TechCrunch News 01月30日
Ireland and Italy send data watchdog requests to DeepSeek: ‘The data of millions of Italians is at risk’
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

中国AI初创公司DeepSeek及其大型语言模型近期引发广泛关注,但同时也面临着数据保护监管机构的审查。爱尔兰和意大利的数据保护机构已向DeepSeek发出问询,要求其提供在欧洲处理公民数据的详细信息。此外,欧洲消费者组织也对DeepSeek的数据处理方式提出了投诉,尤其关注其如何处理个人数据以及是否符合GDPR规定。DeepSeek在中国的运营和数据存储也引起了监管机构的注意,他们正在调查DeepSeek收集、存储和处理用户数据的具体做法,以及如何保护未成年用户的数据。

🇮🇪 意大利和爱尔兰数据保护机构已正式向DeepSeek发出问询,要求其详细说明如何处理两国公民的个人数据,这表明DeepSeek在欧洲的数据合规性正受到严格审查。

🇪🇺 欧洲消费者组织针对DeepSeek的数据处理方式向意大利数据保护局提出申诉,主要关注其是否符合欧盟的GDPR规定,特别是个人数据的收集、使用和保护方面。

🇨🇳 DeepSeek的数据存储和运营均在中国进行,其隐私政策指出,数据从其他国家传输到中国时,会“遵守适用的数据保护法”,但监管机构对此表示担忧,并要求提供更多关于中国服务器的详细信息。

🧑‍⚖️ 监管机构还关注DeepSeek如何保护未成年用户的数据,并指出其服务缺乏年龄验证机制,对于14至18岁的用户,仅建议与成人一起阅读隐私政策,但并未强制执行年龄限制。

The jury is still out on whether the Chinese AI upstart DeepSeek is a game changer or part of an elaborate plan by its hedge fund parent company to short Nvidia and other tech stocks. Whichever it might be (maybe both?), DeepSeek and its large language model have made some major waves. And now, it’s catching the eye of data protection watchdogs. 

Today the Irish Data Protection Commission confirmed to TechCrunch that it has sent a note to DeepSeek requesting details concerning how the data of citizens in Ireland is processed by the company. “The Data Protection Commission (DPC) has written to DeepSeek requesting information on the data processing conducted in relation to data subjects in Ireland,” said a spokesperson.

The letter from Ireland’s DPA was sent less than 24 hours after the data protection watchdog in Italy sent a similar note to the company. DeepSeek has yet to respond to either request publicly. However, its mobile app no longer appears in both the Google and Apple app stores in Italy.

The Italian move appeared to be the first major move from one such watchdog since DeepSeek went positively viral in recent days, Euroconsumers, a coalition of consumer groups in Europe, has filed a complaint to the Italian Data Protection Authority related to how DeepSeek handles personal data in relation to GDPR, the data protection regulatory framework in Europe. 

The Italian DPA confirmed today that it subsequently wrote to DeepSeek with a request for information. “A rischio i dati di milioni di persone in Italia,” it notes. (“The data of millions of Italians is at risk.”) DeepSeek has 20 days to respond.

Two key details about DeepSeek that many noticed are that the service is made and operates out of China. Per its privacy policy, this includes the information and data that DeepSeek collects and stores, which is also housed in its home country.

DeepSeek also briefly notes in its policy that when it transfers data to China from the country where DeepSeek is being used, it does so “in accordance with the requirements of applicable data protection laws.”  

But Euroconsumers — the organization that brought a successful case against Grok last year over how it used data to train its AI — and the Italian DPA want more detail. 

Addressing Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence, the Italian DPA said it wants to know what personal data is collected, from which sources, and for which purposes – including what information is used to train its AI system – along with what the legal basis is for processing. It also wants more details on those servers in China. 

Further, it writes in its information request, it wants to know “in the event that personal data is collected through web scraping activities,” how users who are “registered and those not registered to the service have been or are informed about the processing of their data.”

The news outlet MLex notes that Euroconsumers also highlighted that there are no details regarding how DeepSeek protects or restricts minors on its services, from age verification to how it handles minors’ data.

(DeepSeek’s age policy notes that it is not intended for users under the age of 18, although it does not provide a way to enforce that. For those between the ages of 14 and 18, DeepSeek suggests these younger users read through the privacy policy with an adult.)

Euroconsumers and the Italian watchdog represent the first effort to make a move against DeepSeek. They might not be the last, although follow-ups may not be as swift. 

Earlier today, DeepSeek was a prime topic at a press conference at the European Commission. Thomas Regnier, Commission Spokesperson for Tech Sovereignty, was asked whether there are concerns at the European level over DeepSeek related to security, privacy, and censorship. For now, though, the main message appeared to be: it’s too soon to say anything about any investigations.

“The services offered in Europe will respect our rules,” Regnier noted in a response to a question about data privacy, adding that the AI Act applies to all AI services offered in the region. 

He declined to say whether DeepSeek, in the EU’s estimation, respected those rules or not. He was then asked whether the app’s censorship on topics that are politically sensitive in China fell afoul of free speech rules in Europe and if that merited an investigation. “These are very early stages, I’m not talking about an investigation yet,” Regnier said quickly in response. “Our framework is solid enough to tackle potential issues if they are here.”

Questions TechCrunch sent to the ICO in the U.K. about DeepSeek received a similar response: DeepSeek, in effect, will be subject to the same scrutiny as any other GenAI developer. But no further actions yet.

“Generative AI developers and deployers need to make sure people have meaningful, concise and easily accessible information about the use of their personal data and have clear and effective processes for enabling people to exercise their information rights,” said a spokesperson. “We will continue to engage with stakeholders on promoting effective transparency measures, without shying away from taking action when our regulatory expectations are ignored.”

Meanwhile, could new avenues of regulatory questioning open around areas like copyright and IP protection?

Many have marvelled at how DeepSeek’s very existence seems to challenge assumptions about the actual costs of training and operating an LLM or a generative AI service: its cheaper infrastructure and cost base undermine the idea that building foundational AI and running generative AI applications have to cost a fortune in chips, data center usage and energy consumption.

But more recently, some have started to raise questions about all that. Microsoft and OpenAI say that there appears to be evidence that it was partly trained on “distillations” from their proprietary models. There would be an uncanny irony in this if it proves to be true — given the many legal and other dramas that have swirled around how some LLM builders have allegedly regarded intellectual property and copyright.

We have contacted DeepSeek regarding the Italian DPA complaint and will update this post as more information becomes available. In the meantime, DeepSeek’s apps have now been pulled from the major Italian app stores, although it appears to still be live online in the country.

Updated with further detail on regulatory responses, legal issues and status of the service in Italy.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

DeepSeek 数据保护 GDPR 人工智能 监管审查
相关文章