CDN, DDoS protection, DNS, and edge compute platform sitting in front of a large fraction of the internet.
Cloudflare publishes several compliance and legal pages that change over time. Under GDPR Article 28, data controllers using Cloudflare as a processor must continuously verify that "sufficient guarantees" remain in place โ which means tracking changes to these pages as they happen. Below are the 4 most relevant pages, what typically changes on each, and ready-to-paste monitoring prompts.
Choose the pages that matter most and get an alert when something meaningful changes. The free plan covers 3 monitors.
Start with 3 free monitors โhttps://www.cloudflare.com/gdpr/subprocessors/ โ
Typical change frequency: quarterly
Alert me when Cloudflare adds or changes sub-processors. Report the name, product area, and processing purpose. Ignore formatting changes.
https://www.cloudflare.com/cloudflare-customer-dpa/ โ
Typical change frequency: yearly
Monitor the Cloudflare DPA for changes to log processing, transfer mechanisms, or entity lists. Ignore version numbers.
https://www.cloudflare.com/privacypolicy/ โ
Typical change frequency: yearly
Alert me when Cloudflare changes log retention, traffic data collection, 1.1.1.1 DNS data handling, or introduces AI training from customer data. Ignore editorial changes.
https://www.cloudflarestatus.com/ โ
Typical change frequency: weekly
Alert me on Cloudflare incidents affecting global routing, Zero Trust, DNS, or any incident mentioning customer data. Ignore minor regional issues.
Hosting locations: Global edge network, 310+ cities
EU-US Data Privacy Framework: Certified
Ready to start monitoring Cloudflare?
Set up monitoring free โ