Cloudflare Earns ISO/IEC 27701:2019 Certification for Privacy Management
Cloudflare has announced that it has been certified to the ISO/IEC 27701:2019 privacy standard. According to the company, it is one of the first organizations in its industry to achieve this certification, and the first web performance and security company to be certified under the new standard as both a data processor and a data controller.
The certification is the result of a third-party audit of Cloudflare's Privacy Information Management System (PIMS), which was conducted by A-LIGN in March 2021. The company's PIMS was assessed against the full set of 31 controls required for personal data controllers, plus the 18 additional controls for personal data processors—a total of 49 controls that Cloudflare had to meet to cover both roles in its scope.
What ISO/IEC 27701:2019 Covers
ISO/IEC 27701:2019 (ISO 27701) is a privacy extension to the ISO/IEC 27001 and ISO/IEC 27002 standards, which are widely used for establishing and running an Information Security Management System (ISMS). While ISO 27001 is held by more than 36,000 organizations across 131 countries, ISO 27701 is a relatively new addition to the ISO 27000 series. It adapts the ISMS framework to the creation of a Privacy Information Management System (PIMS), with an emphasis on continuous improvement of privacy practices.
What makes ISO 27701 significant is its explicit alignment with the EU's General Data Protection Regulation (GDPR). The standard includes an annex that maps its requirements to Articles 5 through 49 (excluding Article 43) of the GDPR. This is unusual for an ISO standard, which typically references other international ISO standards rather than a specific region's regulations.
Although Article 42 of the GDPR encourages the creation of official data protection certification mechanisms, none have yet been approved by the European Data Protection Board or the UK's Information Commissioner's Office. As a result, ISO 27701 serves as an externally audited, GDPR-aligned benchmark for organizations seeking to demonstrate compliance in the absence of an official certification scheme.
What the Certification Means for Customers
For Cloudflare customers, the ISO 27701 certification provides independent verification that the company's privacy program meets GDPR-aligned industry standards. It complements the Data Processing Addendum (DPA) that Cloudflare makes available to all customers through its dashboard, offering multiple layers of assurance for how personal data is handled.
A few specific requirements under ISO 27701 illustrate what the certification entails:
- International data transfers: Organizations must maintain policies and documented procedures for transferring personal data across jurisdictions. Cloudflare's approach includes an internal policy that restricts such transfers unless specific criteria are met. Customers also enter into a standard DPA that sets out processing restrictions, and Cloudflare publishes a list of sub-processors along with the countries where processing may occur.
- Data minimization: Organizations must document their data minimization objectives and the mechanisms used to achieve them. Cloudflare maintains internal policies covering the full data lifecycle, aiming to collect only the minimum amount of personal data necessary for a defined purpose. The company also states that it has implemented a Privacy by Design policy that requires evaluations before products and services collect or process personal data.
Becoming Certified
Achieving ISO 27701 certification is a multi-step process. It involves understanding and planning for the standard, identifying and adapting relevant controls, conducting internal audits, and then undergoing external audits—which themselves take place in two stages. Once certified, an organization's privacy management system is subject to ongoing internal and external audits on an annual basis to ensure that it continues to meet the standard's requirements.
Cloudflare's ISO 27701:2019 certificate is available to customers upon request from their sales representative. Alongside Cloudflare's existing ISO 27001:2013 certification, the new certificate adds to the compliance resources available on the company's website at www.cloudflare.com/compliance. Questions about the certification can be directed to [email protected].



