Cloudflare and GDPR compliance
Cloudflare is a privacy-first company. As such, the General Data Protection Regulation ("GDPR") represents many steps we were already taking. We do not sell personal data we process, or use it for any purpose other than delivering our services. In addition, we let people access, correct, and delete their personal information, and give our customers control over the information passing through our network.
To learn more, explore our GDPR FAQ below, or check out Cloudflare’s overall privacy policy.
Frequently asked questions
What personal data does Cloudflare process for its customers and where?
What specific technical and organizational security measures does Cloudflare provide for personal data?
How does Cloudflare address the requirements of Art. 44 of the GDPR regarding personal data transfers to the U.S.?
Is Cloudflare certified to the EU-U.S. Data Privacy Framework?
What safeguards apply to my data under the Data Privacy Frameworks?
What additional data protection safeguards does Cloudflare provide?
Does the U.S. Clarifying Lawful Overseas Use of Data ("CLOUD") Act affect how Cloudflare views its obligation to turn over data in response to U.S. government legal process?
Do the U.S. Foreign Intelligence Surveillance Act ("FISA") Section 702 and Executive Order 12333 discussed in the Schrems II decision affect Cloudflare?
How can Customers on Self-Service Agreements make sure the proper cross-border data transfer mechanisms are in place with Cloudflare?
How can Enterprise Customers make sure the proper cross-border data transfer mechanisms are in place with Cloudflare?
What tools does Cloudflare have for its customers to geographically restrict access to data?
Are there any enforceable rights and effective remedies available to EU data subjects in the U.S. where data is processed by Cloudflare or Cloudflare's sub-processors?
How is Cloudflare dealing with cross-border transfers to and from the UK?
Resources on the GDPR
Cloudflare features that support data protection
Encryption
Cloudflare's network can encrypt data throughout its journey from origin servers to end-users, using the very latest protocols.
Privacy-first analytics
Cloudflare's Web Analytics does not use any client-side state, such as cookies or localStorage, to collect usage metrics — and never 'fingerprints' individual users.
Data localization
In many regions — including Japan — Cloudflare lets organizations control which regional data centers their traffic is inspected in and where logs are sent.
Access management
Cloudflare Zero Trust lets organizations enforce country-specific access rules, block risky sites and content, and log access events for internal applications and data.
Reporting
Cloudflare Logs gives granular insights into every HTTP request, helping you investigate potential breaches and other security incidents.
Certifications
Cloudflare complies with many industry-standard security certifications, including several focusing on privacy and personal data protection.