Why Privacy Certification Matters
Privacy is recognized internationally as a fundamental human right, most notably in the United Nations' 1948 Universal Declaration of Human Rights (Article 12) and the 1976 International Covenant on Civil and Political Rights (Article 17). Cloudflare's position is that building a better Internet requires building one where users don't have to sacrifice personal information — location, age, interests, shopping habits, or beliefs — simply to navigate online.
Valuing privacy in principle is one thing; proving it in practice is another. Cloudflare's approach combines product design choices, internal policies, and independent third-party examinations that verify its privacy and security controls actually work as described.
International Privacy Standards
Cloudflare's privacy program is built around core principles such as transparency, privacy by design, collecting the minimum personal data necessary for services to function, and processing data only for specified purposes. Earlier this year, Cloudflare became one of the first organizations in its industry to certify to ISO/IEC 27701:2019, an international privacy standard that translates concepts from the EU's General Data Protection Regulation (GDPR) into a framework for managing privacy.
This certification matters because it provides independent, third-party verification that Cloudflare's privacy program meets GDPR-aligned industry standards — reassuring customers that their information is handled properly whether Cloudflare acts as data processor or data controller.
The standard defines 31 controls for organizations that are personal data controllers and 18 additional controls for those that are personal data processors. These controls cover best practices for data handling, transparency, documenting legal bases for processing, international data transfers, and handling data subject rights.
Data Transfer Controls
One requirement of the standard is maintaining documented policies and procedures for international personal data transfers. Cloudflare addresses this through an internal policy that restricts cross-jurisdiction data transfers unless specific criteria are met. All customers, free or paid, enter into a standard Data Processing Addendum available on the Cloudflare Customer Dashboard, which sets restrictions on processing personal data on behalf of customers. Cloudflare also publishes a list of sub-processors and the countries or jurisdictions where processing may occur.
Data Minimization
The standard also requires documented data minimization objectives, including the mechanisms used to meet them. Cloudflare's internal policies cover data management across its full lifecycle. The goal is simple: if certain personal data isn't required to deliver a service, Cloudflare prefers not to collect it at all. Where collection is necessary, only the minimum amount for the identified purpose is collected and processed for the minimum necessary duration, all transparently documented in the public privacy policy.
Cloudflare also maintains a Privacy by Design policy that sets rigorous evaluation standards for products and services that process personal data.
Security Certifications as Privacy Protection
Strong security is integral to privacy — protecting personal data from unauthorized access helps keep it private. Cloudflare demonstrates its security posture through several certifications:
- ISO 27001:2013: An industry-standard information security certification covering implementation of an Information Security Management System (ISMS) and security risk management processes. Cloudflare has held this certification since 2019.
- SOC 2 Type II: Attests that Security, Confidentiality, and Availability controls are in place per the AICPA Trust Service Criteria, covering protection of customer data.
- PCI DSS 3.2.1: Cloudflare maintains Level 1 compliance, held since 2014. Its Web Application Firewall (WAF), Cloudflare Access, Content Delivery Network (CDN), Time Service, Workers, and Workers KV are PCI compliant solutions. An annual audit is conducted by a third-party Qualified Security Assessor (QSA).
- BSI Qualification: Recognition by Germany's Federal Office for Information Security as a qualified provider of DDoS mitigation services.
Cloudflare continues exploring additional privacy certifications. It is monitoring the EU's approval of the first official GDPR codes of conduct from May 2021 and considering other standards, including ISO 27018 cloud privacy certification.
Privacy-Enhancing Technology
A significant part of Cloudflare's privacy approach is avoiding unnecessary data collection outright. Several tools are designed with this principle embedded:
- 1.1.1.1 Public DNS Resolver: A privacy-first resolver for which Cloudflare committed to retaining no personal data about requests. Independent accountants conducted a privacy examination that confirmed Cloudflare had no personal data to sell. If product behavior ever changes, Cloudflare will commission another examination to verify that no single entity can identify who is visiting a given website.
- Web Analytics: Collects usage metrics without client-side state like cookies or localStorage, and never fingerprints individual users.
- Oblivious DoH (ODoH): A proposed DNS standard co-authored by engineers from Cloudflare, Apple, and Fastly that separates IP addresses from DNS queries so no single entity can see both simultaneously.
- Universal SSL: Now called Transport Layer Security, this encrypts web content that previously traveled as plain text — akin to sending personal information in a locked box rather than on a postcard. Available to all customers, free and paid.
Certifications, policies, and technology all serve the same end: maintaining user trust by respecting privacy rights as data transits Cloudflare's network and being transparent about how data is handled and secured. Details on these efforts are available at Cloudflare's Trust Hub.



