---
title: "The EU representative position, and Cloudflare's two permissions: Trooth changelog - Trooth"
description: "Trooth now relies on the Article 27(2)(a) exemption instead of appointing an EU representative, with the events that would change that written down, and the Cloudflare connector names the two read permissions it needs."
canonical_url: "https://trooth.co/changelog/2026-09-28-eu-representative-and-cloudflare-permissions"
markdown_url: "https://trooth.co/changelog/2026-09-28-eu-representative-and-cloudflare-permissions.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

[Back to changelog](https://trooth.co/changelog)

Fix

September 28, 20261 minute read

# The EU representative position, and Cloudflare's two permissions

Trooth now relies on the Article 27(2)(a) exemption instead of appointing an EU representative, with the events that would change that written down, and the Cloudflare connector names the two read permissions it needs.

## What changed

Earlier on September 28 the security page said an EU representative would be appointed by November 30, because Trooth's processing of people in the European Union was regular. What Trooth can measure does not show that: two cookie choices from visitors in the European Economic Area, the United Kingdom or Switzerland have been recorded since receipts began on September 27. The security page and the GDPR Compliance Statement now say that no representative is appointed under the exemption in Article 27(2)(a) of the GDPR, which covers occasional processing that includes no special category data and is unlikely to put anyone's rights at risk. A representative is appointed within 30 days of the first customer established in the European Union, or sooner if that processing becomes regular, and the position is reassessed at every quarterly access review. The EU AI Act statement now points to that answer instead of calling it open. The Connector and Read-Only Access Disclosure now lists Cloudflare, with the two permissions its reads need: Zone: Zone: Read and Zone: Zone Settings: Read.

## Why it changed

The EU representative decision earlier the same day rested on processing Trooth does not measure, and the Cloudflare connection form said its permissions were not listed.

## Who is affected

- **Affected:** Anyone reading Trooth's security page or its General Data Protection Regulation (GDPR) statement, and anyone connecting Cloudflare. Nothing a developer calls changed.
- **Availability:** Public. No account needed.
- **Release stage:** Available.
- **Areas:** Legal, Platform.

## What to do

**No action required.** Nothing to do. A Cloudflare connection made with a wider token keeps working.

## Dates

- **Announced:** September 28, 2026, the day this entry was written. Entries are never backdated.
- **Released:** September 28, 2026.

## What this does not fix

The exemption is a judgment on today's processing, not a permanent answer, and it has not been reviewed by counsel.

## Read more

- [Security controls](https://trooth.co/security/controls)
- [Connector and Read-Only Access Disclosure](https://trooth.co/connectors)

On this page

- What changed
- Why it changed
- Who is affected
- What to do
- Dates
- What this does not fix
- Read more

[Fix](https://trooth.co/changelog?type=fix)[Security](https://trooth.co/changelog?type=security)[Legal](https://trooth.co/changelog?area=legal)[Platform](https://trooth.co/changelog?area=platform)

[Back to changelog](https://trooth.co/changelog)

## Related changes

- [SEP.28SecurityRecovery codes, confirmed alerts, and a key policy the verifier followsCompany workspace +2](https://trooth.co/changelog/2026-09-28-recovery-codes-and-confirmed-alerts)
- [SEP.28ImprovementRetention with an end, continuity powers made clear, and production watchedLegal +2](https://trooth.co/changelog/2026-09-28-retention-continuity-and-deploy-controls)
- [SEP.28FixCorrections from the September 28 audit: contract 1, one interface catalog, a complete bill of materialsAPI +5](https://trooth.co/changelog/2026-09-28-fresh-audit-corrections)
- [SEP.28FixA site-wide quality sweep: underlined legal links, keyboard-reachable code, readable small textPlatform +1](https://trooth.co/changelog/2026-09-28-site-wide-quality-sweep)
- [SEP.27ImprovementContinuity, succession and service transition, written downLegal](https://trooth.co/changelog/2026-09-27-continuity-succession-and-transition)
- [SEP.27MethodologyThe two Standards and the About page, rebuilt as referencesMethodology +1](https://trooth.co/changelog/2026-09-27-standards-and-about-page-as-references)

## Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

[RSS](https://trooth.co/changelog/rss.xml)[Legal only](https://trooth.co/changelog/rss.xml?area=legal)[Needs action](https://trooth.co/changelog/rss.xml?action=required)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current Machine-Readable Trust Profile per company, each fact labeled with its source. The part Trooth witnessed is a signed statement whose signature anyone can check later; the company's own declarations are not signed.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth now - it's free!",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Changelog",
      "item": "https://trooth.co/changelog"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "The EU representative position, and Cloudflare's two permissions",
      "item": "https://trooth.co/changelog/2026-09-28-eu-representative-and-cloudflare-permissions"
    }
  ]
}
```
