Cloudflare AI Gateway
GDPR Compliance
Data Handling
Cloudflare documents EU data-localization controls for metadata/logs via Customer Metadata Boundary, which can keep Customer Logs in the EU. However, AI Gateway also uses third-party AI Gateway sub-processors located in the United States and OpenAI is described as operating servers globally, so EU-only processing for AI Gateway inference is not guaranteed from the cited primary sources.
AI Gateway logs are enabled by default and persist until the customer deletes older logs or disables logging; storage is capped by plan limits (for example 100,000 logs on Workers Free across all gateways and 10,000,000 logs per gateway on Workers Paid). Customers can opt out of log collection at the gateway level or per request.
Cloudflare's Workers AI data-usage documentation states Cloudflare does not use customer content to train AI models or improve Cloudflare or third-party services without explicit consent. AI Gateway documentation states prompts/responses may be logged by default for observability, with logging configurable or disabled.
Certifications & EU AI Act
Cloudflare states it is fully committed to developing AI-powered products in ways that align with the EU AI Act, says it does not provide high-risk AI systems, and says GPAI models offered on Workers AI are provided by third parties responsible for their own AI Act compliance.
Verification
- https://developers.cloudflare.com/ai-gateway/ ↗
- https://developers.cloudflare.com/ai-gateway/reference/pricing/ ↗
- https://developers.cloudflare.com/ai-gateway/observability/logging/ ↗
- https://developers.cloudflare.com/ai-gateway/reference/limits/ ↗
- https://developers.cloudflare.com/workers-ai/platform/data-usage/ ↗
- https://developers.cloudflare.com/data-localization/metadata-boundary/ ↗
- https://developers.cloudflare.com/data-localization/metadata-boundary/logpush-datasets/ ↗
- https://www.cloudflare.com/privacypolicy/ ↗
- https://www.cloudflare.com/cloudflare-customer-dpa/ ↗
- https://www.cloudflare.com/gdpr/subprocessors/ ↗
- https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/ ↗
- https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/ ↗
- https://www.cloudflare.com/trust-hub/gdpr/ ↗
- https://www.cloudflare.com/trust-hub/responsible-ai/ ↗
- https://www.cloudflare.com/trust-hub/compliance-resources/eu-cloud-code-of-conduct/ ↗
Cloudflare provides a public DPA, public sub-processor disclosures, SCC-based transfer language, and documented EU metadata-localization controls. For AI Gateway specifically, the cited primary sources do not guarantee EU-only inference processing, and listed AI Gateway sub-processors include U.S.-based providers, so EU companies should treat inference-related cross-border transfers as possible.