Cloudflare Web Analytics measures page views via a small beacon script (static.cloudflareinsights.com), without setting cookies and without client-side fingerprinting. Cloudflare Inc. is based in the USA.
Cloudflare Web Analytics differs technically from Google Analytics quite clearly: there is no client identifier, no cookies and no cross-device merging. The counting of "visits" happens server-side based on the referrer and a short-lived, non-persistent signal. This removes the main argument for the consent requirement — access to information stored on the device does not take place.
The debate therefore shifts to two levels. First, the third-country transfer: even a cookie-free beacon is loaded from a Cloudflare server, which transmits the visitor's IP address to Cloudflare (USA). Cloudflare is certified under the Data Privacy Framework, so the transfer is generally covered; it still belongs in the privacy policy. Second, the legal basis for the processing itself — here the legitimate interest in data-minimising audience measurement usually holds, which should be recorded in a short balancing test.
In practice this means: anyone running Cloudflare Web Analytics in cookie-free default mode can in many cases do without a consent banner for this tool — provided there are no other consent-requiring services on the page. As soon as Google Fonts from Google, a YouTube embed or marketing pixels also run, the page needs a banner anyway, and then it is cleaner to include the analytics too.
Because no cookie is set and no identifier is read from the device, the core process is, on the prevailing interpretation, not subject to consent under § 25 (1) TDDDG. Two check points remain: the beacon script and the aggregated data run via Cloudflare in the USA — this transfer needs a basis. And a legitimate interest under Art. 6 (1)(f) GDPR must be documented for processing the (aggregated, but derived from IP and user agent) data.
The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.
This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.