INTEGRITY Cloudflare Docs

Manage PII

Cloudflare Gateway gives you multiple ways to safely handle your employees' personally identifiable information (PII) in activity logs:

Only the Super Administrator can assign roles and determine who has permission to view PII. To add or remove the Cloudflare Zero Trust PII role for a user in your organization, refer to Roles.

Types of PII

Cloudflare Gateway can log the following types of PII:

Exclude PII

When you exclude PII, Gateway logs activity without storing any employee PII. This differs from the default redaction behavior — excluded PII is not stored and cannot be retrieved by any role, including the Super Administrator.

Changes to this setting do not affect PII already stored in previous logs.

To turn on the setting to exclude PII:

  1. In Cloudflare One, go to Traffic policies > Traffic settings.
  2. In Traffic logging, turn on Exclude personally identifiable information (PII) from logs.