Data Localization Suite

A plain-language configuration guide covering all three components: Regional Services, Customer Metadata Boundary, and Geo Key Manager.

Cliff Notes — in plain English

Data Localization Suite lets a company tell Cloudflare "keep my data in this specific country/region and don't let it leave."

  1. Regional Services — normally Cloudflare processes your website traffic at whichever data center is fastest, anywhere in the world. This setting says "only decrypt and read my traffic inside [France / the EU / the US / wherever I pick]." Traffic from elsewhere gets forwarded there still locked (encrypted) and is only opened once it lands in the approved zone.
  2. Customer Metadata Boundary — this is about the logs, not the live traffic. Cloudflare normally records details like who visited your site and when. This setting says "only store those records in the US" or "only in the EU," instead of wherever's convenient globally.
  3. Geo Key Manager — this is about your website's "master key" (the certificate/private key that makes HTTPS encryption work). Normally that key gets copied to every Cloudflare location worldwide. This setting restricts which countries are even allowed to hold a copy of it.

Who needs this and why: companies operating in Europe (GDPR), government contractors, banks, healthcare, or anyone under a law/contract requiring customer data to stay in a specific country. It's a compliance tool, not a speed booster — it can occasionally make things a bit slower since you're deliberately limiting where things can happen instead of letting Cloudflare pick the fastest option worldwide.

It's also an expensive, Enterprise-only add-on — not something a small business would buy without a specific legal/contractual reason.

Overview Regional Services Customer Metadata Boundary Geo Key Manager Supported Regions

What is the Data Localization Suite?

The Data Localization Suite (DLS) is a collection of three Cloudflare tools that let you control where your traffic is decrypted, where your traffic logs are stored, and where your TLS private keys live — all while still using Cloudflare's global network for performance and security. It exists for organizations that need to comply with data residency regulations, such as GDPR, or that have contractual/regulatory requirements to keep certain data within a specific country or region.

It is an Enterprise-only paid add-on. Each of the three components below is configured and licensed separately — you don't need all three, and most customers start with just one, depending on what their compliance requirement is actually about (traffic processing, log storage, or key storage).

If your requirement is about......use this component
Where HTTPS traffic gets decrypted/inspectedRegional Services
Where request logs and analytics are storedCustomer Metadata Boundary
Where your private TLS/SSL keys are storedGeo Key Manager

Regional Services

Regional Services controls which Cloudflare data centers are allowed to decrypt and process your HTTPS traffic (TLS termination). Traffic is still accepted at any Cloudflare data center worldwide for basic network-layer DDoS protection, but if a request arrives outside your configured region, it's forwarded to your region still encrypted and only decrypted once it reaches an in-region data center. Everything that requires reading decrypted traffic — WAF, Bot Management, Cache, Workers, Load Balancing — only runs inside that region.

This is a compliance control, not a speed optimization — it may add latency in some cases since traffic isn't always routed to the geographically closest data center, only the closest in-region one.

Ways to configure it

There are three ways to apply Regional Services, and most customers only need one, depending on how traffic reaches Cloudflare:

OptionBest for
Regional HostnamesMost deployments — regionalizing specific proxied hostnames (most common)
Regionalized Spectrum ApplicationsTraffic addressed by IP that needs Static IPs or Bring Your Own IP (BYOIP)
Regionalized IP BindingsBroad, self-serve regionalization of whole BYOIP prefixes via API

Configure Regional Hostnames (dashboard) — the most common path

  1. Go to the DNS > Records page in the Cloudflare dashboard for the zone you want to regionalize.
  2. Create (or edit) a DNS record for the hostname you want to regionalize.
  3. From the Region dropdown on that record, select the region you want to use. This applies to all DNS records sharing that same hostname.

After setup, you can confirm traffic is landing in the right region by checking the IngressColoName field in your Zero Trust Network Session logs, which shows the data center where traffic actually entered Cloudflare's network.

Before you start: Regional Services is an Enterprise-only add-on, and DNS Regionalization specifically requires your account team to enable the entitlement first — it isn't self-serve out of the box. Some newly announced regions also require separate approval from Cloudflare, so confirm availability of your target region with your account team.
Good to know: Regionalizing to a single-country region (other than the US) removes Cloudflare's standard automatic failover for that traffic, since it can't fail over to data centers outside the country. Multi-country regions (like the European Union) keep the standard SLA and failover behavior.
Source: Regional Services overview, Regional Hostnames setup

Customer Metadata Boundary (CMB)

CMB controls where your traffic metadata and logs are stored — things like request URLs, timestamps, and firewall events that could identify your end users. It's a simpler, account-wide setting: you choose either the EU or the US as your boundary region, and by default no boundary is applied (logs may be stored anywhere globally).

Configure Customer Metadata Boundary (dashboard)

  1. In the Cloudflare dashboard, go to Settings > Configurations.
  2. Under Customer Metadata Boundary, select the region you want: eu or us. Selecting Global removes any boundary (the default).

To review or change the setting later, go back to Settings > Configurations > Preferences and locate the Customer Metadata Boundary section.

Scope: CMB can currently only be applied at the account level — not per-zone. If you only want it applied to some of the zones in an account, those zones need to be moved to a separate account first. Only SuperAdmin and Admin roles can change this configuration.
Good to know: Once a boundary is set, dashboard analytics and log views are only visible to users whose sessions happen to route to the configured region's core data center — this is based on network routing, not your physical location, so you may see "no data" unexpectedly. If your team needs guaranteed access from anywhere, enable Allow out-of-region access, which keeps the data stored in-region but lets authorized users view it regardless of where their session routes.
Source: Customer Metadata Boundary overview, Get started

Geo Key Manager

Geo Key Manager controls where your private TLS/SSL keys are stored — the cryptographic keys Cloudflare uses to decrypt your HTTPS traffic. By default, keys are encrypted and distributed to every Cloudflare data center for fast local decryption; Geo Key Manager restricts that distribution to specific countries or regions.

Important limitation: Geo Key Manager currently only works with custom (uploaded) certificates — not Cloudflare-managed Universal SSL certificates — and configuration is done entirely through the API for the newer version (v2). There is no v2 dashboard option today.

Version 1 (dashboard-available) — US, EU, or High-Security data centers only

  1. Follow Cloudflare's standard steps to upload a custom certificate.
  2. For Private Key Restriction, choose one of: Distribute to all Cloudflare data centers, US data centers only, EU data centers only, or Highest security data centers only.
  3. Select Upload Custom Certificate to finish.

Version 2 (API only, Closed Beta) — configurable country allow/block lists

V2 lets you define a policy with allow/block lists of specific countries or regions (e.g. "store in the EU and US" or "store in the EU but never France"). You follow the same custom-certificate upload flow via the API, but include a policy parameter on the request instead of the older geo_restrictions parameter (the two are mutually exclusive).

Good to know: If a Cloudflare data center near your visitor doesn't hold your private key, that data center has to request a temporary session key from a data center that does before it can decrypt traffic — this adds latency (up to roughly a second) on the first connection if the key-holding data center is far away.
Source: Geo Key Manager overview, Setup guide

Supported Regions reference

Not every region is available for every DLS component. A few common examples:

RegionGeo Key ManagerRegional ServicesCustomer Metadata Boundary
European Union✅✅✅
United States✅✅✅
United Kingdom✅ (v2 only)✅Uses EU boundary
Canada✅ (v2 only)✅✘
Australia✅ (v2 only)✅✘
FedRAMP Moderate (Domestic)✅ (v2 only)✅✅ (uses US boundary)

Regional Services supports the widest range of regions — including individual countries (Germany, France, Japan, Brazil, and many others), compliance-framework regions (FedRAMP, IRAP Protected, ISO 27001 Certified EU), and even "exclusive of" regions that exclude specific countries rather than restrict to them. Customer Metadata Boundary is limited to just EU or US. Geo Key Manager's country list depends on whether you're using v1 (US/EU/High-Security only) or the v2 Closed Beta (broader country list).

Source: Region support — full list