd. and Beijing DeepSeek Artificial Intelligence Co., Ltd., operators of the DeepSeek chatbot service.
- Consequence
- Definitive limitation of processing of Italian users' data under GDPR Art. 58(2)(f); no fine set; non-compliance exposes the operators to Art. 170 of the Italian Code and Art. 83(5)(e) GDPR fines.
- Status
- Urgency order issued alongside a full investigation; further determinations reserved.
FAQ
What did Italy's Garante order against DeepSeek?
In Provvedimento n. 33 of 30 January 2025 (doc. web n. 10098477), the Garante ordered the two Chinese operators of DeepSeek to stop, with immediate effect, processing the personal data of people located in Italy, using Article 58(2)(f) of the GDPR.
Was DeepSeek fined?
No fine was set in this order. It is a processing limitation. The Garante opened a separate investigation, and non-compliance can trigger criminal liability under Art. 170 of the Italian Privacy Code and administrative fines under Art. 83(5)(e) of the GDPR.
Why did the Garante say GDPR applied to a Chinese company?
It found the operators fell under Art. 3(2) of the GDPR because they offered the DeepSeek service to people in the EU, and it noted they had not designated a written EU representative under Art. 27.
Does the order apply outside Italy?
It binds processing of data belonging to people located in Italian territory. It does not by itself block DeepSeek across the EU, though it became an early national action other regulators referenced.
Primary sources
- Garante, Provvedimento del 30 gennaio 2025 [doc. web n. 10098477] (full order, Italian with English translation).
- Garante press release: "Intelligenza artificiale: il Garante privacy blocca DeepSeek" / "The Italian Data Protection Authority blocks DeepSeek".