Cloudflare and GDPR compliance

Cloudflare is a privacy-first company. As such, the General Data Protection Regulation ("GDPR") represents many steps we were already taking. We do not sell personal data we process, or use it for any purpose other than delivering our services. In addition, we let people access, correct, and delete their personal information, and give our customers control over the information passing through our network.

To learn more, explore our GDPR FAQ below, or check out Cloudflare’s overall privacy policy.

GDPR compliance illustration

Frequently asked questions

Resources on the GDPR

Critical Infrastructure - Resources - Title 1 - image

Whitepaper

Cloudflare's policies around data privacy and law enforcement requests
Download PDF  
Whitepaper - Thumbnail 5
How Cloudflare helps address data protection and locality obligations in Europe
Download PDF  
Thumbnail - Insight - Template 1 Lightbulb

Link

Cloudflare sub-processors
Learn More  
Insight thumbnail - rocket
Cloudflare's data processing addendum
Download PDF  
Insights - thumbnail
Cloudflare Data Processing Addendum: Standard Contractual Clauses for Customers
Learn More  

Cloudflare features that support data protection

Security lock icon
Encryption

Cloudflare's network can encrypt data throughout its journey from origin servers to end-users, using the very latest protocols.