This blogpost, although very long, is a very simplified summary of the legal wranglings about an order placed on Cloudflare to block access to sanctioned Russian outlets for users of its DNS service in France.
On 15 July 2026, France’s Council of State (Conseil d’Etat) dismissed Cloudflare’s challenge against a blocking order. The order had been previously issued by Arcom, the country’s audiovisual and digital media regulator, under the sanction regimes of the European Union against Russia.
This ruling is important because it establishes that EU sanctions can be enforced on the providers of internet infrastructure, not just on the platform or the publisher, based on open-ended blocking orders.
One could take the view that the ruling is welcome, as it overcomes a potential barrier to court-imposed obligations to force respect for sanctions.
One could equally take the view that forcing a smaller DNS provider (Cloudflare is a comparatively small provider in France for DNS resolution services, which it offers alongside its content delivery and security services) to impose a flawed solution (DNS blocking), in one Member State, is of limited practical value (it is easy to circumvent, even accidentally, and only impacts the small proportion of the French population that uses Cloudflare for DNS resolution). As it makes it seem that something meaningful is being done, it could also undermine efforts to implement more holistic solutions.
What Cloudflare was asked to do
The French audiovisual and digital media regulator Arcom identified 19 web addresses that were deemed to be spreading materials emanating from Russian media entities placed under European sanctions list against Russia, namely those included in the sanctions list according to Council Regulations (EU) 833/2014 (EU) 269/2014, (EU) 2022/350.
On 9 July 2025, Arcom issued a notification requiring Cloudflare to implement “appropriate measures for preventing access to those services on French territory” within 72 hours and maintain such blocking until the removal of sanctions by the Council of the European Union. In practice, it involved implementing a domain blocking policy in France. This runs very strongly contrary to Cloudflare’s policies on this topic, which it lay out in detail in its 2025 transparency report. The order was different from other content blocking orders it received in France, which it implemented via geo-blocking of French-users from the content in question.
Which part of Cloudflare received the order
Notice was addressed to Cloudflare Portugal, Unipessoal Lda, based in Lisbon. This is the legal representative of Cloudflare in the EU according to Article 13 of the Digital Services Act (DSA). The law actually applied in this case is not the DSA, but French national law (Article 11(II) of the 2004 LCEN) and EU regulations (833/2014, 269/2014 and 2022/350).
What Cloudflare argued
Cloudflare’s argument is based on different legal bases.
First of all, it asked to refer the case to the Court of Justice of the European Union (CJEU). More specifically, it argued that Article 9 of the DSA (orders to act against illegal content) should be read in together with the Charter of Fundamental Rights, namely Articles 16 (freedom to conduct a business) and 52 (general provision on limitations of rights). Read this way, these provisions preclude national authorities from imposing:
- a blocking order framed as an obligation to achieve a result without specifying the means
- an obligation to apply any means to prevent access, when (i) there is an easy way to bypass the measures through other providers, (ii) no measures have been applied to the actual publishers/hosts of the content, and (iii) compliance would require restructuring of its service architecture.
In addition, Cloudflare also argued that Article 16 of the Charter of Fundamental Rights (freedom to conduct a business) was endangered. It claimed it would be an excessive measure for it to have to take measures to modify its DNS network infrastructure to put the block in place, as well as a threat to the quality of the service.
To demonstrate that, Cloudflare relied on Article 52 of the Charter of Fundamental Rights (the provision defining when a limitation on the Charter of Fundamental Rights is permissible). Their assessment was that this limitation of their rights under the Charter’s Article 16 did not pass the three-step test of being provided for by [predictable and clear] law, not interfering with the essence of the freedom, and being necessary and proportional to a goal of general public interest in the European Union.
Furthermore, Cloudflare brought forward three procedural objections with regards to the adoption of Arcom’s decision. First, it objected that the decision was insufficiently reasoned, failing to disclose the factual background of the case as well as confirming the meeting of legal conditions. Second, it argued the decision was taken through an irregular procedure, since it was made without giving Cloudflare an opportunity to express their point of view and therefore violated Article L. 122-1 of the Code on Relations between the Public and the Administration. Third, it argued that Arcom should have sent warnings to the publishers or the hosts of the content, before the issuance of the blocking order to the infrastructure provider.
The Court’s Decision
On Article 9 DSA and request for a CJEU referral: rejected
According to the Court, Article 9(2) DSA merely establishes procedural minimums for the order after its issuance on the basis of other laws (whether Union or national). Therefore, it ruled that the decision by Arcom already met all these procedural requirements (citing legal basis, stating reasons, identifying the authority that issued the decision, giving information about redress available). As there was no longer any question of a “serious difficulty of interpretation” of EU law, the Court did not refer the matter to the CJEU but decided it directly pursuant to acte clair doctrine. This broadly seems like a legally solid assessment.
On Article 16 (freedom to conduct a business): rejected
According to the Court, French law gave Cloudflare complete discretion as to how to comply. Any penalty for not complying would have to be imposed through a procedure consistent with principles of proportionality. And crucially, the evidence showed that there could not possibly be an excessive burden involved, since Cloudflare already provides such blocking capabilities for free (for malware, certain pornographic content and geo-blocking) and other DNS/access providers (including the largest one) were able to comply without difficulty. This is more tenuous legally – making a voluntary best effort for different kinds of content does not automatically mean that a legal obligation, with no criteria for what constitutes success or failure is proportionate. For example, nobody wants to access malware, so circumvention of the block is not an issue, while some people do want to access sanctioned material, so ease of circumvention of the block is an issue.
On Article 52 (proportionality): rejected
The Court applied the usual three-part test:
- Provided for by law: The limitation is justified by the French national law (Article 11(II) LCEN), and by EU Regulations 833/2014, 269/2014 and 2022/350; This seems legally weak – telling Cloudflare to do something, in the hope that the something that it has done will be considered to be enough, seems to be fundamentally out of line with the notion of being “provided for by law”.
- Legitimate objective of general interest: It aimed at countering propaganda in support of the war against Ukraine, in relation to the safeguarding of the values, the security, the integrity and the public order of the Union. This is unquestionably respected.
- Necessary and proportionate: Considering the room left to providers in applying the measure, the conditions for the imposition of the penalty, and the absence of any less restrictive means to fulfil the legitimate objective, also this last criterion also appears to be respected.
On the procedural objections: rejected
Regarding insufficient reasoning, the Court determined that the decision referred to all the necessary elements: the facts on which the decision was based (the findings made by Arcom on 26 and 27 June 2025), the legal provisions empowering the decision, the executive act implementing those legal provisions, and the relevant EU regulation. Regarding the irregularity of the procedure, the Court stated that there is no need for the notification of the block of a list of addresses to a DNS to be preceded by a prior adversarial phase. Regarding the absence of a prior warning to the publishers of the content, the Court decided that the step is not required when the addresses in question are linked to already sanctioned entities.
The takeaway
This case illustrates the structural deficiency in implementing EU sanctions law : despite there being rules such as Regulation 833/2014 and 269/2014 which automatically prohibit certain activities throughout the whole territory of the Union, there is no uniform way for enforcing these prohibitions and no coordination between national jurisdictions. Each Member State is left to develop their own approach.
The DSA, just like its predecessor, the E-Commerce Directive, establishes a regime of non-liability for technical intermediaries – caching providers (whicth is broadly Cloudflare’s main business), hosting providers, and internet access providers (“mere conduits”) – for illegal content that they unknowingly host or provide access to. It does not, with some exceptions, prohibit or criminalise any particular type of content.
This friction was never meant to be eliminated by the DSA, also not for court orders, as it explicitly stated in Recital 31: “this Regulation does not provide the legal basis for the issuing of such orders, nor does it regulate their territorial scope or cross-border enforcement.” Therefore, there are now up to 27 different national bodies enforcing an identical provision one order at a time. This is precisely the fragmentation Cloudflare pointed to in this case; with some justification, it claimed that it is easy to bypass the measures through providers of other countries. Indeed, with research finding that over one-in-five French internet users avail of VPNs, around a fifth of the population could be circumventing such restrictions without even being aware of the fact.
