PARIS — In a major legal victory for internet infrastructure giant Cloudflare, a panel of three judges at the Paris Judicial Court has decisively rejected a motion by French pay-TV titan Canal+ seeking to impose crippling daily financial penalties of €50,000. Canal+ had attempted to penalize Cloudflare for allegedly failing to fully implement dynamic anti-piracy blocking orders targeting illegal streams of Formula 1 and MotoGP events.
The September 17 ruling offers a critical legal interpretation of the responsibilities held by web infrastructure and transit providers in the ongoing European war against online sports piracy. While French courts have increasingly ordered diverse digital intermediaries—ranging from public DNS resolvers and virtual private networks (VPNs) to content delivery networks (CDNs) and search engines—to restrict access to infringing material, this case illuminates the widening gap between rights holders demanding absolute blocking and the technical realities governing internet architecture.
Executive Overview
Over the past two years, French courts have issued an expanding wave of injunctions designed to stymie illegal sports streaming. Originally directed primarily at traditional Internet Service Providers (ISPs), these judicial orders now capture the foundational layers of the modern web. However, enforcing broad blocking mandates across decentralized network providers has exposed severe technical friction.
The crux of the latest legal battle centered on April 2026 rulings from the Paris Judicial Court, which ordered Cloudflare to block domains linked to illegal Formula 1 and MotoGP broadcasts. Canal+, holding exclusive broadcasting rights for these premier motorsports in France, monitored Cloudflare’s compliance and concluded that the infrastructure company fell drastically short.

Claiming that Cloudflare selectively applied blocking measures exclusively through its Content Delivery Network (CDN) while leaving its ubiquitous 1.1.1.1 public DNS resolver completely untouched, Canal+ hauled Cloudflare back to court. The broadcaster demanded severe financial leverage: a staggering €50,000 per day for every non-compliant site, alongside identical penalties for any future domain flagged by France’s media regulator, Arcom.
Ultimately, the three-judge panel sided with Cloudflare, ruling that the company’s implementation of CDN-level blocks represented a "reasonable and proportionate" measure under European law. The court firmly established that Cloudflare cannot be held universally liable for the fluid, adaptive tactics of pirate operations—such as switching CDNs or spinning up mirror domains—nor can it be forced to compromise the core architectural framework of its public DNS resolver.
Detailed Chronology of the Legal Clash
The Spring Injunctions: F1 and MotoGP
The legal friction originated in April 2026, when the Paris Judicial Court handed down two separate injunctions demanding that Cloudflare block 21 domains associated with unauthorized Formula 1 streams and 16 domains broadcasting illegal MotoGP content.
Significantly, the initial court orders were broad. They did not prescribe a specific technical methodology for how Cloudflare had to execute the blocks; rather, they mandated that access from French territory had to be obstructed "by any effective means." This phrasing left the door open for interpretation regarding which of Cloudflare’s distinct operational arms—its edge CDN or its 1.1.1.1 public DNS resolver—should bear the enforcement burden.

The Escalation: Canal+ Claims Non-Compliance
Dissatisfied with what it observed on the ground, Canal+ returned to the Paris court in May 2026 to request severe daily coercive fines. The broadcaster argued that Cloudflare was deliberately circumventing the spirit of the court’s intent.
According to legal filings summarized by the court, Canal+ alleged that Cloudflare had selectively deployed blocks only via its CDN service. In the case of the Formula 1 domains, Canal+ asserted that this narrow implementation resulted in a mere three out of 21 targeted domains being effectively blocked. A nearly identical compliance rate was claimed for the MotoGP directive, where only three out of 16 domains experienced interference. Furthermore, Canal+ pointed out that even among the few sites initially impeded, two quickly rebounded within a week—one by migrating to an alternative CDN provider and another by routing traffic through newly minted mirror domains.
To compel strict compliance, Canal+ petitioned the court to slap Cloudflare with a €50,000 daily penalty for each non-compliant domain, alongside an automatic €50,000 daily penalty for any additional site flagged to Cloudflare by Arcom, the French audiovisual and digital communication regulatory authority.
The Defense: Technical Constraints and Architectural Realities
In its defense, Cloudflare emphasized insurmountable technical constraints. The company argued that its global public DNS resolver, 1.1.1.1, possesses an architectural design that inherently does not support selective content blocking at the resolver layer without fundamentally undermining its functionality and user trust.

Furthermore, Cloudflare reminded the bench that the original April rulings explicitly granted the company the autonomy to choose which of its services to deploy, provided its actions contributed meaningfully to suppressing copyright infringement. Cloudflare maintained that deploying blocks via its CDN was not only the correct choice under these architectural boundaries but also infinitely more effective at the network edge than manipulating global DNS resolution.
The Court’s Ruling on September 17
On September 17, 2026, the three-judge panel delivered its verdict, dismissing the penalty requests from Canal+ in their entirety and denying a separate request for €20,000 in legal costs.
The court validated Cloudflare’s technical defense on several key fronts:
- Good Faith Efforts: While noting that Cloudflare’s CDN-only approach achieved partial domain coverage, the judges interpreted this implementation as evidence of a genuine, good-faith willingness to assist in combating intellectual property infringement.
- Third-Party Evasion: The panel explicitly absolved Cloudflare of responsibility for pirate operators evading blocks by switching to rival CDNs or deploying mirror sites. The court ruled that policing these subsequent migrations falls squarely on the shoulders of the rights holder, who must petition new intermediaries or report mirrors to Arcom.
- Proportionality and the UPC Telekabel Precedent: Canal+ attempted to leverage the European Court of Justice’s landmark UPC Telekabel Wien ruling, arguing it obligates intermediaries to achieve effective blocking. The Paris court countered that the same ruling only requires intermediaries to take reasonable measures—a threshold the court determined Cloudflare had successfully met.
Supporting Context & Metrics: The 1.1.1.1 Safe Haven
The fallout from this ruling cements a vital precedent: Cloudflare’s widely used 1.1.1.1 public DNS resolver remains entirely block-free in France, preserving the company’s long-standing operational philosophy regarding DNS neutrality.

Cloudflare’s official transparency reports consistently corroborate this stance. In its most recent disclosures, the company reiterated a clear corporate boundary: "To date, Cloudflare has not blocked content through the 1.1.1.1 Public DNS Resolver." This policy remains steadfast despite mounting pressure and formal judicial orders from multiple European jurisdictions, including France and Italy.
+-------------------------------------------------------------------------+
| CLOUDFLARE'S DUAL-TRACK ENFORCEMENT |
+-------------------------------------------------------------------------+
| |
| [1.1.1.1 Public DNS] ------> ARCHITECTURALLY UNTOUCHED |
| |-> Zero content blocks globally |
| |-> Preserves core DNS integrity |
| |
| [Edge CDN Infrastructure] -> ACTIVE GEOGRAPHIC BLOCKING |
| |-> 1,238 domains geoblocked in France |
| (H2 2025 transparency data) |
| |-> Real-time stream mitigation via APIs |
+-------------------------------------------------------------------------+
While the DNS resolver remains untouched, Cloudflare utilizes its CDN network aggressively to comply with geographic restrictions. Transparency figures reveal that Cloudflare geoblocked 1,238 domains in France during the second half of the previous year under a unified court order, following another 662 domains restricted across seven separate orders in the year’s first half.
Official Statements and Industry Strategy
Cloudflare has actively articulated its philosophy directly to European regulators. In a comprehensive submission to the European Commission regarding its Counterfeit and Piracy Watch List consultation, the infrastructure firm made a passionate case against weaponizing global public DNS resolvers for content censorship.
Instead of broad, blunt-force DNS or IP address blocking—which security experts argue can lead to collateral damage and over-blocking—Cloudflare advocates for agile, real-time mitigation protocols tailored for live broadcasts.

"For live content, where speed is crucial, Cloudflare has built real-time mitigation mechanisms that allow vetted rightsholder partners to flag infringing streams," the company informed the European Commission. "When those streams are running through our network, we act on them in seconds."
This proprietary stream-mitigation framework allows verified rights holders to directly flag illicit video streams traversing Cloudflare’s network, resulting in rapid intervention without requiring heavy-handed judicial mandates that target fundamental internet plumbing.
Future Outlook and Broader European Implications
Although Cloudflare has successfully warded off the immediate threat of punitive fines in the Paris Judicial Court, the legal war is far from over. Canal+ retains the right to appeal the September 17 rulings, meaning higher appellate courts in France may yet have the final say on the duties of CDN providers.
Furthermore, Cloudflare is not alone in navigating this hostile judicial landscape. Non-profit public DNS resolver Quad9 faces a similarly aggressive and potentially existential legal challenge in France. Pay-TV giant beIN Sports has pursued Quad9 with multi-thousand-euro daily penalty requests—pegged at up to €580,000 a day in parallel proceedings—for refusing to institute pirate content blocks on its 9.9.9.9 DNS resolver. The Paris court’s impending decision on the Quad9 case will serve as a crucial bellwether for independent, non-commercial infrastructure providers operating within European borders.

As European courts grapple with the reality of dynamic sports piracy, the legal dividing line between reasonable technological cooperation and impossible regulatory burden is becoming sharply defined. For now, Cloudflare’s victory establishes that while internet intermediaries must assist rights holders where technically feasible, they cannot be financially penalized for the inherent limitations of their infrastructure or the relentless adaptability of online pirates.
