The difference is:
In one case, you download the whole database.
In the other case, you essentially tell the company "hey, I’m visiting website with hash 12345, is that bad?".
This can be abused. Google could with it create a database of everyone who visit, say, pornhub.com, for example, by logging everyone who visits a page with the same hash as pornhub.com
Same with file-based malware databases:
You tell it "I have the file with hash 12345, is it bad?" And, if Google - or the NSA, CIA, FBI, whatever – want to get a list of everyone who has that file, they just ask the database provider to log everyone who checks that hash against the database, then go to the ISP to get the real name of the owner of that IP, and then SWAT the person.
This is very much a possible risk.