Cloudflare

Companies & groups · US

Kategorija
Companies & groups
Būstinė
San Francisco US
Registruota
2017-01-16
Deklaruotos metinės išlaidos
50 000–99 999 € (pačios deklaruota)
Svetainė
http://www.cloudflare.com
Skaidrumo registras
580322225469-90 ↗
Susitikimai su EK
Pateiktos pozicijos
Pozicijos dokumentai
Paminėjimai spaudoje
Sumą deklaruoja pati organizacija Skaidrumo registre; institucijos jos netikrina.

Susitikimai pagal metus

2020420211202322025520262

Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 14 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.

Susitikimai su Europos Komisija

Skelbiami tik susitikimai su Komisijos nariais, jų kabinetais ir generaliniais direktoriais. Susitikimai žemesniu lygiu ir daugelis kontaktų Parlamente bei Taryboje į registrą nepatenka.
DataPriėmėTema
2026-05-28Communications Networks, Content and TechnologyGlasswing project
2026-04-23Communications Networks, Content and TechnologyExchange of views on the fight against online piracy
2025-04-30Communications Networks, Content and TechnologyCybersecurity
2025-03-18Cabinet of Commissioner Michael McGrathForthcoming Digital Fairness Act, protection of minors, data protection, simplification
2025-03-11Cabinet of Commissioner Maroš ŠefčovičGlobal trade developments
2025-03-11Cabinet of Commissioner Maroš ŠefčovičGlobal trade developments
2025-01-23Cabinet of Executive Vice-President Henna VirkkunenEU tech agenda
2023-10-10Cabinet of Vice-President Věra JourováConnectivity, cyber-security, DSA, DMA
2023-10-10Cabinet of Vice-President Věra JourováConnectivity, cyber-security, DSA, DMA
2021-03-29Cabinet of Commissioner Thierry BretonDSA
2020-12-02Cabinet of Commissioner Thierry BretonRoundtable with platforms on DSA and DMA
2020-12-02Cabinet of Commissioner Thierry BretonRoundtable with platforms on DSA and DMA
2020-12-02Cabinet of Commissioner Thierry BretonRoundtable with platforms on DSA and DMA
2020-02-11Cabinet of Executive Vice-President Margrethe VestagerDigital services act

Ką pateikė viešoms konsultacijoms

2024-02-08 · Report on the application of the General Data Protection Regulation ↗ originalus šaltinis
Cloudflare welcomes the opportunity to contribute to the European Commissions call for evidence on the application of the General Data Protection Regulation (GDPR). Please find our detailed comments attached.

Ką rašo savo pozicijos dokumentuose

Ištraukos iš organizacijos pačios įkeltų dokumentų, be trumpinimų ir perpasakojimų.
Report on the application of the General Data Protection Regulation · 3 p.

Response to the European Commission’s call for evidence on the application of the General Data Protection Regulation Cloudflare welcomes the opportunity to contribute to the European Commission’s call for evidence on the application of the General Data Protection Regulation (GDPR), based on our practical experience both as a controller and a processor of personal data since the GDPR became applicable six years ago. Introduction and background on Cloudflare Cloudflare is an Internet performance and security company that is on a mission to help build a better Internet. Our global network of over 310 Points of Presence (PoPs) in over 120 countries serves an average of 50 million HTTP requests per second.1 In the EU alone, we have 40+ PoPs in 25 Member States. Our current suite of services includes, among others, application services (e.g.

…we have 40+ PoPs in 25 Member States. Our current suite of services includes, among others, application services (e.g. DDoS protection, bot management) and Secure Access Service Edge (“SASE”) products, which offer our customers’ employees the ability to authenticate and securely connect to internal resources from anywhere, and provide better control over and visibility into the users, traffic, and data accessing a large network — vital capabilities for modern, globally distributed organizations. On balance, the GDPR has definitely moved the needle in the right direction for giving people more control over their personal data and in protecting their privacy. In a couple of key areas, however, we believe the way the GDPR has been applied to data flowing across the Internet has not helped and in fact may even jeopardize the protection of personal data.

…to data flowing across the Internet has not helped and in fact may even jeopardize the protection of personal data. The first area where we see this is with respect to cross-border data transfers. Location has become a proxy for privacy in the minds of many EU data protection regulators, and we think that is the wrong result. The second area is an overly broad interpretation of what constitutes “personal data” by some regulators with respect to Internet Protocol or “IP” addresses. We contend that IP addresses should not always be considered personal data, especially when the entities handling IP addresses have no ability on their own to tie those IP addresses to individuals. This is important because the ability to implement a number of industry-leading cybersecurity measures relies on the ability to gain threat intelligence from Internet traffic metadata, including IP addresses.

…measures relies on the ability to gain threat intelligence from Internet traffic metadata, including IP addresses. We provide further explanation of these two areas of concern below. 1 https://www.cloudflare.com/network/ Ref. Ares(2024)975379 - 08/02/2024 Location should not be a proxy for privacy After the “Schrems II” decision in 2020 by the Court of Justice of the European Union (CJEU),2 which invalidated the EU-US Privacy Shield, we saw many EU Data Protection Authorities (DPAs) double down on their view that European personal data simply could not be processed in the United States in a way that would be consistent with the GDPR. The EU’s recent approval of the EU-US Data Privacy Framework re-established adequacy for US entities that certify to the framework, so these cross-border data transfers are not currently an issue.

…for US entities that certify to the framework, so these cross-border data transfers are not currently an issue. But if the Data Privacy Framework were to be invalidated again, which is a possible scenario, then we could again find ourselves in a place where the GDPR is applied to mean that EU residents’ personal data cannot be processed in the US, therefore promoting what we believe is a misconception that data localization should be a proxy for data protection. In fact, the opposite is the case: our experience and recent research3 have shown that GDPR-induced data localization threatens an organization’s ability to achieve integrated management of cybersecurity risk and limits an entity’s ability to employ state-of-the-art cybersecurity measures that rely on cross-border data transfers to make them as effective as possible.

…state-of-the-art cybersecurity measures that rely on cross-border data transfers to make them as effective as possible. This directly clashes with the obligation Article 32 GDPR places on data controllers and processors to “develop appropriate technical and organizational measures to ensure a level of security appropriate to the risk”, “taking into account the state of the art”.

…measures to ensure a level of security appropriate to the risk”, “taking into account the state of the art”. In addition, data localization undermines information sharing within industry and with government agencies for cybersecurity purposes, which is generally recognized as vital to effective cybersecurity.4 Applying data transfer rules to IP addresses makes it harder to effectively protect personal data and could lead to fragmentation of the Internet One particularly problematic application of GDPR in this context is the treatment of IP addresses as personal data, making them subject to data transfer restrictions under the GDPR. As the Internet is a global network, Internet traffic – which necessarily contains IP addresses – will often cross national borders.

…is a global network, Internet traffic – which necessarily contains IP addresses – will often cross national borders. IP addresses are also part of important metadata used for cybersecurity purposes: advanced machine learning/predictive AI techniques that look at IP addresses to protect against DDoS attacks, prevent risks from malicious bots, or otherwise guard against personal data breaches, will draw on attack patterns and threat intelligence from around the world to the benefit of EU entities and residents. If the Data Privacy Framework were to be invalidated as the EU-US Privacy Shield was in the Schrems II decision, then we could find ourselves in a place where the GDPR is applied to mean that IP addresses ostensibly linked to EU residents cannot be processed in the US, or potentially not even leave the EU.

IP addresses ostensibly linked to EU residents cannot be processed in the US, or potentially not even leave the EU. If this were the case, then providers would have to start developing Europe-only networks to ensure IP addresses never cross jurisdictional boundaries. 4 https://www.enisa.europa.eu/topics/national-cyber-security-strategies/information-sharing 3 Swire, Peter and Kennedy-Mayo, DeBrae and Bagley, Andrew and Modak, Avani and Krasser, Sven and Bausewein, Christoph, Risks to Cybersecurity from Data Localization, Organized by Techniques, Tactics, and Procedures (2023). 2 Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems. 2 A world where IP addresses are always treated as personal data and subject to the GDPR’s data transfer rules could therefore come perilously close to requiring a walled-off European Internet.

…to the GDPR’s data transfer rules could therefore come perilously close to requiring a walled-off European Internet. This would not only seriously hamper the deployment of a number of critical cybersecurity measures necessary for keeping personal data safe and private, it likely would cut the EU off from any number of global marketplaces, information exchanges, and social media platforms. A possible solution would be to consider that IP addresses are not always “personal data” subject to the GDPR. In 2016 – even before the GDPR took effect – the CJEU established the view in Breyer v. Bundesrepublik Deutschland5 that dynamic IP addresses constituted personal data only if the processing entity could link them to an individual.

…that dynamic IP addresses constituted personal data only if the processing entity could link them to an individual. Unfortunately, many EU DPAs applied the decision as if dynamic IP addresses were always personal data under the GDPR, without considering whether an entity actually has a way to tie the IP address to a real person.6 Keeping privacy in focus As demonstrated above, a misguided application of the GDPR that places privacy protections above all other considerations – even appropriate security measures – can actually cause unintended harm to data protection. If taken too far, this approach would not only negatively impact cybersecurity and data protection, but could even put into question the functioning of the global Internet infrastructure as a whole, which depends on cross-border data flows.

…question the functioning of the global Internet infrastructure as a whole, which depends on cross-border data flows. In order to prevent this, without necessarily having to re-open the GDPR again at this moment, we would like to propose the following: First, the Commission could encourage the EDPB to adopt guidelines for DPAs, clarifying that IP addresses should not be considered personal data when they cannot be linked by an entity to a real person. This would follow the relative approach adopted by the CJEU in the Breyer case, as described above. The pending CJEU decision in SRB v EDPS7 could provide some further helpful clarification in this regard. Second, the European Commission and the EDPB should clarify that the GDPR’s application should be considered with the cybersecurity benefits of data processing in mind.

14 → 12

originalus šaltinis (PDF) ↗

Kokias ES temas nurodo sekanti

On a European level, Cloudflare follows issues related to the Digital Single Market, with particular interest in policy areas related to data protection, cybersecurity, connectivity, AI, online content / intermediary liability and internet governance.

Paminėjimai spaudoje

Straipsniai, kuriuose organizacijos pavadinimas paminėtas pažodžiui IR kurie liečia teisę ar reguliavimą. Vien paminėjimas nereiškia, kad straipsnis yra apie lobizmą.
2026-08-05 · Tivubiz · IT
A seguito della notifica, il Ceo di Cloudflare, Matthew Prince, aveva accusato Agcom di censura minacciando l’intero Paese Italia di interrompere i propri servizi. Successivamente, la protesta si era…