Hosting and network
GDPR Cloudflare
In an indie stack, Cloudflare is used for DNS, CDN, WAF, and bot protection. Entity cited: Cloudflare, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Cloudflare
Yes. Public Customer DPA.
Stated role
The customer is the controller (or a third party's processor) and Cloudflare is the processor, or sub-processor where applicable.
Personal data
The customer DPA annex cites IP addresses in customer logs, the names and emails of Cloudflare Zero Trust users, personal data that may be contained in customer content, and administration logs (IP, email).
Sub-processors of Cloudflare
Public list of sub-processors of the Cloudflare services.
Transfers outside the EU
Hosting / location
Data passes through the Cloudflare network. The sub-processor list mentions locations including the United States, the EEA, the United Kingdom, Japan, Australia, Canada, Singapore, India, and England. The cookies documentation (stated update: 5 May 2026) states that, without the Data Localization Suite, cookie data may be processed in a data center in the United States. That suite lets you choose where it is processed (Regional Services) and logged (Customer Metadata Boundary). A single region for all services: not disclosed.
EU–United States Data Privacy Framework
Cloudflare, Inc. is registered. Exact EU-U.S. Data Privacy Framework status: Active - Re-certification under Review. Same status for the United Kingdom extension and the Swiss-U.S. DPF.
Cookies
The “Cloudflare Cookies” documentation (stated update: 5 May 2026) states that these cookies, set on customers' sites according to the products enabled, are strictly necessary unless stated otherwise. Published names: __cflb (load balancer session affinity), __cf_bm (Bot Management or Bot Fight Mode), cf_clearance, cf_chl_rc_i, cf_chl_rc_ni, and cf_chl_rc_m (Challenge Platform), cf_ob_info and cf_use_ob (Always Online), __cfwaitingroom (Waiting Room), __cfruid and _cfuvid (rate limiting). The cookies page of the cloudflare.com site points to a separate list, in the cookie preferences.
Typical use, written by StackLégal and not by the vendor: DNS, CDN, WAF, and bot protection.
History
Last update: October 4, 2026.
Cookies: the “Cloudflare Cookies” documentation replaces the previous summary. Hosting re-read.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Cloudflare a processor within the meaning of the GDPR?
The customer is the controller (or a third party's processor) and Cloudflare is the processor, or sub-processor where applicable.
What DPA does Cloudflare publish?
Yes. Public Customer DPA. https://www.cloudflare.com/cloudflare-customer-dpa/
Which further sub-processors does Cloudflare publish?
Public list of sub-processors of the Cloudflare services. https://www.cloudflare.com/gdpr/subprocessors/
Where does Cloudflare state that it processes data, including outside the EU?
Data passes through the Cloudflare network. The sub-processor list mentions locations including the United States, the EEA, the United Kingdom, Japan, Australia, Canada, Singapore, India, and England. The cookies documentation (stated update: 5 May 2026) states that, without the Data Localization Suite, cookie data may be processed in a data center in the United States. That suite lets you choose where it is processed (Regional Services) and logged (Customer Metadata Boundary). A single region for all services: not disclosed.
Is Cloudflare registered under the EU–United States Data Privacy Framework?
Cloudflare, Inc. is registered. Exact EU-U.S. Data Privacy Framework status: Active - Re-certification under Review. Same status for the United Kingdom extension and the Swiss-U.S. DPF. https://www.dataprivacyframework.gov/participant/5666
Which personal data does Cloudflare mention?
The customer DPA annex cites IP addresses in customer logs, the names and emails of Cloudflare Zero Trust users, personal data that may be contained in customer content, and administration logs (IP, email).
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.