You deploy a CNIL-compliant CMP: no analytics before consent. Performance goes through Cloudflare US: every request is logged at the edge — IP, URL, TLS fingerprint — before reaching your French origin. The register mentions only the host. CDN DPA: missing.
Cookies and CDN: two layers. The banner covers browser scripts and cookies. The CDN performs edge server processing sometimes invisible to the CMP.
What the CDN processes without visible cookies
Visitor IP, timestamp, requested URL, user agent, response codes, cache hit or miss. Sometimes proprietary cookies (bot fight, edge A/B tests). Purposes: DDoS security, performance, sometimes CDN product analytics.
| Element | Your site | CDN edge |
|---|---|---|
| CMP covers | Page scripts | Not automatic |
| Data | Third-party cookies | IP/URL logs |
| Processor | Host | CDN = separate processor |
| Transfer | EU origin | Edge sometimes US |
Consent, exemption, legitimate interest
Strictly necessary cookies (cart session): exempt — precise limited list. Audience measurement: prior consent under CNIL guidance — not Google Analytics without opt-in. CDN security logs: often legitimate-interest security — document, minimise, limited retention (see log retention).
Choose and document the CDN
Read CDN privacy and cookie policies. Sign DPA and SCCs if transfer. Prefer European edge if possible. Update register and banner with explicit third-party mention.
The climax: the visit starts at the CDN, not your PHP
Decide and move forward without blind spots
First list CDN, fonts, analytics, and tag managers. Inspect third-party requests before and after consent with developer tools. Sign DPA and run transfer analysis for US CDN, or migrate to EU edge. Align with transfers outside the EU and review guides and the directory.
Frequently asked questions
Does a CDN create cookies?
Sometimes; IP and URL logs remain possible and are personal data processed by a separate processor.
Is site consent enough?
No — CDN DPA, legal basis, and user information required. Origin banner does not automatically cover edge processing.
US CDN and GDPR?
SCCs and transfer impact assessment; or European CDN and edge if strict residency is required.
How to audit?
Network tab, CDN policy, DPA, register, test without consent to observe real flows.
The first visit trace is often written at the CDN — your cookie banner should know that as well as your register.
