Cloudflare Revamps Transparency Reports for 2024

Cloudflare has published its 2024 Transparency Reports, marking a significant overhaul of a disclosure practice the company has maintained for over a decade. The new reports cover fresh topics, include additional data points, and adopt a revised format designed to improve readability. Transparency reporting has become an industry best practice and is now codified in the European Union's Digital Services Act (DSA), which shaped several of the changes in this year's edition.

A Decade of Disclosure, Now DSA-Aligned

Cloudflare's transparency reports have historically served dual purposes: publishing raw numbers on legal requests and abuse reports, while also articulating the principles behind the company's handling of those matters. Over the years, the scope has grown from a focus on government requests for customer information to include civil requests, legal demands to restrict or terminate services, and the mechanics of abuse handling for websites on Cloudflare's network.

This year's updates are largely driven by the DSA, which replaced the e-Commerce Directive and introduced tiered transparency obligations for different types of online services. Most of Cloudflare's offerings are pass-through intermediary services—primarily security and performance tools—that carry limited reporting duties under the DSA. The company's hosting services face additional requirements concerning abuse-related actions. Cloudflare states that its existing reports already satisfied much of the DSA's mandate, but the 2024 edition incorporates specific data categorizations and formatting aligned with the regulation's requirements.

BLOG-2750-hero

New Data Points and a Split Structure

The 2024 reports add several new categories of information, including expanded classifications of hosted content abuse, automated mitigation actions for phishing and technical abuse, mean response times for various abuse report types, and new classes of customer information requests. Consistent with DSA expectations, a machine-readable version of the underlying data accompanies the published reports. The company has also introduced "additional context" boxes designed to flag notable trends or developments during the reporting period.

To make the expanded information more digestible, Cloudflare has split the report into two distinct documents:

  • Legal Requests for Information—covering law enforcement, government, and civil requests for customer data in the U.S. and globally.
  • Abuse Processes—detailing Cloudflare's handling of abuse reports and responses to legal orders seeking termination or restriction of user services.

One notable relocation: the company's "warrant canaries" now reside on the transparency report landing page within Cloudflare's Trust Hub rather than inside the reports themselves. These statements affirm actions the company has never taken, and Cloudflare confirms all canaries remain intact—nothing on that list has changed.

Continued Cadence

Cloudflare will maintain its semi-annual publication schedule. Reports remain available on the company's Transparency page and via an RSS feed. The company expects the format to keep evolving as its product portfolio grows and the regulatory landscape shifts.