The DPO approves French hosting "100% EU". Engineering then enables Cloudflare for cache and DDoS protection — no DPA, no region restriction, logs visible from the US dashboard. Production residency is European; the edge layer is not.
European residency is a promise on the full processing chain. CDN, managed WAF, or global load balancer redistribute copies, logs, and sometimes request bodies — often forgotten in the register.
Prod → edge → logs chain
| Link | Typical data | Residency question |
|---|---|---|
| Origin (EU host) | Files, HTML, API | Documented DC |
| CDN edge | Cache, visitor IP | POP outside EEA? |
| CDN logs | IP, URL, UA | Retention where? |
| WAF / bot fight | Blocked requests | US processor? |
| CDN support | Tickets with logs | Global access |
Frame CDN under GDPR
Sign DPA with CDN provider. Restrict regions if available (EU PoPs only). Minimise logs: retention, IP anonymisation. Update register: CDN = processor distinct from host. Run transfer analysis if entity or logs outside EEA — see Schrems II.
Some hosts integrate European CDN — verify whether logs stay with them or a third party.
Scenario A vs B
Scenario A — Strict EU: EU origin plus CDN with contractual EU PoPs plus EU logs plus no US support. Edge cost and performance sometimes lower — assumed choice.
Scenario B — Framed global performance: global CDN plus SCCs plus supplementary measures plus documented DPIA. Heavier legally; acceptable if justified.
Cross-check cookie consent CDN if tracking coupled.
The climax: EU promise stops at first CNAME
That is the gap in copy-pasted privacy policies: origin ≠ user journey.
Decide and move forward without blind spots
First inventory all CNAMEs and proxies in front of origin. Sign CDN DPA and configure EU-only mode if required. Update register and privacy policy accordingly. Test headers and DNS resolution to see where edge actually responds. Finally compare European CDNs via the directory and compare tool.
Frequently asked questions
CDN invalidates EU residency?
Can create transfers and processing outside EEA — analyse DPA, enabled regions, log content.
What metadata does CDN see?
IP, URLs, headers, possible cookies, user agent, security logs — often personal data.
Limit CDN to EU?
Possible on some offers — verify contract and config, not defaults.
EU host + free Cloudflare?
Possible with DPA, SCCs, EU config — never automatic or exempt from Schrems analysis.
Trace the CNAME before signing the "100% European" promise — that is often where logs leave.
