Is Cloudflare Compliant with EU Digital Sovereignty? (2026 Audit)
Last reviewed: 6 February 2026
Sovereignty Verdict
Tool
Cloudflare
Sovereignty Score
Risk Level
Cloudflare is US-incorporated and as a reverse proxy has access to decrypted traffic content; this uniquely sensitive position creates high sovereignty risk under CLOUD Act.
Cloudflare operates critical internet infrastructure for millions of websites and applications, providing CDN, DDoS protection, DNS, and increasingly compute (Workers) and storage (R2) services. Its position as an infrastructure intermediary means Cloudflare sees all traffic passing through its network—a uniquely sensitive sovereignty position.
This audit examines Cloudflare through a European sovereignty lens. The assessment is indicative and continuously reviewed.
Cloudflare's role is distinctive: as a reverse proxy and security layer, it has visibility into all traffic content, making its jurisdiction and data handling particularly consequential for sovereignty assessment.
Data Residency & Control
Cloudflare processes traffic through its global network of data centres.
**Data Localisation Suite**: Cloudflare offers a Data Localisation Suite (Enterprise) that allows customers to control where traffic is inspected and where encryption keys are stored. Regional Services can restrict processing to EU data centres.
**Keyless SSL**: Cloudflare's Keyless SSL allows organisations to keep SSL/TLS private keys on their own infrastructure while using Cloudflare's network. This prevents Cloudflare from having direct access to decrypt traffic.
**Traffic visibility**: As a reverse proxy, Cloudflare can inspect all HTTP/HTTPS traffic passing through its network (when using standard SSL). This includes request bodies, API payloads, authentication tokens, and user data in transit.
**Workers and R2**: Cloudflare Workers (compute) and R2 (storage) can be configured for specific regions. Workers deployed on EU-only jurisdictions limit compute processing to EU data centres.
**Metadata**: Cloudflare collects extensive metadata about traffic patterns, request origins, and security events. This metadata is processed globally.
Jurisdictional Exposure
Cloudflare, Inc. is incorporated in the United States (Delaware), headquartered in San Francisco.
**CLOUD Act**: Cloudflare can be compelled to produce data in its possession, including traffic logs, cached content, DNS query logs, and potentially decrypted traffic content. Cloudflare's unique position as infrastructure intermediary means it has access to data flowing between users and applications.
**Transparency**: Cloudflare publishes detailed transparency reports and has publicly refused to comply with certain controversial takedown requests. Their transparency positioning is among the strongest of US technology companies.
**Canary and legal stance**: Cloudflare maintains warrant canaries and has publicly discussed their approach to government requests. Their stated policy is to challenge overbroad requests and not voluntarily provide data.
**GDPR**: Cloudflare provides a DPA and has achieved ISO 27001 and SOC 2 certifications. Their GDPR compliance is generally well-regarded in the industry.
GDPR, NIS2, DORA Relevance
**GDPR**: Cloudflare processes personal data through traffic (IP addresses, request content) and analytics. The Data Localisation Suite addresses some data residency concerns for Enterprise customers.
**NIS2**: As critical internet infrastructure, Cloudflare's own security posture is relevant for organisations relying on it for DDoS protection and availability. Dependency on a single security provider creates concentration risk.
**DORA**: Financial entities should evaluate Cloudflare as a critical ICT infrastructure dependency. Its role in availability and security makes it a significant third-party risk.
**Infrastructure criticality**: Cloudflare's position is unique—it's not just a SaaS tool but a layer of internet infrastructure. Its compromise or unavailability would cascade across all dependent services.
Operational Lock-in & Exit Risk
**Vendor lock-in**: Low to moderate for basic CDN/security. Higher for organisations using Workers, R2, D1 (database), and other platform services. DNS migration is straightforward; compute platform migration requires more effort.
**Switching ease**: CDN and DDoS protection migration is relatively straightforward. DNS changes propagate quickly. Workers applications require rewriting for alternative platforms.
**Auditability**: Enterprise plans offer comprehensive logging, analytics, and audit capabilities. Cloudflare Logs (formerly Logpush) enables real-time log export.
**Switching costs**: Low for basic CDN. Moderate for advanced security configurations. High for Workers-based applications.
European Alternatives
European CDN and security infrastructure alternatives:
**Bunny.net** (Slovenia): EU-headquartered CDN with global network. Competitive pricing and clean API. Offers edge compute (Bunny Edge Scripting). Trade-off: smaller network, fewer security features. Migration feasibility: easy.
**KeyCDN** (Switzerland): Swiss CDN provider with strong privacy positioning. Trade-off: CDN-focused, limited security features. Migration feasibility: easy.
**Myra Security** (Germany): German security CDN with DDoS protection, WAF, and CDN. Strong compliance positioning for German and EU markets. Trade-off: smaller global network. Migration feasibility: moderate.
**OVHcloud CDN** (France): CDN offering from European cloud provider. Trade-off: less specialised than dedicated CDN providers. Migration feasibility: easy.
**Self-hosted solutions**: Nginx/HAProxy with Fail2ban or ModSecurity for security. Full sovereignty. Trade-off: significant operational overhead, no managed DDoS protection. Migration feasibility: hard.
Bunny.net is the most capable EU-headquartered CDN alternative for general use.
Who This Matters For
**Fractional CTOs and technical advisors**: Cloudflare's infrastructure position means it sees all traffic. This should be explicitly assessed in sovereignty reviews, particularly for organisations handling sensitive data in transit.
**Engineering leaders**: Teams using Cloudflare Workers should assess platform lock-in separately from basic CDN usage. Keyless SSL and Data Localisation Suite offer meaningful sovereignty controls for Enterprise customers.
**Procurement and due diligence**: Cloudflare's role as security infrastructure makes it a critical vendor. Enterprise Data Localisation Suite should be evaluated for organisations with sovereignty requirements.
Key Takeaways for Technical Leaders
- •Cloudflare scores 35/100—its infrastructure position gives it unique visibility into all traffic, but strong transparency practices partially offset risk
- •Data Localisation Suite (Enterprise) and Keyless SSL provide meaningful technical sovereignty controls
- •As a reverse proxy, Cloudflare has access to decrypted traffic content—a uniquely sensitive position
- •Bunny.net (Slovenia) is the most capable EU-headquartered CDN alternative
- •Organisations should evaluate Cloudflare Workers lock-in separately from basic CDN/security services
Sovereignty Report Available
Quick-reference report with FAQ, topic cluster links, and structured data.
Migration Blueprints
Considering a move? See Migration Blueprints
Audit your technology stack
This analysis covers one tool. Your Technology Stack Audit scores your entire technology stack as one system and gives you a prioritised, fix-first roadmap. One-off €99.
Audit my technology stack — €99