Why we apply human rights frameworks to abuse decisions
Cloudflare published its first Human Rights Policy last year, formalizing a commitment to the UN Guiding Principles on Business and Human Rights (UNGPs). The policy covers familiar ground: data privacy, workforce rights, and the concrete operational steps the company takes to meet those obligations. But one area that demands particular attention is how the company responds to reports of abuse involving services it provides.
The UNGPs are a useful lens here because they ask companies to think systematically about how their decisions affect people, and to build processes around that thinking. Policymakers are moving in the same direction. The European Union’s Digital Services Act incorporates human rights principles into binding obligations for intermediaries, which suggests rights-respecting abuse processes are not just an ethical choice but likely a legal one down the road.
In practice, applying human rights frameworks to abuse response means focusing on three principles: fair process for both complainants and users, proportionality in any action taken, and transparency about decisions.
The stakes of Internet access
The UN has called the Internet an enabler of all human rights, not just expression, opinion, and association. People rely on it for education, commerce, employment, and social connection. Activists and human rights defenders use it to expose abuses and build global movements. All of that depends on access.
That access is under pressure from multiple directions. Governments impose shutdowns to suppress dissent, often alongside censorship, surveillance, and targeted attacks on journalists. Infrastructure gaps exclude people for economic reasons. Private companies trying to solve content problems can overblock unrelated sites. Cyberattacks make even critical services unreachable. Gatekeepers can limit entry for commercial reasons, silencing those without financial or political clout.
The upshot for any company that controls infrastructure: do not take access for granted. Processes that could limit Internet access need to be thoughtful and grounded in human rights principles.
What the free services model changes
Cloudflare is unusual among infrastructure providers because many of its services can be signed up for free online. That model lowers barriers to security, letting nonprofits, small businesses, developers, and vulnerable voices protect themselves from attacks they could not otherwise afford. It also holds out the possibility of making DDoS attacks ineffective as a tool of silencing, which would disproportionately help those without other defenses.
But free self-service signup means Cloudflare often does not pick its customers; they pick it. For every dissenting voice challenging an oppressive regime, there may be a bad actor using the service in ways inconsistent with the company’s values. The abuse framework therefore has to balance expanding access and ending cyberattacks against addressing genuine harm, both alone and with the broader Internet community.
The UNGP protect/respect/remedy split gets complicated online
Under the UNGPs, governments have a duty to protect human rights, while companies have a responsibility to respect them through due diligence and remediation of harm they cause. Applying that division online is hard for a structural reason: no single provider delivers the Internet. A single website may involve a site owner, a host, a domain registrar, a registry, a reverse proxy, a CDN, a transit provider, ISPs, and a browser — before counting captcha providers, open source maintainers, plug-ins, and payment processors.
Because many providers are responsible for access, online abuse is usually caused by a third party, not by the infrastructure provider. That means a company like Cloudflare may have few targeted options to address harm without affecting access. Blocking parts of the Internet, or stepping aside to let a site be taken down by cyberattack, can have outsized negative effects on others’ rights.
Cloudflare subscribes to three principles in building abuse processes: fair process, proportionality, and transparency. The company also engages with human rights groups including the Global Network Initiative, the UN’s B-Tech Project, and its own Project Galileo partners to understand the impact of its policies.
Grievance mechanisms for complainants
The UNGPs emphasize that harmed individuals should have access to remediation mechanisms, whether judicial or private, that are equitable, predictable, and transparent. Cloudflare offers an abuse reporting form open to anyone online, with detailed guidance on how to report problematic activity. Complainants worried about retaliation, such as those reporting threats or harassment, can submit anonymously, although that may limit follow-up.
Because Cloudflare protects entities from cyberattacks, a complainant may not know who hosts the content causing the harm. When someone seeks removal of content and Cloudflare is providing only performance or security services, it cannot remove anything. Instead, it forwards the complaint to the website owner and hosting provider for appropriate action.
Fair process for Cloudflare users
Abuse complaints are not always submitted in good faith. Cloudflare has received complaints that appear designed to intimidate journalists reporting on government corruption, silence political opponents, or disrupt competitors. A fair process therefore also requires fairness to the users who might suffer consequences of a complaint.
Cloudflare generally notifies users of potential complaints so they can respond, though individual circumstances and anonymous complaints sometimes make that difficult. Users are given notice of potential actions and an opportunity to provide additional information before decisions are made, and they can seek reconsideration after the fact.
Proportionality across product types
Proportionality in human rights law means any interference with rights should be as limited and narrow as possible to address the harm. That is especially important for Internet infrastructure because of the dependencies among providers and the cascading effects one action can have. A single ISP shut-off can deprive thousands or millions of their only means of reaching loved ones, working, or participating in political debate. Voluntary action by a provider can do the same.
For abuse complaints, proportionality argues for routing responses to whoever can take the most targeted action. A complaint about a single image or post should not result in an entire website being taken down. The principle shapes Cloudflare’s differentiated approach for different products:
- When Cloudflare hosts content — through products like Pages, Images, or Stream — it can take granular action on specific pieces of content. An acceptable hosting policy enables notice and takedown, with the Cloudflare user given an opportunity to remove content themselves first or contest the takedown.
- When Cloudflare is providing only security services that prevent a site from being taken offline by a DDoS attack, there is no targeted action available on particular content. Termination of security services is generally not the right remedy: it only resolves a content concern if the site is removed from the Internet entirely, which is illegal in most jurisdictions. A vigilante cyberattack is inconsistent not just with proportionality but with notice and due process, and offers no remediation if there is a mistake.
- When Cloudflare is providing core Internet technology services like DNS, only blunt instruments are available.
In cases where Cloudflare cannot act proportionately, other actors in the ecosystem — typically website owners or hosting providers — can remove individual pieces of content. Proportionality sometimes means recognizing that Cloudflare is not the right party to act, while still playing a role in helping complainants find the right provider.
The EU embraced this logic in the Digital Services Act: requests to address illegal content should generally be directed to the specific provider with the technical and operational ability to act, to minimize negative effects on access to legal content.
Transparency in abuse handling
Transparency is core to Cloudflare’s approach, both as a company value and because it lets decisions affecting human rights be publicly scrutinized. Cloudflare publishes blog posts about difficult decisions and uses those to engage with external stakeholders. More systematically, it maintains a public page describing its approach to abuse and expands its biannual transparency report to cover the full range of abuse responses, from content removal in storage products to reports of child sexual abuse material to the National Center for Missing and Exploited Children (NCMEC).
When Cloudflare terminates even DDoS protection
There is a limited set of circumstances where Cloudflare will terminate even security services. Most are tied to legal obligations reflecting the judgment of policymakers and impartial decision makers about when barring entities from Internet access is appropriate. Even then, Cloudflare tries to provide notice and, where possible, the opportunity to fix the problem first. The categories include:
- Child Sexual Abuse Material: Cloudflare reports allegations of CSAM to NCMEC. When it has reason to believe, in conjunction with those working in child safety, that a site is solely dedicated to CSAM or that the site owner is deliberately ignoring legal takedown requirements, it may terminate services. Such terminations are now included in its biannual transparency report.
- Sanctions: US law prohibits business with parties on the Specially Designated Nationals (SDN) list, which includes terrorist organizations and human rights violators. Targets of sanctions receive notice and can challenge the designation. Cloudflare terminates services to identifiable SDN-listed entities. The US also restricts business with Cuba, North Korea, Syria, Iran, and the Crimea, Luhansk, and Donetsk areas of Ukraine; general licenses may allow for certain services even where individuals come from those regions.
- Court orders: Cloudflare occasionally receives US court orders to terminate services due to copyright or other prohibited content. Because it does not host the content, it does not see termination of security services as effective — and its experience bears that out, as most domains subject to such orders have already stopped using the service by the time action is required. Cloudflare may terminate services to repeat infringers in response to valid, due-process-compliant orders.
- SESTA/FOSTA: The 2018 US laws created broad criminal liability for services facilitating prostitution or sex trafficking. Cloudflare regards the law as “profoundly misguided and poorly drafted,” noting its documented harms to sex workers’ safety and the GAO's finding that it was largely ineffective against trafficking. To avoid criminal liability risk, Cloudflare may terminate services to domains that appear to fall under the law. It has done so for a few domains since enactment and intends to report those terminations in its transparency report.
- Technical abuse: For phishing and malware distributed through its services, Cloudflare prefers to place a warning interstitial page, protecting potential victims and disrupting the attack. When a user is intentionally phishing or distributing malware and security interests support stronger action, it may terminate service to the intentionally malicious domain.
- Voluntary terminations: In three publicized cases — The Daily Stormer in 2017, 8chan in 2019, and the blocking of Kiwi Farms in 2022 — Cloudflare voluntarily terminated services or blocked access. Each case had distinct facts, but the common elements were sites whose users had inspired physical harm in the offline world and a failure by law enforcement or other more targetedly-positioned providers to effectively address the harm.
Cloudflare maintains that taking sites offline by DDoS is almost never a proportionate response to content-based harms, and notes that jurisdictions like the EU are grappling with regulatory responses that aim to preserve human rights online. The company continues to refine its abuse processes, drawing on stakeholder conversations, policymaker engagement, and experience as it goes.



