data-protection

4 posts

cloudflare

Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver (opens in new tab)

Cloudflare reports that an independent Big Four accounting firm has confirmed its 1.1.1.1 public DNS resolver continues to meet its privacy commitments. The review was conducted because Cloudflare’s DNS infrastructure has expanded and become more complex since the previous examination in 2020. Cloudflare says it aims to make privacy the default and encourages other public DNS providers to undergo similar independent reviews. ## Renewed Independent Privacy Examination - Cloudflare launched 1.1.1.1 in 2018 as a fast, privacy-focused DNS resolver. - A first independent review took place in 2020. - After major changes to its technology stack and DNS platform, Cloudflare commissioned the same accounting firm to conduct another examination. - The latest review examined evidence collected after the 2024 calendar year and took several months to complete. - The resulting report is available through Cloudflare’s compliance resources. ## Confirmed Privacy Commitments The examination confirmed that: - Cloudflare does not sell or share public resolver users’ personal data with third parties. - Resolver data is not used to target users with advertisements. - Cloudflare retains or uses the requested DNS information, rather than information identifying the person making the request. - Source IP addresses are anonymized and deleted within 25 hours. - DNS query information is not combined with other Cloudflare or third-party data in a way that could identify individual users. ## Limited Network Troubleshooting Data - Cloudflare may use randomly sampled network packets for troubleshooting and attack mitigation. - These samples represent no more than 0.05% of total traffic. - The samples can include the querying IP address, but are used solely for operational security and network reliability purposes. ## Scope of the Latest Review - Unlike the broader 2020 examination, the latest review focused exclusively on privacy commitments. - The earlier review also covered how Cloudflare handled anonymized transaction and debug logs, known as “Public Resolver Logs.” - Cloudflare says the use of those logs has evolved, including supporting services such as Cloudflare Radar. - The company maintains that these changes do not affect personal information or user privacy. Cloudflare’s practical position is that 1.1.1.1 users should not have to trust privacy promises alone: independent examinations should verify them. It recommends reviewing the published accountant’s report and continues to present 1.1.1.1 as a privacy-first DNS option.

discord

Getting Global Age Assurance Right: What We Got Wrong and What's Changing (opens in new tab)

Discord’s CTO says the company mishandled communication around its global age-assurance rollout, leading users to believe that face scans or ID uploads would be required for everyone. Discord’s stated goal is to protect teens and restrict age-sensitive content while preserving the normal experience for most users and avoiding collection of users’ identities. The company plans to use internal signals for most age determinations and privacy-focused third-party verification only when necessary. ## Where Discord Says It Fell Short - Discord did not clearly explain how age assurance would work or who would be affected. - Many users mistakenly believed that everyone would need to submit a face scan or government ID. - The company acknowledges that skepticism about technology companies collecting personal data is justified. - Discord says the rollout was not intended to create a pretext for gathering more personal information. ## The Goal of Age-Appropriate Experiences - More than 90% of users are expected to continue using Discord without verifying their age. - Discord wants teenagers to receive stronger safeguards while allowing adults to access the full range of content. - The approach is being influenced by laws already taking effect in the UK and Australia, with Brazil, Europe, and several US states following. - Discord says building its own system could demonstrate that age can be verified without identifying users. ## Internal Age Determination - Discord’s systems may determine age using account-level signals, including: - Account age - Whether a payment method is attached - Server membership patterns - General account activity - The system will not read private messages, analyze conversations, or inspect posted content. - Discord compares this process to existing safety systems used to detect spam, raids, and coordinated abuse. - The company plans to publish its methodology before the global launch. ## What Happens If Verification Is Required - Fewer than 10% of users are expected to need additional verification. - Users who do not verify can keep: - Their accounts - Servers - Friends lists - Direct messages - Voice chat access - They will only lose access to age-restricted content and the ability to change certain default safety settings intended to protect teens. - A user’s age group will remain private and will not be visible to other Discord users. ## Third-Party Verification Partners - Discord plans to use vendors when its internal systems cannot confirm that a user is an adult. - Vendors are intended to return only an age group, not the user’s identity. - Discord says vendors cannot connect verification information back to a Discord account, and Discord cannot use the process to learn the user’s identity. - Partners undergo security and privacy reviews, contractual data-use restrictions, and retention and deletion requirements. - Verification data is generally deleted immediately after it is no longer needed. - Discord clarified that the vendor involved in a previous customer-service security incident is not used for age assurance and is no longer a partner. - The company tested Persona in the UK in January but decided not to proceed with that vendor. Discord’s revised approach emphasizes minimal data collection, multiple verification choices, and transparency about how age estimation works. Publishing the methodology and clearly explaining vendor safeguards will be essential to rebuilding user trust.

figma

EU Hosting for Figma and FigJam Files | Figma Blog (opens in new tab)

Figma announced EU hosting for Figma and FigJam file data, giving European organizations more control over data location while retaining the benefits of its cloud platform. The service is intended to address regional privacy and regulatory concerns and is available exclusively to Enterprise customers. File contents are hosted primarily in Frankfurt, with backups in Dublin, though some metadata, login information, and temporary in-transit data remain outside the EU. ## EU Data Hosting Availability - Customers can host the document contents of Figma and FigJam files within the EU. - The option is available only on Figma’s Enterprise plan. - Existing customers can migrate files from the US after upgrading to Enterprise. - Account managers coordinate migration dates, and eligible customers can join a migration waitlist. ## Hosting Locations and Infrastructure - Primary file storage is located in Frankfurt, Germany. - Backup data is stored in Dublin, Republic of Ireland. - Figma uses AWS as its cloud infrastructure provider. ## Data Included and Excluded - EU hosting initially covers the contents of supported Figma and FigJam files. - User metadata and login data are not hosted within the EU. - Some data moving through Figma’s systems may be temporarily stored outside the EU. - Customers should consult Figma’s file-type breakdown to determine which data is covered. ## Security and Compliance Figma positions EU hosting as an addition to its existing security and privacy measures, including: - SOC 2 Type II reporting - ISO 27018 and ISO 27001 certifications - Level 2 adherence to the EU Cloud Code of Conduct The feature is particularly relevant to organizations such as Volkswagen Group, which require stronger control over data residency for regulatory and data-protection reasons. Organizations with strict EU residency requirements should evaluate which data types are covered and consider Figma Enterprise for localized file hosting.

figma

Designing in the cloud with confidence | Figma Blog (opens in new tab)

Figma’s post announces that it has received the EU Cloud Code of Conduct compliance mark, making it one of only 17 companies to earn the designation at the time. The certification signals that Figma’s privacy and security practices have been independently validated against GDPR-related cloud data protection standards. Figma presents this as reassurance for global teams, particularly organizations operating in or expanding into Europe. ## Commitment to Global, Secure Collaboration - Figma says scaling design work across regions requires a reliable and trustworthy product. - Its international strategy includes: - Building features for users around the world - Expanding its global presence - Protecting customers’ design intellectual property - Meeting regional security and compliance requirements - The company emphasizes transparency around its security practices and track record. ## EU Cloud Code of Conduct Compliance - Figma became one of only 17 companies to receive the EU Cloud Code of Conduct compliance mark. - The Code is described as a leading European standard for cloud data protection. - The mark indicates that Figma has established processes intended to handle user data in compliance with the EU’s General Data Protection Regulation (GDPR). - Figma’s privacy and security policies were validated by SCOPE Europe, the accredited monitoring body for the Code. ## What It Means for Customers - Figma users can have greater confidence that their design data is handled according to recognized security standards. - European organizations and companies planning international expansion can use Figma with clearer assurance about its compliance posture. - The company directs readers to the EU Cloud Code of Conduct and its broader security documentation for more information. Figma’s practical message is that customers can continue using its cloud-based design platform with increased confidence in its European data protection and security controls.