AI Data Concerns: Italian Data Protection Authority Seeks Answers from DeepSeek

As data protection professionals, keeping abreast of developments regarding personal data risks is essential. One recent concern involves the Italian Data Protection Authority (IDPA), the Garante, requesting information from Hangzhou and Beijing-based DeepSeek Artificial Intelligence companies. The inquiry centers around the chatbot service provided by DeepSeek, which presents potential high risks to millions of users’ personal data in Italy.

Core Concerns and Inquiries:

Given the sensitivity of the situation, the Garante has sought thorough details on several fronts. These include the nature of personal data being collected, their origins, purposes behind the data processing, and whether data is stored on servers situated in China. Such inquiries highlight the ongoing effort to assess data flows and ensure that they comply with the General Data Protection Regulation (GDPR).

The Italian Authority has specifically urged DeepSeek to clarify the types of information that train their AI system. This request extends to whether data collection involves web scraping methods, thus requiring transparency on how users—both registered and unregistered—are informed about the treatment of their data.

Timeline for Compliance:

The pressure is on the companies involved, as they must respond with the requisite information within 20 days. This timeline underscores the urgency and importance the regulator places on understanding this potential threat to data privacy.

Implications for Data Professionals:

For data protection professionals, this situation serves as a notable example of rigorous regulatory oversight in action. It reaffirms the significance of understanding legal bases for data processing and ensuring systems are transparent about data usage. The case also highlights the criticality of geographical data storage considerations concerning data protection compliance.

The activities by the Garante emphasize the vigilant stance that data protection authorities are taking in the wake of AI advancements. Professionals in the field should closely monitor such developments, as they may set precedents for future data governance standards and enforcement actions.

Original source link: [https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/10096856]