A New Privacy Validation for Cloudflare’s Global Network
Privacy regulations vary significantly across the globe, and the rules governing cross-border data transfers are particularly complex. The European General Data Protection Regulation (GDPR) sets a high standard for handling personal information, with Chapter V of the regulation specifically addressing transfers of personal data across borders. While knowing where data is stored is important, how that data is handled and secured is equally critical. Cloudflare has long held the position that data must be protected consistently, whether it stays in one country or is transferred around the world.
Today, Cloudflare announced that it has received the EU Cloud Code of Conduct compliance mark, an official demonstration of GDPR compliance for its cloud services.
The Background of the EU Cloud Code of Conduct
The GDPR anticipated that organizations would seek consistent and transparent ways to demonstrate safe data handling. Article 40 of the regulation encourages the creation of codes of conduct:
“The Member States, the supervisory authorities, the Board and the Commission shall encourage the drawing up of codes of conduct intended to contribute to the proper application of this Regulation, taking account of the specific features of the various processing sectors and the specific needs of micro, small and medium-sized enterprises.”
This approach has historical precedent. The 1995 EU Data Protection Directive (Directive 95/46/EC) also made provisions for community codes to be submitted for formal approval by official EU bodies. However, it took until May 2021—five years after the GDPR was adopted—for the first code of conduct to gain official approval. The European Data Protection Board approved the “EU Data Protection Code of Conduct for Cloud Service Providers” (EU Cloud CoC) as the first official GDPR code of conduct. It was brought to the board by the Belgian supervisory authority on behalf of SCOPE Europe, which developed the code with input from the European Commission, cloud computing community members, and European data protection authorities.
The EU Cloud CoC provides a framework for both buyers and providers of cloud services. It helps buyers understand how a provider handles personal information, while providers undergo independent assessment to prove they meet the code’s requirements. Because the code has received formal approval, customers of compliant providers can be confident that their personal information is handled in accordance with the GDPR.
What the Code Requires
The code translates Article 28 of the GDPR (“Processor”) into actionable requirements for cloud service providers. These include data protection policies, technical and organizational security measures, terms and conditions, confidentiality and recordkeeping, customer audit rights, data breach handling, and processes for subprocessing—when a third party is subcontracted to process personal data alongside the main processor.
The code also touches on international data transfers, but it should be noted it is not itself a “safeguard” or a tool for legitimizing third-country transfers. An additional module for that purpose is still under development as of March 2023.
Two Examples from the Code
One: Customer Support for Impact Assessments. The code requires providers to have documented procedures to help customers with their data protection impact assessments. Under the GDPR:
“...an assessment of the impact of the envisaged processing operations on the protection of personal data.” - Article 35.1, GDPR
Cloudflare meets this by publishing details of its sub-processors and directing customers to audit reports available in the Cloudflare dashboard. The GDPR also notes that compliance with approved codes of conduct shall be taken into account in impact assessments (Article 35.8), further benefiting both parties.
Two: Effective Encryption. The code mandates that when providers offer encryption, it must be implemented effectively—using strong, trusted techniques that keep pace with the state-of-the-art and prevent abusive access to personal data. Cloudflare has a strong track record here, making encryption available for free to all its customers. Its Research Team, which includes academic researchers and cryptographers, designs and deploys encryption protocols to defend against active and passive attacks. Recently, Cloudflare announced that post-quantum cryptography would be included for free, forever.
The code contains 87 statements, or “controls,” in total. The full document is available at https://eucoc.cloud/en/home.
Cloudflare’s Compliance Status
Cloudflare joined the EU Cloud Code of Conduct’s General Assembly in May 2022. After an independent assessment process by SCOPE Europe, the accredited monitoring body, Cloudflare has now been verified for 47 cloud services.

EU Cloud CoC Verification-ID: 2023LVL02SCOPE4316. For further information, visit the public register at https://eucoc.cloud/en/public-register.
Part of a Growing Privacy Portfolio
The EU Cloud Code is the latest addition to Cloudflare’s privacy certifications. Two years ago, it was among the first in its industry to receive ISO/IEC 27701:2019, and it later became the first Internet performance and security company to be certified to ISO/IEC 27018:2019. This January, Cloudflare completed its annual ISO audit with third-party auditor Schellman, and its new certificate covering ISO 27001:2013, ISO 27018:2019, and ISO 27701:2019 is available for download from the Cloudflare dashboard.
Looking ahead, Cloudflare is also following the development of the proposed Global Cross Border Privacy Rules (CBPR) certification. This potential single global standard, already supported by several governments in North America and Asia, could facilitate safe data transfers between participating countries worldwide.
Existing customers can download copies of Cloudflare’s certifications and reports from the Cloudflare dashboard; new customers may request them from their sales representative. The latest information about certifications and reports is available at Cloudflare’s Trust Hub.



