8 Total
1 High severity
6 Medium severity
1 Low severity
Summary

This document establishes Cloudflare's practices for collecting, processing, and using personal information from visitors to Cloudflare websites and from users of Cloudflare services. The policy authorizes data collection including IP addresses, device information, and browsing behavior both when individuals directly interact with Cloudflare and when their traffic passes through Cloudflare's infrastructure serving third-party websites. The policy permits processing of this data for security, analytics, and marketing purposes, and authorizes disclosure to service providers, partners, and in response to legal requests.

Technical / Legal Breakdown

This document is Cloudflare's Privacy Policy governing the collection, use, and disclosure of personal information across Cloudflare's websites, products, and services, with stated legal bases including consent, legitimate interests, and contractual necessity under applicable frameworks including GDPR and CCPA. The policy states that Cloudflare collects information provided directly by users, information collected automatically (including log data, IP addresses, device identifiers, and cookies), and information from third-party sources, and the terms authorize use of this data for service delivery, security operations, product improvement, and marketing communications. Notably, the policy distinguishes between Cloudflare acting as a data controller for its own customer and website visitor data versus acting as a data processor for data passing through its network on behalf of customers, a structurally important distinction that limits Cloudflare's stated obligations regarding end-user data processed on behalf of enterprise clients. The policy references GDPR for EU and UK users, CCPA and CPRA for California residents, and other applicable regional frameworks, with Cloudflare asserting Privacy Shield successor mechanisms and Standard Contractual Clauses for international data transfers, though the enforceability of specific transfer mechanisms may depend on evolving regulatory guidance. Material compliance considerations include the adequacy of consent mechanisms for cookies and tracking technologies, the scope of data retention practices, and the handling of personal data transiting Cloudflare's global network on behalf of business customers.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

2 important changes detected

2 versions captured · Last updated: May 2026

What changed Cloudflare's privacy policy was updated on May 5, 2026, but the detected change is a minor navigation and service listing update rather than a substantive revision to privacy terms. The change reorganized how support and professional services are presented in the document's reference materials. This appears to be a formatting or organizational revision with no material impact on what data Cloudflare collects, how it uses your information, or what rights you have.
Why this matters This change does not materially affect consumer privacy rights, data handling practices, or obligations. The detected modification reorganizes how Cloudflare's support services and product listings appear in the policy reference section rather than changing any substantive privacy commitments or data practices. No consumer action is required in response to this update.
View full change record →
What changed Cloudflare's Privacy Policy was updated on April 18, 2026 to reorganize its navigation and service descriptions. The change adds new service sections including 'Support and success bundles', 'Optimized Cloudflare experience', 'Professional services', 'Expert-led implementation', 'Technical account management', 'Focused technical management', and 'Security operations service' with 'Cloudflare monitoring and response'. The update also removes certain navigation items related to 'Expert-led success' and reorganizes product listing sections. This appears to be a structural and navigational change rather than a substantive modification to privacy obligations, data handling practices, or consumer rights.
Why this matters The updated Privacy Policy reflects organizational changes to Cloudflare's service menu and navigation structure. The change adds descriptions of new enterprise support services including professional services, technical account management, and security operations monitoring. These additions appear to be informational changes to the document's navigation structure rather than modifications to privacy practices, data collection, or consumer rights. No new privacy obligations or data handling practices are established by this change.
View full change record →

High — 1 provision
Medium — 6 provisions
Low — 1 provision

Monitoring

Cloudflare has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Controller vs Processor Distinction and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 05:58 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000282
Version ID CA-V-002136
SHA-256 11345595e27ea9423cbed8c6821f4134b453229474987c5b21b3afaf0d42d79c
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans