Beitragsbild KI-generiert, redaktionell geprüft (EU AI Act Art. 50).
TL;DR
According to its privacy policy, the free version of DeepL processes submitted text to train its own neural networks, and under the terms of use it must not be used for personal data. DeepL Pro deletes texts after translation and does not use them to improve the product, but requires a data processing agreement under Article 28 GDPR when personal data is involved. Whether DeepL is allowed at work is therefore decided by a company usage policy: which content may go into which version, which plan is used with a DPA, and how employees are told.
Table of Contents (7 sections)
This article was first published in 2020 and was rewritten in September 2026 against DeepL's current privacy policy and the Pro terms and conditions (version of July 2026). The old advice, "redact personal data first", is no longer enough, because DeepL itself now separates permitted use by version and contract.
Is DeepL safe? The short answer
DeepL data protection depends on the version. According to the privacy policy, the free version processes texts to train DeepL's own neural networks, and under the terms of use it is excluded for personal data. DeepL Pro deletes texts after translation, but for personal data it requires a data processing agreement, which the company concludes before use.
Without a usage policy, every person at their desk decides for themselves whether the customer contract goes into the translation window. That decision belongs in a company policy.
DeepL Free or DeepL Pro: What happens to the texts
The operator is DeepL SE, based in Cologne. Its privacy policy distinguishes between the free version and the Pro services in sections 3 and 4.
In the free version, DeepL processes uploaded content "for a limited period" in order "to train and improve our neural networks and algorithms". This also applies to corrections made to translation suggestions. According to the terms of use, the free version must not be used for texts "containing personal data of any kind". Such texts are permitted "only as part of a DeepL Pro subscription".
For the Pro services (Translator, API, Write), section 4 states that texts are not stored permanently and are deleted after translation. They are not used to improve quality. Three exceptions are in the small print. The "Saved translations" and glossary features store content in the account. Clause 3.1.4 of the Pro terms and conditions permits encrypted temporary storage for up to 72 hours for debugging in the event of certain error patterns. And for document translation, DeepL stores metadata such as file type, language pair and character count for 14 days, in Free and Pro alike.
Another point is the place of processing. Clause 3.1.3 of the Pro terms and conditions permits DeepL to process content on its own servers or on infrastructure of cloud providers. DeepL reserves the right to determine the location of processing; a different arrangement is possible, but has to be negotiated. The registered office in Cologne is not a contractual commitment on where the data is processed.
| Criterion | DeepL Free | DeepL Pro (Individual, Team, Business, Enterprise) |
|---|---|---|
| Texts used for model training | yes, for a limited period (privacy policy, section 3) | no (section 4) |
| Storage after translation | "for a limited period" (section 3) | deleted after the service is performed; exceptions: saved translations, glossary, up to 72 hours for debugging (T&C 3.1.4) |
| Personal data | excluded under the terms of use | only with a data processing agreement (T&C 8.1.4) |
| DPA under Article 28 GDPR | not provided for | provided by DeepL |
| Place of processing | no commitment | DeepL determines the location; a different arrangement is possible (T&C 3.1.3) |
| Central administration | none | SSO from Team, domain management and SCIM from Business |
"Pro" is not a single plan. The pricing page lists Individual, Team, Business and Enterprise. Individual names "No use of your data for model training" as its first benefit; Team and Business include all benefits of Individual. For a company, administration matters more than the character quota: single sign-on is available from Team, domain management and user provisioning from Business. Without these features, employees set up private accounts, and IT sees none of it.
Is DeepL GDPR-compliant?
The question cannot be answered in this form, because the GDPR assesses processing operations, not products. The company remains the controller for the translation of a customer letter (Article 4(7) GDPR). DeepL becomes a processor (Article 4(8)) as soon as personal data is sent to the service. For that, Article 28(3) GDPR requires a contract.
Personal data is more than a name. Article 4(1) GDPR covers "any information relating to an identified or identifiable natural person". An email signature, a staff number in a draft contract or the salutation in a quotation is enough.
For the free version this means: personal data is contractually excluded, and there is no data processing agreement. Anyone who enters it anyway processes without an Article 28 contract and hands the text over for a purpose the company does not control: training the models. This also affects trade secrets without any personal reference, to which the GDPR does not apply at all.
How a supervisory authority examines the matter is shown by the Bavarian State Commissioner for Data Protection (BayLfD) in its paper "AI in a nutshell 2: AI-based language translation tools" (in German). It requires the processing operations to be delineated individually, from training and the storage of login and input data to their "further use [...] for example for further training of the AI system". For each operation, the personal reference has to be checked and, where necessary, restricted. As a means to that end, the paper names "a service instruction to employees concerning the input of the content to be translated, or anonymisation". Added to this is the clarification of responsibility, up to a data processing agreement. For passing data on to third parties for further training, the paper says public bodies "regularly" lack a legal basis.
The paper is addressed to Bavarian public authorities. The assessment steps can be transferred to companies, with Article 6(1)(b) or (f) GDPR as the legal basis instead of the performance of a public task.
DeepL DPA: no personal data without a data processing agreement
DeepL prescribes the contract itself. Clause 8.1.4 of the Pro terms and conditions obliges the customer to inform DeepL and to conclude a data processing agreement provided by DeepL as soon as personal data is to be transmitted. The same clause requires the customer to have its own legal basis for that data. According to the privacy policy, DeepL handles the conclusion of the contract via sales(at)deepl.com.
The template is publicly available. It names DeepL SE as the processor, names customers, employees and applicants of the controller as the data subjects, and contains the obligations from Article 28(3) GDPR: processing only on documented instructions, a duty of confidentiality for staff, and measures under Article 32 GDPR.
A signed DPA is the beginning of the assessment. Article 28(1) GDPR permits only processors that provide "sufficient guarantees" of lawful processing. For DeepL, four points remain to be clarified. The cloud sub-processors and the place of processing from clause 3.1.3. The debugging access from clause 3.1.4. The retention period of 90 days after the end of the contract for saved translations from clause 3.1.2. And the SOC 2 Type II report from the Trust Center. A DPA review runs the same way for DeepL as for any other cloud service. Anyone operating an ISMS under ISO/IEC 27001:2022 will find the framework in controls 5.19 to 5.23 of Annex A on suppliers and cloud services.
DeepL for businesses: A usage policy in five steps
No employee should have to answer the question "Can I use DeepL at work?" alone. A usage policy answers it once for everyone:
- Classify content: public, internal, personal, confidential. For each class it is fixed whether it may go into the free version, into the Pro plan, or into no cloud translator at all. Personal content is excluded from the free version under the terms of use.
- Choose a plan and conclude the DPA. A plan with central administration (single sign-on from Team, domain management from Business) ties the accounts to the company. The DPA is signed before the first item of personal data.
- Document the processing. Translation with DeepL is recorded as a processing activity under Article 30 GDPR, with legal basis, data categories and DeepL as processor. The results of the DPA review are filed there.
- Configure features deliberately. Saved translations and glossaries stay in the account, document translations leave metadata for 14 days. Both are permissible, but both belong in the deletion concept and in the configuration standard for the accounts.
- Instruct and train. The BayLfD explicitly names the service instruction to employees as a means of limiting the personal reference at input. It only works if employees know the difference between Free and Pro. Why the free version is blocked on the company network or restricted to public texts is something security awareness explains better than a list of prohibitions.
The same assessment applies to every other AI tool from the cloud. How the trade-off looks for language models is described in the article on the opportunities and risks of ChatGPT.
Assessment
In 2020, the answer to the question in the title was: remove personal data, then it works. In 2026, it is a question of contract. DeepL excludes the free version for personal data in its terms of use and ties the use of Pro to a data processing agreement. That makes DeepL in a company an ordinary case of processing on behalf of a controller, with the usual homework: contract, verification of the guarantees, documentation, instruction.
The registered office in Cologne spares none of it. The terms and conditions reserve DeepL's choice of infrastructure and place of processing, and the debugging exception shows that "will be deleted" comes with conditions in the contract text. Anyone who wants to settle these points for all cloud services at once does so in an ISMS under ISO 27001.
Sources
- DeepL SE: Privacy Policy, sections 3, 4, 6.5 and 7 (accessed 6 September 2026)
- DeepL SE: Terms and Conditions DeepL Pro, clauses 3.1.2, 3.1.3, 3.1.4 and 8.1.4, version of July 2026 (the English version is binding)
- DeepL SE: Data processing agreement under Article 28 GDPR, template (PDF, in German)
- DeepL SE: Security and compliance and Pricing and plans (accessed 6 September 2026)
- Bavarian State Commissioner for Data Protection: AI in a nutshell 2: AI-based language translation tools (PDF, in German) and Guidance on data protection in AI projects, version of March 2026 (in German)
- Regulation (EU) 2016/679 (GDPR): Articles 4, 6, 28, 30, 32
Next Step
Our certified security experts will advise you on the topics covered in this article — free and without obligation.
Free · 30 minutes · No obligation
