• Latest
  • Trending
Can a fine for a data protection breach be levied against a corporation?

Can Cloudflare be used permissibly?

7. November 2022
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Can Cloudflare be used permissibly?

7. November 2022
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
security 2168233 1280

The issue of whether US SaaS providers can be used permissibly or whether products such as Jira, Zendesk, various CRM systems and others do not violate data protection law has actually been clear since the ECJ’s Schrems II decision(see here).

Key Facts
  • The Schrems II decision against US SaaS providers is crucial for data protection in Germany.
  • Cloudflare could violate the GDPR if users' personal data is affected.
  • Cologne Higher Regional Court found that Cloudflare is liable for copyright infringements when using temporary DDoS.
  • Data encryption is a key point that Cloudflare mentions in its privacy policy.
  • Zendesk offers extensive encryption standards such as HTTPS/TLS for secure working.
  • It is currently not possible to select the storage location of the data with Cloudflare.
  • The use of Cloudflare should be carefully checked by data protection officers.

As things stand, you can find out how to offer SaaS system as a US provider in Germany in a longer article here.

By the way, this issue affects many popular WordPress plugins and services like Cloudflare. In the case of Cloudflare, it is especially true that the OLG Cologne has just ruled that the provider would be liable for copyright infringement(see this post). Because Cloudflare, at least if you use more than just the services to possibly prevent DDoS attacks, stores the content itself on their servers to provide caching and CDN services. What is not very problematic for a normal website that ONLY provides content, such as a blog or similar (apart from the copyright infringements relevant in the OLG Cologne case), is no longer so unproblematic for dynamic content and personal user data. This would affect, for example, forums, communities, and sites that you can log into. Although a CDN does not log user data as such, it does log the personal data that is entered when using the portal. At least, if the provider does not configure CDN usage properly and excludes dynamic user content.

In all places where Cloudflare’s caching or CND services are used, the storage on whichever Cloudflare servers is used is not only for the transmission of the requested information. However, due to the missing Privacy Shield requirements, this probably leads to the fact that a GDPR-compliant use of Cloudflare is not possible, at least if, as explained above, personal data of the users are affected. This is because a contract processing agreement is out of the question. And as pointed out in my article on offering SaaS services, the strict view is that corporate binding rules or standard contractual clauses are probably not possible either.

It might be possible to fully encrypt all data, as Amazon is apparently currently doing with AWS in the European data centers, but I couldn’t find anything about this at Cloudflare at the moment. The link to the privacy policy there does not work. A closer look reveals an English-language privacy statement that explains that the Privacy Shield is no longer used, but is very vague about the alternatives.

Thus, the only point to the encryption

10. DATA SECURITY, DATA INTEGRITY AND ACCESS

We take all reasonable steps to protect information we receive from you from loss, misuse or unauthorized access, disclosure, alteration and/or destruction. We have put in place appropriate physical, technical and administrative measures to safeguard and secure your information, and we make use of privacy-enhancing technologies such as encryption. If you have any questions about the security of your personal information, you can contact us at privacyquestions@cloudflare.com.

It may be doubted whether this is sufficient for an official data protection officer to scrutinize particularly strictly. Providers such as Zendesk are already much further ahead in this respect from their own testing for clients and regulate, for example:

Data-in-Transit encryption

All communications with Zendesk’s user interfaces and APIs are encrypted using industry-standard HTTPS/TLS (TLS 1.2 or higher) over public networks. This ensures that all traffic between you and Zendesk is secure. For email, we use opportunistic TLS by default. Transport Layer Security (TLS) is a protocol for secure encryption and delivery of email that prevents eavesdropping between mail servers as long as peer services support this protocol. Exceptions to encryption include, but are not limited to, use of product-integrated SMS features and third-party applications, integrations, or services that Subscribers use at their discretion.

 

Data-at-Rest Encryption

Service data is encrypted on AWS using data-at-rest encryption (AES-256).

 

There is also the problem that, as far as I know at the moment, Cloudflare, unlike AWS etc., does not allow you to choose where the data is stored. While a website operator would have to provide this information, he will probably not receive an answer from Cloudflare.

Conclusion: The use of Cloudflare should be well thought through by your own data protection officer.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AmazonBlogCopyright infringementCorporateData protection LawE‑mailInformationMailPortalPrivacySaasServerserviceSicherheitStandard contractual clausesUrheberrecht

Weitere spannende Blogposts

The Legal Questions Bot on ITMediaLaw.com: Now even smarter and more helpful!

Key Considerations When Offering an AI-Based Chatbot
15. September 2023

What's new? Content Awareness The bot already has a content awareness feature that allows it to understand the context of...

Read moreDetails

Blockchain and AI in law – new territory or proven terrain?

blockchain und ki im recht neuland oder bewaehrtes terrain
9. November 2023

Introduction: Discourses at the interface of technology and law Last week, there was an exciting discussion with a doctoral student...

Read moreDetails

OLG Hamm and e-mail

OLG Hamm and e-mail
10. July 2024

OLG Hamm: Proof of e-mail access remains a challenge In a recent ruling (case no. 26 W 13/23 dated 10.08.2023),...

Read moreDetails

Flying jurisdiction for Youtube not at the end?

youtube 3503481 960 720
7. November 2022

The Düsseldorf Regional Court has ruled in a preliminary injunction proceeding that the UWG amendment of December 2020 did not...

Read moreDetails

CEO, Managing Director, President…watch out for job titles

CEO, Managing Director, President…watch out for job titles
7. November 2022

If you comb through business portals such as LinkedIn or the imprint content of many websites, you will find numerous...

Read moreDetails

What should be considered when running sweepstakes on social media?

What should be considered when running sweepstakes on social media?
7. November 2022

Sweepstakes on social media are a great way to build customer loyalty or even to grow your own social media...

Read moreDetails

Hangover is a disease? Attention to advertising statements

Manufacturer’s information when applying for electrical appliances
24. September 2019

A hangover is a disease. Advertising statements that a dietary supplement is intended to prevent or reduce its consequences for...

Read moreDetails

Artificial intelligence (AI) for process automation

341a2ee477801be4d12fc33c1120d10e
4. July 2024

The introduction of artificial intelligence (AI) into business processes offers enormous opportunities to increase efficiency and competitiveness, but also presents...

Read moreDetails

Drafting contracts for SaaS companies: Tips from an IT law expert

Drafting contracts for SaaS companies: Tips from an IT law expert
10. October 2024

Software as a Service (SaaS) has established itself as the dominant business model in the IT industry. For SaaS companies,...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024

In this exciting episode of the itmedialaw.com podcast, we take a deep dive into the highly topical subject of digital...

Read moreDetails
4f3597d5481e0f38e37bf80eaad208c7

The IT Media Law Podcast. Episode No. 1: What is this actually about?

26. August 2024
fcb134a2b3cfec5d256cf9742ecef1cd

The unconventional lawyer: a nerd in the service of the law

26. September 2024
8ffe8f2a4228de20d20238899b3d922e

Web3, blockchain and law – a critical review

26. September 2024
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung