A New Set of Privacy Basics for a New Era
Cloudflare is an official sponsor of Australia's Privacy Awareness Week 2023, a designation that carries particular weight given the recent spate of large-scale data breaches affecting millions of Australian citizens. The official theme, "Privacy 101: Back to Basics," arrives at a moment when both public attention and regulatory momentum—including the Attorney General's Privacy Act Review Report 2022—are squarely focused on how personal data is protected.
Traditional privacy fundamentals such as notice and consent remain necessary, but they are no longer sufficient. Rapid technological change and evolving threat vectors mean that protecting personal data now requires proactive security tools and privacy-enhancing technologies. For Cloudflare, this is part of a broader mission: building a more private and secure Internet. The company's commitment to Australia dates back to 2012, when Sydney became its 15th data center, and it has supported more than 300 customers in Australia and New Zealand since establishing its local entity in 2019, including major banks and digital natives such as Canva.
Cloudflare's support for Privacy Awareness Week centers on three new "privacy basics" that it believes are essential in the current environment:
- Minimize the data you collect, and then only use that data for the purpose for which it was collected.
- Employ reasonable and appropriate security measures—with the bar for what this means going higher every day.
- Create a culture of privacy by default.
Minimizing Personal Data in the Clear
Technological controls offer a way to reduce the volume of personal data flowing into the Internet's data ecosystem, regardless of an individual's country of residence. Cloudflare's 1.1.1.1 public DNS resolver, launched in 2018, does not retain personal data about web requests. Independent accountants conducted a privacy examination that confirmed there was no personal data to sell. When combined with the WARP VPN, the resolver also prevents an Internet service provider from seeing the sites and apps a user accesses—even if those communications are encrypted.
DNS requests are more revealing than many people realize. Unlike paper envelopes, which carry only sender and recipient addresses, digital DNS queries contain timestamps, full domains and subdomains visited, and session durations. This is why Cloudflare has emphasized DNS over HTTPS (DoH) as a core privacy measure.
Going further, Cloudflare was an early backer of Oblivious DoH (ODoH), a proposed DNS standard co-authored by engineers from Cloudflare, Apple, and Fastly. ODoH separates IP addresses from query contents by inserting a proxy between client and resolver. The proxy sees only the query's destination, while the resolver sees the query content but only the proxy's IP address—so the identity of the requester and the content of the request are unlinkable. This technology underlies Apple's iCloud Private Relay system, for which Cloudflare serves as a second relay.
The same principle powers Oblivious HTTP (OHTTP), an emerging IETF standard built on standard hybrid public-key cryptography. Cloudflare's Privacy Gateway service relays encrypted HTTP requests between clients and application servers. Cloudflare sees where a request originates but not its contents; the application sees contents but not origins. Neither party has the full picture. Cloudflare deployed Privacy Gateway for Flo Health Inc.'s Anonymous Mode, ensuring that Flo cannot see user IP addresses and Cloudflare cannot see request data contents.
Cloudflare's web analytics product takes a similar approach to data minimization. Instead of relying on client-side cookies or IP-based fingerprinting, it uses a simple JavaScript snippet to generate site metrics without compromising visitor privacy.
Security as a Privacy-Enhancing Function
Almost every data protection law globally requires reasonable and appropriate security measures for processed personal data. Security failures are often at the root of major data breaches, and in Australia, several recent high-profile incidents have underscored this connection.
Cloudflare's security services screen for threats on its network before they can reach a customer's systems. This configuration effectively makes security a privacy-enhancing function in itself. From the start, Cloudflare has framed its systems to keep data private, including from Cloudflare itself, and has made public policy and contractual commitments to that effect in its transparency reports and Data Processing Addendum.
The balance between encryption and security inspection is critical. Cloudflare introduced Universal SSL in 2014 to support encrypted connections to all customers, but "blindly passing along encrypted packets would undercut some of the very security that we're trying to provide." Encrypted malicious code that reaches an end destination could access protected information. In June 2022, when Atlassian disclosed a remote code execution vulnerability affecting Confluence Server and Data Center, Cloudflare quickly rolled out a new WAF rule for all customers. The location of stored data—Australia, Germany, the U.S., or India—would not have mattered had the vulnerability been exploited; the global WAF deployment was what stopped it.
Many of the largest data breaches begin with something simpler than an exploited software flaw: phishing and social engineering attacks that trick employees into visiting malicious sites or surrendering credentials. The FBI's Internet Crime Report ranks business email compromise and email account compromise as the costliest threat, with U.S. businesses losing nearly $2.4 billion. Cloudflare's Zero Trust solutions are designed to interrupt this attack chain:
- Link Isolation opens email links in Cloudflare's Remote Browser Isolation technology, isolating risky links and zero-day attacks from user devices and the corporate network.
- Data Loss Prevention tools identify and stop exfiltration of sensitive information.
- Area 1 identifies and blocks phishing emails, malicious code, and ransomware payloads before they reach inboxes.
These tools, combined with hardware keys for multifactor authentication, were instrumental in thwarting an SMS phishing campaign in 2022 that targeted more than 130 companies—many of which later suffered customer data exposure. Cloudflare itself also relied on its Access product to ensure only authenticated users could reach internal Confluence systems during the Atlassian vulnerability period.
These protections depend on sophisticated machine learning to identify malicious activity patterns, but they do not require data to reside in any particular geography—allowing organizations to keep large-scale data sets private without sacrificing global technical posture.
Privacy as an Organizational Commitment
Beyond public-facing technologies, Cloudflare applies several less visible processes to embed privacy in its operations. Employees receive privacy training during orientation and participate in targeted data protection training throughout the year, depending on their engagement with personal data. Product development teams conduct privacy impact assessments and retain personal data only as long as necessary. Cloudflare states that it does not track end users across sites, does not sell personal information, and does not monetize DNS requests.
The company holds a range of third-party certifications, including ISO 27001, ISO 27701, ISO 27018, AICPA SOC2 Type II, FedRamp Moderate, PCI DSS 3.2.1, WCAG 2.1 AA and Section 508, C5:2020, and the EU Cloud Code of Conduct. It also maintains a defined posture toward government and third-party data requests, requiring strict adherence to due process. Cloudflare has committed to challenging law enforcement requests that would conflict with privacy laws of the requester's country of residence—such as Australia's Privacy Act—and maintains a policy of notifying customers of legal process before complying, where legally permitted.
Looking Ahead
Cloudflare is closely following Australia's privacy law reform discussions and has signaled its 2023 focus on the APEC Cross-Border Privacy Rules (CBPR) System to demonstrate its commitment to global privacy standards and safe cross-border data transfers.



