Tools & AI8 min read

Is DeepL GDPR-compliant? Translation and data protection

DeepL can be used in a GDPR-compliant way, mainly with DeepL Pro and a DPA. Free stores text, per DeepL. Here is what to watch for.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

Short answer: DeepL can be used in a GDPR-compliant way, but not in every version. According to DeepL, text sent through DeepL Pro and the API Pro is not stored after translation and is not used to improve the models. In the free version, DeepL states that text may be stored and used to improve the service. DeepL is a German provider based in Cologne. That builds trust, but on its own it is not a guarantee of compliance.

DeepL Free or DeepL Pro: the key difference

The version decides what happens to your text. Both plans translate well, but they handle data differently. For professional use, the second point matters most.

  • DeepL Free: according to DeepL, text may be stored and used to improve the service.
  • DeepL Pro and API Pro: according to DeepL, no storage after translation.
  • DeepL Pro: according to DeepL, your text is not used to train the models.
  • A data processing agreement is offered only for Pro, according to DeepL.
  • Rule of thumb: sensitive or personal text does not belong in the free version.

What DeepL says about data protection

The points below are the provider's own statements. They come from DeepL's documentation and can change. Check the current version before you rely on them.

  • According to DeepL, Pro text is deleted again after translation.
  • According to DeepL, Pro does not use your text to train the models.
  • According to DeepL, DeepL Pro provides a DPA under Art. 28 GDPR.
  • According to DeepL, the company is based in the EU and runs EU servers.
  • These statements do not replace your own check of the current policies.

Your role as the controller

Even with DeepL Pro, you remain the controller under the GDPR. The provider is a processor. Lawful use is your responsibility, not the tool's.

  • You need a legal basis under Art. 6 GDPR for the processing.
  • You sign a DPA under Art. 28 GDPR before you start.
  • You apply data minimisation (Art. 5 GDPR): only necessary data.
  • You check whether personal data needs to be there at all.
  • You record the processing in your register.

Be careful with special category data

Some data is specially protected. Art. 9 GDPR lists the special categories in a closed list. A plain name or phone number is not one of them, but it still deserves care.

  • Special categories: health, origin, religion, political opinion, biometrics.
  • Stricter rules and higher requirements apply to this data.
  • Name, address and phone number are personal, but not special category.
  • Do not enter unnecessary details into a translation tool.
  • When in doubt, remove or replace the value before translating.

Pseudonymise before you translate

You can lower the exposure before the text reaches DeepL. Replace names and identifiers with placeholders. After translation, put the real values back.

  1. 1Spot the sensitive values in the text: names, customer numbers, addresses.
  2. 2Replace those values with reversible placeholders.
  3. 3Send only the pseudonymised text to DeepL.
  4. 4Receive the translation and restore the placeholders.
  5. 5Review the result before you use it further.
CriterionDeepL FreeDeepL Pro / API Pro
Storage of textPossible, per DeepLNo storage, per DeepL
Use to improve modelsPossible, per DeepLNo, per DeepL
DPA (Art. 28 GDPR)Not offeredAvailable, per DeepL
For personal dataNot suitablePossible with a DPA
RecommendationNon-sensitive text onlyProfessional use

This is where ONYRI Sanitize fits in. The tool detects sensitive data in the text and replaces it with reversible tokens before the text goes to an AI or a translator. The mapping between token and real value stays in the browser and is never sent to the server. After the answer, the original values are restored. Important and honest: this is pseudonymisation, not anonymisation. Pseudonymised data stays personal data (GDPR Recital 26). A tool like this replaces neither a DPA nor a legal basis. It reduces exposure, it does not remove it.

Takeaway: DeepL can be used in a compliant way, mainly with Pro and a DPA. The free version is not suited to personal content. You stay the controller. Less data in the prompt means less risk.

Frequently asked questions

Is DeepL GDPR-compliant?
DeepL can be used in a GDPR-compliant way, mainly with DeepL Pro and a DPA. According to DeepL, Pro text is not stored. But lawful use remains your responsibility.
Can I enter personal data into DeepL Free?
Better not. According to DeepL, text in the free version may be stored and used to improve the service. That is not suitable for personal or confidential content.
Does DeepL offer a data processing agreement (DPA)?
According to DeepL, a DPA under Art. 28 GDPR is available for DeepL Pro. Check the current documentation and sign the agreement before production use.
Is DeepL Pro alone enough for GDPR compliance?
No. You remain the controller and need a legal basis, data minimisation and proper processes. A provider alone does not make processing compliant.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next