A formal framework for an existing commitment
Cloudflare has released its first human rights policy, formalizing a commitment first made last year when the company joined the Global Network Initiative (GNI) and pledged support for the UN Guiding Principles on Business and Human Rights (UNGPs). The policy outlines how the company intends to put that responsibility into practice across its business functions.
The development process drew on conversations inside and outside the company. Internally, the goal was to capture and build on existing practices around privacy, security, and transparency that predate the formal policy. Externally, Cloudflare consulted human rights experts, participated in working groups with other ICT companies through the B-Tech project and GNI, and engaged with Project Galileo partners on how to apply human rights principles to specific situations.
Why the UNGPs matter for infrastructure providers
The UNGPs, endorsed by the UN Human Rights Council in 2011, distinguish the state's duty to protect human rights from a business's responsibility to respect them. For companies, this means avoiding infringement on the rights of others and addressing adverse impacts they may be involved in. The framework also calls for grievance mechanisms for affected individuals or communities.
Human rights, as defined by the 1948 Universal Declaration of Human Rights, are universal rights that range from the most fundamental, like the right to life, to those that make life worth living, such as rights to food, education, work, health, and liberty. Per the UN Human Rights Office of the High Commissioner, these interdependent rights may only be restricted in specific, well-defined situations subject to due process.
Companies typical meet their UNGP obligations through a stated commitment and processes for identifying, preventing, and mitigating risks of harm. This includes conducting due diligence on whether activities might contribute to harm, reducing risks that are identified, and remediating actual harms, with priority given to severe impacts based on scope, scale, or difficulty of remedy.
The relevance for a provider like Cloudflare was underscored in a 2017 report from the UN Special Rapporteur on freedom of expression, which noted that content delivery networks are "strategically positioned on the Internet infrastructure to counter malicious attacks that disrupt access" and can serve as a "bulwark against government and private overreach." The report recommended such companies incorporate human rights safeguards, reduce information collection by design, engage with stakeholders, and improve transparency.
A policy grounded in existing practice
Cloudflare's policy is intended to make explicit and systematic what the company says has long been part of its culture. Prior efforts cited in the announcement include:
- Universal SSL, making encryption available to all customers
- Encrypted DNS and SNI protocols to protect metadata privacy
- Unmetered DDoS mitigation to stop attacks without usage limits
- Free protection programs for at-risk groups, including Project Galileo, the Athenian Project, Cloudflare for Campaigns, and Project Fair Shot
- Transparency documentation on government requests, difficult decisions, and product abuse considerations
The company cites a "long-standing belief" that the Internet should be faster, more reliable, more private, and more secure for everyone. The formal policy derives from the UNGP expectation that businesses state their commitment publicly and back it with operational processes.
Next steps
Cloudflare says the policy is the first step toward a dynamic human rights program rather than a static document, with expectations that it will evolve. The company will continue to refine its approach as it learns from experts and stakeholders, and reassesses which human rights issues are most salient to its operations.



