English
consentglass · GDPR scanner for websites

HomeGuides › Service

Using Cloudflare Web Analytics in a GDPR-compliant way

Cloudflare Web Analytics measures page views via a small beacon script (static.cloudflareinsights.com), without setting cookies and without client-side fingerprinting. Cloudflare Inc. is based in the USA.

Cloudflare Web Analytics differs technically from Google Analytics quite clearly: there is no client identifier, no cookies and no cross-device merging. The counting of "visits" happens server-side based on the referrer and a short-lived, non-persistent signal. This removes the main argument for the consent requirement — access to information stored on the device does not take place.

The debate therefore shifts to two levels. First, the third-country transfer: even a cookie-free beacon is loaded from a Cloudflare server, which transmits the visitor's IP address to Cloudflare (USA). Cloudflare is certified under the Data Privacy Framework, so the transfer is generally covered; it still belongs in the privacy policy. Second, the legal basis for the processing itself — here the legitimate interest in data-minimising audience measurement usually holds, which should be recorded in a short balancing test.

In practice this means: anyone running Cloudflare Web Analytics in cookie-free default mode can in many cases do without a consent banner for this tool — provided there are no other consent-requiring services on the page. As soon as Google Fonts from Google, a YouTube embed or marketing pixels also run, the page needs a banner anyway, and then it is cleaner to include the analytics too.

Is this a risk?

Because no cookie is set and no identifier is read from the device, the core process is, on the prevailing interpretation, not subject to consent under § 25 (1) TDDDG. Two check points remain: the beacon script and the aggregated data run via Cloudflare in the USA — this transfer needs a basis. And a legitimate interest under Art. 6 (1)(f) GDPR must be documented for processing the (aggregated, but derived from IP and user agent) data.

What you can do

Häufige Fragen

Does Cloudflare Web Analytics need a cookie banner?
In cookie-free default operation, on the prevailing view, no, because there is no access to information stored on the device. The US transfer and the balancing test still have to be documented.
How does it differ from Cloudflare bot management?
Bot management (including the __cf_bm cookie) serves security and is usually technically necessary. Web Analytics is a separate product for audience measurement; only this one is meant here.
Is the transfer to Cloudflare in the USA permitted?
Cloudflare Inc. is certified under the EU-US Data Privacy Framework, which generally covers the transfer. The privacy policy must name Cloudflare as recipient and the transfer.
Is legitimate interest enough as a legal basis?
For data-minimising, aggregated audience measurement without profiling, Art. 6 (1)(f) GDPR usually holds. The balancing test should be briefly recorded in writing, including the option to object.

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.