Cloudflare first to pass audits for new Global CBPR privacy certifications
Cloudflare has completed audits against two new international privacy frameworks: the Global Cross-Border Privacy Rules (Global CBPRs) for data controllers and the Global Privacy Recognition for Processors (Global PRP). The company says it is the first organization to be successfully audited against both standards, announced on Data Privacy Day. Formal certification is expected once the certifications officially launch, anticipated later in 2025.
These two new validations extend Cloudflare's existing privacy compliance portfolio, which already includes ISO 27701:2019, ISO 27018:2019, and adherence to the EU Cloud Code of Conduct, the first official GDPR code of conduct. Combined, these certifications cover official privacy validations in 39 jurisdictions, from Australia and Austria to Sweden and the United States. Four additional jurisdictions — the United Kingdom, Bermuda, Mauritius, and the Dubai International Finance Centre — are in the process of joining and recognizing the Global CBPR certifications.
What the Global CBPR System is
The Global CBPR System was established on April 30, 2024 by the Global CBPR Forum, an intergovernmental body whose members include Australia, Canada, Japan, Republic of Korea, Mexico, Philippines, Singapore, Chinese Taipei, and the United States. The UK, Bermuda, Mauritius, and the Dubai IFC are associate members, signaling their intent to become full members.
The system is a voluntary, enforceable, international framework built on accountability. It provides a baseline level of privacy protection for consumers through a set of rules for handling personal information, while enabling data flows across jurisdictions with different data protection laws. The framework is consistent with the core principles of the OECD Guidelines on the Protection of Privacy and Trans-Border Flows of Personal Data.
Cloudflare applied to join on May 1, 2024, the first day after the system's establishment, and has now passed the audits required for certification.

Certification requirements
To be certified under the Global CBPR System, organizations must meet all fifty requirements, which are derived from nine Global CBPR Privacy Principles. These requirements cover how organizations collect, manage, and safeguard personal information in their custody — including the personal details of customers, employees, and job applicants. For Cloudflare, that scope also includes network information: observations about how its global cloud platform handles server, network, or traffic data generated in the course of providing services.

The related Global PRP certification covers personal information processed on behalf of another organization, typically a customer. Its eighteen requirements stem from two principles most relevant to that context: Security Safeguards and Accountability. For Cloudflare, this covers data processed under the Data Processing Addendum signed with all customers, chiefly Customer Content flowing across the network and the Customer Logs generated by those data flows. Organizations must meet every one of the eighteen requirements to be Global PRP certified.
Preventing Harm | Notice | Collection Limitation |
|---|---|---|
Uses of Personal Information | Choice | Integrity of Personal Information |
Security Safeguards | Access and Correction | Accountability |
Key requirements in practice
The requirements across both frameworks center on familiar data protection principles: notice, choice, collection limitation (data minimization), data subject access and correction, adequate security, preventing harm, integrity of personal information, accountability, and uses of personal information. A few examples illustrate how Cloudflare addresses them.
Notice. One CBPR requirement asks organizations to provide clear and easily accessible statements about practices and policies governing personal information — a privacy statement. Cloudflare points to its privacy notice, visible from the footer of each page on its website, and links to that notice when collecting personal data through forms. This aligns with the transparency expectations in Article 13 of the EU's GDPR.
Limiting use. Another CBPR requirement asks whether organizations limit use of collected personal information as identified in their privacy statement. Cloudflare's Privacy Policy commits to sharing or disclosing personal information only as necessary to provide services or as otherwise described in the policy, except in cases where notice and an opportunity to consent are provided first. Internal documentation, kept in line with the accountability principle, records what data is processed and for what purposes.
Security safeguards. Both frameworks include requirements to describe physical, technical, and administrative safeguards protecting personal information. Cloudflare's information security program is built in accordance with the ISO/IEC 27000 family of standards, with full details of controls documented in Annex 2 ("Technical and Organizational Security Measures") of its Customer Data Processing Addendum.
Processor accountability. The Global CBPR framework also requires mechanisms to ensure that obligations to individuals are met when personal information processors, agents, contractors, or other service providers handle data on the organization's behalf. Cloudflare requires vendors that handle its or its customers' personal information to sign a Data Processing Addendum, flowing the commitments made to customers down to vendors, including security requirements.
Availability
Further details on the Global CBPR System and Global PRP — including the full requirements and related news — are available at globalcbpr.org. Cloudflare's certifications and reports are available to customers through the Trust Hub and can be downloaded from the Cloudflare dashboard.




