When Legal Systems Collide Over Data
Governments have long sought access to online records—for criminal investigations, intelligence gathering, and other purposes. For service providers, these requests carry a fundamental tension: the data in question does not belong to them. Law enforcement's work is important, but providers hold customer data in trust, and that trust is the foundation of their business.
The problem deepens because nations disagree on what constitutes adequate data protection. The United States permits disclosure of communication content only under specific legally defined circumstances. The European Union treats privacy and data protection as fundamental rights under the GDPR. These frameworks differ in both scope and whom they cover—differences that matter when foreign governments make legal requests.
The Court of Justice of the European Union has repeatedly found U.S. legal restrictions, along with voluntary frameworks like Privacy Shield and its predecessor Safe Harbor, insufficient for EU privacy compliance—largely due to U.S. laws permitting collection of non-citizen data for foreign intelligence purposes. The European Data Protection Board has taken the position that a U.S. criminal law request, outside a legal process where EU countries retain some control over produced information, fails as a legitimate basis for transferring GDPR-protected data.
Defaulting to the Most Protective Standard
These are ultimately disputes over when one government may compel a provider to hand over another nation's citizens' data. From Cloudflare's perspective, the fights were inevitable. Its response has combined technical controls with explicitly stated policies—preferring the most privacy-protective standard when two legal frameworks conflict, and always requiring legal process before releasing data.
Cloudflare's transparency reports, published since 2013, document public commitments about handling data requests. The reports include warranted "canaries": statements about actions the company has never taken. Removing a canary serves as a limited signal when legal restrictions prevent direct disclosure. The company has also pledged to challenge in court any order to break these commitments. These long-standing commitments now mirror the types of provisions the European Commission recommends for GDPR compliance via Standard Contractual Clauses.
As a security company, Cloudflare maintains strict access controls, logging and monitoring, backed by multiple third-party assessments each year—with no exemption for law enforcement. The company states it has never installed law enforcement software or equipment anywhere on its network, and has never provided any government with a feed of customer content transiting the network.
Encryption, Keys, and Content Integrity
Cloudflare holds that strong encryption of content and metadata is essential for online privacy, and encryption must itself be trustworthy. Public commitments to that end include never turning over Cloudflare's or its customers' encryption or authentication keys to anyone, and never weakening or subverting encryption at someone's request.
Other commitments address integrity of the Internet itself: Cloudflare has never modified customer content or changed the intended destination of DNS responses at the request of law enforcement or any other third party.

Notice, and Fighting What Can't Be Disclosed
Cloudflare's policy has always favored notifying customers when legal process targets their data, giving them an opportunity to challenge the request. In 2014, with the Electronic Frontier Foundation, Cloudflare litigated a National Security Letter that barred it from disclosing the letter's receipt; the court permitted disclosure after three years.
Cloudflare accepts that law enforcement may sometimes need to restrict disclosure temporarily to protect an investigation. But any non-disclosure provision should require government justification, an explicit time limit, and last only as long as strictly necessary. While U.S. courts have suggested indefinite non-disclosure orders pose constitutional problems, and 2017 Department of Justice guidance capped such orders at one year except in extraordinary circumstances, some agencies have continued seeking them. Cloudflare reports receiving at least 28 non-disclosure orders since 2017 lacking an end date. Working with the ACLU, Cloudflare threatened litigation in each case—and in each case, the government added time limits, enabling Cloudflare to provide customers notice.
When a legal request would force Cloudflare to violate laws like the GDPR, its approach is to push the conflict back where it belongs: between the two governments disputing access to the data. The company has committed, publicly and through its Data Processing Addendum, to ask a court to quash requests on conflict-of-law grounds where necessary.
Principles for a Multi-Jurisdictional Network
Operating a global network within diverse privacy regimes ultimately relies on durable values: maintain principled and transparent practices, respect privacy, demand due process, and give customers notice so they can make their own decisions about their data.



