Data Localization: A Compliance Tool, Not a Privacy Silver Bullet
Strong cybersecurity is the most effective way to protect the privacy of personal information—often more so than keeping data within a specific jurisdiction. However, customers in Europe, India, Australia, Japan, and elsewhere have told us they need data localization solutions to meet regulatory obligations within their privacy programs.
With Data Privacy Day approaching on January 28, we find ourselves in an interesting spot. We disagree with the idea that data localization equals better privacy, yet we want to support customers who must comply with specific regulations. That's why we introduced the Data Localization Suite (DLS) in 2020: to help customers navigate a protection landscape increasingly focused on where data resides.
With DLS, customers can use Cloudflare's global network and security measures while keeping the data we process on their behalf local. Since launch, adoption has been strong, and we're now making the suite more comprehensive and easier to operate.
What DLS Addresses
Customers face a confusing patchwork of regulations that can restrict cross-border data flows. We hear regularly from businesses unsure how to comply when one country's rules suggest they can't use another country's products without extensive safeguards. We don't think that's the right way to regulate the Internet—we're encouraged by developments toward common data protections across jurisdictions—but while that evolves, DLS helps customers manage their obligations.
DLS was built around three customer concerns:
- How do I keep my encryption keys in my jurisdiction?
- How can application services like caching and the WAF run only in my jurisdiction?
- How can logs and metadata stay within my jurisdiction?
The suite addresses these with three components:
Encryption Keys. Keyless SSL and Geo Key Manager ensure private SSL/TLS key material never leaves the EU. With Geo Key Manager, customers choose to store keys only in data centers within a specified region; keys are protected with cryptographic access control so they can only be used there. Keyless SSL goes further—Cloudflare never possesses the private key material at all.
Regional Services. This ensures Cloudflare only decrypts and inspects HTTPS traffic inside the customer's chosen region. Traffic hitting the network anywhere is forwarded in encrypted TCP form to a data center in the chosen region, where decryption and Layer 7 security measures—like WAF—are applied.
Customer Metadata Boundary. When enabled, no end user traffic logs containing IP addresses processed on the customer's behalf leave the chosen region. Currently available in the EU and US only.
Expanding the Geographic Footprint
DLS launched with Europe and America in mind, but many customers wanted Asia-Pacific coverage. In September of last year, we added support for Regional Services in Japan, Australia, and India. Then in December 2022, Geo Key Manager became available across 15 regions, with customers able to allow- and deny-list regions for fine-grained control over where key material is stored.
We've published a technical deep dive on how we built Geo Key Manager v2.
Easier Configuration
Regional Services and the Customer Metadata Boundary offered important protections, but they were too hard to use. Both required manual steps by Cloudflare teams and had confusing or missing public APIs. That's changing with two usability improvements:
- Regional Services now has a dedicated UI and API, accessible from the DNS tab, with different regions settable on a per-hostname basis.
- The Metadata Boundary can now be enabled via a self-service API.
These changes give customers more direct control over exactly how to localize traffic components.
What's Next
DLS is available today for enterprise customers. More details on configuration are in the developer documentation. This year we plan to support many more regions for Regional Services and the Metadata Boundary, and to provide full data localization support across all Zero Trust products.



