Home Blog Is Cloudflare GDPR Compliant? DPA and Data Localization

GDPR

Is Cloudflare GDPR Compliant? DPA and Data Localization

Posted by Kevin Yun|August 20, 2026

Cloudflare publishes a versioned data processing addendum that forms part of your subscription agreement, relies on the EU-US Data Privacy Framework for transfers to the United States, maintains a public subprocessor list, and sells a set of controls that let you decide where your traffic is inspected and where its metadata is stored. That is a stronger position than most infrastructure vendors offer. It also describes a service that sits in front of every request to your site, which makes the configuration decisions unusually consequential.

This article covers which version of the DPA governs you, what role Cloudflare occupies, how the transfer position is built, what the Data Localization Suite actually controls, and where the subprocessor mechanics sit.

Where The DPA Is, And Which Version Governs

Cloudflare's addendum is published at cloudflare.com/dpa, which resolves to cloudflare.com/cloudflare-customer-dpa/. The version live when we checked, on 7 August 2026, was Version 6.4, effective 3 April 2026. Version 6.3, effective 20 June 2025, is listed on the same page under previous versions — which is a neat illustration of the point below.

Two things about how it attaches are worth reading carefully. First, it forms part of your Main Agreement, whether that is an Enterprise Subscription Agreement, a Self-Serve Subscription Agreement, or another written or electronic agreement — so the same document governs a free-tier site and an enterprise deployment, with the surrounding agreement differing. Second, and more usefully, the DPA states that it replaces and supersedes any previously applicable data processing terms from the date the customer signed or otherwise agreed to it.

That supersession clause is the reason to record your DPA effective date rather than just noting that a DPA exists. Cloudflare's addendum has run through many published versions, and older ones remain findable. When a reviewer asks which terms govern, the answer is a version number and a date, not a URL.

What Cloudflare Is In Your Chain

Cloudflare's addendum sets the position that the customer is the controller or processor and Cloudflare is the processor or sub-processor as applicable, and that Cloudflare processes personal data on that basis.

What makes this different from every other vendor in this cluster is the data involved. Cloudflare sits in the request path, and its own annex spells out what that means. The data subjects are your end users — anyone accessing your domains, networks, websites, APIs and applications — plus your administrators. The categories include personal data in Customer Logs, "such as IP addresses," personal data in Customer Content, and IP addresses and email addresses in administrative audit logs.

The annex is equally direct about special categories: your end users and partners may upload content to your properties that includes them, and the extent of that is determined and controlled by you in your sole discretion. In other words, Cloudflare has written down that it does not know what is passing through, and that this is your problem to scope.

The practical consequence is that Cloudflare belongs in your Article 30 record whether or not anyone at your company thinks of it as a data tool. Every visitor's IP address is personal data, and it is being processed by a named processor on your instruction. Keeping your record of processing activities accurate means listing the infrastructure, not just the applications.

Transfers: The Data Privacy Framework, And What Sits Behind It

Cloudflare's addendum handles transfers with a definition rather than a clause, which is elegant and easy to miss. In defining what counts as a Restricted Transfer, it states that a transfer of personal data to the United States made pursuant to the Data Privacy Framework is not a Restricted Transfer at all.

Where a transfer is restricted, the addendum applies the EU Standard Contractual Clauses, with UK-protected data covered by those same clauses as amended by the UK Addendum, and conflicts between the two resolved under the Addendum's own provisions. Cloudflare's GDPR materials also point to supplementary measures and safeguards written into the addendum as contractual commitments, with its security measures set out in an annex.

Better still, the addendum makes the switchover automatic and tells you when it happens: Cloudflare undertakes to notify you if its Data Privacy Framework certification lapses or is invalidated, at which point transfers are immediately deemed Restricted Transfers and the Standard Contractual Clause provisions apply. That is a meaningfully stronger commitment than a fallback clause alone, because it does not depend on you noticing.

There is also a third mechanism most vendors do not have. Cloudflare states it is certified to the Global Cross-Border Privacy Rules System and the Global Privacy Recognition for Processors System, warrants that it will keep that certification current, and commits to telling you if it lapses. That covers transfers between participating jurisdictions outside the EU/UK frame — worth knowing if your users are not only European.

The pattern is the one worth looking for in any US vendor: a primary route, pre-agreed clauses underneath, and a duty to tell you when the top layer fails.

The Data Localization Suite, And What It Controls

This is where Cloudflare offers something genuinely unusual, and where the detail matters more than the headline.

The Data Localization Suite is a set of tools for choosing where Cloudflare inspects and stores data while still using its global network. Its documentation describes three distinct controls, and they cover different things: Geo Key Manager governs where your private encryption keys are stored, the Customer Metadata Boundary keeps traffic metadata — the logs and analytics that could identify your end users — within a region you select, and regional services govern where HTTPS traffic is decrypted and processed.

Read that as three separate questions rather than one residency switch. "Our data stays in the EU" is not a claim the Suite supports on its own; what it supports are specific answers about keys, about metadata, and about where decryption happens. If a customer asks you to warrant EU-only processing, the honest response is to say which of those three you have configured.

The Suite is a product with its own availability and commercial terms rather than a default setting, so confirm what is included on your plan before describing it to anyone else. This is the same discipline our guide to subprocessor management applies to vendor claims generally: evidence the configuration, do not assume the capability.

Subprocessors And The Authorisation You Already Gave

Cloudflare maintains its subprocessor list at cloudflare.com/gdpr/subprocessors/.

The authorisation model is broad and you agreed to it. The addendum records a general written authorisation from the customer for Cloudflare to appoint other members of the Cloudflare Group as subprocessors, and for Cloudflare and its group to appoint third-party data centre operators and business, engineering and customer support providers. In exchange, Cloudflare commits that any subprocessor is engaged only under a written contract imposing terms no less protective than its own, and that it remains liable to you for that subprocessor's breaches.

The timings are specific and asymmetric. Cloudflare commits to adding new and replacement subprocessors to the published list at least thirty days before they begin processing. Your window to object on reasonable data protection grounds is ten days from the notification. If you object and Cloudflare can reasonably provide the service without that subprocessor and chooses to, you have no further rights under the clause. If Cloudflare requires it and cannot satisfy your objection, you may terminate the applicable Order Form — but only for the services that would use the new subprocessor. And if you do not object in time, you are deemed to have consented and to have waived the right to object.

Thirty days of notice against ten days to act is the shape to plan around. Nobody reads a subprocessor page weekly, which is how a deemed consent happens by default rather than by decision.

Common Mistakes With Cloudflare And GDPR

Leaving it out of the processor inventory. Teams list their CRM and forget the layer every request passes through. Visitor IP addresses are personal data and Cloudflare processes them.

Recording "we have a DPA" without a version. The addendum supersedes prior terms from the date you agreed to it. Record the version number and effective date, because that is the question a reviewer actually asks.

Describing the Data Localization Suite as EU residency. It controls key storage, metadata location and decryption location as three separate settings, and it is a product rather than a default. Confirm what your plan includes and what is actually enabled, then warrant only that — a contractual promise outrunning the technical reality is how this goes wrong.

Reading a superseded version. Cloudflare publishes its previous versions on the same page, and older addenda are indexed and easy to find. The governing document is the version you agreed to.

Not budgeting for assistance costs. The addendum provides that you cover Cloudflare's costs for assisting with data subject requests, impact assessments and transfer assessments. Reasonable, and a surprise if you have promised a customer free-flowing support.

FAQ

Where is Cloudflare's DPA?

At cloudflare.com/dpa, which resolves to the customer DPA page. It forms part of your Main Agreement, whether that is an enterprise or self-serve subscription. The version live when we checked on 7 August 2026 was Version 6.4, effective 3 April 2026, and the addendum states that it supersedes previously applicable data processing terms from the date you agreed to it.

Is Cloudflare a controller or a processor?

Its addendum states that the customer is the controller or processor and Cloudflare is the processor or sub-processor as applicable, processing personal data on that basis. Because Cloudflare sits in the request path, the personal data involved includes the connection data and IP addresses of everyone visiting your properties.

Does Cloudflare rely on the Data Privacy Framework or SCCs?

Both, in a defined order. Its addendum provides that a transfer to the United States made under the Data Privacy Framework is not a Restricted Transfer, and applies the EU Standard Contractual Clauses to restricted transfers, with the UK Addendum amending them for UK-protected data.

Does the Data Localization Suite keep my data in the EU?

It gives you controls over three separate things: where private encryption keys are stored, where traffic metadata and logs are kept, and where HTTPS traffic is decrypted and processed. Which of those apply depends on what you have configured and what your plan includes, so describe the specific settings rather than making a general residency claim.

Closing Thought

Infrastructure is where privacy records go quiet. A team can produce a careful inventory of the tools people log into and never mention the network layer that sees every request before any of those tools do. It is not an oversight born of carelessness so much as of category: nobody experiences a CDN as a place where data is held.

Cloudflare is better documented than most vendors you will assess, which makes the gap in your own records the interesting part rather than anything in theirs. Your customers will eventually ask you the same question you should be asking here: who sees this data before we do. ComplyDog hosts a compliance portal on your own domain carrying your DPA, your subprocessor list — infrastructure included — your data subject request intake and your security page. It will not configure your network. It will mean the list is written down before somebody asks for it.