The infrastructure company Cloudflare — 803 requests, 9 nodes, an 88-second recording, seven of the nodes being Cloudflare's own infrastructure. Beyond it, no data goes out in this recording: there are no requests to Google Analytics or advertising recipients. The consent mechanism — OneTrust — is present and self-hosted on the first party. The only third-party node, Google Tag Manager, loads in health-check mode and pulls in no tags. Security headers are set in a full set. No violations were recorded.
Timeline of the leak
Declared versus actual
Transfer timings
OneTrust self-hosted on Cloudflare's infrastructure, 26 requests.
Cloudflare's own performance measurement.
Container GTM-NDGPDFZ in health-check mode gtg_health=1; pulled in no tags.
Recording of consent by the OneTrust platform.
Cloudflare Turnstile, fires on submission of the contact form.
Detected trackers
- OneTrust (ot.www.cloudflare.com, cdn.cookielaw.org, privacyportal.onetrust.com) — consent-management platform, self-hosted on the first party, records consent
- Google Tag Manager (www.googletagmanager.com, container GTM-NDGPDFZ) — loader in health-check mode (gtg_health=1), pulled in no tags in the recording
- Cloudflare Insights (static.cloudflareinsights.com) — own performance measurement
- Cloudflare Turnstile (challenges.cloudflare.com) — own check in place of a CAPTCHA, fires on form submission
Context
www.cloudflare.com is the site of Cloudflare, Inc., a provider of content-delivery, security and cloud infrastructure. The controller in the policy is Cloudflare, Inc. The site is served through Cloudflare’s own infrastructure (cf-ray, server: cloudflare).
The recording: 803 requests, 9 nodes, a recording length of 88.2 seconds, taken on 16 August 2026. Of the nine nodes, seven belong to Cloudflare’s own infrastructure: the main domain, the subdomain of the self-hosted consent platform ot.www.cloudflare.com, challenges.cloudflare.com and brunhild.challenges.cloudflare.com (Turnstile), static.cloudflareinsights.com, cdn.cookielaw.org (OneTrust resources). There are two third-party nodes: Google Tag Manager and privacyportal.onetrust.com — the OneTrust consent-recording endpoint. The session runs across the plans, contact-enterprise-sales, sase pages and the privacy-policy page.
The processing of the site side is described by Cloudflare’s cookie policy, last updated 19 October 2023.
Who receives data directly
Beyond Cloudflare’s infrastructure — only Google Tag Manager (a loader, without tags) and the OneTrust consent-recording endpoint.
Declared versus actual
The policy discloses analytics and advertising technologies. Unlike the typical discrepancy, here the document names the recipients directly. The cookie policy lists four categories and describes Google Analytics and Google Tag Manager by name, with the purpose “tracks user behaviour”, provides Bizible and Demandbase, and for each technology gives an opt-out link. Separately it describes the own Zaraz product, which loads third-party tools on the Cloudflare-network side rather than in the user’s browser.
The actual composition of requests is narrower than what is declared. In this recording, of the analytics and advertising technologies named in the policy only the Google Tag Manager loader fired, and that in health-check mode (gtg_health=1), and it pulled in not a single tag. No requests to Google Analytics, to advertising or other third-party recipients were recorded across 803 requests. That is, the site’s actual behaviour at the moment of the recording is more modest than what the policy permits.
The consent mechanism is present and self-hosted. OneTrust is loaded from the markup in the first seconds, delivering the banner SDK and the consent settings from the subdomain ot.www.cloudflare.com, that is, from the first party rather than from an external OneTrust domain. The consent record goes to privacyportal.onetrust.com at +5779 ms. Choice management is placed in the site footer via the “Cookie Preferences” link (in the United States, “Your Privacy Choices”), as declared in the policy.
Security headers are set in a full set. The site sets strict transport with subdomain inclusion, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban, the referrer policy strict-origin-when-cross-origin, a permissions policy banning geolocation, camera and microphone, and a content-security-policy. This is the fullest set among the sites analysed.
The form check is on the own infrastructure. On submission of the contact form, Cloudflare Turnstile (challenges.cloudflare.com) fires — an own check in place of a third-party CAPTCHA, so the check data does not go to an external provider.
Consent: what is proven and what is not
Proven: the consent mechanism is present and works on the first party. The OneTrust requests are read from the recording: the SDK stub, the consent settings, the banner SDK — all from ot.www.cloudflare.com. The consent record goes to the OneTrust endpoint at +5779 ms.
Proven: there are no third-party analytics or advertising transmissions in the recording. Across 803 requests not a single request to Google Analytics or advertising recipients was recorded. The only third-party loader, Google Tag Manager, works in health-check mode and pulls in no tags.
Noted: the Google Tag Manager loader precedes the consent record. The request to googletagmanager.com goes out at +2173 ms, the consent record at +5779 ms. The loader, however, carries the health-check marker gtg_health=1 and transmits no analytics data. As a standalone violation this is not recorded, since no data transmission followed the loader; it is noted as the only place where a third-party script is initiated before consent is recorded.
Not proven and not asserted: the behaviour of the tags with consent given. Which tags the Google Tag Manager container would have loaded with active consent to analytics or targeting cookies is not established from this recording — at the moment of capture it did not load them. The policy permits Google Analytics and other technologies, but the recording contains no actual firing of them.
Not proven and not asserted: the state of cookies on the device. Cookie headers and response bodies were removed from the published file during sanitisation.
Separately: the browser was sending the DNT: 1 header during capture. This had no effect on the composition and addressing of the requests.
Boundaries of observation
The recording covers several pages of the site, including the contact form and the privacy-policy page. The observation records the browser’s behaviour, not the services’ internal workings: server-side processing, contractual relationships with recipients and settings on their side are not verified by a browser recording.
Two levels should be distinguished separately. This analysis concerns the behaviour of the site www.cloudflare.com as the operator of its own web resource. Cloudflare’s role as an infrastructure provider for other sites — the content-delivery network, the _cf_bm and _cfuvid cookies, the serving of third-party content — is a separate level of processing in the capacity of a processor for third-party operators, and it is not assessed by this recording of the own site.
The file is published sanitised of personal data: cookie headers in requests, response bodies and the body of the OneTrust consent record were removed. The conclusion about the absence of third-party transmissions rests on the network level — the composition, addresses and initiators of all 803 requests are read from the recording, and among them there are no requests to analytics or advertising recipients beyond Cloudflare’s infrastructure.
The identification of services rests on domains and address patterns: OneTrust — by onetrust.com, cookielaw.org and the paths ot/scripttemplates, consentreceipts; Google Tag Manager — by googletagmanager.com and the gtg_health marker; Cloudflare Insights — by cloudflareinsights.com; Turnstile — by challenges.cloudflare.com; the serving provider — by the cf-ray and server: cloudflare headers.
Conclusion
On Cloudflare’s own site, at the moment of the recording, no data goes beyond the company’s infrastructure: there are no requests to Google Analytics or advertising recipients, and the only third-party loader — Google Tag Manager — works in health-check mode and pulls in not a single tag. The OneTrust consent mechanism is present, self-hosted on the first party, and records consent. The cookie policy discloses the analytics and advertising technologies by name, with opt-out mechanisms. Security headers are set in a full set, and the form check runs on the own Turnstile.
The only point worth attention is the Google Tag Manager loader, which is initiated before consent is recorded; however, it carries the health-check marker and transmits no data, so it is not recorded as a violation. On the results of the recording, no violations were recorded.
The analysis concerns the behaviour of the Cloudflare site as the operator of its own resource and does not assess Cloudflare’s role as an infrastructure provider for other sites — that is a separate level of processing requiring separate consideration.
977d3a3a26d37110c68338ba714ac9bff2b494c91a535862c5371c5e7eac4313