BlogsCloudflareData Privacy & Protection Compliance

Data Privacy & Protection Compliance

Data Privacy & Protection Compliance

70
posts
2018–2026

Cloudflare's commitment to data privacy and protection has evolved significantly, driven by regulatory changes and a core mission to build a better internet. This evolution includes transparent policy updates, GDPR compliance measures, and the development of privacy-enhancing solutions like the Data Localization Suite (DLS). The DLS allows customers to use Cloudflare's global network and security measures while keeping data local, addressing concerns around encryption keys, regional service terms. Cloudflare for Government has achieved FedRAMP Class D (High) certification, building on its existing FedRAMP Moderate authorization. This new certification signifies a substantial increase in security requirements, enabling Cloudflare to handle the nation's most sensitive unclassified data. The FedRAMP High offering is built on Cloudflare's single, global network, leveraging the Data Localization Suite to ensure traffic inspection and processing occurs exclusively within U.S. data centers. This unified platform provides federal agencies with the same cutting-edge technologies as commercial enterprise customers, including Zero Trust security tools, application performance, and new developer features. The systems developed for FedRAMP High will also form the foundation for pursuing U.S. Department of Defense Impact Level 4 (DoD IL4) authorization.

2026

Serving the most critical missions- Cloudflare for Government achieves FedRAMP Class D (High) Certified status

8/10/2026

This post announces Cloudflare for Government's achievement of FedRAMP Class D (High) certification status, a significant upgrade from its previous FedRAMP Moderate authorization. It details the increased complexity and impact of High-level controls, which are designed for the nation's most sensitive unclassified data. The post emphasizes that this offering is built on Cloudflare's single, global network and leverages the Data Localization Suite to ensure data processing within U.S. data centers. It also announces the intention to use these systems as the foundation for pursuing U.S. Department of Defense Impact Level 4 (DoD IL4) authorization.

Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver

4/1/2026

This post details the results of an independent privacy examination of the 1.1.1.1 public DNS resolver, confirming its adherence to core privacy commitments. It highlights the anonymization and deletion of source IP addresses within 25 hours, the non-sale or sharing of personal data, and the retention of only necessary information for identification. The post also clarifies the use of sampled network packets for troubleshooting and attack mitigation, and the evolution of log data usage for services like Cloudflare Radar, while reaffirming the commitment to not combine DNS query data with other data for individual identification.

Introducing Custom Regions for precision data control

3/18/2026

Introduces Custom Regions as an extension of the Regional Services product, allowing customers to define their own geographical boundaries for traffic processing. This includes new capabilities for defining region membership using expressions (e.g., country codes) and calculating optimal in-region routing based on performance and availability. Also expands pre-defined regions to include Turkey, UAE, IRAP, and ISMAP.

2025

Detecting sensitive data and misconfigurations in AWS and GCP with Cloudflare One

3/21/2025

This post announces the expansion of Cloudflare One's CASB product to include Data Loss Prevention (DLP) functionality for AWS S3 and Google Cloud Storage. It introduces the ability to scan these cloud storage services for sensitive data (like PII and financial information) and misconfigurations (IAM, bucket settings). The post details the serverless architecture used for efficient and secure scanning within the customer's cloud environment and highlights the benefits of posture management features for identifying cloud security issues.

Enhance data protection in Microsoft Outlook with Cloudflare One’s new DLP Assist

3/21/2025

Introduced DLP Assist, a lightweight application for Microsoft Outlook (Desktop and Web) that integrates with Cloudflare Workers and a DLP engine. The DLP engine uses OCR to analyze attachments and raw text for sensitive data, with low-latency, real-time checks due to distributed policy configuration. It provides real-time user feedback via ribbon notifications and can trigger final warnings before sending. Integration with outbound MTAs (like Microsoft Purview) allows for blocking, encryption, or approval actions. Violation data can be exported via Logpush. Future enhancements include AI-driven confidence level tuning for email scanning.

Improving Data Loss Prevention accuracy with AI-powered context analysis

3/21/2025

This post introduces a significant advancement in Cloudflare's Data Loss Prevention (DLP) solution: AI-powered context analysis. This new capability leverages Workers AI and Vectorize to analyze the context of potential data matches, significantly reducing false positives and improving detection accuracy. The post details the technical implementation, the benefits of AI-driven learning from customer feedback, and the integration with Cloudflare's developer platform. It also outlines current limitations and future plans for expanding this AI-powered feature across other security products.

Preserving content provenance by integrating Content Credentials into Cloudflare Images

2/3/2025

This post introduces the integration of the Coalition for Content Provenance and Authenticity (C2PA) standard into Cloudflare Images, enabling content creators to preserve the entire provenance chain of their digital media. This feature allows for cryptographic signing of image transformations, ensuring tamper-evidence and enabling verification of content origin and edits, thereby enhancing data privacy and combating misinformation.

Cloudflare meets new Global Cross Border Privacy standards

1/28/2025

Cloudflare announced successful audits against the new Global Cross-Border Privacy Rules (Global CBPRs) for data controllers and the Global Privacy Recognition for Processors (Global PRP). These validations demonstrate adherence to global standards for privacy-respecting data flows across jurisdictions. The Global CBPR System is an accountability-based system facilitating privacy-respecting data flows among member economies, based on nine core privacy principles. The Global PRP certification covers data processed on behalf of customers, focusing on security safeguards and accountability. The post details how Cloudflare meets specific requirements related to notice, use of personal information, security safeguards, and accountability with processors, referencing its privacy policy, customer data processing addendum, and information security program.

2024

Expanding Regional Services configuration flexibility for customers

5/22/2024

This post introduces expanded capabilities for Regional Services, enabling customers to configure data processing locations with greater flexibility. It details the concept of Software Defined Regionalization (SDR) as the future of data localization, allowing for granular control over which traffic is regionalized and where. New regional offerings are announced, including specific countries and 'Exclusive of' regions, as well as a 'Cloudflare Green Energy' region. The post also reiterates the technical underpinnings of Regional Services, including encryption in transit and at rest, and how Anycast networks are adapted to respect regional boundaries by forwarding traffic to appropriate data centers for inspection and processing.

New Consent and Bot Management features for Cloudflare Zaraz

5/15/2024

This post introduces significant updates to Cloudflare Zaraz, enhancing its capabilities in managing online consent and bot traffic. It details the integration of Cloudflare Zaraz CMP with IAB TCF requirements and Google Consent Mode v2 signals, enabling users to comply with new advertising regulations in the EEA, UK, and Switzerland. The post also highlights improvements in Bot Management within Zaraz, allowing users to fine-tune which requests trigger analytics and conversion pixels, thereby controlling costs and preventing bot-driven data collection.

Announcing two highly requested DLP enhancements: Optical Character Recognition (OCR) and Source Code Detections

3/5/2024

This post announces two significant enhancements to Cloudflare's Data Loss Prevention (DLP) service: Optical Character Recognition (OCR) for extracting sensitive data from images and predefined source code detections for various programming languages. These features aim to provide more granular control and reduce risks of data breaches and non-compliance by enabling inline blocking of sensitive information in both image and code formats, and integrating with existing DLP policies for data in transit and at rest.

Reflecting on the GDPR to celebrate Privacy Day 2024

1/26/2024

This post critically examines the application of GDPR, arguing that its focus on data localization as a proxy for privacy is detrimental to actual data protection and cybersecurity. It highlights how strict cross-border data transfer rules can hinder global threat intelligence and bot management. The post also challenges the broad interpretation of IP addresses as always constituting personal data, suggesting that this can lead to internet balkanization and that context (i.e., the ability to re-identify an individual) should be a key factor in this determination. It references legal cases like Schrems II and Breyer v. Bundesrepublik Deutschland, and the ongoing SRB v EDPS case, to support its arguments.

2023

Have your data and hide it too: an introduction to differential privacy

12/22/2023

This post introduces differential privacy (DP) as a crucial enhancement to private aggregation protocols like DAP. It explains how DP adds noise to aggregates to prevent attackers from inferring individual data points, addressing the limitations of multi-party computation alone. The post highlights the risks of deanonymization attacks on census data and LLMs, and demonstrates how DP can protect against these by providing a rigorous mathematical framework for privacy guarantees, complementing existing privacy-preserving measurement efforts.

Privacy-preserving measurement and machine learning

9/29/2023

This post introduces Cloudflare's active participation in the IETF Privacy Preserving Measurement working group and their implementation of the Distributed Aggregation Protocol (DAP). It details the principles behind DAP, including data minimization and the use of secret sharing and multi-party computation (MPC) to aggregate data without revealing individual measurements. The post also discusses challenges like input validation, addressed by zero-knowledge proofs (ZKPs), and the potential for non-linear aggregation, highlighting Cloudflare's commitment to privacy-preserving data collection and machine learning.

Cloudflare One for Data Protection

9/7/2023

Announced Cloudflare One for Data Protection, a unified suite combining DLP, CASB, ZTNA, SWG, RBI, and cloud email security services. This suite is architected to address modern data risks, including those posed by AI tools and source code exposure. The post highlights three common customer use cases: securing AI tools and developer code, gaining visibility into data exposure, and ensuring compliance with regulations like GDPR, CCPA, HIPAA, and GLBA. It emphasizes how Cloudflare One simplifies management, improves effectiveness, enhances productivity, and increases organizational agility in data protection.

What’s next for Cloudflare One’s data protection suite

9/7/2023

This post details the evolution of Cloudflare's data protection suite, focusing on Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) capabilities. It highlights enhancements made over the past year, including improved DLP customization (MIP labels, custom profiles, match count controls), deeper detections (context analysis, file type control, expanded predefined profiles), and more detailed logging. CASB enhancements include expanded API integrations (18 SaaS apps) and improved findings management. A key development is the convergence of CASB and DLP, enabling scanning of SaaS apps for sensitive data. Upcoming features include Exact Data Match with custom wordlists, predefined profiles for source code and health data, and API-driven CASB & DLP for data-at-rest protections in Microsoft 365 and GitHub.

DLP Exact Data Match beta now available

7/13/2023

This post introduces Exact Data Match (EDM) as a new capability within Cloudflare's Data Loss Prevention (DLP) suite. EDM allows customers to securely upload lists of specific sensitive data (e.g., customer credit card numbers) which are then hashed before reaching Cloudflare. This enables highly targeted DLP detections, significantly reducing false positives compared to generic pattern matching, and enhances data privacy by ensuring cleartext data never leaves the customer's browser.

Consent management made easy and clear with Cloudflare Zaraz

4/18/2023

Introduced Cloudflare Zaraz Consent Manager, a feature that simplifies gathering and managing user consent for third-party tools. It provides an opt-in consent modal, customizability to match brand identity, and automatically re-emits pageview events for scripts once consent is granted, preventing data loss. The feature aims to ensure compliance with privacy regulations like GDPR and ePrivacy Directive.

Helping protect personal information in the cloud, all across the world

3/30/2023

This post announces Cloudflare's achievement of the EU Cloud Code of Conduct compliance mark, demonstrating GDPR compliance for 47 cloud services. It details the significance of the EU Cloud CoC as an official GDPR code of conduct, its coverage of data protection policies and security measures, and how it assists customers with Data Protection Impact Assessments and encryption capabilities. The post also highlights other privacy certifications like ISO 27001, 27018, and 27701, and mentions ongoing interest in the Global Cross Border Privacy Rules (CBPR) certification.

One-click ISO 27001 certified deployment of Regional Services in the EU

3/18/2023

Introduced a new region for Regional Services that is ISO 27001 certified within the EU, ensuring that traffic is only decrypted and processed in data centers meeting this security standard. Also launched a new UI for the Data Localization Suite that allows per-hostname region configuration and self-serve log flow management for metadata boundaries.

Cloudflare One DLP integrates with Microsoft Information Protection labels

3/14/2023

This post announces the integration of Cloudflare One Data Loss Prevention (DLP) with Microsoft Purview Information Protection labels. This integration allows organizations to leverage their existing Microsoft sensitivity labels within Cloudflare's platform to detect and control the movement of sensitive data across their corporate traffic, extending Microsoft's data classification capabilities beyond its native environment.

Inside Geo Key Manager v2: re-imagining access control for distributed systems

1/27/2023

Introduced Geo Key Manager v2 (GeoV2), a significant upgrade to the previous system, by replacing its identity-based broadcast encryption and revocation with Attribute-Based Encryption (ABE). This change addresses inflexibility in access control policies, enabling richer data localization and quicker restriction of access to sensitive key material. GeoV2 also resolves performance issues and manual key rotation challenges faced by GeoV1. The post details the architectural challenges of managing private keys in a distributed system and explains how ABE provides a more scalable and flexible solution, avoiding single points of failure. Cloudflare has open-sourced its ABE implementation in CIRCL.

Navigating the changing data localization landscape with Cloudflare’s Data Localization Suite

1/26/2023

This post details updates and usability improvements for Cloudflare's Data Localization Suite (DLS). It introduces dedicated UIs and APIs for enabling Regional Services on a per-hostname basis and self-service API for the Customer Metadata Boundary. It also announces expanded regional support for Geo Key Manager and Regional Services, and outlines future plans for broader regional support and integration with Zero Trust products.

Investing in security to protect data privacy

1/25/2023

This post emphasizes the critical role of robust security measures, including WAF, DDoS protection, and encryption in transit, in protecting personal data, arguing that effective security is paramount regardless of data location. It highlights how Cloudflare's global network and threat intelligence capabilities enable real-time protection against evolving cyber threats, minimizing the risk of data compromise.

Cloudflare's CASB integration with Salesforce and Box

1/12/2023

This post announces the expansion of Cloudflare CASB with new integrations for Salesforce and Box. It highlights how these integrations allow IT and security administrators to scan these critical SaaS applications for security risks like publicly shared files, default permissions, and unauthorized access, thereby enhancing data privacy and protection for business-critical information stored in these platforms.

How Cloudflare CASB and DLP work together to protect your data

1/11/2023

This post details the integration of Cloudflare's Cloud Access Security Broker (CASB) and Data Loss Prevention (DLP) capabilities. It highlights how CASB scans SaaS applications for misconfigurations and security issues, while DLP for data-in-transit prevents sensitive data from moving across the network. The key contribution is the announcement of upcoming SaaS DLP, which will scan data stored *within* SaaS applications (like PII, PCI, custom regex in documents, spreadsheets, PDFs) to provide comprehensive data protection coverage beyond network traffic.

Announcing Custom DLP profiles

1/10/2023

This post announces the general availability of custom Data Loss Prevention (DLP) profiles within Cloudflare One. Previously offering predefined detections for common identifiers, Cloudflare now allows customers to create their own detection rules using regular expressions to identify unique sensitive data like intellectual property or trade secrets. This enhances visibility and control over data, integrating seamlessly with Cloudflare Gateway's secure web gateway capabilities and expanding the DLP roadmap with features like data at rest scanning and Microsoft Sensitivity Label support.

2022

A new, configurable and scalable version of Geo Key Manager, now available in Closed Beta

12/15/2022

Introduced a new, configurable, and scalable version of Geo Key Manager available in Closed Beta. This version allows customers to define custom policies for private key storage based on country, region, or compliance standards (e.g., 'only store my private keys in India', 'only store my private keys in the European Union', 'only store my private keys in FIPS compliant data centers'). Key improvements include enhanced flexibility to mix and match rules (allowlist/blocklist), dynamic scalability to accommodate network expansion without manual intervention, and built-in redundancy restrictions to prevent customers from creating availability concerns. The post also highlights upcoming features like a UI, performance metrics, and extension to other certificate types.

Democratizing access to Zero Trust with Project Galileo

12/12/2022

This post announces the extension of Cloudflare's Zero Trust products to all organizations participating in Project Galileo, a program that provides cybersecurity to non-profits and civil society organizations. This initiative democratizes access to enterprise-level security, addressing the digital divide and the limitations of 'one-size-fits-all' security models. The post highlights how Project Galileo participants like the CyberPeace Institute, Information Technology Disaster Resource Center, Meedan, and the Organization of American States are leveraging Cloudflare Zero Trust to secure their operations, protect employees, and focus on their missions.

The Linux Kernel Key Retention Service and why you should use it in your next application

11/28/2022

This post introduces the Linux Kernel Key Retention Service as a novel approach to protecting cryptographic keys. It highlights how this service, by keeping keys within the kernel's address space, mitigates memory access violations and prevents leaks that can occur in user-space applications, even those written in memory-safe languages. This directly contributes to Cloudflare's data privacy and protection efforts by offering a more robust method for safeguarding sensitive cryptographic material.

Privacy Gateway: a privacy preserving proxy built on Internet standards

10/27/2022

This post introduces Privacy Gateway, a new service built on the Oblivious HTTP (OHTTP) standard and hybrid public-key cryptography. Privacy Gateway acts as a privacy-preserving proxy, encrypting HTTP requests and responses between clients and application servers. This ensures that Cloudflare does not see the content of requests, and application servers do not see the client's IP address or other network identifiers. The post details how Privacy Gateway provides 'request privacy' and 'client privacy,' its architecture, and integration steps for developers. It highlights use cases like privacy-respecting telemetry, healthcare applications, and DNS privacy (Oblivious DNS), positioning it as a specialized tool for sensitive applications.

Stronger than a promise: proving Oblivious HTTP privacy properties

10/27/2022

This post details the formal, computer-aided security analysis of Oblivious HTTP (OHTTP), a protocol designed to decouple 'who' from 'what' is sent by using end-to-end encrypted requests forwarded through a relay. It explains the protocol's design, its use of HPKE and Binary HTTP, and the simplified model used for analysis, demonstrating how OHTTP prevents linkability between clients and their requests/responses, thereby enhancing data privacy.

Private by design: building privacy-preserving products with Cloudflare's Privacy Edge

9/28/2022

This post introduces Privacy Edge, a suite of products designed to help developers build privacy into their applications. It details four components: Privacy Gateway (using Oblivious HTTP for IP-blinding relays), Code Auditability (verifying code integrity via hashing, exemplified by WhatsApp Web integration), Private Proxy (a platform for proxying traffic with privacy protocols, including token-based authentication and geolocated IP assignment), and Cooperative Analytics (a multi-party computation system based on the Distributed Aggregation Protocol for privacy-preserving analytics).

Regional Services comes to India, Japan and Australia

9/22/2022

This post announces the general availability of Regional Services in India, Japan, and Australia, expanding the Data Localization Suite's coverage. It details how Regional Services work by forwarding encrypted traffic to data centers within the customer-selected region for decryption and application of Layer 7 products, addressing the limitations of anycast networks in respecting regional borders. The post also highlights the growing global trend towards data localization and Cloudflare's commitment to supporting more regions in the future.

Launching In-Line Data Loss Prevention

6/20/2022

This post introduces Data Loss Prevention (DLP) as a native part of the Cloudflare One platform. It addresses customer challenges in understanding data flow, especially with the rise of SaaS tools, and explains how DLP integrates with Zero Trust architecture by identifying data based on keywords, patterns, and file types. The post details the implementation through DLP Profiles and HTTP policies within Cloudflare Gateway, leveraging Cloudflare's global network for scalable DLP solutions.

Cloudflare Zaraz launches new privacy features in response to French CNIL standards

6/15/2022

Cloudflare Zaraz has launched new privacy features to help organizations comply with GDPR and CNIL standards for third-party analytics tools. These features include: 1. Removing URL query parameters (e.g., UTM, gclid) to prevent fingerprinting. 2. Hiding originating IP addresses from third-party servers, configurable at a tool level or globally. 3. Clearing sensitive information from User Agent strings for server-side integrations. 4. Removing external referrers while preserving same-domain referrals for analytics accuracy. The post provides a step-by-step guide for configuring Google Analytics with these new features, emphasizing server-side loading via Cloudflare Workers and manual cleaning of Google Analytics configurations to avoid personal data collection.

Cloudflare achieves key cloud computing certifications — and there’s more to come

5/23/2022

This post announces Cloudflare's achievement of ISO/IEC 27018:2019 certification, completion of its C5 attestation, and its joining of the EU Cloud Code of Conduct General Assembly. It details the significance of ISO 27018 as a privacy extension to ISO 27001/27002, outlining its controls for protecting personal data processed in public clouds. The post also explains the C5 attestation's role in evaluating cloud security programs and the EU Cloud Code of Conduct's aim to demonstrate GDPR compliance for cloud service providers. It highlights Cloudflare's commitment to not using customer personal data for marketing or advertising, as reinforced in its Data Processing Addendum.

What Cloudflare is doing to keep the Open Internet flowing into Russia and keep attacks from getting out

4/3/2022

This post details Cloudflare's actions and observations regarding the internet in Russia following the invasion of Ukraine. It highlights the Russian government's efforts to control internet access and content, contrasting this with Russian citizens' adoption of tools like Cloudflare WARP to maintain access to the open internet and non-Russian news sources. The post also discusses Cloudflare's role in blocking cyberattacks originating from Russia and argues against complete service withdrawal, emphasizing the importance of keeping the Russian internet open for its citizens to access uncensored information.

Cloudflare and CrowdStrike partner to give CISOs secure control across devices, applications, and corporate networks

3/17/2022

This post details a new integration between Cloudflare's Zero Trust services (Access and Gateway) and CrowdStrike's endpoint security solutions. This partnership allows for real-time device posture assessments from CrowdStrike to be used as a condition for granting access to applications and networks via Cloudflare's Zero Trust platform. It also highlights Cloudflare's participation in the CrowdXDR Alliance for telemetry sharing and CrowdStrike's role as an incident response partner.

Announcing experimental DDR in 1.1.1.1

3/8/2022

This post introduces and explains the experimental support for Discovery of Designated Resolvers (DDR) in Cloudflare's 1.1.1.1 service. DDR is a new mechanism that allows clients to automatically discover and upgrade to secure DNS transports (DoH, DoT) from unencrypted UDP/TCP connections, thereby enhancing end-user privacy and driving more encrypted DNS usage on the internet. It details the threat model, the mechanics of DDR using certificate-based authentication and SVCB records, and provides instructions for testing.

iCloud Private Relay: What Cloudflare Customers Need to Know

3/2/2022

This post details Cloudflare's role as a 'second relay' in Apple's iCloud Private Relay service. It explains how Cloudflare's infrastructure and expertise in modern encryption protocols (TLS 1.3, QUIC, MASQUE) enable this privacy-enhancing feature. The post also provides guidance for website operators on handling Private Relay traffic, ensuring geolocation accuracy, maintaining performance, and adapting fraud/bot management systems to shared IP addresses, highlighting that Cloudflare customers require no action as their systems are already equipped to handle this traffic.

HPKE: Standardizing public-key encryption (finally!)

2/25/2022

This post introduces Hybrid Public Key Encryption (HPKE) as RFC 9180, a new standard for public-key encryption designed for simplicity, reusability, and future-proofing. It details the motivation, design goals (algorithm agility, authentication modes), and construction of HPKE, highlighting its use in emerging privacy-focused internet standards like Encrypted Client Hello and Oblivious DNS-over-HTTPS, and its implementation in Cloudflare's CIRCL library. This contributes to Cloudflare's broader efforts in privacy-enhancing technologies.

Deep dive into a post-quantum key encapsulation algorithm

2/22/2022

This post introduces the concept of Key Encapsulation Mechanisms (KEMs) and their importance in secure communication, particularly in the context of post-quantum cryptography. It explains the mathematical underpinnings of KEMs, focusing on the Learning With Errors (LWE) problem and its relation to lattices, and details the construction of FrodoKEM as an example. This contributes to the data privacy thread by addressing the future security landscape and the need for quantum-resistant encryption to maintain long-term data protection.

Deep dive into a post-quantum signature scheme

2/22/2022

This post introduces the concept of digital signatures and their importance in authentication, drawing parallels to real-world identity verification. It then dives deep into the technical details of post-quantum signature schemes, specifically CRYSTALS-Dilithium, explaining its mathematical underpinnings (Lattice-based cryptography, SIS problem) and algorithmic construction (identification schemes, Fiat-Shamir transformation). This contributes to the feature thread by detailing a critical cryptographic advancement necessary for future data privacy and protection in the face of quantum computing threats, extending the thread's scope to proactive security research.

Need to keep analytics data in the EU? Cloudflare Zaraz can offer a solution

2/3/2022

Introduces Cloudflare Zaraz as a solution to address GDPR compliance concerns related to third-party tool data transfers, specifically the Austrian Data Protection Authority's ruling on Google Analytics. Zaraz leverages Cloudflare Workers to load third-party tools in the cloud, not the browser, enabling features like IP address masking and Data Loss Prevention (DLP) scanning. It also integrates with Cloudflare's Data Localisation Suite (Regional Services and Customer Metadata Boundary) to provide data residency options for Zaraz services.

Happy Data Privacy Day!

1/28/2022

This post details Cloudflare's ongoing efforts in data privacy and protection, highlighting the development and deployment of privacy-enhancing technologies like Oblivious DNS over HTTPS (ODoH) and Oblivious HTTP (OHTTP). It introduces Selective Logging in Cloudflare Gateway, allowing administrators to control log collection for privacy. The post also discusses the company's response to the Log4j vulnerability with WAF rules and Zero Trust Access, and addresses the complexities of data localization, emphasizing Cloudflare's Data Localization Suite and its approach to GDPR compliance and Schrems II.

2021

Introducing the Customer Metadata Boundary

12/7/2021

Introduced the Customer Metadata Boundary, an extension of the Data Localisation Suite, to ensure end-user traffic metadata that identifies a customer remains within the EU. This is achieved by routing metadata-identifying log messages (containing the customer's Account ID) to EU core data centers and preventing their transfer outside the EU when the boundary is enabled.

Privacy-Preserving Compromised Credential Checking

10/14/2021

This post introduces MIGP (Might I Get Pwned), a new privacy-preserving compromised credential checking protocol. It details the motivation for such a protocol, the threat of data breaches and credential stuffing, and the limitations of existing services. The post explains the MIGP protocol's advancements, including its ability to check for similar passwords (not just exact matches) and its privacy-preserving properties (no password information leaked, minimal username information leaked). It also discusses breach extraction attacks and countermeasures. Finally, it announces the public demo and open-sourced Go implementation of MIGP, and its deployment within Cloudflare's infrastructure.

Exported Authenticators: The long road to RFC

10/13/2021

This post introduces Exported Authenticators (EAs) as a new extension to TLS, designed to enhance authentication possibilities. It explains how EAs provide application-layer authentication as strong as TLS peer authentication, allowing for features like multiple certificates or passwordless logins. The post details the design and standardization process of EAs within the IETF, highlighting their close adherence to TLS 1.3 design principles and the importance of channel binding for security. This contributes to the broader theme of data privacy and protection by advancing the security of internet communications.

Privacy Pass v3: the new privacy bits

10/12/2021

This post announces Privacy Pass v3.0, detailing significant improvements to the browser extension and the underlying protocol. Key contributions include refactoring the extension for better maintainability and modularity, enabling easier integration of future service providers. It also highlights progress on standardizing the Privacy Pass protocol at the IETF and introduces the concept of metadata in tokens to combat 'hoarding' or 'farming' attacks, proposing key rotation as a potential solution with its own limitations. The post emphasizes the ongoing effort to balance user privacy with bot mitigation.

Introducing Zero-Knowledge Proofs for Private Web Attestation with Cross/Multi-Vendor Hardware

8/12/2021

This post introduces the development and open-sourcing of a Zero-Knowledge Proof system for private web attestation. This innovation aims to enhance user privacy by allowing websites to verify the authenticity of hardware security keys without learning sensitive information like the manufacturer or model, thereby reducing the risk of user identification and moving beyond the limitations of existing WebAuthn attestation. It represents a significant step in Cloudflare's ongoing efforts to improve privacy across the internet.

Working with those who protect human rights around the world

7/29/2021

This post details Cloudflare's expansion of its commitment to data privacy and protection by actively supporting human rights defenders and democratic processes. It introduces 'Radar Alerts,' a new program built on Cloudflare's global network visibility, to help civil society partners track and document Internet shutdowns and protect democratic elections from cyberattacks. This initiative leverages existing infrastructure and partnerships to provide real-time insights into network anomalies that signal disruptions.

Certifying our Commitment to Your Right to Information Privacy

7/29/2021

This post details Cloudflare's certification to ISO/IEC 27701:2019, an international standard for managing personal data processing, demonstrating adherence to GDPR-aligned industry standards. It also highlights other security certifications like ISO 27001, SOC 2 Type II, and PCI DSS, and discusses privacy-enhancing technologies such as 1.1.1.1 DNS resolver, Web Analytics, Oblivious DoH, and Universal SSL.

Data Privacy Day 2021 - Looking ahead at the always on, always secure, always private Internet

1/28/2021

This post details Cloudflare's ongoing efforts and future plans related to data privacy and protection, particularly in response to evolving global regulations like GDPR, Schrems II, and the CCPA. It highlights the company's focus on international data transfers, the development of the Data Localization Suite (DLS) to address data localization challenges, and its commitment to privacy-enhancing technologies like Encrypted Client Hello (ECH), OPAQUE, and Oblivious DNS-over-HTTPS (ODoH). The post also outlines Cloudflare's policies regarding data privacy and law enforcement requests, emphasizing its commitment to customer data protection.

2020

Helping build the next generation of privacy-preserving protocols

12/8/2020

This post details Cloudflare's proactive efforts in developing and deploying new privacy-preserving protocols, including Encrypted Client Hello (ECH), Oblivious DNS-over-HTTPS (ODoH), and OPAQUE. It highlights the importance of protecting metadata, not just content, and positions these initiatives as a continuation of Cloudflare's long-standing commitment to building a more private and user-respecting internet, building upon previous work in Universal SSL, TLS 1.3, QUIC, and DNS security.

Improving DNS Privacy with Oblivious DoH in 1.1.1.1

12/8/2020

This post introduces and explains Oblivious DNS over HTTPS (ODoH), a new proposed DNS standard co-authored by Cloudflare engineers. ODoH enhances DNS privacy by separating IP addresses from queries, ensuring no single entity can see both simultaneously. It achieves this through public key encryption and a network proxy between clients and DoH servers, providing technical guarantees for privacy beyond policy-based trust. Cloudflare is launching support for ODoH in its 1.1.1.1 service with several launch partners.

Privacy needs to be built into the Internet

12/7/2020

This post introduces Phase 3 of the Internet, where privacy joins universal connectivity and security as a core tenet. It discusses the challenges posed by data localization requirements, particularly in light of GDPR and the invalidation of the Privacy Shield framework. The post announces new tools from Cloudflare that enable companies to situate users' data in specific countries and regions, and new protocols that build privacy into the Internet's structure. It also mentions updates on quantum-resistant algorithms, privacy-preserving DNS resolver services (like 1.1.1.1), secure password mechanisms, and web analytics without user tracking.

Introducing the Cloudflare Data Localization Suite

12/7/2020

Introduced the Cloudflare Data Localization Suite, an add-on for Enterprise customers, to provide granular control over where data is stored and protected at the edge. This suite includes features like Keyless SSL and Geo Key Manager for controlling TLS private key access locations, Regional Services for managing where HTTPS requests and responses are inspected, and Edge Log Delivery for sending logs directly from the edge to customer-chosen destinations. Additionally, Cloudflare Workers Durable Objects now support Jurisdiction Restrictions, allowing developers to ensure data is stored and processed only within specified jurisdictions.

Are you GDPR-compliant? New phishing message harvests credentials with GDPR lure

9/23/2020

This post details a specific phishing campaign that exploits misconceptions about GDPR compliance to harvest credentials. It highlights the technical methods used by attackers, including spoofing email headers and leveraging compromised websites, and underscores the importance of employee education and advanced security solutions to combat such threats. This contributes to the thread by demonstrating a real-world attack vector that targets users' understanding of data privacy regulations, and how Cloudflare (through Area 1 Security) is actively working to detect and prevent these sophisticated attacks.

UtahFS: Encrypted File Storage

6/9/2020

This post introduces UtahFS, a proof-of-concept for end-to-end encrypted file storage. It addresses the need for users to have complete control over their sensitive data, going beyond transport-layer and disk encryption. UtahFS implements features like encrypted directory structure, partial file access without full download/decrypt, and uses object storage, skip lists, Merkle Trees for integrity, and Path ORAM for hiding access patterns. This represents a significant advancement in providing users with granular control and privacy for their stored data.

The Mistake that Caused 1.1.1.3 to Block LGBTQIA+ Sites Today

4/2/2020

This post details a mistake in the initial rollout of '1.1.1.1 for Families', a filtered DNS service. An incorrect content categorization feed led to the inadvertent blocking of LGBTQIA+ sites. The post explains the licensing of categorization data, the intended narrow definition of 'Adult Content' mirroring Google SafeSearch, and the technical challenges in quickly updating data structures across the global network. It highlights the immediate actions taken to create an allow list for affected sites and the subsequent generation and deployment of the corrected data structure. The post also outlines future protections to prevent similar errors.

Announcing the Beta for WARP for macOS and Windows

4/1/2020

This post announces the beta release of WARP for macOS and Windows, extending the privacy and security features of the 1.1.1.1 app to desktop operating systems. It highlights the use of the Wireguard protocol for fast and secure connections, the free basic service, and plans for WARP+ support and eventual Linux client availability. This marks a significant expansion of Cloudflare's user-facing privacy tools beyond mobile devices.

Introducing 1.1.1.1 for Families

4/1/2020

This post introduces '1.1.1.1 for Families,' a new offering built upon the existing 1.1.1.1 DNS resolver. It addresses user requests for content filtering by providing two options: one that blocks malware and another that blocks both malware and adult content. This expands the privacy-focused DNS service to include parental controls and enhanced security for home networks, leveraging Cloudflare's site categorization and filtering technology.

Announcing the Results of the 1.1.1.1 Public DNS Resolver Privacy Examination

3/31/2020

This post announces the results of an independent examination of the 1.1.1.1 public DNS resolver's privacy commitments. It details the examination process, including technical measures like IP truncation and limited data retention, and addresses some initial ambiguities in communication regarding log retention. The post also clarifies and refines the specific privacy commitments for the 1.1.1.1 resolver, emphasizing that personal data will not be sold or shared, source IPs will not be retained in non-volatile storage (except for a small, sampled subset for network troubleshooting), and transaction logs will be deleted within 25 hours. It highlights the importance of proving privacy commitments and encourages other organizations to do the same.

Empowering Your Privacy

1/28/2020

This post, published on Data Privacy Day, articulates Cloudflare's comprehensive approach to data privacy. It details specific privacy-enhancing technologies developed and supported by Cloudflare, including Universal SSL, Privacy Pass, ESNI, 1.1.1.1 Public DNS Resolver, DNS over HTTPS (DoH), and the 1.1.1.1 Mobile Application with WARP. It also outlines Cloudflare's internal practices, such as employee education, privacy-by-design in product development, internal compliance with regulations like GDPR and CCPA, and a security-focused approach to privacy. The post emphasizes empowering individuals and entities to reduce personal data collection and use, regardless of their location or specific privacy priorities.

2019

Supporting the latest version of the Privacy Pass Protocol

10/28/2019

This post details the evolution of the Privacy Pass protocol, a privacy-preserving technology developed in collaboration with the academic community. It announces support for Privacy Pass v2.0 with an updated browser extension, improved cryptographic functionality (including hash-to-curve methods and key rotation), and new integrations like hCaptcha. The post also highlights the rollout of a new server backend using Cloudflare Workers and ongoing standardization efforts for Oblivious Pseudorandom Functions (OPRFs) and the Privacy Pass protocol itself.

2018

Verschlüsselung von SNI: Wie einer der großen Internet-Bugs behoben wurde

9/24/2018

This post introduces and announces the launch of Encrypted SNI (ESNI) across Cloudflare's network, a significant advancement in internet privacy. It explains the vulnerability of the previously unencrypted SNI field, which revealed visited websites to ISPs and eavesdroppers, and details how ESNI encrypts this information. The post highlights Cloudflare's collaboration with industry partners like Mozilla, Apple, and Fastly in developing and standardizing ESNI, positioning it as a new trend to make the encrypted web even more private and secure.

Roughtime: Securing Time with Digital Signatures

9/21/2018

This post introduces Roughtime, a free, high-availability, low-latency authenticated time service. It addresses the critical issue of clock skew in clients, which can lead to TLS certificate errors and security vulnerabilities. Roughtime uses digital signatures to ensure the accuracy and authenticity of time, making it a valuable tool for securing cryptographic operations like TLS certificate validation. Cloudflare's deployment of Roughtime serves to hold themselves accountable for the validity of TLS artifacts and to promote the growth of the Roughtime ecosystem by encouraging independent participation.

Enable Private DNS with 1.1.1.1 on Android 9 Pie

8/16/2018

This post details the integration of Cloudflare's 1.1.1.1 DNS service with Android 9 Pie's new Private DNS mode, enabling DNS over TLS (DoT) for encrypted DNS queries. It explains the benefits of DoT for user privacy, the configuration steps, and discusses the broader context of internet privacy, including the role of TLS, DNSSEC, and the ongoing effort to encrypt SNI. The post also touches upon the complexities of DNS in an IPv6 world and Cloudflare's efforts to support dual-stack environments.

Introducing DNS Resolver for Tor

6/5/2018

This post introduces a Tor onion service for Cloudflare's 1.1.1.1 DNS resolver, offering an even higher level of anonymity by preventing the resolver from seeing the client's IP address and obscuring DNS requests from the ISP. It also details the technical implementation of Tor onion services and the security considerations for using such a service, including the use of certificates and Alt-Svc headers for discoverability and trust.