• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Can Cloudflare be used permissibly?

7. November 2022
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
security 2168233 1280
Key Facts
  • The Schrems II decision against US SaaS providers is crucial for data protection in Germany.
  • Cloudflare could violate the GDPR if users' personal data is affected.
  • Cologne Higher Regional Court found that Cloudflare is liable for copyright infringements when using temporary DDoS.
  • Data encryption is a key point that Cloudflare mentions in its privacy policy.
  • Zendesk offers extensive encryption standards such as HTTPS/TLS for secure working.
  • It is currently not possible to select the storage location of the data with Cloudflare.
  • The use of Cloudflare should be carefully checked by data protection officers.

The issue of whether US SaaS providers can be used permissibly or whether products such as Jira, Zendesk, various CRM systems and others do not violate data protection law has actually been clear since the ECJ’s Schrems II decision(see here).

As things stand, you can find out how to offer SaaS system as a US provider in Germany in a longer article here.

By the way, this issue affects many popular WordPress plugins and services like Cloudflare. In the case of Cloudflare, it is especially true that the OLG Cologne has just ruled that the provider would be liable for copyright infringement(see this post). Because Cloudflare, at least if you use more than just the services to possibly prevent DDoS attacks, stores the content itself on their servers to provide caching and CDN services. What is not very problematic for a normal website that ONLY provides content, such as a blog or similar (apart from the copyright infringements relevant in the OLG Cologne case), is no longer so unproblematic for dynamic content and personal user data. This would affect, for example, forums, communities, and sites that you can log into. Although a CDN does not log user data as such, it does log the personal data that is entered when using the portal. At least, if the provider does not configure CDN usage properly and excludes dynamic user content.

In all places where Cloudflare’s caching or CND services are used, the storage on whichever Cloudflare servers is used is not only for the transmission of the requested information. However, due to the missing Privacy Shield requirements, this probably leads to the fact that a GDPR-compliant use of Cloudflare is not possible, at least if, as explained above, personal data of the users are affected. This is because a contract processing agreement is out of the question. And as pointed out in my article on offering SaaS services, the strict view is that corporate binding rules or standard contractual clauses are probably not possible either.

It might be possible to fully encrypt all data, as Amazon is apparently currently doing with AWS in the European data centers, but I couldn’t find anything about this at Cloudflare at the moment. The link to the privacy policy there does not work. A closer look reveals an English-language privacy statement that explains that the Privacy Shield is no longer used, but is very vague about the alternatives.

Thus, the only point to the encryption

10. DATA SECURITY, DATA INTEGRITY AND ACCESS

We take all reasonable steps to protect information we receive from you from loss, misuse or unauthorized access, disclosure, alteration and/or destruction. We have put in place appropriate physical, technical and administrative measures to safeguard and secure your information, and we make use of privacy-enhancing technologies such as encryption. If you have any questions about the security of your personal information, you can contact us at privacyquestions@cloudflare.com.

It may be doubted whether this is sufficient for an official data protection officer to scrutinize particularly strictly. Providers such as Zendesk are already much further ahead in this respect from their own testing for clients and regulate, for example:

Data-in-Transit encryption

All communications with Zendesk’s user interfaces and APIs are encrypted using industry-standard HTTPS/TLS (TLS 1.2 or higher) over public networks. This ensures that all traffic between you and Zendesk is secure. For email, we use opportunistic TLS by default. Transport Layer Security (TLS) is a protocol for secure encryption and delivery of email that prevents eavesdropping between mail servers as long as peer services support this protocol. Exceptions to encryption include, but are not limited to, use of product-integrated SMS features and third-party applications, integrations, or services that Subscribers use at their discretion.

 

Data-at-Rest Encryption

Service data is encrypted on AWS using data-at-rest encryption (AES-256).

 

There is also the problem that, as far as I know at the moment, Cloudflare, unlike AWS etc., does not allow you to choose where the data is stored. While a website operator would have to provide this information, he will probably not receive an answer from Cloudflare.

Conclusion: The use of Cloudflare should be well thought through by your own data protection officer.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AmazonBlogCopyright infringementCorporateData protection LawE‑mailInformationMailPortalPrivacySaasServerserviceSicherheitStandard contractual clausesUrheberrecht

Weitere spannende Blogposts

BaFin and the regulation of e-money (including computer games)

BaFin and the regulation of e-money (including computer games)
11. December 2022

What is BaFin? BaFin is the Federal Financial Supervisory Authority and is the German supervisory authority for credit institutions, insurance...

Read moreDetails

Right of withdrawal for NFT purchases?

What is “digital property” and how can I benefit from it?
23. January 2023

Introduction When you purchase a product or service through NFT, you usually have a right of withdrawal. This means that...

Read moreDetails

Website operators are liable for data processing of like buttons

Facebook pages, data protection and August 1, 2019
29. July 2019

At the end of last year, I reported that the Advocate General of the ECJ had recommended that the ECJ...

Read moreDetails

Legal analysis and finding solutions to the DOSB expert opinion on esport

DOSB and Esport: A commentary
28. August 2019

What is it all about? Currently, the report commissioned by the DOSB to assess whether esport can be regarded as...

Read moreDetails

Google must also read emails – imprint obligation

medienrecht
7. November 2022

Anyone offering services on the Internet must provide an imprint in accordance with § 5 of the German Telemedia Act....

Read moreDetails

Amazon can’t just freeze seller funds

Purchased reviews on Amazon
4. July 2019

The District Court of Hildesheim has put a stop to Amazon, by means of an injunction, forbidding its well-known practice...

Read moreDetails

Twitter must not block accounts for no reason

Lupus in Saxonia
14. November 2019

The topic of how US social networks such as Twitter, Facebook or Instagram deal with German law has become increasingly...

Read moreDetails

Frankfurt Regional Court grants repayment claim from gambling losses

Frankfurt Regional Court grants repayment claim from gambling losses
4. January 2023

The Frankfurt am Main Regional Court has issued a very exciting ruling on the question of whether a German gambler...

Read moreDetails

Telecommunications providers and revocation

Telecommunications providers and revocation
7. November 2022

I regularly deal with clients who have issues with their telecom provider, and frankly it's hard to determine which provider...

Read moreDetails
Eigentum an Software – Wem gehört eigentlich der Code?
Copyright

Eigentum an Software – Wem gehört eigentlich der Code?

14. July 2025

Während ich an meinem eigenen WordPress-Plugin code, taucht immer wieder eine Frage auf: Gehört mir diese Software wirklich? Im Alltagsverständnis...

Read moreDetails
Startup ohne Entwickler?

Startup ohne Entwickler?

8. July 2025
Keine stillschweigende AGB-Änderung – Schweigen gilt nicht als Zustimnung

Keine stillschweigende AGB-Änderung – Schweigen gilt nicht als Zustimnung

7. July 2025
So langsam nimmt der Shop Form an

So langsam nimmt der Shop Form an

3. July 2025
Dark Patterns: UX-Tricks im Visier von Gesetzgeber und Gerichten

Dark Patterns: UX-Tricks im Visier von Gesetzgeber und Gerichten

2. July 2025

Podcastfolge

KI im Recht: Chancen, Risiken und Regulierung – der IT Media Law Podcast Episode 3

KI im Recht: Chancen, Risiken und Regulierung – der IT Media Law Podcast Episode 3

28. August 2024

Willkommen zur dritten Episode unseres Podcasts "IT Media Law"! In dieser Folge tauchen wir ein in die faszinierende Welt der...

Read moreDetails
KI im Rechtssystem: Auf dem Weg in eine digitale Zukunft der Justiz

KI im Rechtssystem: Auf dem Weg in eine digitale Zukunft der Justiz

13. October 2024
Rechtliche Risiken bei langen Entwicklungszeiten und der Stornierung von Crowdfundingspielen

Rechtliche Risiken bei langen Entwicklungszeiten und der Stornierung von Crowdfundingspielen

20. April 2025
Juristische Trends für Startups 2025: Chancen und Herausforderungen

Juristische Trends für Startups 2025: Chancen und Herausforderungen

19. April 2025
Digitale Souveränität: Europas Weg in eine selbstbestimmte digitale Zukunft

Digitale Souveränität: Europas Weg in eine selbstbestimmte digitale Zukunft

12. November 2024

Video

Mein transparente Abrechnung

Mein transparente Abrechnung

10. February 2025

In diesem Video rede ich ein wenig über transparente Abrechnung und wie ich kommuniziere, was es kostet, wenn man mit...

Read moreDetails
Faszination zwischen und Recht und Technologie

Faszination zwischen und Recht und Technologie

10. February 2025
Meine zwei größten Herausforderungen sind?

Meine zwei größten Herausforderungen sind?

10. February 2025
Was mich wirklich freut

Was mich wirklich freut

10. February 2025
Was ich an meinem Job liebe!

Was ich an meinem Job liebe!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung