Back to Tools
DeepL logo

DeepL

GDPR Compliant

German machine translation and writing assistant, processing customer data exclusively on its own servers in the EEA.

🇩🇪Germany🇪🇺EU Hosted🇪🇺 EuropeanFreemium
DeepL website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountryGermany
OwnershipEuropean-owned
Foreign Disclosure ExposureNone known
Data Hosting Location
European Union"The data is processed exclusively on DeepL's servers in the EEA, the data is not transferred to the USA" and "The customer data is stored on servers in the EU". Source: deepl.com/en/privacy (read 2026-08-24).
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Low Risk
SCCs in Place
Last Verified24 August 2026

How we reached this

Controller is DeepL SE, Maarweg 165, 50825 Cologne, Germany, named in the privacy policy alongside group entities in the UK, Netherlands, Poland, USA and Japan; the German SE is the parent, so no non-EU company controls the group. Customer data is stated to stay on DeepL's own servers in the EEA. Two US touchpoints are disclosed and do not involve translation content: Cloudflare filters website traffic and "if necessary also to Cloudflare servers in the USA", and payments run through Stripe Payments Europe Ltd. in Dublin which "will transfer the data to Stripe, Inc., located in the USA". No data processing agreement was located at a public URL during this review, so dpaAvailable is left false rather than assumed; DeepL Pro customers should request one directly.

About DeepL

Translation That Stays in the EEA

DeepL translates text, whole documents and live speech, and its Write product rewrites and corrects text in the same interface. An API covers the same models for product integration, and glossaries let teams pin brand and product terminology so translations stay consistent across a site.

For marketing teams the practical use is localising landing pages, ads and email at a quality that needs light editing rather than a rewrite, and the document mode keeps formatting intact in DOCX and PDF.

Where the Data Goes

This is the part that separates DeepL from most language models on the market. The privacy policy states plainly that "the data is processed exclusively on DeepL's servers in the EEA, the data is not transferred to the USA", and that "the customer data is stored on servers in the EU".

The controller is DeepL SE of Maarweg 165, Cologne, a German company. The group includes DeepL US Inc. in Delaware alongside UK, Dutch, Polish and Japanese entities, but the parent is the German SE, so there is no non-EU corporate owner able to be served under the CLOUD Act.

Two US touchpoints remain and are worth knowing about. Traffic to the website is routed through Cloudflare for attack filtering, which the policy says may involve Cloudflare servers in the USA, and payments go through Stripe Payments Europe in Dublin, which may pass data to Stripe, Inc. in the USA. Neither touches translation content.

Free Versus Pro

The free translator is explicit that content sent to it is used to improve the service. The policy asks users to "only enter content that you wish to transfer to our services". Paid Pro plans are the ones that carry the data protection guarantees, so the free tier is the wrong place for client copy.

Other European options in this category are listed under translation and localisation.

Key Features

Machine translation across 30+ languages
Document translation preserving DOCX and PDF formatting
DeepL Write for rewriting and tone adjustment
Glossaries for brand and product terminology
REST API for product and workflow integration
Voice translation for meetings

Pros & Cons

Translation data stays on DeepL's own servers in the EEA, stated explicitly in the policy
German parent company, so no US corporate owner subject to the CLOUD Act
Output quality generally needs editing rather than rewriting
Free tier content is used to improve the service, so it is unsuitable for client material
No data processing agreement published at a findable public URL
Website traffic passes through Cloudflare, which may involve US servers

DeepL GDPR & data protection: common questions

Is DeepL GDPR compliant?

Yes. On the evidence we checked, DeepL meets the requirements European businesses usually need. DeepL is a European company headquartered in Germany, data is hosted within the European Union.

Where does DeepL store data?

DeepL states: ""The data is processed exclusively on DeepL's servers in the EEA, the data is not transferred to the USA" and "The customer data is stored on servers in the EU". Source: deepl.com/en/privacy (read 2026-08-24).". Data is hosted within the European Union.

Does DeepL offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for DeepL. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover →

Is DeepL a European company?

Yes. DeepL is headquartered in Germany and, as far as we can establish, European-owned.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at DeepL and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.