Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
Can I use DeepL at work? DeepL data protection for businesses
Security Awareness

Can I use DeepL at work? DeepL data protection for businesses

DeepL Free uses input for training and excludes personal data. DeepL Pro requires a DPA. What a company usage policy has to define, step by step.

Chris Wojzechowski Managing Director
Updated: September 6, 2026 5 min read read
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK) T.I.S.P. Board-Mitglied

Beitragsbild KI-generiert, redaktionell geprüft (EU AI Act Art. 50).

TL;DR

According to its privacy policy, the free version of DeepL processes submitted text to train its own neural networks, and under the terms of use it must not be used for personal data. DeepL Pro deletes texts after translation and does not use them to improve the product, but requires a data processing agreement under Article 28 GDPR when personal data is involved. Whether DeepL is allowed at work is therefore decided by a company usage policy: which content may go into which version, which plan is used with a DPA, and how employees are told.

Table of Contents (7 sections)

This article was first published in 2020 and was rewritten in September 2026 against DeepL's current privacy policy and the Pro terms and conditions (version of July 2026). The old advice, "redact personal data first", is no longer enough, because DeepL itself now separates permitted use by version and contract.

Is DeepL safe? The short answer

DeepL data protection depends on the version. According to the privacy policy, the free version processes texts to train DeepL's own neural networks, and under the terms of use it is excluded for personal data. DeepL Pro deletes texts after translation, but for personal data it requires a data processing agreement, which the company concludes before use.

Without a usage policy, every person at their desk decides for themselves whether the customer contract goes into the translation window. That decision belongs in a company policy.

DeepL Free or DeepL Pro: What happens to the texts

The operator is DeepL SE, based in Cologne. Its privacy policy distinguishes between the free version and the Pro services in sections 3 and 4.

In the free version, DeepL processes uploaded content "for a limited period" in order "to train and improve our neural networks and algorithms". This also applies to corrections made to translation suggestions. According to the terms of use, the free version must not be used for texts "containing personal data of any kind". Such texts are permitted "only as part of a DeepL Pro subscription".

For the Pro services (Translator, API, Write), section 4 states that texts are not stored permanently and are deleted after translation. They are not used to improve quality. Three exceptions are in the small print. The "Saved translations" and glossary features store content in the account. Clause 3.1.4 of the Pro terms and conditions permits encrypted temporary storage for up to 72 hours for debugging in the event of certain error patterns. And for document translation, DeepL stores metadata such as file type, language pair and character count for 14 days, in Free and Pro alike.

Another point is the place of processing. Clause 3.1.3 of the Pro terms and conditions permits DeepL to process content on its own servers or on infrastructure of cloud providers. DeepL reserves the right to determine the location of processing; a different arrangement is possible, but has to be negotiated. The registered office in Cologne is not a contractual commitment on where the data is processed.

CriterionDeepL FreeDeepL Pro (Individual, Team, Business, Enterprise)
Texts used for model trainingyes, for a limited period (privacy policy, section 3)no (section 4)
Storage after translation"for a limited period" (section 3)deleted after the service is performed; exceptions: saved translations, glossary, up to 72 hours for debugging (T&C 3.1.4)
Personal dataexcluded under the terms of useonly with a data processing agreement (T&C 8.1.4)
DPA under Article 28 GDPRnot provided forprovided by DeepL
Place of processingno commitmentDeepL determines the location; a different arrangement is possible (T&C 3.1.3)
Central administrationnoneSSO from Team, domain management and SCIM from Business

"Pro" is not a single plan. The pricing page lists Individual, Team, Business and Enterprise. Individual names "No use of your data for model training" as its first benefit; Team and Business include all benefits of Individual. For a company, administration matters more than the character quota: single sign-on is available from Team, domain management and user provisioning from Business. Without these features, employees set up private accounts, and IT sees none of it.

Is DeepL GDPR-compliant?

The question cannot be answered in this form, because the GDPR assesses processing operations, not products. The company remains the controller for the translation of a customer letter (Article 4(7) GDPR). DeepL becomes a processor (Article 4(8)) as soon as personal data is sent to the service. For that, Article 28(3) GDPR requires a contract.

Personal data is more than a name. Article 4(1) GDPR covers "any information relating to an identified or identifiable natural person". An email signature, a staff number in a draft contract or the salutation in a quotation is enough.

For the free version this means: personal data is contractually excluded, and there is no data processing agreement. Anyone who enters it anyway processes without an Article 28 contract and hands the text over for a purpose the company does not control: training the models. This also affects trade secrets without any personal reference, to which the GDPR does not apply at all.

How a supervisory authority examines the matter is shown by the Bavarian State Commissioner for Data Protection (BayLfD) in its paper "AI in a nutshell 2: AI-based language translation tools" (in German). It requires the processing operations to be delineated individually, from training and the storage of login and input data to their "further use [...] for example for further training of the AI system". For each operation, the personal reference has to be checked and, where necessary, restricted. As a means to that end, the paper names "a service instruction to employees concerning the input of the content to be translated, or anonymisation". Added to this is the clarification of responsibility, up to a data processing agreement. For passing data on to third parties for further training, the paper says public bodies "regularly" lack a legal basis.

The paper is addressed to Bavarian public authorities. The assessment steps can be transferred to companies, with Article 6(1)(b) or (f) GDPR as the legal basis instead of the performance of a public task.

DeepL DPA: no personal data without a data processing agreement

DeepL prescribes the contract itself. Clause 8.1.4 of the Pro terms and conditions obliges the customer to inform DeepL and to conclude a data processing agreement provided by DeepL as soon as personal data is to be transmitted. The same clause requires the customer to have its own legal basis for that data. According to the privacy policy, DeepL handles the conclusion of the contract via sales(at)deepl.com.

The template is publicly available. It names DeepL SE as the processor, names customers, employees and applicants of the controller as the data subjects, and contains the obligations from Article 28(3) GDPR: processing only on documented instructions, a duty of confidentiality for staff, and measures under Article 32 GDPR.

A signed DPA is the beginning of the assessment. Article 28(1) GDPR permits only processors that provide "sufficient guarantees" of lawful processing. For DeepL, four points remain to be clarified. The cloud sub-processors and the place of processing from clause 3.1.3. The debugging access from clause 3.1.4. The retention period of 90 days after the end of the contract for saved translations from clause 3.1.2. And the SOC 2 Type II report from the Trust Center. A DPA review runs the same way for DeepL as for any other cloud service. Anyone operating an ISMS under ISO/IEC 27001:2022 will find the framework in controls 5.19 to 5.23 of Annex A on suppliers and cloud services.

DeepL for businesses: A usage policy in five steps

No employee should have to answer the question "Can I use DeepL at work?" alone. A usage policy answers it once for everyone:

  1. Classify content: public, internal, personal, confidential. For each class it is fixed whether it may go into the free version, into the Pro plan, or into no cloud translator at all. Personal content is excluded from the free version under the terms of use.
  2. Choose a plan and conclude the DPA. A plan with central administration (single sign-on from Team, domain management from Business) ties the accounts to the company. The DPA is signed before the first item of personal data.
  3. Document the processing. Translation with DeepL is recorded as a processing activity under Article 30 GDPR, with legal basis, data categories and DeepL as processor. The results of the DPA review are filed there.
  4. Configure features deliberately. Saved translations and glossaries stay in the account, document translations leave metadata for 14 days. Both are permissible, but both belong in the deletion concept and in the configuration standard for the accounts.
  5. Instruct and train. The BayLfD explicitly names the service instruction to employees as a means of limiting the personal reference at input. It only works if employees know the difference between Free and Pro. Why the free version is blocked on the company network or restricted to public texts is something security awareness explains better than a list of prohibitions.

The same assessment applies to every other AI tool from the cloud. How the trade-off looks for language models is described in the article on the opportunities and risks of ChatGPT.

Assessment

In 2020, the answer to the question in the title was: remove personal data, then it works. In 2026, it is a question of contract. DeepL excludes the free version for personal data in its terms of use and ties the use of Pro to a data processing agreement. That makes DeepL in a company an ordinary case of processing on behalf of a controller, with the usual homework: contract, verification of the guarantees, documentation, instruction.

The registered office in Cologne spares none of it. The terms and conditions reserve DeepL's choice of infrastructure and place of processing, and the debugging exception shows that "will be deleted" comes with conditions in the contract text. Anyone who wants to settle these points for all cloud services at once does so in an ISMS under ISO 27001.

Sources

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

About the author

Chris Wojzechowski
Chris Wojzechowski

Managing Director

E-Mail

Managing Director of AWARE7 GmbH with many years of expertise in information security, penetration testing and IT risk management. Graduate of the Internet Security master's program at Westfälische Hochschule (if(is), Prof. Norbert Pohlmann). Bestselling author with Wiley-VCH and lecturer at the ASW-Akademie. His assessments of cybersecurity and digital sovereignty have appeared in Welt am Sonntag, WDR, Deutschlandfunk and Handelsblatt, among others.

10 Publikationen
  • Einsatz von elektronischer Verschlüsselung - Hemmnisse für die Wirtschaft (2018)
  • Kompass IT-Verschlüsselung - Orientierungshilfen für KMU (2018)
  • IT Security Day 2025 - Live Hacking: KI in der Cybersicherheit (2025)
  • Live Hacking - Credential Stuffing: Finanzrisiken jenseits Ransomware (2025)
  • Keynote: Live Hacking Show - Ein Blick in die Welt der Cyberkriminalität (2025)
  • Analyse von Angriffsflächen bei Shared-Hosting-Anbietern (2024)
  • Gänsehaut garantiert: Die schaurigsten Funde aus dem Leben eines Pentesters (2022)
  • IT Security Zertifizierungen - CISSP, T.I.S.P. & Co (Live-Webinar) (2023)
  • Sicherheitsforum Online-Banking - Live Hacking (2021)
  • Nipster im Netz und das Ende der Kreidezeit (2017)
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK) T.I.S.P. Board-Mitglied
Certified ISO 27001ISO 9001AZAV

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen